Cybersecurity Basics
Security Theater: Why Everything You've Been Told to Do Online Isn't Actually Keeping You Safe
You've been doing all the right things.
You never click links in emails from strangers. You don't give your Social Security number over the phone. You've got that little piece of tape over your laptop camera. You delete suspicious messages the moment they arrive.
And yet — according to the FBI's 2024 Internet Crime Report — adults over 60 lost more than $3.4 billion to cybercrime last year. More than any other age group.
Here's the uncomfortable question: What if the habits you've been taught are focused on the wrong threats?
This is what security experts call security theater — actions that feel protective but don't address how real attacks actually happen. It's the digital equivalent of locking your front door with three deadbolts while leaving the back window wide open.
Here's the reframe: before you add more security habits to your routine, you need to know which ones are doing real work — and which ones are just making you feel safer without making you be safer.
What Security Theater Is — and Why Smart People Fall for It
The term comes from security researcher Bruce Schneier, who used it to describe airport security measures that look impressive but don't address actual risk. Removing your shoes at the TSA line is the most famous example: it became policy after a single failed shoe-bomber incident in 2001. Billions of people have removed their shoes since. Security experts debate whether it has ever stopped anything.
We feel safer doing it. That feeling is the whole point — and the problem.
Online security has accumulated the same kind of theater over the decades. Rules get circulated, repeated, and repeated again until they feel like common sense — even when the original threat they addressed has changed, or when the rule itself creates a false sense of protection that stops people from addressing the real risk.
For seniors especially, this matters. The advice most people received when they first started using the internet was designed for the threats of that era — obvious phishing pages, obvious viruses, obvious Nigerian prince emails. That advice isn't wrong, exactly. It's just not where the danger is anymore.
The 3 "Safety" Habits That Don't Actually Protect You
Deleting Suspicious Emails Before Opening Them
This one feels intuitive. If you don't open it, you can't be harmed. Twenty years ago, that was partially true — some viruses could spread through email preview panes.
Modern email clients don't work that way. The real danger in a phishing email isn't in opening it — it's in clicking links or downloading attachments. Deleting without reading actually means you might be discarding legitimate messages you've flagged too cautiously.
But here's the bigger issue: your inbox isn't where your biggest risk lives anymore. Attackers don't need to trick you into opening anything. They often already have your username and password from a data breach at a company you've used — a grocery store loyalty program, a streaming service, a retailer — and they're quietly testing those credentials at your bank right now without ever sending you a single email.
Covering Your Webcam
This became popular advice after security researchers demonstrated that malware could remotely activate cameras. It's a real threat — for corporate espionage targets, political activists, and high-value individuals who have been specifically targeted with sophisticated attacks.
For most people? Criminals want your money, not a photo of you in your kitchen. The webcam tape does nothing against the attacks that are actually targeting seniors at scale: account takeover through stolen credentials, fake tech support calls, government impersonation, and investment fraud.
Cover it if you want — it costs nothing. But don't let it make you feel like you've done your security work for the day.
Changing Your Password Every 90 Days
This was once standard advice from corporate IT departments. The logic made sense when passwords were most often stolen by insiders with long-term access. Today, passwords are stolen instantly — through data breaches, phishing pages, or malware — and used or sold within hours.
Worse: the research shows that forced password changes make people less secure. Carnegie Mellon University published a study showing that people who are required to change passwords regularly start using predictable patterns. "Springtime1!" becomes "Summertime1!" becomes "Falltime1!" — and those patterns are easier to crack than a stable, strong password you set once and leave alone.
The only thing that matters is not how often you change your password. It's whether your password is unique to each website — so that a breach at one site can never unlock another.
What Hackers Actually Target (And Where Seniors Are Most Exposed)
Understanding where the real risk lives changes everything. Here's what the data actually shows.
Credential Stuffing
This is responsible for the majority of unauthorized account access, and most people have never heard of it.
When a company you've used — a retailer, a subscription service, a travel site — suffers a data breach, the stolen database (containing usernames and passwords) is sold on the dark web. Criminals buy these lists and run automated programs that try each username/password combination at banks, brokerages, and email providers. Millions of attempts per hour. No human typing required.
If you've ever reused a password across two websites, your accounts are probably on one of these lists right now. It has nothing to do with how careful you've been with your own email — it has to do with whether any company you trusted has ever been breached.
SIM Swapping
This one can drain a bank account in an afternoon, and most seniors have never heard of it.
A SIM swap is when a criminal calls your phone carrier — armed with just your name, address, and last four digits of your Social Security number, which are widely available from past data breaches — and convinces them to transfer your phone number to a SIM card the criminal controls. Our full SIM swap scam guide covers the warning signs and how to lock this down before it happens to you.
Once they have your phone number, they receive every text message your bank sends you for two-factor authentication. They reset your account passwords, pass the two-factor check with your phone number, and transfer funds. By the time you notice your phone has stopped working, the damage may already be done. (Our two-factor authentication setup guide explains why an authenticator app is safer here than text-message codes.)
Dark Web Exposure You Don't Know About
Every time a company you've done business with suffers a data breach, your personal information — name, email address, home address, date of birth, and sometimes Social Security number — ends up for sale on criminal marketplaces. The average American's information appears in multiple data breaches. Most people have no idea.
This isn't hypothetical. You can check right now by visiting haveibeenpwned.com and entering your email address — our step-by-step guide on finding out if your information was in a data breach walks through exactly what to do with the results. Most people are surprised by how many breaches list their information.
The 3 Things That Actually Protect You
1. Dark Web and Identity Monitoring That Watches What You Can't See
The most valuable thing you can do right now has nothing to do with changing your own behavior — it's getting an early-warning system that watches the places you can't access.
Services like Aura continuously monitor dark web marketplaces, criminal forums, and breach databases for your personal information. When your Social Security number, email, or financial account details appear where they shouldn't, you get an alert immediately — before the damage is done.
Aura also monitors your credit report, watches for changes (a common first sign of identity theft), tracks your bank accounts for suspicious transactions, monitors your home title for unauthorized deed transfers, and provides up to $1 million in identity theft insurance if something does slip through.
This is fundamentally different from the habits we discussed earlier. Instead of you trying to spot every threat manually, a system is watching automatically — covering the blind spots you can't cover yourself.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
2. A Unique Password for Every Account (The Only Way to Beat Credential Stuffing)
The single highest-impact change most people can make is also one of the simplest once it's set up: a different password for every website you use.
This completely eliminates your credential stuffing vulnerability. Even if one company you've used suffers a major breach, your bank, email, and other accounts stay safe — because the stolen password doesn't open them.
The only realistic way to do this is with a password manager. It stores a unique, randomly generated password for every site behind one master password that only you know. When you visit your bank's website, it automatically fills in your credentials. You never have to remember — or type — a complex password again. See our best password managers for seniors comparison and our step-by-step password manager setup guide to get started today.
Far from making things harder, most people find that a password manager makes logging into things faster than remembering passwords manually.
3. Locking Down Your Phone Number Against SIM Swapping
Call your phone carrier this week and ask them to:
- Add a PIN or passcode required before any account changes
- Enable "port freeze" or "number lock" to prevent transfers without your explicit in-store authorization
This one call eliminates most SIM swap risk. When a criminal tries to transfer your number, they'll hit a wall they can't talk their way around.
Separately: when you're using internet outside your home — at a coffee shop, library, doctor's waiting room, or hotel — your connection can be intercepted on shared networks. A VPN (Virtual Private Network) encrypts your traffic so it can't be read even if someone is watching the network. NordVPN works on your phone, tablet, and computer with a simple on/off button. The first month is free — worth using on your next trip away from home.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
The Retirement Savings Blind Spot
There's one threat worth calling out specifically because it disproportionately targets seniors: financial fraud aimed at retirement accounts.
Criminals know that many adults over 60 have spent decades building savings in IRAs, 401(k)s, and brokerage accounts. When credential stuffing or a SIM swap gives them access to an online brokerage, they can liquidate positions and initiate wire transfers in minutes. These funds are extremely difficult to recover.
One legitimate question to ask your financial advisor: should some portion of your retirement savings live outside the digital ecosystem entirely? Physical assets — including precious metals — are immune to online theft by definition. There's no login to crack, no SIM to swap, no password to steal.
If you're exploring that question, Augusta Precious Metals specializes in helping retirement investors move a portion of savings into gold or silver IRAs. They have an A+ BBB rating and specifically build in a mandatory educational period before any purchase decision — a design intended to prevent the pressure-tactics that scammers in the precious metals space are known for using.
This isn't investment advice. It's a reminder that your financial security has layers — and not all of them need to live online.
Affiliate Disclosure: This article may contain affiliate links. If you make a purchase through these links, we may earn a small commission at no extra cost to you. We only recommend products we genuinely believe in. This helps support our work and allows us to continue providing free content.
The Social Engineering Problem (The Threat No Software Catches)
Here's the conclusion that cuts deepest: the reason seniors are disproportionately targeted isn't technical sophistication. It's because most adults over 55 were raised with social norms that say: when someone in authority contacts you, you cooperate. You don't hang up. You don't question. You help.
Scammers exploit those norms deliberately. They use the language of authority (IRS, Medicare, your bank, the Social Security Administration). They use urgency ("your account will be closed in 24 hours"). They use shame ("don't tell your family — this is embarrassing"). They use affection (the grandparent scam specifically weaponizes love to bypass judgment).
No antivirus scan catches a convincing phone call. No webcam tape stops a fake Medicare representative.
The most protective thing you can learn is the short list of things legitimate institutions never do:
- Ask you to pay anything with gift cards
- Ask you to wire money to "protect" or "secure" it
- Ask you to keep a conversation secret from your family
- Threaten you with arrest or account closure on an inbound call
- Ask for remote access to your computer to fix a "virus"
When those things happen on a phone call, they are the scam. Every time.
Your Real Protection Plan — Three Steps This Week
Step 1: Check haveibeenpwned.com with your email address to see which breaches have your information. Then set up identity monitoring with Aura — credit, dark web, bank, and home title in one dashboard.
Step 2: Call your phone carrier and add a PIN and port freeze to your account. This is the SIM swap protection most people skip.
Step 3: Set up a password manager and start with your email and bank accounts. Those two protect everything downstream.
That's it. Three actions. They won't make you immune to every threat, but they address the threats that are actually targeting you — credential stuffing, SIM swaps, dark web exposure, and unmonitored account takeover — more effectively than any combination of webcam tape and 90-day password resets.
Stop performing safety. Start building it.
Last updated: 2026-06-30
Stay One Step Ahead — Without the Tech Jargon
Join thousands of adults over 55 who get our weekly ClearShield briefing: plain-English updates on the scams making the rounds, the tools that actually help, and the habits worth keeping. No scare tactics. No tech jargon. Just clear, honest information once a week.
Related reading
Online Safety After Losing a Spouse: A Step-by-Step Guide for Seniors
Grieving seniors are a top target for scammers. Here's how to protect your identity, finances, and accounts in the weeks and months after losing a spouse.
The Security Advice You're Following Is Theater — Here's What Actually Protects You
Most common cybersecurity tips look safe but do almost nothing. Learn which habits are security theater and what actually stops real threats to seniors.
Identity Theft Protection for Seniors: A Complete Safety Guide
Learn how to protect yourself from identity theft as a senior — what to watch for, what tools actually help, and what to do if it happens to you.