Comments
Doug • July 22, 2026 7:54 AM
I read articles like this and shudder. I’m married and nearly all of our financial accounts are shared. Trying to figure out a security schema that works for two people who have vastly different understandings of security and risk is not trivial.
Billy Jack • July 22, 2026 8:02 AM
I received an e-mail last night from a former customer of mine. The only explanation I can think of is that he or his wife gave out their gmail address and password to someone spoofing something called paperlesspost.
I got his telephone number from one of the early morning coffee drinkers a few minutes ago and am getting ready to call him to warn him and suggest that he contact his bank and credit card companies and that he should probably start changing passwords. If I can’t get hold of him, I’ll probably drive out to his house in a bit to talk to him in person.
It would surprise me if he didn’t use the same weak password on everything.
Rontea • July 22, 2026 8:49 AM
This is why layered security and zero-trust practices are absolutely essential in our connected world. A single point of failure—your core account, your phone number, your email—can cascade into a total compromise if it’s the foundation for everything else. Social engineering is powerful because it exploits human trust, and spoofed calls or texts can look perfectly legitimate in the moment.
Two key takeaways: diversify your digital keys and never authenticate inbound. Call your bank or provider directly using a verified number, and treat unsolicited messages—even those that look official—as suspect. One proactive measure today can prevent a full-scale loss tomorrow.
Steve • July 22, 2026 9:00 AM
@Doug
Haha, I hear that. I managed to go over the severe ramifications of poor security and when she got it and asked what to do I went over the biggest must/must not ensuring she understood everything along the way. I asked questions to verify her understanding on each point. Now if she runs into anything she asks. 🙂
The thing to overcome is the considerations on looking at seemingly hard to understand things. So I had to find some outcome which was not acceptable to her and working with her as a team member to overcome the threat she was not willing to have, it then became easy to consult her understanding and willingness to do / not do things. All done on a gradient that she could handle.
And as you know security is a balancing act. 🙂
Concerned • July 22, 2026 9:51 AM
With the ability to voice clone within three seconds using current machine learning / DSP techniques, I’m afraid even point #3 is no longer fool-proof: “3. Never move a meaningful sum until you have heard the person’s voice.”
One idea was to have a secret phrase / password between you and your loved ones to “authenticate” them, when calling in emergencies like this.
Subscribe to comments on this entry
Leave a comment
Sidebar photo of Bruce Schneier by Joe MacInnis.


























