Signal Over Noise #32

December 10th, 2025

Dear Reader,

Last weekend, a close family member lost access to their email account.

Not “forgot the password” lost. Fully taken over — the attackers changed the recovery email, changed the recovery phone, and locked them out completely. By the time they realized what happened, the account belonged to someone else.

Here’s the thing: they’re not careless. BT is merging with EE in the UK right now, and scammers are flooding inboxes with fake invoices and password resets that look legitimate. During a corporate transition, weird emails from your provider are expected. The usual advice — “be suspicious of unexpected messages” — breaks down when the legitimate company is also sending confusing messages.

They clicked something they shouldn’t have during a confusing period. That’s all it took.

Frank Abagnale — the con artist from Catch Me If You Can who now consults on fraud prevention — puts it bluntly: “Getting victims under the ether has absolutely nothing to do with how smart or educated they are. In fact, highly educated individuals are more likely to become victims.

The difference between people who get scammed and those who don’t isn’t intelligence or caution. It’s whether an attacker caught them at the right moment with the right story.


Your email is the master key

Most people think of email “hacking” as embarrassing but manageable — someone reads your messages, maybe sends spam from your account. You reset the password and move on.

That’s not what happens when attackers take over completely.

Your email is the recovery method for everything else. Banking, Amazon, government services, social media — they all use email for password resets. Control the email, and you don’t need to hack anything else. You just politely ask each service to reset the password, and the link goes to you.

Within 24 hours of a complete takeover, attackers can cascade into your entire digital life. Financial accounts get password resets and contact detail changes. Government services like HMRC use email verification. Shopping accounts with saved payment methods become personal ATMs. And social media becomes a tool to scam your contacts.

That last part is the really nasty bit.


The scam gets personal

With access to years of email history, attackers learn how you write, what you’ve discussed, your children’s names, recent events — all the details that make a message feel authentic. Then they start messaging your contacts from your actual address.

Within hours of the takeover, people started receiving messages from the compromised account. I got one myself:

“Can we have a swift email exchange for a few minutes? Are you available on email? Unable to get in touch over the phone due to a serious throat pain caused by Tonsillitis”

Classic pattern: urgency (“swift exchange”), a reason they can’t verify by phone (throat pain), vague enough to see if I’d bite before making the actual ask. If I’d replied, the next message would have been about money.

The giveaway? They’d never message me like that. But someone less familiar with their communication style might not catch it.

The average loss in these scams is around £7,000. When the message comes from someone’s actual compromised account rather than a spoofed number, success rates go up significantly.


Why corporate transitions are perfect cover

The BT/EE situation is a textbook case of why mergers create security nightmares. During any corporate transition, customers expect a flood of confusing communications — new account numbers, changed payment details, updated terms of service, system migration notices, rebranded everything.

Scammers know this. They time their campaigns to coincide with announced mergers, acquisitions, and major system changes. The legitimate noise provides perfect cover for fraudulent messages.

This pattern repeats with every major corporate transition. The companies celebrate with marketing campaigns while their customers pay for it with increased fraud exposure.


The recovery problem

The part that is rarely considered afterwards is that recovering a fully compromised account is hard.

When attackers change both your recovery email and recovery phone, you can’t just reset your password. The normal self-service options are gone. You’re generally looking at calling support, proving your identity with account numbers and potentially photo ID, and waiting 3-7 days for a security team to verify and reset.

During that time, the attackers still have access, unless the security team is able to block the account immediately. If not, then the attackers are reading incoming emails, resetting passwords on other accounts, and potentially covering their tracks.

Even after you regain access, you might not be fully recovered. Sophisticated attackers set up persistence mechanisms before they’re locked out: email forwarding rules that silently copy everything to their address, filters that delete security alerts so you don’t see evidence of continued activity, OAuth tokens granted to apps they control that survive password changes.

After recovering, you need to check settings for forwarding rules you didn’t create, filter rules that hide security emails, connected apps you don’t recognize, and all login activity for the past month. Most people don’t know to look for these. The attackers count on it.


What actually helps (and what doesn’t)

Let me be direct about what works and what’s mostly theatre.

Actually effective:

Authenticator app 2FA — Apps like Google Authenticator or Authy generate codes that attackers can’t intercept remotely. This is the single most important thing you can do.

A password manager with family sharing — 1Password or Bitwarden. Not just for convenience, but for having a secure place to store 2FA backup codes and for setting up emergency access. If something happens, recovery doesn’t depend on memory.

A separate recovery email — your recovery email should be a different provider than your main email, with its own strong password and 2FA. If your main email is compromised, your recovery email is the only way back in.

Partially effective:

Strong passwords matter, but in a complete takeover scenario, password strength is irrelevant. The attackers aren’t guessing your password — they’re using the password reset function after phishing you for access.

Security questions are weak by design. Your mother’s maiden name, your first pet, your childhood street — all findable on social media or through your email history once compromised.

Mostly theatre:

“Be vigilant” is the standard advice. It’s not wrong, but it fails when legitimate companies send confusing emails (like during mergers) and when people don’t know specifically what to look for.


Setting this up for family

The holiday period sees a spike in these scams every year — more online shopping, more gift card purchases, more “urgent” messages that don’t feel out of place. If you’re going to have the security conversation with family, now’s the time.

The fundamentals above apply to everyone. But for family members you want to help protect, there are a few additional steps worth taking.

Family sharing on your password manager1Password and Bitwarden both offer family plans with emergency access features. You can help if they get locked out, without having day-to-day access to their passwords. Store their backup codes and recovery phrases there too.

A family code word — if anyone gets a message asking for money, they ask for the code word first. No code word, no money, call directly. Simple, but it short-circuits the urgency that makes these scams work.

Regular check-ins — review accounts together periodically. Check for suspicious logins, unfamiliar emails, anything weird. Small problems get caught before they become catastrophic.

This isn’t foolproof. Nothing is. But it moves from “hope nothing bad happens” to “have a system for when it does.”


The damage control checklist

If you’re helping someone recover from an email takeover:

First 24 hours: Contact the email provider immediately. File a fraud report — in the UK, Action Fraud (0300 123 2040); in the US, IdentityTheft.gov or 1-877-438-4338; in Spain, Policía Nacional (091). Alert your bank and financial institutions. Place fraud alerts with credit agencies. Warn close contacts not to respond to suspicious messages from the compromised account.

Once you regain access: Check forwarding rules and delete any you didn’t create. Check filter rules — same. Review connected apps and revoke anything unfamiliar. Change password and enable app-based 2FA. Change recovery email and phone to ones you control.

Over the next week: Change passwords on all important accounts, starting with financial, then government, then everything else. Check your credit report for new accounts opened in your name. Review the sent folder — were scam messages sent to your contacts? Document everything for potential police reports or insurance claims.

Ongoing: Monitor credit reports for 6-12 months. Watch for physical mail about credit cards you didn’t apply for. Keep records of what happened and when.


The point

R. Paul Wilson, who consults for Scotland Yard on fraud, writes that victims often “shoulder full responsibility for being fooled, as if they are to blame for losing their own money.” That shame keeps people from talking about it — and lets scammers keep operating.

What would have helped here isn’t complicated: 2FA enabled before it happened, a separate recovery email, knowing who to call when it went wrong, having a password manager set up months ago instead of now.

Most security advice assumes perfect prevention. Real security is about damage control and recovery resilience when prevention fails — because eventually, for someone you care about, it will.

If you have elderly relatives (or honestly, any relatives) who manage their own email, maybe have this conversation before something happens. Walk through their recovery options. Set up a password manager together. Make sure there’s a way back in that doesn’t depend on the security they’ve already lost.

It’s not a fun conversation. It’s an important one.


The AI angle

You might be wondering where AI fits into a this newsletter issue about email security. Well, the uncomfortable truth is that AI is making attackers faster. Phishing emails that used to take hours to craft now take seconds. Voice cloning can fake a family member’s voice from a few seconds of audio. Personalized scam messages can be generated at scale, tailored to each target based on scraped data.

But — and this is the important part — the underlying social engineering tactics haven’t changed. Urgency, authority, fear, confusion during transitions. The same psychological levers that con artists have pulled for centuries. AI just lets attackers pull them faster and at greater scale.

That’s actually useful to know. It means the defenses that work against traditional social engineering still work against AI-powered attacks. The fundamentals — 2FA, separate recovery emails, verification code words, healthy skepticism during corporate transitions — remain effective even as the attack tools get more sophisticated.

The speed is increasing. The playbook remains the same.


Quick reference

For yourself:

  • 2FA enabled on email (authenticator app, not SMS)
  • Recovery email is a separate provider with its own 2FA
  • Backup codes stored in password manager
  • Know your email provider’s recovery process

For family members:

  • Password manager set up with emergency access
  • Recovery information documented
  • Family code word established
  • Regular security check-ins scheduled

If you’ve dealt with something similar, or if this prompted you to have a security conversation with family, hit reply and let me know.

Until next week, Jim

€9.00

The AI Writing Field Guide

Stop Sounding Like Everyone Else Using AI
The 5-step system for teaching AI what your voice actually sounds like — not… Read more

Get it now!

Signal Over Noise is weekly, reader-first publication on AI “without the hype” published by Jim Christian. If you’ve been forwarded this issue, you can subscribe for free: go.signalovernoise.at.


Made with ❤️ in Valencia by Jim Christian. For feedback, please reach out to [email protected].

Built with Kit