
Passport scans, tax filings, and a support ticket platform nobody secured right. An investigative breakdown for business leaders.
Ever notice how the biggest breaches are never announced, they are filed?
Not a press conference. Not a statement from leadership or, say, the CEO. You learn about one of the largest crimes this year o my when those responsible file A Form. Submitted to a state attorney general on a Wednesday in July, in the same stack as a dozen dental offices and a regional wePassport scans, tax filings, and a support ticket platform nobody secured right. An investigative breakdown for business leaders.
Ever notice how the biggest breaches are never announced, they are filed?
Not a press conference. Not a statement from leadership or, say, the CEO. You learn about one of the largest crimes this year o my when those responsible file A Form. Submitted to a state attorney general on a Wednesday in July, in the same stack as a dozen dental offices and a regional wellness clinic. That is how the world learned that one of the four largest accounting firms on earth had client tax documents walk out the door.
Ernst and Young filed breach notifications with the California Attorney General on July 15, 2026, and with Vermont regulators the following day, according to reporting from Cyberpress and Cybersecurity News.
The notification letter itself was dated July 13.
EY employs roughly 406,000 people. Booked $53.2 billion in global revenue last year.
A company that size has a security budget larger than most of the businesses reading this newsletter have in total revenue.
It did not matter. It never does. That's why Cyber Crime Junkies exists and why I wrote the crime trilogy Moving Target.Because nobody attacked EY in order to hit EY.
The two week window nobody was watching
Reconstruct the timeline and the story gets worse, not better.
An unauthorized third party accessed a third-party IT service management platform between March 28 and April 12, 2026, and downloaded multiple documents. EY did not notice on March 28. EY did not notice on April 12. EY identified anomalous activity on April 23, according to the breach notification quoted by [SecurityAffairs](https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html).
Eleven days after the intruder finished and left.Sit with that gap. Somebody had roughly sixteen days inside a system, took what they wanted, packed up, and was gone almost two weeks before anyone at a Big Four firm raised a hand. Then it took until mid July for the people whose documents were taken to find out.
An IT service management platform, in plain language, is the help desk ticket system. When an EY employee working on a client tax return hits a technical problem, they open a ticket. To explain the problem, they attach the file causing it. That file is a tax document. Containing a name, an address, a Social Security number, investment holdings, income figures. Everything a criminal needs to become you at the IRS.
Multiply that by every ticket, every tax season, every office. The help desk quietly became a filing cabinet holding copies of the most sensitive paperwork the firm touches, and nobody drew it on the org chart that way.
[Cybernews](https://cybernews.com/security/ey-data-breach-tax-documents/) reported that EY notified affected individuals through the California Department of Justice filing, confirming attackers reached a vendor platform used to support employees performing client tax work. [SC Media](https://www.scworld.com/brief/ernst-young-data-breach-exposes-client-tax-information) reported the exposed material included personal and financial data used in tax filings, with the exact nature of the data still undisclosed.
What is Confirmed
Being precise matters here, because the internet is already filling the gaps with guesses.
Confirmed: EY detected anomalous activity on its networks on April 23, 2026, and opened an investigation with outside cybersecurity experts.
Confirmed: that investigation determined an unauthorized third party accessed a third-party IT service management platform between March 28 and April 12, and downloaded multiple documents.
Confirmed: the documents may have contained personal and financial information used to prepare tax filings. Reporting from [Mallory](https://www.mallory.ai/stories/019f709d-e306-7dc1-a8cb-9258476bef76) adds that exposed data included information tied to some individuals’ investment holdings with EY institutional clients.
Confirmed: EY says it secured its systems, removed the unauthorized access, and notified federal law enforcement.
Confirmed: EY is offering 24 months of identity monitoring and restoration services through Experian.
Confirmed: EY stated it has no evidence of misuse of the files and no indication that any specific individual was targeted.
Confirmed: the compromised environment belonged to a vendor, not to EY.
But Wait, There's More: What the Filings Hide
Now the part that should bother a business leader more than any of the above.
Not disclosed: which vendor. EY has not named the third-party platform that was compromised. Every other organization running that same product is currently unable to check whether they are exposed to the same problem. A commenter on the BleepingComputer piece made the observation bluntly, and it is a fair one. Withholding the vendor name protects the vendor. It does not protect the next victim.
Not disclosed: how many people are affected. No number appears in the public reporting. Not an estimate, not a range.
Not disclosed: whether exposure stops at the United States. [SC Media](https://www.scworld.com/brief/ernst-young-data-breach-exposes-client-tax-information) noted EY has not specified whether the breach extends beyond its U.S. client base. EY operates in more than 150 countries.
Not disclosed: who did it. No ransomware group has claimed responsibility. EY has not said whether ransomware was involved at all, per Cybernews.
That silence cuts two ways. Either the extortion demand is still in negotiation, or the documents were quietly taken for resale and nobody is going to announce anything.
Not disclosed: what the attacker did during those sixteen days beyond downloading. Access and exfiltration are two different findings. Persistence is a third.
Not disclosed in any verifiable source I could locate: the widely circulated October 31, 2026 deadline to enroll in the Experian monitoring. It appears in secondary summaries. I could not confirm it in the primary reporting. If you received a letter, the date on your letter governs. Do not take mine or anyone else’s for it.
That is a lot of blank space in a disclosure from a firm that audits other companies’ controls for a living.
Rewind to 2023, because this already happened
Here is what makes the 2026 incident more than a bad news cycle. EY has been standing in this exact spot before.
In May 2023, the Russian speaking crime group Clop began exploiting a previously unknown flaw in MOVEit Transfer, a file transfer product made by Progress Software that organizations use to move large sensitive files between parties. The attacks began around Memorial Day weekend, timed for a long American holiday when nobody is watching the console. Progress patched on May 31.
Too late by then. Clop had already swept through.By July 2023, [BankInfoSecurity](https://www.bankinfosecurity.com/clop-crime-group-adds-62-ernst-young-clients-to-leak-sites-a-22514) reported that 62 clients of Ernst and Young had been added to Clop’s data leak site. The stolen material ran to roughly 3 terabytes and included financial reports and accounting documents from client folders, passport scans, visa scans, risk and asset management documents, contracts and agreements, credit agreements, audit reports, and account balances.
Read that inventory again slowly. Passport scans. Credit agreements. Audit reports.
The named clients were heavily Canadian and heavily recognizable. [Cybernews](https://cybernews.com/security/td-ameritrade-ernst-young-moveit-attacks-data-published/) listed Air Canada, Constellation Software, Laurentian Bank, Staples Canada, Sun Life, TD Bank, UPS Canada, and the University of Toronto among them. Clop posted a taunt advertising the EY data for sale, then published sample archives when negotiations went nowhere.
An EY spokesperson at the time called the attack limited and said the vast majority of systems using the transfer service across the global organization were not compromised, per BankInfoSecurity.
Both statements can be technically accurate and still miss the point entirely. The percentage of systems compromised was small. The sensitivity of what sat inside them was not.
MOVEit did not stop at EY. By January 2024, [Cybersecurity Dive](https://www.cybersecuritydive.com/news/progress-software-moveit-meltdown/703659/) counted breaches or downstream exposures at more than 2,700 organizations affecting the personal data of more than 93 million people. [Emsisoft](https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/) found finance and professional services accounted for 13.3 percent of known victims. One vulnerability in one file transfer tool, and a hole opened under a third of the global economy.
See more about The MoveIt Breach at Cyber Crime Junkies:
What is NOT a Breach
There is also a third episode people keep folding into the story incorrectly. In October 2025, researchers found a 4TB SQL Server backup tied to EY’s Italian entity sitting publicly accessible on Microsoft Azure. That was a configuration mistake, not an intrusion, and it is a separate matter from the 2026 support platform breach.
Three incidents. Three completely different failure modes. One common thread running through all of them.
The rackets do not pick locks anymore
Cybercriminals are not hooded loners in basements. They are companies. They have specialists, revenue targets, customer service functions, and a division of labor that would look familiar to anyone who has run a sales org.
Clop has operated since 2019 under several names in the research community, and typically hunts organizations with revenue above $5 million, according to Cybernews reporting on U.S. official assessments. The group even advertised penetration testing services to its victims after breaking in. That is not a joke about criminals. That is a business bolting on an upsell.
And businesses optimize. Once you understand that, the strategy becomes obvious.
Breaking into Ernst and Young directly is expensive. Hundreds of thousands of employees, a real security operations center, real budget, real detection. Breaking into the ticketing vendor EY bought from is cheap. Smaller company. Smaller team. One environment holding attachments from thousands of client engagements at once.
Attack one, reach all of them. The crooks did the math on economies of scale before most boards did.
In 2023 they went through Progress Software to reach EY’s clients. In 2026 they went through an unnamed service management vendor to reach EY’s tax clients. Same play, different hallway. They stopped kicking down the front door because the vendor entrance is unlocked and leads to the same room.
Now apply that to a 40 person firm in Little Rock or Nashville or Cincinnati. You have a payroll processor, a bookkeeping platform, an e-signature service, a cloud backup provider, a managed print vendor, an outsourced help desk. Every one of them holds copies of your documents. Every one of them is a smaller, softer target than you are, and several of them are smaller and softer than you assume.
You did not sign a vendor contract. You signed a set of keys to your filing cabinet.
The Risk Arithmetic for a Small Company
A firm the size of EY absorbs this. It has a general counsel, a communications team, a breach response retainer, and a line item for 24 months of Experian for an undisclosed number of people. The stock does not move. The clients mostly stay.
A 60 person business does not absorb it. It gets the same notification letter obligations, the same state attorney general filings, the same phone calls from angry clients, and none of the machinery. And it usually finds out later than EY did, because it has nobody watching at 2 a.m. on a Saturday of a holiday weekend.
Sixteen days of access. Eleven days to detect. Three months to notify. Those were the numbers at a firm with a genuine security program.
What are yours? Most owners I ask cannot answer, and that answer is itself the finding.
One clear action
If you got a notice from EY, treat it as real, not as junk mail from a law firm. Change any password you have reused anywhere. Turn on multifactor authentication, meaning a second proof of identity beyond your password, on every financial and email account tied to those records. Then file an IRS Identity Protection PIN, because tax documents in criminal hands become fraudulent returns filed in your name next filing season. Watch for it early, not in April.
If you run a business, do this instead, and do it this month.
Write down every outside vendor that touches, stores, or transmits your client documents. Not the vendors you pay the most. The vendors that hold paperwork. Payroll, accounting platform, document management, help desk, backup, e-signature, marketing automation. Most owners get to eleven or twelve names and then remember four more they forgot.
Then ask each one three questions in writing. Where does our data live. How fast do you notify us if you are breached, in hours. Who else can see our files inside your environment.
Any vendor that cannot answer within a week has just told you the answer.
That list is the single most valuable hour of security work a small business can do, and it costs nothing but the hour. If you want somebody to sit on the other side of the table while you build it, that is the sort of thing a virtual chief security officer does at NetGain, and it is a lot cheaper than the letter you would otherwise be writing to your clients.
What this story actually is
The headline says EY had a breach. That framing lets every reader who does not audit Fortune 500 companies scroll past.
The story underneath is that the paperwork of an entire economy now sits in third-party platforms that nobody in the chain of custody has ever inspected, and organized crime groups figured that out several years before most boards did. EY is not the cautionary tale. EY is the demonstration, run at a scale large enough that the rest of us can finally see the mechanics.
Two breaches, three years apart, both through somebody else’s software. Nobody had to touch EY’s front door either time.
One bad ticket system, and the paperwork starts walking.
Why This Story Hits Home
I have sat in the room after. I have watched a founder explain to his wife why the retirement account is gone. I have listened to a sixty-eight-year-old woman apologize to me, apologize, for being defrauded by an organization with a customer service department and a training program. I have watched executives get told the voice on the recording is theirs and see the exact moment they realize it is.
Nobody needed a framework in that room.
They needed somebody to have told them the story before it happened to them.
That is the entire reason these books exist.
It was always about what it costs each of us to be visible.
Your face. Your voice. Your address. Your kid's school. Your calendar. Your habits. Every one of them is now an input into a machine that can imitate you, and imitation is all a criminal needs, because the person on the other end of the phone was never verifying you.
They were recognizing you.
Recognition is not verification. It never was. We just never had to know the difference before.
Stevie Parker learned the difference in a conference room with the shades pulled down.
You can learn it for the price of a paperback.
Book One: Moving Target, The Art of Online Camouflage. How they find you, and how she was found.
Special Author Edition Hardcover (30% off)
Book Two: Moving Target, The Obedient Machine. What happens when the machine you trusted does exactly what you told it.
Also available as Audiobooks.
Book Three: Moving Target, Ghost and the Machine. Available for PreSale. Releases on September 22nd. How she vanished, and what she saw from the outside.
Books One and Two are available now, everywhere books are sold. Book Three arrives September 22, one week before Cybersecurity Awareness Month, and the presale is open at CyberCrimeJunkies.com.
Grab any one of them. They all can be read at any point.
Then go look at what a stranger can find out about you in eleven minutes and a hundred and ninety-nine dollars.
She did not get to choose whether she became a target.
You still can.
Move. They miss.
David Dean Mauro | Cyber Crime Junkies | Chaos Brief | FBI InfraGard | Moving Target Trilogy | NetGain Technologiesllness clinic. That is how the world learned that one of the four largest accounting firms on earth had client tax documents walk out the door.
Ernst and Young filed breach notifications with the California Attorney General on July 15, 2026, and with Vermont regulators the following day, according to reporting from Cyberpress and Cybersecurity News.
The notification letter itself was dated July 13.
EY employs roughly 406,000 people. Booked $53.2 billion in global revenue last year.
A company that size has a security budget larger than most of the businesses reading this newsletter have in total revenue.
It did not matter. It never does. That's why Cyber Crime Junkies exists and why I wrote the crime trilogy Moving Target.Because nobody attacked EY in order to hit EY.
The two week window nobody was watching
Reconstruct the timeline and the story gets worse, not better.
An unauthorized third party accessed a third-party IT service management platform between March 28 and April 12, 2026, and downloaded multiple documents. EY did not notice on March 28. EY did not notice on April 12. EY identified anomalous activity on April 23, according to the breach notification quoted by [SecurityAffairs](https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html).
Eleven days after the intruder finished and left.Sit with that gap. Somebody had roughly sixteen days inside a system, took what they wanted, packed up, and was gone almost two weeks before anyone at a Big Four firm raised a hand. Then it took until mid July for the people whose documents were taken to find out.
An IT service management platform, in plain language, is the help desk ticket system. When an EY employee working on a client tax return hits a technical problem, they open a ticket. To explain the problem, they attach the file causing it. That file is a tax document. Containing a name, an address, a Social Security number, investment holdings, income figures. Everything a criminal needs to become you at the IRS.
Multiply that by every ticket, every tax season, every office. The help desk quietly became a filing cabinet holding copies of the most sensitive paperwork the firm touches, and nobody drew it on the org chart that way.
[Cybernews](https://cybernews.com/security/ey-data-breach-tax-documents/) reported that EY notified affected individuals through the California Department of Justice filing, confirming attackers reached a vendor platform used to support employees performing client tax work. [SC Media](https://www.scworld.com/brief/ernst-young-data-breach-exposes-client-tax-information) reported the exposed material included personal and financial data used in tax filings, with the exact nature of the data still undisclosed.
What is Confirmed
Being precise matters here, because the internet is already filling the gaps with guesses.
Confirmed: EY detected anomalous activity on its networks on April 23, 2026, and opened an investigation with outside cybersecurity experts.
Confirmed: that investigation determined an unauthorized third party accessed a third-party IT service management platform between March 28 and April 12, and downloaded multiple documents.
Confirmed: the documents may have contained personal and financial information used to prepare tax filings. Reporting from [Mallory](https://www.mallory.ai/stories/019f709d-e306-7dc1-a8cb-9258476bef76) adds that exposed data included information tied to some individuals’ investment holdings with EY institutional clients.
Confirmed: EY says it secured its systems, removed the unauthorized access, and notified federal law enforcement.
Confirmed: EY is offering 24 months of identity monitoring and restoration services through Experian.
Confirmed: EY stated it has no evidence of misuse of the files and no indication that any specific individual was targeted.
Confirmed: the compromised environment belonged to a vendor, not to EY.
But Wait, There's More: What the Filings Hide
Now the part that should bother a business leader more than any of the above.
Not disclosed: which vendor. EY has not named the third-party platform that was compromised. Every other organization running that same product is currently unable to check whether they are exposed to the same problem. A commenter on the BleepingComputer piece made the observation bluntly, and it is a fair one. Withholding the vendor name protects the vendor. It does not protect the next victim.
Not disclosed: how many people are affected. No number appears in the public reporting. Not an estimate, not a range.
Not disclosed: whether exposure stops at the United States. [SC Media](https://www.scworld.com/brief/ernst-young-data-breach-exposes-client-tax-information) noted EY has not specified whether the breach extends beyond its U.S. client base. EY operates in more than 150 countries.
Not disclosed: who did it. No ransomware group has claimed responsibility. EY has not said whether ransomware was involved at all, per Cybernews.
That silence cuts two ways. Either the extortion demand is still in negotiation, or the documents were quietly taken for resale and nobody is going to announce anything.
Not disclosed: what the attacker did during those sixteen days beyond downloading. Access and exfiltration are two different findings. Persistence is a third.
Not disclosed in any verifiable source I could locate: the widely circulated October 31, 2026 deadline to enroll in the Experian monitoring. It appears in secondary summaries. I could not confirm it in the primary reporting. If you received a letter, the date on your letter governs. Do not take mine or anyone else’s for it.
That is a lot of blank space in a disclosure from a firm that audits other companies’ controls for a living.
Rewind to 2023, because this already happened
Here is what makes the 2026 incident more than a bad news cycle. EY has been standing in this exact spot before.
In May 2023, the Russian speaking crime group Clop began exploiting a previously unknown flaw in MOVEit Transfer, a file transfer product made by Progress Software that organizations use to move large sensitive files between parties. The attacks began around Memorial Day weekend, timed for a long American holiday when nobody is watching the console. Progress patched on May 31.
Too late by then. Clop had already swept through.By July 2023, [BankInfoSecurity](https://www.bankinfosecurity.com/clop-crime-group-adds-62-ernst-young-clients-to-leak-sites-a-22514) reported that 62 clients of Ernst and Young had been added to Clop’s data leak site. The stolen material ran to roughly 3 terabytes and included financial reports and accounting documents from client folders, passport scans, visa scans, risk and asset management documents, contracts and agreements, credit agreements, audit reports, and account balances.
Read that inventory again slowly. Passport scans. Credit agreements. Audit reports.
The named clients were heavily Canadian and heavily recognizable. [Cybernews](https://cybernews.com/security/td-ameritrade-ernst-young-moveit-attacks-data-published/) listed Air Canada, Constellation Software, Laurentian Bank, Staples Canada, Sun Life, TD Bank, UPS Canada, and the University of Toronto among them. Clop posted a taunt advertising the EY data for sale, then published sample archives when negotiations went nowhere.
An EY spokesperson at the time called the attack limited and said the vast majority of systems using the transfer service across the global organization were not compromised, per BankInfoSecurity.
Both statements can be technically accurate and still miss the point entirely. The percentage of systems compromised was small. The sensitivity of what sat inside them was not.
MOVEit did not stop at EY. By January 2024, [Cybersecurity Dive](https://www.cybersecuritydive.com/news/progress-software-moveit-meltdown/703659/) counted breaches or downstream exposures at more than 2,700 organizations affecting the personal data of more than 93 million people. [Emsisoft](https://www.emsisoft.com/en/blog/44123/unpacking-the-moveit-breach-statistics-and-analysis/) found finance and professional services accounted for 13.3 percent of known victims. One vulnerability in one file transfer tool, and a hole opened under a third of the global economy.
See more about The MoveIt Breach at Cyber Crime Junkies:
What is NOT a Breach
There is also a third episode people keep folding into the story incorrectly. In October 2025, researchers found a 4TB SQL Server backup tied to EY’s Italian entity sitting publicly accessible on Microsoft Azure. That was a configuration mistake, not an intrusion, and it is a separate matter from the 2026 support platform breach.
Three incidents. Three completely different failure modes. One common thread running through all of them.
The rackets do not pick locks anymore
Cybercriminals are not hooded loners in basements. They are companies. They have specialists, revenue targets, customer service functions, and a division of labor that would look familiar to anyone who has run a sales org.
Clop has operated since 2019 under several names in the research community, and typically hunts organizations with revenue above $5 million, according to Cybernews reporting on U.S. official assessments. The group even advertised penetration testing services to its victims after breaking in. That is not a joke about criminals. That is a business bolting on an upsell.
And businesses optimize. Once you understand that, the strategy becomes obvious.
Breaking into Ernst and Young directly is expensive. Hundreds of thousands of employees, a real security operations center, real budget, real detection. Breaking into the ticketing vendor EY bought from is cheap. Smaller company. Smaller team. One environment holding attachments from thousands of client engagements at once.
Attack one, reach all of them. The crooks did the math on economies of scale before most boards did.
In 2023 they went through Progress Software to reach EY’s clients. In 2026 they went through an unnamed service management vendor to reach EY’s tax clients. Same play, different hallway. They stopped kicking down the front door because the vendor entrance is unlocked and leads to the same room.
Now apply that to a 40 person firm in Little Rock or Nashville or Cincinnati. You have a payroll processor, a bookkeeping platform, an e-signature service, a cloud backup provider, a managed print vendor, an outsourced help desk. Every one of them holds copies of your documents. Every one of them is a smaller, softer target than you are, and several of them are smaller and softer than you assume.
You did not sign a vendor contract. You signed a set of keys to your filing cabinet.
The Risk Arithmetic for a Small Company
A firm the size of EY absorbs this. It has a general counsel, a communications team, a breach response retainer, and a line item for 24 months of Experian for an undisclosed number of people. The stock does not move. The clients mostly stay.
A 60 person business does not absorb it. It gets the same notification letter obligations, the same state attorney general filings, the same phone calls from angry clients, and none of the machinery. And it usually finds out later than EY did, because it has nobody watching at 2 a.m. on a Saturday of a holiday weekend.
Sixteen days of access. Eleven days to detect. Three months to notify. Those were the numbers at a firm with a genuine security program.
What are yours? Most owners I ask cannot answer, and that answer is itself the finding.
One clear action
If you got a notice from EY, treat it as real, not as junk mail from a law firm. Change any password you have reused anywhere. Turn on multifactor authentication, meaning a second proof of identity beyond your password, on every financial and email account tied to those records. Then file an IRS Identity Protection PIN, because tax documents in criminal hands become fraudulent returns filed in your name next filing season. Watch for it early, not in April.
If you run a business, do this instead, and do it this month.
Write down every outside vendor that touches, stores, or transmits your client documents. Not the vendors you pay the most. The vendors that hold paperwork. Payroll, accounting platform, document management, help desk, backup, e-signature, marketing automation. Most owners get to eleven or twelve names and then remember four more they forgot.
Then ask each one three questions in writing. Where does our data live. How fast do you notify us if you are breached, in hours. Who else can see our files inside your environment.
Any vendor that cannot answer within a week has just told you the answer.
That list is the single most valuable hour of security work a small business can do, and it costs nothing but the hour. If you want somebody to sit on the other side of the table while you build it, that is the sort of thing a virtual chief security officer does at NetGain, and it is a lot cheaper than the letter you would otherwise be writing to your clients.
What this story actually is
The headline says EY had a breach. That framing lets every reader who does not audit Fortune 500 companies scroll past.
The story underneath is that the paperwork of an entire economy now sits in third-party platforms that nobody in the chain of custody has ever inspected, and organized crime groups figured that out several years before most boards did. EY is not the cautionary tale. EY is the demonstration, run at a scale large enough that the rest of us can finally see the mechanics.
Two breaches, three years apart, both through somebody else’s software. Nobody had to touch EY’s front door either time.
One bad ticket system, and the paperwork starts walking.
Why This Story Hits Home
I have sat in the room after. I have watched a founder explain to his wife why the retirement account is gone. I have listened to a sixty-eight-year-old woman apologize to me, apologize, for being defrauded by an organization with a customer service department and a training program. I have watched executives get told the voice on the recording is theirs and see the exact moment they realize it is.
Nobody needed a framework in that room.
They needed somebody to have told them the story before it happened to them.
That is the entire reason these books exist.
It was always about what it costs each of us to be visible.
Your face. Your voice. Your address. Your kid's school. Your calendar. Your habits. Every one of them is now an input into a machine that can imitate you, and imitation is all a criminal needs, because the person on the other end of the phone was never verifying you.
They were recognizing you.
Recognition is not verification. It never was. We just never had to know the difference before.
Stevie Parker learned the difference in a conference room with the shades pulled down.
You can learn it for the price of a paperback.
Book One: Moving Target, The Art of Online Camouflage. How they find you, and how she was found.
Special Author Edition Hardcover (30% off)
Book Two: Moving Target, The Obedient Machine. What happens when the machine you trusted does exactly what you told it.
Also available as Audiobooks.
Book Three: Moving Target, Ghost and the Machine. Available for PreSale. Releases on September 22nd. How she vanished, and what she saw from the outside.
Books One and Two are available now, everywhere books are sold. Book Three arrives September 22, one week before Cybersecurity Awareness Month, and the presale is open at CyberCrimeJunkies.com.
Grab any one of them. They all can be read at any point.
Then go look at what a stranger can find out about you in eleven minutes and a hundred and ninety-nine dollars.
She did not get to choose whether she became a target.
You still can.
Move. They miss.
David Dean Mauro | Cyber Crime Junkies | Chaos Brief | FBI InfraGard | Moving Target Trilogy | NetGain Technologies
