Lesson 1.1

1.1: Nobody Picked You

9 minutes

Nobody Picked You

In 2023, the DNA-testing company 23andMe announced that attackers had gotten into about 14,000 customer accounts. The strange part: no 23andMe system was hacked. There was no cracked database and no software flaw. The attackers walked in through the front door, using email addresses and passwords that had leaked from other websites’ breaches, some of them years earlier.

To 23andMe, every one of those logins looked normal. The email was right, the password was right, and the door opened.

Then it got worse. 23andMe had a feature that let relatives share DNA information with each other, so each compromised account exposed data belonging to family members who had done nothing wrong at all. Fourteen thousand broken-into accounts turned into roughly 6.9 million exposed profiles: ancestry details, genetic information, names, locations.

The people who lost their data were never targeted. Nobody chose them. A machine tried a list, and their names were on it.

The attack has a name

Credential stuffing is software that takes leaked email-and-password pairs and tries them against thousands of other websites, automatically, around the clock. That one sentence explains most account break-ins that happen to ordinary people.

The logic is simple. If your email and password leaked from a shopping site in 2019, and you used that same password for your bank, your inbox, or your DNA-testing account, the attacker doesn’t need to hack any of those places. They log in. The software does this millions of times an hour, across millions of stolen credentials. It doesn’t know who you are, and it doesn’t care. It only cares whether the door opens.

The same pattern, at home

The Ring camera takeovers of 2019 worked the same way. Families heard strangers’ voices coming through cameras in their children’s bedrooms, and the news said Ring had been hacked. It hadn’t. Attackers were replaying passwords those families had used on other sites that really were breached. Same email, same password, and now someone else could open the camera feed.

It’s worth pausing on what that means: the creepiest, most personal-feeling violation on this list was fully automated and completely impersonal, right up until a human bought the working login from whoever ran the software.

Why this changes everything

You are not hiding from a person. There is no one on the other end studying you, guessing your dog’s name, or deciding you’re worth the effort. What’s on the other end is a machine working through a list.

Once you see it that way, protection stops feeling hopeless and starts looking mechanical:

  • A reused password puts you on the list. That’s the whole risk. It has nothing to do with how interesting you are or how careful you feel online, and everything to do with whether a password you use has ever leaked anywhere.
  • Getting off the list doesn’t require outsmarting anyone. You need the automated replay to fail, and it fails the moment every site has its own password. Then a leak at one site opens exactly one door, you get an alert about it, and you re-lock it in minutes.

That’s the plan for the rest of this course: getting you off those lists, one layer at a time. Unique passwords take you off the credential-stuffing list. A password manager makes unique passwords painless. Two-factor authentication and passkeys make even a stolen password useless. Each layer defeats a different machine.

Nobody picked you. Everything that follows builds on that one idea.