Other Signs of Phishing

You may think the worst thing that can happen to an account is getting the account hacked, and then losing access to it. Not strictly true! You can be hacked in ways that don’t shut you out of an account and instead have that account used, without your knowledge, to gather data on you or defraud others.

Hacking Leisure Accounts

Your Spotify, your Netflix, or other leisure accounts often don’t provide direct access to a credit card number. Generally speaking, many accounts like this want you to re-enter your password to make a purchase, and will send a receipt if a purchase is made, to keep kids from racking up hundreds of dollars without their guardian realizing. Or, otherwise, they’ll auto-bill and don’t show or ask for a credit card after the first time, unless it expires. It’s tough to snatch credit card info from an account.

Even so, having someone else tapping into them is not a small concern. Firstly – is that password/email combo used anywhere else? Modern users generally don’t use the same password and email for every single account like they used to in the old days, but some still do, and if that some includes you, time to start changing passwords before they try that password/email combo on your bank! (This is the single biggest reason not to use the same password multiple places, by the way!)

Let’s say your Spotify and Netflix account are hacked, but the hacker doesn’t reset the password, and the password is a one-off one for that one alone. They’re then often trying to avoid alerting you that the account has been breached so you don’t reset the password. If you’re using a premium service like Spotify Premium, they’re after ad-free music without having to pay for it. Seems harmless. Largely just annoying. However, leaving an account open to a stranger runs the risk of them somehow gathering information on your account (whether that’s by calling support and asking them questions, or riffling through your watch history to gather info) and distributing it elsewhere (they almost certainly had your email and your password to gain access to the account in the first place and may figure out, say, you have a gym account with a particular branch based on a playlist name, or that you have kids based on your view history) or deciding to lock you out when you’d be really, really annoyed by it. This is one reason those accounts now send alerts when the service has been accessed from somewhere different geographically.

You may find hints that something is amiss in your recommendations. Many of these services have watch- or listen- histories: if something doesn’t seem familiar in your listening history, it’s time to change the password.

Hacked Social Media Accounts

A little less harmless is an accessed social media account. In the past, hackers used to immediately change the password on the account: get in, lock the owner out, do whatever they want with the account before support can catch up and return the account to its rightful owner. But, with the rise of 2FA, that is much harder to do than it used to be. And even if a user doesn’t have 2FA enabled, the account will often send an alert that the password has been changed regardless. So, instead, hackers just don’t change the password! Today’s hackers will often begin sending DMs out of the social media account while the main user still has access, which oftentimes makes their scam look more real as a bonus – you’re still posting stories featuring you, and the hacker is sending DMs to people at the same time. The main user – if they’re not supervising their DMs – may have no idea their account is being used to try and hack other accounts.

For example: right now, there are scams on Discord run by sending someone a DM with a link to a “server they should join” which is really a fake login page with nothing behind it, hoping the target types their credentials into it, and then using that information to get in. The account doesn’t get it’s password changed and the person who’s been hacked doesn’t know it happened if they’re used to participating in large servers with a lot of people, or if they have their notifications off.

Bigger Problems – Email

In terms of severity, the average person relies very heavily on their email account and would be losing a lot of data if it gets hacked. Emails contain tons of sensitive information (utilities, addresses, tax info, et cetera) all valuable to a data thief. Even lacking data, a hacker gaining access is still a problem! Much like the social media scams, some hacks don’t make an attempt to change the password, they just start sending, and the person whose account is doing the sending may genuinely not realize they’ve been compromised until they get a reply. Worse, a hacked email will continue to accumulate other email addresses, and will regularly try to hack them – meaning your account is sending the link that leads to your friends and coworkers getting defrauded. And, of course, not everyone sends important communications via their email, and many emails are just to have access to things like Netflix accounts… but if that Netflix account has, say, a password reset request sent to the email address, and the person cohabiting your mailbox just uses it and then deletes it without you seeing it, and then changes the password to your Netflix account without changing the billing information, you’re not going to be able to get in to that Netflix account until Support can help you. And that might be a minute, if you’re still assuming it was the Netflix account that got hacked, not your email!