The risk of sensitive personal data leaks is higher than ever, fueling identity theft, phishing attacks, financial account hijacks, and scams. It’s also a time when nation-backed hackers skillfully target critical infrastructure like mobile networks. A major hack revealed last year led the FBI to advise trusting only end-to-end encrypted communications.
No security is foolproof against a determined attacker, but you can make yourself a harder target. Nancy and I have so far avoided major cybercrimes but have faced fraud attempts.
One stemmed from a non-profit’s security breach that exposed our personal data from background checks. Freezing our credit records avoided a lot of misery.
In the past, many HumbleDollar readers could just avoid the online world and hope for the best. Today, hope is not a plan. Avoiding the online world may now place you at more risk.
Failing to create secure online accounts – like with the IRS or Social Security – only makes it easier for criminals to impersonate you because so much more personal data has become available on the dark web. The National Public Data breach last year was allegedly large and damaging. Troy Hunt’s excellent site will show if you were likely affected.
The IRS, for instance, has a backlog of 470,000 open fraud cases from fake tax returns for fraudulent refunds. Who suffers in situations like this? You do, when you try to file your legitimate tax return after a scammer used your identity, whether you file with paper or electronically. This kind of cybercrime is easier to avoid if you’ve already created an IRS.gov account and secured it well.
Ready to boost your security? Follow this Sweet 16 checklist – an hour a week, and in a month or two, you’ll be far better protected. If tech isn’t your strength, ask a trusted friend or family member for help.
Online Account Security
- Use a Password Manager – Replace weak passwords with strong, unique ones. Apple, Google, and Microsoft offer free built-in managers, while cross-platform options like DashLane work across all major operating systems (OS) and web browsers. Good password managers also simplify digital estate planning.
- Enable Two-Factor Authentication (2FA) – Start with your password manager, then secure critical accounts: your cell phone provider, email, banking, and investments. Email is crucial for password resets, and securing your cellular account helps prevent SIM swap
- Freeze Your Credit – Lock your credit at Equifax, Experian, and TransUnion for free. Temporarily lift a freeze when needed. Store your freeze PIN securely in your password manager or a home safe.
- Freeze ChexSystems Data – Banks use ChexSystems to verify new accounts. A freeze here lowers your risk of bank account hijacking.
- Get an IRS IP PIN – This newer IRS PIN offering differs from e-filing PINs by making it harder to file fraudulent returns. Enroll first in ID.me for identity verification, then activate IP PIN on IRS.gov. A new, unique PIN is generated annually by IRS for filing.
- Secure Your Social Security Account – Create a Login.gov account, then register on SSA.gov to prevent fraudsters from claiming your benefits before you do.
- Upgrade Your 2FA – Move beyond basic SMS/email codes to more secure methods:
- Hardware passkeys like YubiKeys
- Biometric passkeys (FaceID or TouchID)
- Passkeys, or
- An Authenticator app (ensure it has backup/restore capability to avoid lockouts when changing phones)
Device Security
- Install Security Updates Promptly – Update your OS, browser, and apps as soon as updates are available. Security flaws are patched before they become widely known, but once revealed, attackers exploit them within hours.
- Replace Unsupported Devices – If your device no longer receives updates, it’s a security risk. Even hardware has vulnerabilities, and manufacturers release firmware updates to mitigate them. Most devices get 5-7 years of support—when yours stops, upgrade.
Networking Security
- Secure Your Wi-Fi – Enable password protection on your home network. Use a password manager to generate a long, random Wi-Fi password and securely share it with family.
- Change Default Admin Passwords – If you own your router or networking gear, replace the default admin password. If updates aren’t automatic, set a calendar reminder to check for updates twice a year.
- Use Encrypted Communication – Apple and Google encrypt calls/chats only when both parties use the same OS. For highly sensitive conversations, use WhatsApp or Signal for end-to-end encryption.
Avoiding Scams
- Never Click Links in Emails or Texts – Instead, go directly to the official app or website. If the request is legitimate, you’ll find notifications or secure messages there. This prevents attackers from stealing your login credentials.
- Use Call Screening Tools – Enable scam/spam filters on your phone. Cellular providers offer free tools:
- AT&T: Active Armor
- Verizon: Call Filter
- T-Mobile: Scam Shield/Scam Block
- Learn Scam Prevention Tips – AARP offers 25 tips to help members avoid scams.
- Check AARP’s Scam-Tracking Map – Check this free Scam-Tracking Map to see scams in your area. Report your own scam close calls to help others.
Did you just log in? If you don't see the commenting form, please refresh the page.
Looks like iOS 19 may support end-to-end encryption using RCS 3.0 with Android devices, a positive step if true for folks who prefer Apple’s iMessage over 3rd party apps like Signal or WhatsApp:
https://www.macrumors.com/2025/03/15/ios-19-rcs-upgrades/
Beware the innocent looking barcode and QR code. You see them in many ads, etc. offering a fast way to get more information. You really have no idea where it actually takes you once you scan it. A(nother) scam:
Do NOT scan any mystery gift There is apparently a new scam out there and it’s exceptionally dangerous.
Here’s how it works.
Victims receive a mystery package from an unknown party complete with your name, information and official looking packaging from one of the biggies – think Amazon, Walmart etc – and in it there’s a card saying you’ve received a gift. (Read)
But you don’t know who sent it.
So, naturally, the very same note invites you to scan the QR code included at which point everything on your device is compromised… names, contacts, credit cards, accounts, links etc.
Ace analyst Hayley also tells me as I type that a variation of this is being used in England where criminals are putting fake QR codes over the top of legitimate QR codes at car parks. So, it’s a bonus – you get your money stolen and a fine from the authorities.
From, “Five With Fritz”.
A few days after “Hope is not a plan” was posted here, news hit that Bank of America had lost customer data.
I was a Certified Information Systems Security Professional (CISSP) for a while, which is perhaps the cybersecurity equivalent of a CFA in the financial world. I worked in security for Amazon, AOL, MITRE/DoD, and others. A year ago, I retired from Palo Alto Networks which is a large
security-only vendor.
During my second job in security at BankOne (now part of Chase), I entered with the belief that “surely, at a top 5 bank, security is taken seriously for its own sake.” However, I learned that the huge staff-up that I was part of, complete with Ernst & Young consultants flying in weekly from New York, was about checklist compliance.
That’s where started to stop believing.
I later developed an open-source security tool with contributions from a tech director at the NSA and the senior VP of security at Cisco, who is now an angel investor. I also published an Internet “Standard” (IETF RFC), which launched a security working group that has been active for over 20 years, driving international industry security standards.
So, back to “Hope is not a plan.” The list of suggestions is all good, and I thank David for compiling and posting it. Awareness and education are very important parts of cybersecurity. I may add some of them to my personal practices and encourage readers here to do so as well.
Just don’t confuse “doing something” with being secure.
BankOne had a very well-funded security program when I was there, and I’m sure Bank of America is similarly equipped today. The same was probably true for the US Government Office of Personnel Management when it lost sensitive background investigation data for top secret clearances. Equifax lost credit score data on 147 million Americans (almost certainly yours). “And the beat goes on, and the beat goes on…”
Cybersecurity can be a fun hobby. You can make a living at it. It’s essential to get the basics right. However, even with my professional background, I can’t single-handedly fend off all the hackers (and sheer stupidity) out there, especially as I age.
Considering this, transferring risk may be the most rational approach:
– Move my money into a trust
– Allow an investment firm to manage my assets
– Explore insurance options
– Pay a large lump sum to a CCRC and forget about it (and maybe everything else if I have to go the memory-care route).
Much as I like the tech end of cybersecurity, it’s no longer my life. I’m going to do other things with my time and energy, like hiking and booking our family trip to Europe.
The biggest challenge in security is its asymmetry: attackers face little accountability, while defenders must be nearly perfect. Still, hope isn’t a strategy—preparation is essential, not just for protection but also for financial restitution after a loss.
Glad to hear you’re living the life you want! Best wishes for a smooth and memorable trip.
You bring up a particularly good point when you said “…but also for financial restitution after a loss”. Investment firms like Vanguard and Fidelity have posted their customer requirements to be eligible for restitution after a loss. It’s prudent for an account owner to review those requirements and assure themselves they’re meeting them. For example, Vanguard expects the account owner to “regularly” monitor their account and Fidelity expects the account owner to “frequently” monitor their account. Of course, they both list additional account owner responsibilities as well that must be met to qualify for restitution after a loss.
Very interesting information. OldITGuy, can you share a link for where Vanguard states its policy on this? I’ve looked around a little and can’t locate it. Thanks.
Update: I found it: Security Center | Vanguard Click on “Our promise”.
Yep. Here’s a link straight to it: Security Center | Vanguard
Here’s one for Fidelity: Fidelity Customer Protection Guarantee