The Plain Record

What things really cost, and why.

One Reused Password and an Old Phone Number Emptied Four Accounts in a Weekend

Posted on by Emmett Rasmussenin Technology5 min read

A phone lying face down on a weathered picnic table beside a set of house keys, late afternoon light across the wood
A phone lying face down on a weathered picnic table beside a set of house keys, late afternoon light across the wood

A household discovered on a Sunday afternoon that a savings account had been drained, and spent the following week reconstructing how it happened. The answer had almost nothing to do with the bank, whose security was never defeated in any meaningful sense. It began with a password chosen in about 2013 for an online forum that no longer exists, and it traveled through four accounts by way of a phone number that had been disconnected two years earlier and reassigned to somebody else. Every link in that chain was ordinary and every one of them was avoidable.

The Order It Actually Went In

The forum was breached at some point, along with everybody's email addresses and passwords, and the combination ended up in a collection that circulates freely. Somebody tried that pair against a large number of services, which is automated and costs almost nothing, and it worked on an old webmail account the household had stopped using but never closed. Nothing of value was in that mailbox. What was in it was the address book and, more importantly, a history of which services had ever sent messages to it.

From there the sequence was a series of password resets. The webmail account was listed as the recovery address on a shopping account, the shopping account had a stored card and a delivery address, and the delivery address confirmed an identity well enough to satisfy the account recovery process at a second service. At no point did anybody guess a strong password or break encryption. The whole intrusion was a sequence of legitimate recovery mechanisms, used in order, each one made possible by the previous.

Why the Phone Number Was the Weak Link

The bank was the last account and it was the best defended, requiring a code sent by text message before any transfer to a new destination. That protection worked exactly as designed and it failed anyway, because the number it sent the code to had been given up when the household changed carriers two years earlier. Disconnected numbers are returned to the pool and reassigned, generally within months, and the person now holding it received the codes. They almost certainly had no idea what the messages were, which is the detail people find hardest to accept.

Nobody in the household had done anything careless with the phone number. They had simply never gone back through every account that had it on file, which is a list nobody maintains and which for most families runs to dozens of services. This is the failure mode that turns a good security measure into a liability: a code sent to a number that somebody else answers is worse than no code at all, because everybody involved believes the account is protected. The bank's records showed the code being delivered successfully, which is exactly what they were designed to show.

What Stopped It, and What Nearly Did Not

Two things ended the episode. The transfer out of the savings account was large enough to trigger a review at the receiving institution, which delayed it by a day. And the household happened to look at the account on a Sunday rather than on the following Friday, which is the sort of luck that should not be part of anybody's security arrangement. Faster reporting materially improves the odds of recovery on an unauthorized electronic transfer, and the protections that apply generally depend on notifying the institution promptly.

What nearly went wrong was the reporting itself. The household's first instinct was to call the bank's general number and wait, and it took most of an hour to reach somebody who could freeze anything. The number on the back of the card, the one that reaches a fraud department directly, was the correct route and nobody knew it. Ten seconds of preparation on an ordinary day would have saved fifty minutes on the worst one.

The Protections That Actually Applied

Consumer protections for unauthorized electronic transfers are real, they are meaningful, and they are conditioned on timing. Reporting quickly after the transaction appears on a statement generally limits a customer's exposure substantially, and reporting slowly can leave far more of the loss with the customer. The rules differ between a debit transaction, a credit card charge, and a wire, and the third is the one with the least protection, which is why fraud that matters tends to be directed toward wires.

The practical consequence for a household is to know which instrument was used before making the call, and to make the call in the same hour rather than the same week. Written confirmation matters too. A phone report followed by a short written summary sent the same day, kept with the date, is the record that resolves any later disagreement about when the institution was notified, and that date is frequently the only fact in dispute.

What the Household Changed Afterward

Three things, none expensive. A password manager, so that no credential is ever shared between two services and the 2013 forum password cannot reach anything. An authenticator application in place of text messages wherever a service supports it, since a code generated on a device is not sent anywhere and cannot be delivered to a stranger. And an afternoon spent closing accounts they no longer used, which turned out to be more than twenty and each of which had been a small open door.

The fourth change was the one they thought least about and now recommend most. Every account that matters had its recovery email and recovery phone number checked and corrected, which took about two hours across a weekend. Recovery paths are the part of an account nobody looks at after setup, and they are precisely the part an intruder uses, because a recovery mechanism is designed to let somebody in without the password. That is its purpose rather than a flaw in it, which is why the details it relies on have to be current.

Likely Against Merely Possible

The lesson people draw from a story like this is usually that everything is dangerous, which produces a week of anxiety and no change in behavior. The more useful reading is that the chain used only ordinary, well known mechanisms, and that closing any one link would have stopped it entirely. A unique password on the webmail account ends it at step one. A working phone number ends it at the bank. An authenticator app ends it before the bank is reached at all.

What made this household vulnerable was not a sophisticated adversary but an accumulation of small, sensible decisions made years apart and never revisited: an account kept open in case it was needed, a phone number left on file, a password reused when reusing passwords was normal advice. None of those was a mistake at the time. The Sunday afternoon was simply the day all of them were used at once, by somebody who did not need to be clever about any of it.

About Emmett Rasmussen

Emmett writes about where household advice and professional practice diverge.

View all posts by Emmett Rasmussen

About the author

Emmett Rasmussen

Emmett writes about where household advice and professional practice diverge.

More from Emmett Rasmussen