Sipping an iced coffee in Phnom Penh and scrolling through the phone, a fresh piece of news popped up from Singapore. Local police reported that since mid-August, a string of account-hacking cases has hit the city-state. The modus operandi is always the same: hackers break into the victims' email accounts first, then clean out all their cryptocurrency. Bottom line, it's the classic mistake of using the same password everywhere. Some people had their email passwords leaked ages ago, so hackers are getting in on the first try.
These guys move fast. Once a hacker slips into your email, they immediately set up automatic forwarding or just delete incoming messages in the background, keeping all those transaction alerts from trading platforms completely hidden. Next, they waltz over to hit the password reset button, catching all the verification codes and links. By the time you realize what's happening, your account has long changed hands, your crypto has been completely transferred out without leaving a ripple.
Singapore police quickly issued an advisory urging people never to use the same password for both email and crypto accounts, and to turn on two-factor authentication immediately. It is also a good habit to routinely check your inbox for any weird new forwarding rules or unfamiliar login activity. If anything looks suspicious, contact customer service right away to try and salvage whatever you can.




