Blog → Hacked: A Case Study

Security Case Study

Case study on a friend who got hacked. What she did wrong and what we can learn.

The point of this post is to help improve security awareness and to help prevent people from becoming victims of hackers. Rather than give a list of "the top 5 important things to not get hacked", I wanted to write this as a case study to help people understand what can happen when someone gets hacked, why it happens, and most importantly what we can do to keep ourselves safe on the internet.

The story

A friend of mine had a small business. One day she called me and said she kept having to reset the password for her video conference and credit card processing providers. She would reset the password, then could not login.

I went over to her house and started investigating. I tried resetting the passwords for those accounts, and was immediately not able to login to them. In her inbox, I found a suspicious email saying:
Wendy (not her real name), it looks like your Zoom account is really important to you.


I tried resetting her email passwords, and those would get immediately reset too. A few hours later, another email popped into her inbox with a similar message:
Subject: Wendy (not her real name), it looks like your accounts are really important to you.


At that point her computer seemed compromised, so I switched to my laptop and tried resetting her email passwords. Those passwords were immediately reset after I changed them.

This guy had gotten deep.

She had multiple email accounts, each of which was the password reset for another account. Not too uncommon. This guy had access to all of them. He had a keystroke logger on her computer so could grab any password we entered from there (he later confirmed this in an email). He seemed to be able to read files on the file system. It seemed he could intercept SMS messages sent to her cell phone. And he had some kind of automated software watching her email accounts that let him intercept password reset links — he would get the password reset links before I could and reset the passwords.

The next email from the hacker said:

Wendy (not her real name), if you want your accounts and website back, send $500 dollars in bitcoin to this address ...

A little advice for the future. Start taking your online security more seriously.

Her website's front page had been changed to redirect to a porn website. And past midnight we started getting calls to her phone (we didn't answer because we were fairly certain it was him).

Note: Never pay the ransom. NEVER. I heard a story of a woman in a similar situation. The hacker wanted $300 dollars in bitcoin. She paid the ransom, and the next email said "You were dumb enough to pay the $300, now give me $800 dollars if you want your accounts back."


So how did it get this bad?

Let's take a look at the things she did wrong and what we can learn:

1. You know those security updates that we all hate because they break our computers? She never did those. She would postpone them, or deliberately not shut off her computer, just so it would never do updates. This is most likely how the hacker got in in the first place. She might have unknowingly visited an infected website and gotten hacked through her browser.

2. Her phone was an Android phone. The last time the vendor released security updates for that model was over 2 years prior. I won't say the brand, but hers was a ******** version 4 and the OS could not be upgraded. The Android release for the newer version 7 model would not work on her phone. The Android release for the newest version 9 would not work on the version 7 or her version 4.

From researching, it seemed that for that vendor that is normal. The OS releases were specific to only one or two models within that vendor, instead of being compatible for the vendor's whole line of phones. At that time when I looked, I remember security updates seemed to be only provided for 2 years or so for each of that vendor's models — meaning: buy one of their phones today and only get two years worth of updates before it is no longer safe to use.

3. No 2FA. No authenticator app or hardware key. Setting up 2FA was one of the more crucial steps in getting this guy out and keeping him out.

4. All of her passwords were stored on her computer in a plaintext Notepad .txt file. The hacker was able to find this and use it to gain access to all of her accounts.

5. I'm not sure if her web / email hosting provider was compromised directly or just her account there was compromised. It seemed like a cheap, crappy hosting provider, so I moved her to a new one. And more importantly moved her business email to a reputable, secure provider.


I spent two or three days on getting this guy out. Trying to reset passwords while fighting his automated software, setting up 2FA, wiping her computer, and moving her hosting before I got this guy out and was able to keep him out. I also got her set up with an iPhone.


The most important part: how do we stay safe?

How do we prevent something like this from happening to ourselves?

1. Do the security updates

If your computer or phones' OS maker no longer provides updates for whatever version you are on, it would be well worth upgrading the OS, or moving to a new device. Losing access to an email account because a hacker got in can be VERY expensive. More expensive than a new phone. And not everyone has access to a professional computer person who will work 2–3 days for free to remediate a hacker getting in to your shit.

If you are still on Windows 10 and not subscribed to the long term support release, there have not been updates since October 14, 2025. Understandably you may feel Windows 11 sucks and is a big privacy concern. Apple may be expensive, but Linux is free.

2. Set up 2-Factor Authentication

2FA is important. At least for important accounts. A hardware key or authenticator app is considered more secure than SMS. If you do set up 2FA, I would recommend having at least two types, that way you will not be locked out of your accounts if you lose one of them.

When setting up 2FA, your email provider will give you backup codes. Keep the backup codes encrypted and somewhere safe, or printed and stored where no-one else can get to them (like a safe). Some authenticator app cloud backups have been hacked in the past. I would recommend against cloud backups.

3. Password management

This is a tricky one. I go against the grain and recommend against using password manager apps. There is malware that specifically looks for password managers and will swipe the contents of the copy/paste buffer when they see one. Password manager apps were banned on government computers in some secure environments. *

The safest thing I have come up with so far is a small paper password book. And I would not write down the entire password — maybe leave off a few characters that you can easily remember. And never travel with that password book. That thing stays at home. There was a recent story of a guy who had his crypto account info on a piece of paper in his wallet. He got pulled over and searched by police. When the police body cam footage became public record, his crypto account was drained.

(I am open to anyone having a better answer to this question if anyone has one.)

4. Have an anti-virus

I do not know which brand is best, but something is better than nothing. If you have Microsoft Windows, Defender is free.

5. Keep a backup

Have a backup of your important files. If a hacker does get access and you find yourself in a position where you need to format and reinstall your computer, it is much easier to have a backup ready to go vs. trying to make one with a hacker already controlling your computer. If your computer is infected with ransomware, it is too late to make a backup.


So what happened to Wendy?

We got the hacker out. Wendy was able to continue her business and stay safe from hackers. Her business rose to take top spots on Google and Yelp for her area. She recently retired and now uses Linux on her computer at home.

If a little old lady can use Linux, what is your bitch-ass excuse?


* Password manager footnote: My source is a person who, up until a few years ago, worked for government in a somewhat secure environment. I cannot go into details on this.


← Back to blog Questions? Get in touch