It’s Been a Minute! But This is Too Important

During the month of June, I took part in a four-week webinar series through Charles Schwab regarding cybersecurity – fraud, data breaches, phishing etc.

Not to give AI too much attention here, but it IS front and center with making data hacks and cyber breaches more prevalent and more successful than ever.

To protect your financial assets and digital identity, we all must actively defend against increasingly sophisticated fraud tactics.

Major Cybersecurity Threats to Look Out For

  • Check Fraud & Identity Theft:  Criminals steal or intercept physical mail to alter or wash check information. Because checks contain your name, address, and bank routing numbers, successful check fraud often acts as a gateway to complete identity theft.
  • Impersonation Scams: Bad actors pretend to be from trusted entities—such as government agencies (IRS, SSA, Medicare), law enforcement, or tech support companies (Apple, Microsoft, Amazon)—using aggressive, urgent tones to demand immediate payment or device remote access.
  • Business Email Compromise (BEC) & Real Estate Wire Fraud: Scammers compromise or spoof trusted business/personal email addresses to send fake financial instructions, changing billing locations or wire details for real estate closures.
  • Social Engineering & Relationship Scams: Romance schemes (cultivating fake online emotional attachments) and “pig-butchering” investment schemes use prolonged contact, fake portfolios, and psychological manipulation to pressure victims into wiring funds or buying cryptocurrency.
  • Phishing & Malware: Legitimate looking but fake emails, texts, or pop-ups prompt you to click malicious hyperlinks or download attachments that inject tracking viruses into your device.

Once they get into or on your trusted device without you knowing it, it’s lights out.

 How to Protect Yourself and Your Data

1. Bulletproof Your Account Access

  • Never reuse passwords: Create a strong, unique password for your financial accounts that is at least 8 characters long. Consider using an encrypted password manager that can create long, unique passwords on the spot for you and save them. I use LastPass with a very, VERY long password AND two factor authentication to get in.
  • Turn on Two-Factor Authentication (2FA): Enable this security lock on all financial accounts and all other sensitive logins.
  • Use biometric and verbal safeguards: Activate fingerprint or facial recognition on your mobile apps and request a verbal password or one-time passcode setup for phone support.  Admittedly, I have not moved to biometric safeguards yet.

2. Verify Every Transaction Verbally

  • Ignore contact info inside emails: If you receive sudden changes to wire, payment, or money movement instructions via text or email, do not use the numbers provided in that message.  This is mostly from the investment advisor’s side of things, which is why if you are an investment client of mine, you will be getting a phone call from me for any data transactions that we have not discussed together live.
  • Call a verified number: Pick up the phone and dial your advisor or contact directly using a trusted number you have safely called before to confirm the trade or payment.

3. Practice Safe Communication & Mail Habits

  • Ditch paper checks: Transition to electronic payment options like money links (ACH), online bill pay, or direct deposits.
  • Secure your physical mail: If you must mail a paper check, bring it directly inside the post office rather than an outdoor collection box. Write with indelible black ink so fraudsters cannot wipe your pen strokes.
  • Be vague online: Avoid posting personal identifiers like your birth date, family relationships, pet names, or previous schools on social media platforms. Scammers mine this public data to crack security questions.

4. Tighten Device & Public Network Security

  • Keep tech updated: Routinely apply software, operating system, and web browser updates to patch system vulnerabilities.
  • Evade public Wi-Fi risks: Do not login to financial accounts on public computers or free Wi-Fi zones. Use a personal phone hotspot or Virtual Private Network (VPN) instead, and turn off Bluetooth when traveling.
  • Avoid unexpected links: Never click a link within a sudden email, text, or pop-up ad. Hover over URLs first to see the true destination address, verifying it starts with https://.

Immediate Action Plan if You Suspect Fraud
If you identify suspicious account activity or believe you have accidentally engaged with a scammer, act quickly:

1. Power down your device immediately. This single, immediate action creates an instant digital firebreak that protects your data and accounts while you figure out your next steps.

  • Cuts off the hacker: If malware was just installed, it stops the malicious software from sending your files, passwords, or personal data back to the hacker’s servers.
  • Stops remote control: If a scammer is attempting to remotely access your laptop or phone, pulling the plug cuts their connection instantly.
  • Prevents lateral spreading: It stops the virus or compromise from traveling through your Wi-Fi network to infect other devices in your home or office.

2. Change Your Passwords (From a Separate, Safe Device)
Do not use the compromised device to change passwords. Use a completely different, secure phone or computer to:

  • Change your primary email password first, as hackers use your email to reset passwords for all your other accounts.
  • Change passwords for all financial and banking accounts.
  • Ensure you turn on Two-Factor Authentication (2FA) on every single account that offers it.

3. Run an Offline Malware Scan (you may want or need to hire someone who knows what they are doing)  

4. Monitor and Alert Your Institutions

  • Call Your Bank/Advisor: If you have financial accounts linked to that device, call them immediately to flag potential fraud and have them monitor your accounts.
  • Check Active Sessions: Log into your email from a safe device and check the “Security” or “Recent Activity” tab. Forcefully log out or “terminate” all other active sessions to kick the hacker out.

5. Lock your credit at the three credit bureaus: Experian, Equifax and TransUnion

6. Notify Federal Authorities: File a cybercrime incident report online directly with the FBI via the Internet Crime Complaint Center (IC3.gov).  

I know, it’s a lot to take in, and this was just a summary!

You’ve probably heard many of these tips in the past, but have you taken action to protect yourself and your data?

At least start with your financial institutions to be sure you have unique passwords and 2FA set up on all your logins.

It may only be a first step, but it’s a critical one.