Appearance
6.7 — Digital Emergencies
Statistically the most likely crisis in this volume.
And the one where the first hour matters most, because almost all of the damage happens through cascading access rather than through the initial breach.
The first hour: account compromise
In this exact order.
1. Secure the email account first
Not the account that was compromised — the email account.
**Because email is the master key: every password reset goes there. An attacker with your email has everything.
Change the password to something new and unique, and check the recovery options — a changed recovery phone or a forwarding rule is the standard way access is retained after a password change.
Look specifically for: forwarding rules you did not create, filters that delete or archive incoming mail, and unfamiliar recovery addresses.
2. Turn on two-factor authentication
On email first, then everything else.
And prefer an authenticator app or a hardware key over SMS, because SMS can be intercepted by a SIM swap (below).
3. Sign out of all sessions
Most services have a "sign out everywhere" or "active sessions" control. Changing a password does not always terminate existing logins.
4. Then the other accounts
In order of damage: banking and payment, then anything with money, then social accounts, then everything else.
Unique passwords everywhere. Reuse is how one breach becomes twenty.
5. Tell the bank
Immediately, if any financial account is involved.
Speed matters for recovery, and many protections depend on prompt reporting.
6. Warn your contacts
Because a compromised account is usually used to defraud the people who trust you.
SIM swap
A specific attack worth knowing because it defeats SMS-based security.
Somebody obtains a replacement SIM for your number, then receives your verification codes.
The warning sign: your phone suddenly loses service for no reason.
If that happens and you cannot explain it: contact your operator immediately, and assume any SMS-based security is compromised.
Prevention: use an authenticator app rather than SMS where possible, and add a PIN or port-out protection with your operator.
Ransomware and device compromise
Disconnect from the network immediately. Wi-Fi off, cable out. This stops it spreading to other devices and to backups.
Do not pay. Payment frequently does not produce a working key, funds the operation, and marks you as somebody who pays.
Restore from backup.
And report it — in India, cybercrime is reported on 1930 and through the national cybercrime portal.
Fraud and scams
The three that account for most losses.
The urgent authority
Somebody claiming to be from a bank, the police, a tax authority, a court or a delivery service, and there is a problem requiring immediate action.
The structure is always the same: authority, urgency, and a demand for information or payment.
The rule that defeats all of them: hang up and call back on a number you look up yourself.
No legitimate organisation will object.
The person you know
A message from a friend or family member, from a new number, in trouble, needing money.
And increasingly, a voice — cloned from a short recording — which is convincing and is now cheap to produce.
The rule: verify on a channel you already had. Call the number you have saved for them.
And agree a family code word, now. **A word that anybody genuinely in trouble would use and that a caller could not know. It takes one conversation and it defeats the entire category.
The investment or job that is too good
Guaranteed returns, an unexpected job offer requiring a payment, a trading platform introduced by somebody friendly online.
The rule: any opportunity that requires you to pay first, act fast, or keep it confidential is fraud.
All three of those conditions are diagnostic and legitimate opportunities have none of them.
The prevention that covers most of it
Five things, in order of value.
A password manager, with unique passwords for everything. The single highest-value action, because credential reuse is the mechanism behind a large share of account takeovers.
Two-factor authentication on email, banking and anything with money.
Backups. Three copies, two kinds of storage, one offsite — and one of them not permanently connected, because ransomware encrypts connected backups.
Update software. Most compromises exploit vulnerabilities that have been patched.
And a separate email address for financial accounts, not the one you use publicly.
What to do before it happens
Because 4.4 raised this and it belongs here as an action.
Leave somebody the means of access.
A password manager with an emergency contact, a sealed envelope, or a written list somewhere secure.
Almost every family that has lost somebody reports this as the thing they wish had been done — accounts they cannot reach, photographs they cannot recover, and subscriptions they cannot stop.
It takes an hour.
If it is harassment or extortion
Different, and it needs saying.
Do not pay. Payment in sextortion and blackmail cases reliably produces further demands.
Do not engage.
Preserve evidence — screenshots, numbers, account names, timestamps.
Report it. In India: 1930 and the national cybercrime portal, and the police.
And tell somebody. The leverage in these cases is entirely shame, and it collapses the moment another person knows.
This is genuinely important: the harm from these cases is overwhelmingly psychological, and the isolation is the mechanism.
If it involves a young person, tell an adult they trust immediately — and 1098 is the childline number in India.
What to do with this page
Email first. It is the master key and everything else resets through it.
Check for forwarding rules and changed recovery addresses. A password change alone does not remove access.
Hang up and call back on a number you look up. Defeats the entire urgent-authority category.
Agree a family code word. One conversation, and it defeats voice cloning.
And a password manager with unique passwords is the single highest-value thing in this chapter.
Next: Part 7 — being lost and being stranded, where the first decision decides everything.