The questions families actually ask, answered plainly — no scare tactics, no filler, just what to know and what to do.
If anyone in your household has an email address, a bank login, or a social media profile, you're a target — not because you did anything wrong, but because that's enough for a criminal to start building a profile on you. It's not about being wealthy or careless. It's about being reachable.
The Digital Open Door Audit is a free, 10-minute way to see specifically what's exposed for your family right now, rather than guessing.
Turn on multi-factor authentication (that extra login code step) on your email account. Email is the recovery key to almost every other account you own — if a criminal gets into it, they can reset your banking, social media, and shopping passwords right behind it. It takes about two minutes and stops most account break-ins on its own.
Yes — that's specifically who this site is written for. Every guide here is written the way a detective briefs someone, not the way an engineer documents a product. No prior technical knowledge assumed, no jargon left unexplained.
A criminal only needs a few seconds of someone's voice — often pulled straight from a public social media video — to generate a convincing clone with freely available AI tools. They then call a family member, usually with a manufactured emergency, and use the cloned voice to create panic and urgency so you act before you think to verify.
Not reliably by ear alone — that's the point of the technology. The defense isn't listening harder, it's verifying through a separate channel: hang up and call the person back on their known number, or use a family code word only you'd both know. Never verify identity using the number that called you.
Meaningfully, yes. A traditional romance scam is a human working from a script, which means it can slip up. An AI-driven version can sustain a consistent, emotionally responsive "relationship" with multiple people at once, and it doesn't get tired, distracted, or make the small human errors that used to be the giveaway.
The old advice — "look for typos and bad grammar" — doesn't hold up anymore. AI-generated phishing reads as polished as anything a real company would send. The more reliable tell is the ask itself: unexpected urgency, a request to click a link or "verify" something you didn't initiate, or pressure to act before you'd normally have time to think.
It's a second proof of identity beyond your password — usually a code sent to your phone or generated by an app. It matters because a stolen or leaked password alone is no longer enough to get in: the criminal also needs physical access to your phone, which stops the vast majority of automated break-in attempts cold.
Less often than you'd think — the outdated "change it every 90 days" rule mostly just trains people to pick weaker, more predictable passwords. What actually matters more: use a different password for every account, and change a password immediately if that specific service reports a data breach.
Change that account's password immediately, from a device you know is safe, and check if multi-factor authentication is turned on — if it isn't, turn it on now. Then check your account's recent activity or connected devices list for anything else unfamiliar.
Oversharing specific details that add up: a birthday countdown, a school name in a background photo, a location tag. Individually, none of it seems risky. Together, it hands a stranger everything needed to build trust or locate a child — which is exactly how these approaches actually start.
Frame it as a skill, not a threat — the same way you'd teach them to look both ways before crossing a street. Keep it specific and concrete ("never share your school name with someone you only know online") rather than vague and frightening ("the internet is dangerous"). Specific advice is something a kid can actually act on.
Contact your bank or payment provider immediately — speed matters more than almost anything else here. Change the password on any account that may have been involved, and turn on multi-factor authentication if it wasn't already on. File a report at IdentityTheft.gov. Don't spend time being embarrassed about it first; that delay is the costly part.
Yes, and it's free. You place a freeze separately with each of the three credit bureaus — Equifax, Experian, and TransUnion. Once frozen, no one can open a new loan or credit line in your name without you first lifting the freeze, which only takes a few minutes when you need it yourself.
It depends heavily on how the money was sent. Wire transfers and gift cards are extremely hard to recover once sent. Credit card charges have the strongest built-in protections. Regardless of method, reporting it immediately gives you the best possible odds — every hour of delay makes recovery less likely.
Be very cautious. Secondary "recovery scams" specifically target people who've already lost money once, promising to get it back for an upfront fee. A legitimate bank, law enforcement agency, or credit bureau will never ask you to pay them directly to recover funds or investigate on your behalf.
Join families across the country protecting themselves online — written by a retired NYPD Detective and former FBI Cyber Task Force investigator.