Last week we wrote about passwords, data breaches and the uncomfortable fact that many of our personal details are already scattered across far too many databases. It is easy to look at all that and picture hackers, giant corporations, government agencies and shadowy criminal groups as the main danger.
They are all part of the problem. But in day-to-day life, the biggest risk to our privacy is often much closer to home: people. Sometimes it is a scammer calling at the right moment. Sometimes it is a business employee making a mistake. Sometimes it is a friend sharing something they should not. And, more often than we like to admit, it is us giving away a little more information than we needed to.
That is not meant as blame. It is actually the good news. We cannot personally force every company to secure its systems properly, but we can get better at recognising the situations where our information, money and accounts are most at risk.
Hackers Usually Want a Crowd, Not You Personally
Most hackers are not sitting around studying your life in detail. They want scale: thousands of passwords from a data breach, thousands of email addresses, or thousands of people receiving the same convincing scam message. That is why predictable passwords and reused logins are so useful to them. As we saw with several customers recently, a password based on a car model, familiar number, pet or birthday can feel personal and memorable, but it is exactly the sort of thing automated password tools try. If that password is also used on more than one website, a breach at one forgotten online shop can become access to email, Facebook, Microsoft or other important accounts.
The same applies to scam emails and text messages. A criminal does not need to know everything about you. A leaked name, email address, phone number and recent purchase can be enough to make a fake delivery notice, bank alert or Microsoft warning sound believable.
Technology helps here. Good security software, software updates, strong unique passwords and two-factor authentication all matter. But the first layer of protection is still a moment of healthy suspicion: “Why is this person asking me for this, and how do I know they are really who they say they are?”
The People We Trust Can Still Expose Us
Privacy is not only about strangers breaking into systems. It is also about what happens after we willingly share something with another person. A private message can be screenshotted. A video call can be recorded. A photo of a driver licence sent to a landlord, recruiter, agent or business can end up sitting in an inbox for years. A family member may post holiday photos that reveal you are away. Someone selling an item online might share a screenshot that includes an address, phone number or bank detail without noticing.
None of this needs bad intentions. People are busy, careless and sometimes overly trusting. Social media makes it particularly easy to forget that an audience is still an audience, even if a post is limited to friends or a private group. Privacy settings are useful, but they are not a guarantee that something will stay private once another person can see it.
The same applies when someone is helping you with a computer problem. A legitimate technician should not need your banking password, your MyGov login or a code sent by your bank. If somebody calls unexpectedly claiming to be from Microsoft, Telstra, Amazon, the NBN or your bank and wants remote access to your computer, the safest answer is no. Hang up and contact the organisation yourself using a number from its official website or statement.
Businesses and Government Still Have a Duty
None of this lets companies off the hook. They ask us for enormous amounts of information just to access ordinary services: driver licences, passport details, Medicare numbers, dates of birth, home addresses and payment details. They have a responsibility to collect only what they genuinely need, protect it properly and not keep it forever because storage is cheap. When a business suffers a breach, customers are often told to be vigilant, change passwords and watch their bank accounts. Fair advice, but it can feel backwards when the customer had no choice but to provide the information in the first place. A password can be changed. Your date of birth, old address or identity-document number cannot be changed quite so easily.
Banks, telcos, government agencies and major companies can have good systems, but they are not perfect. Their processes may catch a suspicious payment or account takeover attempt; they may also miss it. That is why it is risky to assume somebody else will always step in before harm is done. We have become a little too comfortable believing that a company, bank or government department will fix the problem because they have the resources and the official logo. Sometimes they will help. But when money is transferred to a scammer, a phone number is taken over, or an account is compromised, the customer is usually the person left spending days or months sorting it out.
The Biggest Weak Point is Often a Rushed Decision
Scammers understand this very well. They do not always need to defeat complicated security systems. They only need a person to be distracted, scared, embarrassed or in a hurry.
- “The payment details have changed and settlement is today.”
- “Your account will be closed unless you act now.”
- “Your computer has a virus. Give us remote access and we’ll fix it.”
- “Don’t tell anyone; this is a secure investigation.”
Those messages work because they create pressure. The scammer wants you to act before you stop and verify the story. This is also why Business Email Compromise scams are so damaging: an attacker gets into a real company email account, reads the conversation, then sends a payment request that looks completely genuine. For any unexpected request involving money, passwords, verification codes or identity documents, slow down. Call the person or business on a known number. Do not reply to the message or use the phone number it provides. A two-minute check can prevent a very expensive mistake.
This is Not About Becoming Paranoid
You do not need to delete every account, abandon online banking or treat every person with suspicion. The aim is simply to be more deliberate about what you share, where you share it and who you trust with it. Before sending a document, ask whether it is really necessary. Before posting something personal, ask whether you would be comfortable with it being forwarded. Before approving a login or reading out a code, ask who benefits from the urgency. And before creating another password based on something familiar from your own life, remember last week’s lesson: memorable for you can also mean predictable for somebody else.
The best part is that these are things you can control. Stronger passwords, a password manager, two-factor authentication, regular updates and a habit of checking before you act will not make you invincible. They will make you much less convenient to scam, hack or manipulate – and most criminals will move on to somebody easier. You don’t need to outrun the bear, you just need to outrun the guy next to you.