FREE NEWSLETTER

Forum › Behavior

Can we be completely safe?

This is going to seem dark, but it’s not my intention to scare anyone, but I’ve had an through about our operational security as investors that I can’t shake.

We’re all already doing complex passwords and two-factor authentication, which I completely agree with.  Be as safe as you can.  But how can any of us fully protect against a home invasion type attack where we’re coerced by force to divulge passwords.  Allow me to explain.

Imagine the worst (Heaven forbid, poo, poo, poo).  Criminals invade and take you and your family hostage in your home.  These criminals, however, are not interested in your costume jewelry or even your safe (although they’ll take that too).  These criminals know that you have an account at X bank or Y brokerage (or even if they don’t know, they force you to tell them).

At gun or knife point they force you to login to your accounts and transfer funds to an account of their choosing.  But won’t those transfers take days, you ask?  Even if they do, where are they going?  You’re tied up in the basement and they are living in your house until the transactions clear.

This scenario isn’t pure fantasy.  It has actually happened to very wealthy targets.  But why should this be reserved to the extremely wealthy who even more likely than ordinary people to have robust physical security?

How can this be prevented?  Some might say to hunker down and buy a lot of guns and ammo.  That’s fine, but the truth is no one can be 100% secure.  At some point you’ll leave the house or mow the lawn and you’re exposed.  Bottom line, if someone really wants to get into your house they can.  Heck, they’d probably just ring the doorbell and pretend to be selling siding.

The only thing I can think of would be for financial institutions to permit their customers to enter a dummy password specifically designed for these situations.  When you login, a fake account screen is created and any transactions “made” are not real, but appear completely real to the observer.  Upon login, police can be altered to your location.  I’m not sure if any financial institutions currently offer this or how this idea would go over.

You probably won’t believe me, but I’m actually not a paranoid person or even a worrier, but I’m having trouble seeing why this kind of crime would not become more common.

More On This Topic

Subscribe
Notify of
42 Comments
Newest
Oldest Most Voted
Ormode
2 months ago

The main problem would be picking out the millionaire next door, and distinguishing him from the guy who really is a couple hundred dollars away from being a homeless vagrant.

Criminals don’t even think this way; if they had money, they would flaunt it, so they are looking for people who are flaunting money.

Dunn Werking
2 months ago

The outgoing transfer lock referenced is a great idea. I am going to act on that.
Another time tested approach is ‘security through obscurity”. Avoid the big house and the fancy car even when you can afford it. I saw this in practice growing up in semi rural New England where as it turned out there were quite few closet multi millionaires in our area. Back in those days, the only potential giveaway was they tended to drive rusty Volvos. 🙂

William Perry
2 months ago
Reply to  Dunn Werking

Harry Sit who writes on his blog The Finance Buff recently emailed me a notice about a July 2026 article about outgoing transfer lock at Vanguard and Fidelity.

Mark Eckman
2 months ago
Reply to  William Perry

Fidelity has a simple setting to provide an alert to the Fidelity staff to contact the customer first. Does it work – who knows? Schwab does not have an option and is slow rolling any res ponse to the issue.

The question really is how many of these thefts really occur? As a CPA, I am trained to be skeptical, but at what point is the additional oversight/system/process/armarment worth the cost to prevent the issue? Your best tool is being diligent, use the best tools avialble, guard your accesss tools and enjoy life.

William Perry
2 months ago
Reply to  Mark Eckman

I found the comments to date in reply to Regulatory Notice 26-02 where FINRA requested comment on proposed changes to help member firms protect senior investors from financial exploitation and all investors from fraud informative to me. My take, in a nutshell, is the current tools at some brokers have become inadequate to protect investors from ACATS fraud and their own self regulating body, FINRA, is striving to establish adequate tools to allow investors to protect themself.

Cammer Michael
9 months ago

One example of a gaping hole in 2 factor authentification. If you have Verizon cable TV and cell phones in the same account, which is how you get the discount rate, then you have the same password for everything. Your 2 factor authentification account name and password is the same as what you’d use to sign in to watch HBO from a TV in a hotel room. Beware.

corrupt
2 months ago
Reply to  Cammer Michael

My BIL was a victim of ID theft… They took control of his phone, and resetting all his password’s was impossible since he no longer had a phone to use as the second factor. It took months to straighten out.

robbie dendulk
9 months ago

I really worry about this with AI. I fear it taking over my account and draining it.
It’s one reason I grudgingly pay my .30% to VG for the human/robot assisted Advisor. I don’t like spending that for such a basic five ETF Portfolio but I’ve come to look at it is one more bit of insurance.
I can’t make any Portfolio changes without his concurrence.

Nick Politakis
9 months ago

Thought provoking article. I emailed my Schwab account rep the other day about how to prevent a(n) fraudulent ACATS transfer but have not heard from him. I think most financial institutions are not doing enough to protect their customers

Randy Dobkin
9 months ago
Reply to  Nick Politakis

A recent White Coat Investor podcast talked about ACATS fraud and how it’s hoped Vanguard will be adding a feature like Fidelity’s lockdown.