• Welcome to the FREE TUGBBS forums! The absolute best place for owners to get help and advice about their timeshares for more than 32 years!

    Join Tens of Thousands of other owners just like you here to get any and all Timeshare questions answered 24 hours a day!
  • TUG started 32 years ago in October 1993 as a group of regular Timeshare owners just like you!

    Read about our 32nd anniversary: Happy 32nd Birthday TUG!
  • TUG has a YouTube Channel to produce weekly short informative videos on popular Timeshare topics!

    All subscribers auto-entered to win all free TUG membership giveaways!

    Visit TUG on Youtube!
  • TUG has now saved timeshare owners more than $24,000,000 dollars just by finding us in time to rescind a new Timeshare purchase! A truly incredible milestone!

    Read more here: TUG saves owners more than $24 Million dollars
  • Wish you could meet up with other TUG members? Well look no further as this annual event has been going on for years in Orlando! How to Attend the TUG January Get-Together!
  • Now through the end of the year you can join or renew your TUG membership at the lowest price ever offered! Learn More!
  • Sign up to get the TUG Newsletter for free!

    Tens of thousands of subscribing owners! A weekly recap of the best Timeshare resort reviews and the most popular topics discussed by owners!
  • Our official "end my sales presentation early" T-shirts are available again! Also come with the option for a free membership extension with purchase to offset the cost!

    All T-shirt options here!
  • A few of the most common links here on the forums for newbies and guests!

I am getting REALLY tired of this... [account hacking]

I signed up for DROP which didn't take much time. I hope it will help because it continuously monitors and removes my name and it is free.

Perhaps this is pissing in the ocean. But some people may want to try it and may ultimately find it valuable. No matter your view, at least the state is trying to do something about the problem - rather than do nothing to protect consumers. The jury is out whether it works, but I am willing to give it a try.

It seems you have already made a judgment before the verdict. If you truly believe there is nothing that can be done about about it then why did you start this thread? Life is short. Focus on positive things you can control. #justsaying
 
Last edited:
I have tried (via a different pathway) to have our info deleted from data brokers, but it doesn't seem to have made a significant difference. Are you familiar with that expression about pissing in the ocean?

Oh, and we're also signed up with the National Do Not Call registry. I'd say the phone rings nearly a dozen times a day from phone numbers that we don't recognize. We don't answer.
You don't honestly believe the do not call registry is still a thing????
 
You don't honestly believe the do not call registry is still a thing????
It's still a thing and still prevents most legitimate companies to have to jump through regulatory hoops and spend lots of money to make sure they don't violate it. Any penalties seem to get dolled out to big companies that violate the law, either intentionally or by accident. They never seem to go after or shut down the scammers that violate the do not call list.
 
It's still a thing and still prevents most legitimate companies to have to jump through regulatory hoops and spend lots of money to make sure they don't violate it. Any penalties seem to get dolled out to big companies that violate the law, either intentionally or by accident. They never seem to go after or shut down the scammers that violate the do not call list.
Yeah but 99% of the calls are from foreign scammers nowdays.
 
Yeah but 99% of the calls are from foreign scammers nowdays.
Basically the do not call list works. Keeping legitimate companies from calling you when your number is on the list. It doesn't work to stop the people who break the law by scamming people.
 
The hacking will continue until data holders are punished for sloppy security measures. The Federal Government, State Governments and affected companies who used these services should fine and sue them until tight procedures are in place. There should be annual inspections and penetration testing to insure that safeguards are in place.
 
Once or twice a year, I will receive a letter from some business or health organization that my information might have been compromised.

My daughter just received one from her OB/GYN office last week. Will hacking ever end - I doubt it.
 
Once or twice a year, I will receive a letter from some business or health organization that my information might have been compromised.

My daughter just received one from her OB/GYN office last week. Will hacking ever end - I doubt it.
Healthcare is the weakest link! Stop giving them your SSN. When I go to a new office, I simply leave that box blank. I've yet to be challenged.

Keep your 3 major credit agency accounts frozen/locked - simple & free.

Don't answer phone calls not in your contacts. Let them leave a msg & call them back.
 
The hacking will continue until data holders are punished for sloppy security measures. The Federal Government, State Governments and affected companies who used these services should fine and sue them until tight procedures are in place. There should be annual inspections and penetration testing to insure that safeguards are in place.
Uh, how is that going to help when so much of this - likely 100% is outside our borders? Off shore?
 
You are probably affected as well, so let's vent together.

My health insurer contracts out certain services. So yesterday I received a letter from one such subcontractor. Guess what? They were hacked and my personal information exposed. And guess what? As compensation, they are offering me one year of an identity protection service. Well, we already currently have a bunch of these services that resulted from hacks of a variety of companies that we've done business with as a consumer. And ever since the great Equifax hack a number of years ago, we already have such a service that we pay for monthly.

Then there's this item in today's news, yet another major hack: https://www.foxnews.com/tech/healthcare-data-breach-exposes-3-75m-patient-records

We try to be very careful about our financial affairs. For example, our credit is frozen. I have an IRS PIN number for filing Federal income tax. If I receive a call claiming to be from a financial institution, I won't speak to the caller and instead find their 800 number and call back. I have different crazy passwords for all of the websites I use.

But the businesses are sloppy. The story is always the same. They hire a software security firm after the fact to contain the breach and then throw affected customers a bone in the form of one year of identity theft monitoring. With the rise of AI, I fear that it will only get worse.

I don't know the solution, if there is one. But I'd like to see some real, far more significant penalties on businesses with lax security. And I don't understand why these businesses don't improve their security prior to a breach. (At least one positive thing so far is that the financial institutions I deal with, such as banks and brokerages, have so far seemed to be pretty secure, unless of course they haven't told me. Willie Sutton robbed banks because that's where the money is, so I'm sure that the hackers are trying hard to get into the bank and brokerage computer systems. A breach of a major financial institution would potentially be a significant disaster.)
You are already doing everything you can do... unless you are still giving healthcare offices your SSN.

We don't have strongest enough penalties. We don't go after US responsible parties. Oh, maybe Congressional testimony and that's it. Was it Equifax years ago who were warned of a security breach or a threat? Instead of getting to work and patched it like a responsibly entity, many higher ups sold their stock. How unethical is that? They should be in jail like the Enron officers.
 
Uh, how is that going to help when so much of this - likely 100% is outside our borders? Off shore?
Many of the companies holding our data that are letting it get hacked are US companies. The problem is, the cat is already out of the bag.
 
  • Like
Reactions: Tia
I am tired of hackers in general. Like flies they are a constant annoyance. Unlike flies, I see no actual purpose for them.

If I was queen 🫅 of the world, I would banish them from existence. Alas, I am a mere timeshare owner. 🌴
 
But the businesses are sloppy. The story is always the same. They hire a software security firm after the fact to contain the breach and then throw affected customers a bone in the form of one year of identity theft monitoring.


People are even more sloppy. Hacking happens because most people choose convenience over everything else. It's the big-picture problem.


Let's say someone steals my phone and manages to unlock it. They'll have access to my email and some social apps. (But probably not because I'd have already changed all the passwords.) But they wouldn't have access to any financial information or a credit card because I think it's foolhardy to store that sort of information on a phone.

Let's say I'm pick-pocketed and and someone gets my wallet. Now they have my driver's license and a credit card. What they don't have is any bank information because I don't have an debit card. I do all my real banking inside the bank, in person.

And then I have a minor bank account JUST for electronic payments -- outgoing bills, incoming orders. If that account reaches a balance that would cause me to lose sleep, I make a withdrawal and walk the money across the street to a different bank with no online-anything associated with it. If that account reaches a balance that would cause me to lose sleep, I put it in a CD, add to an index fund, buy property, etc.

I want it to be hard to scammers and thieves to steal from me. Maybe they'll get me for a few hundred dollars because I let my guard down. But they'll never have "keys to the financial kingdom" because they are incapable of getting the keys. I don't keep the keys on me or online.

PS -- Running Norton, McAfee and similar is worse than using nothing. They slow your computer down 100% of the time but only catch malware if it's older. Identity-theft monitoring is less effective than the scheme I just laid out. And it doesn't make you immune. It just catches it before it becomes a larger problem.
 
I found an old insurance policy on my husband
I called the number I found for the company
There were a lot of personal questions and an attempt to sell me a policy
I was eventually given another number to call, which generated another number, and a fourth number. I gave up.
 
Interesting that we are all lamenting about hacking while being on a website that is all about hacking the timeshare industry.
 
Interesting that we are all lamenting about hacking while being on a website that is all about hacking the timeshare industry.
You have an extremely different definition of "hacking" than most people here if that is what you really think. We are all about getting the best value out of our ownerships, getting the best deals, etc. The "hacking" being talked about here in this thread is stealing, plain and simple. Do you honestly think trying to make the best of our timeshare ownerships is equivalent to stealing??? How ridiculous.

Kurt
 
Yeah, I think your definition of "hacking" is different than the OP's problem - - (stolen account data, potential fraud)
I engaged in fraudulent activity. I went to an owners update and took their money and gave them nothing but grief in return. I feel so guilty....... :p
 
You have an extremely different definition of "hacking" than most people here if that is what you really think. We are all about getting the best value out of our ownerships, getting the best deals, etc. The "hacking" being talked about here in this thread is stealing, plain and simple. Do you honestly think trying to make the best of our timeshare ownerships is equivalent to stealing??? How ridiculous.

Kurt
I stole from the timeshare company. Then I told others at the resort how they can steal from them as well. :)
 
I would argue the method of timeshare development sales is a malicious empty promise hack. This community is all about clawing back from the lies and deceit of the sales and ongoing price gouging practice. In other words we are the ethical hackers.
 
Uh, how is that going to help when so much of this - likely 100% is outside our borders? Off shore?
Proper protection of data and assets can prevent attacks or drastically reduce their effectiveness. It does not matter where the attacks come from.
 
People are even more sloppy. Hacking happens because most people choose convenience over everything else.
This right here - people do not like jumping through hoops, but if it's easy for you and easy for the company, it's likely easy to abuse.
Let's say someone steals my phone and manages to unlock it. They'll have access to my email and some social apps. (But probably not because I'd have already changed all the passwords.) But they wouldn't have access to any financial information or a credit card because I think it's foolhardy to store that sort of information on a phone.

Let's say I'm pick-pocketed and and someone gets my wallet. Now they have my driver's license and a credit card. What they don't have is any bank information because I don't have an debit card. I do all my real banking inside the bank, in person.
In person attacks / physical ones are likely to be extremely rare - at least against digital assets. Your bigger risk is the bank getting phished or the like. I think ACH is the biggest risk, and I'm not aware of a way to opt out of that if you have a checking account.
And then I have a minor bank account JUST for electronic payments -- outgoing bills, incoming orders. If that account reaches a balance that would cause me to lose sleep, I make a withdrawal and walk the money across the street to a different bank with no online-anything associated with it. If that account reaches a balance that would cause me to lose sleep, I put it in a CD, add to an index fund, buy property, etc.
Still likely has ACH. Though again it's the bank's security there.
PS -- Running Norton, McAfee and similar is worse than using nothing. They slow your computer down 100% of the time but only catch malware if it's older.
This depends on what you mean by "similar". Endpoint Security tools like ESET Endpoint Security, Comodo's Internet Security, (IDK if individuals can purchase it but) Crowstrike and the like detect behaviors and block them with various levels of automation. They also all have live threat intelligence so it's no longer a day or three or a month etc to get a new signature like in the old days, it's often hours or less. Once it's seen by any of their customers, the security software of all of their customers will detect it. Many will block on website access or download attempt - before it even fully gets to your computer. And the good tools are lightweight and don't noticeably slow down your computers - usually it's web browsers that do that with bloated web sites nowadays.
Identity-theft monitoring is less effective than the scheme I just laid out. And it doesn't make you immune. It just catches it before it becomes a larger problem.
Having all your credit reports frozen both makes you think twice about applying for credit and stops most problems from potential identity theft AFAIK. Most of the attacks are to get debt in your name, and if that is blocked then they move on. I think the next most likely thing would be tax returns, but those are once a year and usually far less than a credit card balance you could run up, so I'd guess less attractive.
 
Still likely has ACH. Though again it's the bank's security there.

My "real" account is straight savings. Small-town bank. We have flags on the account, "No transactions at all above $X unless BOTH account holders are physically at the bank requesting a cashier's check."

This depends on what you mean by "similar".

The kind available to consumers. I don't run any kind of security at all. But I don't spend time on piracy/porn/gambling/meme/religious/political/genealogy websites which are rife with malware.

I completely agree that most hacks are phishing expeditions using thumb drives dropped in bank parking lots or simply calling someone and asking for the password. "Yeah, this is Chip in IT. I need you to confirm your logon information. I'm seeing a discrepancy."

However, the top 100 most common passwords are STILL the top 100 most common passwords. I'm willing to literally bet my farm that someone reading this has a password of "password." Or "123456." Or "qwerty123."
 
However, the top 100 most common passwords are STILL the top 100 most common passwords. I'm willing to literally bet my farm that someone reading this has a password of "password." Or "123456." Or "qwerty123."
Have you been snooping around my password list !!
 
The kind available to consumers. I don't run any kind of security at all. But I don't spend time on piracy/porn/gambling/meme/religious/political/genealogy websites which are rife with malware.
I was going to argue a little, but in reality I run Linux and no extra security so I can't really say much. I have found that as long as I have been judicious in what I download and from where, even back years ago when I used Windows at home, I've been fine. Most of the security software was always "defense in depth". That said, it has been proven that "be smarter about cyber security" doesn't work with the masses. So while I usually hate to be the "do what I say and not what I do" - well, as you point out, in reality people who take away "don't run security software" are missing a lot of the other "what I do" part, such as not running Windows.
 
Top