惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

WeLiveSecurity

The quest for greater tech independence Why geopolitical turmoil is a gift for scammers, and how to stay safe FrostyNeighbor: Fresh mischief and digital shenanigans Eyes wide open: How to mitigate the security and privacy risks of smart glasses Fake call logs, real payments: How CallPhantom tricks Android users Fixing trivial passwords is as easy as 123456 A rigged game: ScarCruft compromises gaming platform in a supply-chain attack This month in security with Tony Anscombe – April 2026 edition The calm before the ransom: What you see is not all there is GopherWhisper: A burrow full of malware New NGate variant hides in a trojanized NFC payment app Ransomware’s back office: What the ransom note won’t say Why that next data breach alert could be a trap Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Why LinkedIn is a hunting ground for threat actors – and how to protect yourself Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition
Digital assets after death: Managing risks to your loved one’s digital estate
2026-04-01 · via WeLiveSecurity

Digital Security

Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay.

01 Apr 2026  •  , 5 min. read

Digital assets after death: Managing risks to your loved one’s digital estate

Can you imagine all of the things you’ll leave behind when your time is finally up? Heirlooms? Property? Other ‘tangibles’? Now just have a think about all of the digital assets you’re likely to leave for loved ones to manage. Email accounts, shared photos, passwords, playlists, social media profiles and smart devices. The difference is that these may be completely inaccessible once you’re gone, complicating what is already a traumatic process for friends and family. Worse, your digital estate might even be a target for nefarious actors.

It’s worth knowing exactly how to prepare and protect your digital legacy and what else you can do ahead of time to reduce the emotional and physical workload for your loved ones. And what happens next if you’re suddenly plunged into the same situation.

What does the law say?

One of the biggest challenges comes with social media and password management. While banks, tax agencies and card companies have well-rehearsed processes for dealing with the closure of accounts after death, many digital-first companies still treat death as an “edge case,” according to the OpenID Foundation. From a legal perspective, inheritance laws often don’t include digital assets, online policies can be “opaque” and tools fragmented, it says.

Here’s what the state of play is in three key regions:

  • United States: the Revised Uniform Fiduciary Access to Digital Assets Act (RUFADAA) is meant to help in cases like this. But often it results in loved ones being forced to navigate what can be idiosyncratic platform terms of service (ToS).
  • United Kingdom: Experts warn that, unless they plan ahead, families are often left unable to access accounts because platform providers simply refuse. However, a proposed Property (Digital Assets, etc.) Bill aims to classify digital assets as personal property, ensuring they can be included in wills and subject to inheritance laws.
  • Europe: The European Law Institute is trying to harmonize laws across the region, so there are clear guidelines for inheriting digital remains and protecting the information in accounts.

What’s at risk?

For bereaved friends and family, the emotional sucker punch of losing a loved one can be cruelly amplified if they’re unable to retrieve the digital remains of the deceased. Even worse if social media algorithms surface unwanted reminders in the form of birthday notifications or tagged photos. There’s also a financial impact you can’t access crypto and other assets that are rightfully yours. Or if subscriptions you can’t cancel start whittling down your loved one’s funds.

But there’s more. Fraudsters have also spotted an opportunity to make money. First, they’ll scour obituaries and social media posts for personal details with which to impersonate the deceased in:

  • Attempts to deceive credit card companies into opening new lines of credit
  • Tax fraud, where returns are filed in the deceased’s name to claim refunds

The challenge for banks and government agencies is that, once the victim is not actively monitoring their accounts, this kind of fraud can continue for much longer than it would otherwise.

Alternatively, scammers might target the family of a recently departed individual. For example, they might scrape footage of them from the web to create posthumous deepfakes requesting money or information from shell-shocked relatives. Or they could hijack the deceased’s social accounts to do the same. They might even impersonate an insurance company to request payment of a fee in order to release life insurance funds. Or a fictitious “account recovery” service provider claiming they can access your loved one’s digital assets for a fee.

What you can do to manage risk

The first thing to do is get your estate planning in order, or sit down with a loved one to sort theirs. Make a digital inventory of all important accounts, devices and assets, including their logins. This could be complicated if they’re/you’re using passkeys and/or digital wallets to store passwords. But it’s a start.

It’s important to understand that, while most big tech companies offer the ability to transfer access to a “legacy contact,” if you don’t take advantage of this before passing on, the chances are that no one will be able to access your accounts. The main services/features are:

You should also be aware, however, that permissions for the above may be restricted, limiting what you can access and do once inside. But it should at least be possible to secure them, or shut them completely. That’s assuming you don’t need them to receive one-time passwords.

Next, mitigate financial fraud by filing the deceased’s tax return, putting a “deceased alert” on their credit reports across all bureaus, and monitoring for any unusual activity. Cancel their driver’s license and freeze their bank/credit card accounts, deleting them once safe to do so. Cancel any ongoing subscriptions you find.

Finally, avoid sharing too much information in the obituary as fraudsters may be monitoring. And be sure all friends and family members are alert to possible scams.

The worst of times

The above may be easier said than done, especially if you’re preoccupied by your own grief, and the multitude of things to do in the aftermath of a loved one’s passing. That’s why it’s important to plan ahead as much as possible, with legacy contact outreach to the major tech platforms. And to understand exactly what digital scams might look like at this emotionally charged time.

The OpenID Foundation is calling for action from policymakers, tech platforms and standards bodies to make the process easier, more watertight and less traumatic for survivors. But in the meantime, the best you can do will have to do. Even by talking about it, you’re taking a step in the right direction.


Let us keep you
up to date

Sign up for our newsletters