Ir al contenido
LESSON 1 OF 7 · 6 MIN

The $4,600 Lesson

An office administrator received what looked like an online party invitation. The message asked her to click “Download and view the card”. She did. The page asked her to allow a small program to run so the invitation could display properly. She allowed it.

Within seconds somebody else was moving her mouse.

What the attacker went for first

Not her documents. Not her photos. The attacker opened her browser, went straight to the saved-password screen, and read the list. Among those saved passwords was her online banking. He signed in.

The computer was cleaned the same week. Everything looked fine.

The part nobody expects

About a week later $4,600 left the bank account. Cleaning the computer removed the intruder from the machine — but it did not un-steal the passwords he had already copied, and it did not close the access he had set up inside the bank account itself.

Why the browser is the worst place for passwords

Saving passwords in Chrome or Edge feels safe because it asks for your Windows login. In practice, once someone is sitting at your session — through a remote-control tool, or physically — your entire password list is one click away, all of it, at once.

A password manager works differently: it stays locked behind a separate master password, and it does not hand over everything just because someone reached your desktop.

No se permite comentar en este curso.