A friend of mine lost access to her Gmail account last year. Not because she clicked a sketchy link or downloaded malware. She'd reused a password from a fitness app that got breached back in 2022. Someone bought her credentials for about $2 on a dark web forum, tried it on Gmail, and that was it. Game over.
She's not naive. She works in marketing, uses her phone constantly, considers herself pretty tech-savvy. And she still got hit.
That's the thing about how most people actually get compromised — it's rarely cinematic. No shadowy figure typing furiously in a hoodie. It's almost always something boring and preventable.
The Attacks That Actually Hit Regular People
Look, nation-state actors like APT28 (Russia's GRU-linked group) or Lazarus Group (North Korea) mostly go after governments, defense contractors, and financial institutions. You're probably not their target.
But there's a whole ecosystem of lower-level cybercrime that specifically preys on regular people. And it's massive.
Credential Stuffing
This is what happened to my friend. Attackers take huge lists of username/password combos leaked from old breaches — think the 2019 Collection #1 dump of 773 million records, or the RockYou2021 list with 8.4 billion entries — and they just try them everywhere automatically.
Tools like Sentry MBA or OpenBullet can test thousands of credential pairs per minute. It's not hacking in the traditional sense. It's more like trying every key on a giant keyring until one fits.
If you've reused any password anywhere, you're exposed to this. Full stop.
Phishing (Still Wildly Effective)
Phishing gets mocked as an old-school attack, but it keeps working because it keeps evolving. In 2026, we're not talking about the obvious "Nigerian prince" emails anymore. Modern phishing uses AI-generated copy that's grammatically perfect, mimics your bank's exact email template, and sometimes even references your real name, employer, or recent transactions pulled from data broker profiles.
The Anti-Phishing Working Group (APWG) recorded over 1 million unique phishing sites in Q1 2023 alone. That number's only gone up.
Spear phishing — targeted attacks aimed at one specific person — is even nastier. I've seen examples where attackers impersonated someone's actual boss using a display name spoofed to look identical in Gmail's mobile view. You'd have to tap through to check the real sender address, which most people never do.
SIM Swapping
This one's genuinely scary and doesn't require any technical skill from the attacker. They call your mobile carrier, pretend to be you, and convince a customer service rep to transfer your phone number to a SIM they control.
Once they have your number, any SMS-based two-factor authentication is toast. They request a password reset on your email, get the code on their phone, and they're in.
The 2022 attack on Coinbase users via SIM swapping hit over 6,000 customers. Carriers like AT&T and T-Mobile have had documented SIM swap fraud problems for years — T-Mobile settled a lawsuit over it in 2023.
"The attacker doesn't need to be a genius. They need to be patient, and they need you to have done nothing." — That's basically the whole playbook.
Malvertising and Drive-By Downloads
You're reading an article on a totally legitimate news site. An ad loads in the background. That ad contains obfuscated JavaScript that exploits an unpatched browser vulnerability — something like CVE-2024-4947, a Chrome V8 engine flaw patched in May 2024 after it was actively exploited in the wild.
If your browser's not updated, that's it. You didn't click anything. You didn't download anything. You just read the news.
This isn't rare. The 2023 HugoBoss malvertising campaign hijacked Google ad placements to push fake installers for Notepad++ and VLC that bundled infostealers. Hundreds of thousands of impressions before it was caught.
The Defenses That Actually Work
Here's the deal — you don't need to become a security expert. You need about 30 minutes of setup and a couple of habit changes. That's genuinely it. Because most attackers go for easy targets, and if you make yourself even slightly harder to compromise, they'll move on.
Get a Password Manager. Actually Use It.
I know you've heard this. I know you're probably not doing it. I wasn't either for an embarrassingly long time. I spent way too long convincing myself that my system of variations on one password was "basically fine." It's not.
Bitwarden is free, open-source, independently audited, and works across every device and browser. If you want something more polished, 1Password is $2.99/month and arguably the best UI in the category. Dashlane is solid too.
The point isn't which one you pick. The point is every single account gets a unique, randomly generated password. When some obscure forum you forgot you signed up for in 2018 gets breached, that credential is useless everywhere else.
Use an Authenticator App, Not SMS Codes
SMS two-factor authentication is better than nothing, but SIM swapping (and SS7 protocol vulnerabilities that carriers can't fully patch) means it's not that much better.
Switch to an authenticator app. Google Authenticator works fine. Aegis (Android, free, open-source) is my personal pick because it lets you encrypted backups. Authy is popular and syncs across devices, though it has had some controversy around phone number-based recovery.
For accounts you really care about — email, banking, crypto — consider a hardware key. The YubiKey 5 NFC costs about $55 and plugs into USB or taps via NFC. Phishing a hardware key is essentially impossible because it cryptographically verifies the actual domain. A fake login page gets nothing.
Check If You've Already Been Breached
Go to haveibeenpwned.com right now. Type in your email. Troy Hunt (the security researcher who runs it) has indexed over 13 billion breached accounts. If your email shows up, you'll see exactly which breach exposed it and what data was included.
If it says your password was exposed, change that password everywhere you used it. Yes, everywhere. Yes, I know it's annoying. That's what a password manager is for.
Update Your Stuff. Seriously.
That Chrome update you keep dismissing? It might be patching a zero-day being actively exploited right now. The CVE-2024-4947 Chrome flaw I mentioned earlier was being used in real attacks before the patch dropped. People who updated within 48 hours were fine. People who clicked "remind me later" for two weeks weren't.
Enable automatic updates on your phone, your browser, and your operating system. There's almost no downside and the upside is huge.
Be Paranoid About Links in Emails and Texts
Not pathologically paranoid. Just suspicious enough to pause for three seconds.
If you get an email claiming to be from your bank, don't click the link. Open a new tab and type your bank's URL directly. If someone texts you a package tracking link you didn't ask for, don't tap it. If a LinkedIn message has a PDF attachment from someone you don't know personally, don't open it.
I test suspicious URLs in VirusTotal before clicking. It's free, takes ten seconds, and scans against 70+ security vendors. It's not foolproof — very new malicious domains can slip through — but it catches a huge chunk of known bad stuff.
Lock Down Your Carrier Account
To protect against SIM swapping specifically, call your carrier and ask them to add a port freeze or number lock to your account. Also set up a carrier-specific PIN that's required for any account changes. Every major carrier supports this.
AT&T calls it "extra security." T-Mobile has "SIM lock" in their app settings. Verizon has a "Number Lock" option you can enable online. Takes five minutes. Makes SIM swapping dramatically harder.
A Few Things People Overlook
Your Email Account Is the Master Key
Think about it. If someone gets into your email, they can reset the password to everything else — your bank, your Amazon, your Apple ID. Your email account deserves your strongest, most unique password and your best two-factor method.
I'd argue Gmail with Advanced Protection Program enabled (requires a hardware key) is the most secure consumer email option available right now. Proton Mail is end-to-end encrypted by default if you're in a country where you don't trust local surveillance, or just care about privacy.
Public Wi-Fi Isn't the Nightmare It Used to Be
Honest take: public Wi-Fi is less dangerous in 2026 than it was in 2015, because almost everything runs over HTTPS now. A coffee shop man-in-the-middle attack used to let attackers see your traffic in plaintext. Today they'd mostly see encrypted gibberish.
That said, I still wouldn't do online banking on public Wi-Fi without a VPN. Mullvad VPN at $5/month doesn't log anything and has been independently audited. ProtonVPN has a free tier that's actually decent. If I'm just browsing Reddit though? I don't sweat it.
Data Brokers Are Quietly a Huge Problem
Companies like Spokeo, Whitepages, and BeenVerified aggregate your name, address, phone number, employer, relatives' names, and more. Attackers use these to make phishing and social engineering way more convincing.
You can manually opt out from each one — Privacy Rights Clearinghouse has a removal guide — or pay a service like DeleteMe ($129/year) to do it continuously. Not a perfect fix, but it raises the cost of targeting you specifically.
The Honest Priority List
If you do nothing else, do these four things. In this order.
- Get Bitwarden (free) and generate unique passwords for every account, starting with your email and bank.
- Enable an authenticator app on your email, bank, and social accounts. Turn off SMS 2FA where you can.
- Check haveibeenpwned.com and change any passwords that showed up in breaches.
- Turn on automatic updates everywhere. Phone, laptop, browser, router if your router supports it.
That's it. Seriously. You don't need to understand how TLS works or what a SQL injection is. You just need these four habits, and you'll be harder to hit than probably 85% of people online.
The people who get compromised aren't dumb. They're just busy, and they put this stuff off. The attackers are counting on exactly that.
