Showing posts with label cyber attack. Show all posts
Showing posts with label cyber attack. Show all posts

Saturday, July 17, 2021

'Hacking" Stances

A couple of Saturdays back I discovered that one of my online accounts had been “hacked.” 

The good news is that I “discovered” this via transaction emails confirming what appeared to be purchases—a half dozen of them… for various, small-ish (though not small) amounts… all about 4:00 a.m. on a Saturday morning. And trust me, while the pandemic has certainly fueled my online purchases, both the number and the timing were not normal behaviors (nor was the Chinese text in those emails).

The even better news was that I was able to flag those transactions via the provider—and via my credit card company—almost immediately (apparently the foreign hackers and I were the only ones awake at that hour). Even though there was no damage done by this incursion (aside from some temporary heartburn), it brought home to me again the importance of protecting all of my online accounts.


Like many, perhaps most, of you, I have long found managing the sheer volume of online passwords and varying criteria daunting. Oddly, the ever more complex (and varying) password requirements—different lengths, different combinations of caps, numbers and “special” characters, not to mention forced resetting of those passwords—has, if anything, tended to leave me being more casual than I should be regarding some of the practices I know are important. That said, and while I am far from a cybersecurity expert, I try to stay current on the latest advice from those who are—and trust me, it’s a moving target. 

As it turns out, the Labor Department recently issued a set of guidance on the issue of cybersecurity,[i] and while our more immediate focus here has been on the expectations of plan sponsor/fiduciaries, advisors and recordkeepers (particularly in view of the recent reports of Labor Department audits on these practices), my recent experience reminded me that it’s worth noting—and sharing here—the list of “online security tips” for participants included in that guidance. 

Use Strong And Unique Passwords

The most detailed of the tips is also perhaps the most important. The Labor Department recommends that you “use letters (both upper and lower case), numbers, and special characters”—which is increasingly mandated anyway—and to “use 14 or more characters.” We’re also advised not to use letters and numbers in sequence (like “1234” or “abc”), to change passwords every 120 days (or if there’s a security breach—p.s. you probably won’t hear about it until at least 30 days after it’s been detected), and—despite all these strictures—to not only not write it down, but not to “share, reuse, or repeat passwords.”

This is both the most obvious—and in my experience—most nettlesome of the recommendations. Of course, the more complicated the password, the less likely a hacker is to be able to “hack” it. And, unfortunately, the less likely you are to be able to remember it. I’ve seen suggestions on how best to manage this—most commonly these days (including from the Labor Department) the suggestion to use a password “manager.” 

But for those who find that process intimidating (or inconvenient), what I’ve found most useful is the idea of using phrases that are familiar or meaningful to you, but would amount to gibberish in a password field. Something like (for those who took typing classes in high school) “thequickbrownfoxjumped,” particularly if combined with some kind of numerical reference (perhaps “thequickbrownfoxjumpedh1.” You can also use a random combination of words like “fleetwoodChicago1978” (which happens to be when/where I saw Fleetwood Mac perform), or maybe a random combination of month and year (though avoid birthdates, anniversaries, and such)—perhaps something like “januarY2019” (I try to capitalize something other than the first letter). One other neat trick is to use spellings that may mean something to you, but aren’t in the dictionary—like dixshunary, or Septimber. 

The challenge, of course, will be remembering which (random) combination(s) you used for what. But if that leads you to write it down, keep that in a safe place—and don’t store it on your computer! 

Use Multi-Factor Authentication

The very first thing I did with the account that had been hacked (once I had reestablished control) was to set up multi-factor authentication. I have made a practice of doing this with all my accounts, and can only assume that years back, when I set up the account in question, they either didn’t have it available, or I considered it too much of a hassle to set up. No more.

Basically, this means that when you log on and/or initiate a transaction, the system requires the confirmation of a second credential. The most common set up would be to send you a code via text (to a phone number you’ve established on file) or to an email address. If you don’t have this set up yet on your online accounts—do it right away. It’s a life (and savings) saver. And always, always, always, be sure that you are set up to receive notifications any time your account or account information has been changed! Oh—and it bears noting here that the password to your email account is perhaps the most important—because if they hack your email account as well, they can intercept those confirmation emails, and delete them before you even know it has happened! 

Keep Personal Contact Information Current

Odds are the accounts you access with some frequency have current contact information. The problem is, retirement savings often don’t fall into the “with some frequency” category. Let’s face it, we’ve long been advised that we shouldn’t be constantly checking in on our retirement savings, but there’s nothing that says you can’t look without touching. Particularly if you have left some 401(k) balances “behind” with a prior employer.  

Close Or Delete Unused Accounts

It’s unfortunately not uncommon for folks to use the same password(s) for multiple accounts—but using those same passwords for accounts you don’t use (or perhaps don’t even remember using) and ones with current, and perhaps monetary implications, can leave you exposed. You may have gotten one of those (badly spelled) emails from individuals who claim to have accessed your webcam and/or planted some kind of “trojan horse” on your PC, and by way of proof—show you the password that they’ve stolen. While those kind of intrusions are certainly possible, odds are what they did instead was tap into your email—and password—from an old blogging account or such that you simply walked away from years ago. 

There are a couple of easy ways to check out your potential vulnerability—https://haveibeenpwned.com/ or https://monitor.firefox.com/

One the DOL ‘Missed’

Now, for all the value in the tips provided, there is some irony in one they missed—the importance of logging on to your 401(k) account(s) regularly. 

If you have an online account—and these days you may have more than one—and particularly following a change in recordkeepers (and with the recent wave of consolidation there’s been a lot of that[ii]), it is imperative to log on ASAP, and not only establish the unique password noted above, but also set up the multi-factor authentication, provide answers to key security questions, and make sure that you are set up for electronic notifications of any changes to your account. Did I say ASAP? I mean now

After all, if you don’t lay claim to that account—quickly—it’s all the easier for a hacker to do so.   

- Nevin E. Adams, JD


[i] It’s worth acknowledging here that recently there have been numerous situations where plan fiduciaries have been sued for various account intrusions, including participant accounts at Abbott Laboratories (Split Decisions in 401(k) Theft Suit for Plan Sponsor, RK), Estee Lauder (Recordkeeper, Plan Sponsor Charged in 401(k) Account Theft), MandMarblestone Group (Court Backs TPA Counterclaim on Plan Sponsor in 401(k) Cyber Theft Case) and Boeing (Man Charged with Retirement Account Thefts).

[ii] As an additional note of caution, I have now had two of my 401(k) accounts converted (by and from different providers) without the beneficiary information. Now, sooner or later, should it become necessary, the paperwork I submitted once upon a time will surely suffice (and since my spouse is my beneficiary, it shouldn’t matter)—but it’s a good idea to double check such things while you are setting up that password, etc.

Saturday, May 08, 2021

Guidance 'Counseling'

 When the Labor Department issued last month what it called “new guidance” that it further described as “the first time the department’s Employee Benefits Security Administration has issued cybersecurity guidance”—well, I, for one, was expecting… guidance. 

However, rather than an advisory opinion, information letter or even a field assistance bulletin, it turned out instead to be three documents outlining what were termed “best practices for maintaining cybersecurity.”

The issue of cybersecurity has, of course, loomed large in recent months, reportedly emerging as a focus in Labor Department audits and as a point of contention[i] in participant lawsuits. In fact, even the preamble to the final e-delivery regulations stated a year ago that “…the Department expects that many plan administrators, or their service or investment providers, already have secure systems in place to protect covered individuals’ personal information.” 

Now, in fairness, the Labor Department press release did state that it was guidance on those best practices—not that there wasn’t guidance on cybersecurity to be found in those documents. 


Consider that in the component labelled “Cybersecurity Program Best Practices,” none other than the Labor Department itself says, in no uncertain terms, “Plans’ service providers should…” and then proceeds to enumerate 12 precise and distinct elements. The first of these is no less than to “have a formal, well documented cybersecurity program,” followed immediately by “conduct prudent annual risk assessments.” 

Doubtless there are some who would prefer to have a more detailed expectation as to the particulars of those practices, some specific sense as to exactly what constitutes a “cybersecurity program,” the criteria for “strong access control procedures” and what is required in order to “appropriately respond” to past cybersecurity incidents. 

Make no mistake: Plan fiduciaries that aren’t attentive to the issue, much less the best practice guidance and its detailed outlines as to what would constitute “best” practices—well, perhaps the high-level admonitions leave too wide open the determination as to how those mesh with ERISA’s fiduciary standard. That said, and even if the Labor Department has yet to turn a sharp eye upon such things, the plaintiffs’ bar soon surely will.

The elements outlined, while broad, seem to offer at least a basic structure and specifics sufficient to validate an existing program, or—should one not yet be in place—begin its construction. And so, even if there are some specific criteria not yet detailed, plan fiduciaries can know, it seems to me—regardless of this particular guidance—for a certainty that the standards of considering, hiring and monitoring the processes and practices of those who provide support to their plan and its participants require—as they always have—a standard of care and loyalty that has been described as “the highest known to the law.” 

And surely that includes pursuing best practices in protecting both the information and account balances to which they are entrusted. 

- Nevin E. Adams, JD

Saturday, November 14, 2020

5 Steps to Cyber Security

Recent reports of 401(k) thefts and an ongoing concern about cybersecurity (should) have everybody on the alert. Here’s some things you, your plan sponsor clients, and their participants should check out—now.

Find Your Account(s)

It may have been a while since you checked out your 401(k) balance—indeed, many may not have ever  checked it out online. Start by tracking down the website, your user id, your password. If you haven’t done so in a while, you may have lost those credentials—or your access may have been disabled. Even if those credentials are still valid, it’s probably a good time to change them. Make sure you remember those account(s) at previous employers’ 401(k)s that you may have left “behind.” 

Oh, and it will be less frustrating if you don’t do this on the weekend. In my experience, few offer customer service support then, and if you need help getting on, you’ll need some help.

You might also find that it’s a good time to consolidate those 401(k) accounts so that your “check up” can be a bit less burdensome in the future.

Make Sure ‘They’ Can Find You, Too

Addresses change, phone numbers too. You’ll want to make sure that your contact information is up to date. That old work email address probably doesn’t work anymore, either—make sure those “old” 401(k) accounts know where you are.

Change the ‘Locks’

Chances are the last time you logged into your 401(k) account, you were told to come up with a password that was a combination of so many letters and characters you lost count. You may have been prompted to come up with answers to a handful of seemingly random “security” questions (what was  your first concert, after all?). You may have been asked if you wanted something called “multi-factor” authentication (for example, you might be asked to enter a code that is sent to a phone or email account that you have previously authorized). And, if you logged in from a different device (smartphone, or even a different browser), you may well have been asked to confirm that as well.


Frustrating as that series of hurdles can be if you are in a hurry, they’re all designed to stop, or at least slow, someone hacking your account. So, change your password regularly, use a password manager to help you keep up with passwords no human brain could possibly be expected to retain, and definitely go with multi-factor—because when someone who isn’t you accesses your account, you want to know it before  they get in. 

Check Your Beneficiaries

One of the most common areas overlooked is that of beneficiaries—the folks that you want to receive your account balance if you’re no longer “here” the receive them. This is so critical that the Plan Sponsor Council of America focused its recent 401(k) Day campaign on the topic. 

The default assumption if you’re married is your spouse (if you want to designate someone else you’ll need their acquiescence), but—like addresses, spouses have been known to change, children have been known to come along, children have been known to marry individuals that wouldn’t be your first choice, and life situations change. I actually had a situation where my beneficiary designation was (apparently) “lost” during a provider change.  

You’ll want to make sure that who’s on record as your beneficiary is current because things change—and the plan administrator will almost certainly distribute benefits to the person(s) you’ve designated—regardless of “circumstances.” 

Get a ‘Ready’ Read

Oh, and while you’re at it—you might want to check out your retirement readiness—how much you’ll need to retire comfortably, and how close your savings and other assets are to making that a reality. 

That might, in turn, not only provide you with good insights as to how much you need to be setting aside—but provide a sense of comfort as you work with your advisor/investment professional. 

It’s important that your savings be secure, after all—but ultimately you need them to be… enough.

- Nevin E. Adams, JD