- Reader Case: From Cancer Survivor to FIRE - September 1, 2026
- The FIRE Guide to America’s Health Care System (2026) - July 7, 2026
- Planting Your Money Trees - February 23, 2026

Last week, an article appeared on The Globe And Mail about an unfortunate case of an customer of Questrade who lost $70,000 after her trading accounts got hacked.
In early January, Megan Tong lost around $70,000 after hackers logged into one of her self-directed investment accounts, cashed in all her holdings and briefly bought and sold tens of thousands of dollars worth of two Chinese stocks.
But Ms. Tong’s discount brokerage, Questrade Financial Group Inc., has declined to reimburse her for most of the loss, saying it didn’t result from a breach of its system. Instead, the company has described the hack as a likely phishing attack, which isn’t covered by its online security guarantee.
This prompted a flood of anxious emails asking us whether Questrade was still a safe place to keep their money, and what we were doing to keep our money safe.
The short answer is yes, Questrade has the same online security guarantees as any other Big 6 Canadian bank. However, no bank can guarantee your security if you make a mistake that gives an attacker the keys to your vault.
So I thought this would be a good time to talk about how to keep your online financial accounts safe.
Because I’m a FIRE blogger that regularly posts their net worth on the internet, I attract more hacking attempts than the average person. Every month I get a report of all the digital break in attempts from hackers in Russia, Iran, China, North Korea, etc, usually numbering in the hundreds. This site, my bank accounts, and my trading accounts are constantly under assault by people trying to steal my FIRE portfolio. So far, none have succeeded, and here’s how I do it.
Always Type – Never Click
Questrade’s response referenced a phishing attack, which is when an attacker sends you an email with a link to a fake version of your bank’s website designed to steal your password when you log into it.
Gone are the days where you could tell that a website was fake because the layout looked weird, or the text had typos in it. Modern phishing attacks have gotten so sophisticated that you can’t visually tell anymore.
And the worst thing about a phishing attack is that if your account gets breached, you don’t know. There’s no skull-and-crossbones that comes up and say “YOU’VE BEEN HACKED” or anything, the account is just invisibly compromised, a backdoor created for an attacker to exploit later at a time or place of their choosing. It could be months later that they choose to use it to steal your money, and by then you will have no idea what you did wrong, like the person featured in the Globe & Mail article describes.
When it comes to logging into anything important, whether it’s email, your bank, or your brokerage account, get into the habit of pulling up a new browser tab and typing the name manually, every time. I don’t even rely on bookmarks anymore, because those can be hacked too.
Don’t Do Anything Financial on Public Wifi
Public Wifi at cafes have been a boon to digital nomads like us, but they’re also honeypots for hackers.
A compromised router can act as a listening device to your internet traffic, and can even do all the same things a phishing attack can do even if you don’t click any suspicious links.
If you’re tech savvy enough, a Virtual Private Network (VPN) can be used to ensure your connection is secure even if the router is spying on you, but for the average internet user, I would recommend simply not logging into any financial site on a public Wifi connection – ever.
Instead, connect your laptop to the hotspot on your phone and use your cell connection. Alternatively, wait until you’re back home to do any trading. You don’t want the dude sitting behind you to know how much money you have anyway.
Have Unique Passwords
What makes a good password? Is it the length? Is it it’s cleverness? Is it a reference to some obscure song that you loved as a kid?
No. This is what a good password looks like.
xi$jcGrXJ#4YB9D6&jHb
A 20+ character, random, completely garbled string of letters, numbers, and special characters that means absolutely nothing to you or anyone else in your life. These are the passwords that can’t be guessed, and each account you have should have a different password.
Hackers don’t try to steal passwords directly from banks that often because banks have the budgets and IT staff to defend against such attacks. They go after non-financial sites like Reddit or Discord, hoping that if they get the password to that account, the same password might work for your bank.
In order to keep track of all your passwords, you’ll need a password manager like LastPass or 1Password. These services also handle generating secure passwords for you, as well as filling them into each site you log into.
Hardware Token Based 2FA
You’ve probably been told to activate two-factor authentication (2FA) at some point, and many of you likely have thinking that it makes your account more secure.
Here’s a dirty little secret. If you’re using your phone number to receive text codes as your 2FA method, and I find out your phone number, I can probably break into your bank account.
The text message system was never designed to be used to get into bank accounts. As a result, there are security holes large enough to drive a truck through, and crucially, those security issues are so dispersed over so much infrastructure that there’s no way to fix them.
With just your phone number, an attacker can eavesdrop on your phone calls, read your SMS messages, and even track your location. And there’s absolutely nothing you can do to prevent this, because the issue isn’t on your phone. The vulnerability is in the backbone of how telecom companies communicate with each other. Here’s a writeup of how this attack works for the tech-savvy.
The solution is to not use phone numbers for 2FA. Instead, I use a Yubikey.
A Yubikey is a USB stick-like device that you can buy for about $50USD/$70 CAD. After setting it up, you tap this key against the back of your phone and it generates a 6-digit login code for you. The codes are stored on the key itself rather than your computer or your phone, meaning it can’t be stolen via hacking, a virus or other software-based method. In order for someone to get my code, they’d have to gain physical access to the key itself.
Not every bank or brokerage supports a Yubikey, but Questrade does. It’s often listed as “Authenticator app” or something similar.

What If My Bank Doesn’t Support Hardware Tokens?
Of course, the big problem with this is that most banks only support SMS-based 2FA, which as we’ve discussed aren’t very secure at all.
Even worse, many of these banks allow you to reset your password by sending you a code to your phone, so if I know your phone number, I can intercept your SMS, which means I can reset your password, which means I can break into your account. A fellow finance blogger friend lost over $100k like this, and the attacker even tried to blackmail them afterwards to get their accounts back. The FBI had to get involved and it was a mess.
So how do I deal with banks that only support SMS-based 2FA?
Simple.
I keep the business I do with them extremely limited. I might have a credit card account with them, or a checking account with a few hundred bucks so I can use their ATMs, but my rule is that if a bank leaves their backdoor open to hackers, I’m not trusting them with my money.
Conclusion
Security is always a trade-off between safety and convenience, and admittedly, my approach to cyber security is a bit extreme, as FIRECracker likes to remind me as she curses the gauntlet of codes she has to put in whenever she needs to access our financial accounts. But even she has to admit that there’s no way a hacker is getting into our accounts. Because she can barely get in most days.
But because of who we are, and the size of the FIRE portfolio we control, for us these added security measures are worth it.
How do you keep your accounts safe? How much do you consider overkill? Let’s hear it in the comments below.

Hi there. Thanks for stopping by. We use affiliate links to keep this site free, so if you believe in what we're trying to do here, consider supporting us by clicking! Thx ;)
Build a Portfolio Like Ours: Check out our FREE Investment Workshop!
Travel the World: Get flexible worldwide coverage for only $45.08 USD/month with SafetyWing Nomad Insurance
Multi-currency Travel Card: Get a multi-currency debit card when travelling to minimize forex fees! Read our review here, or Click here to get started!
Travel for Free with Home Exchange: Read Our Review or Click here to get started. Please use sponsor code kristy-d61e2 to get 250 bonus points (100 on completing home profile + 150 after first stay)!






Really excellent read. Thank you for posting. I would also add not to brag about your net worth around others. As you mentioned, your book and blog have put a target on you. I cringe when I hear people openly brag about their net worth. It can easily draw the wrong kind of attention, and might cause others to be resentful.
Thanks. Yeah, definitely do NOT do what I do when it comes to talking about money in public.
CRYPTO SCAM RECOVERY SUCCESSFUL – A TESTIMONIAL OF LOST PASSWORD TO YOUR DIGITAL WALLET BACK.
My name is Oliver Noah, Am from . I’m sharing my experience in the hope that it helps others who have been victims of crypto scams. A few months ago, I fell victim to a fraudulent crypto investment scheme linked to a broker company. I had invested heavily during a time when Bitcoin prices were rising, thinking it was a good opportunity. Unfortunately, I was scammed out of $120,000 AUD and the broker denied me access to my digital wallet and assets. It was a devastating experience that caused many sleepless nights. Crypto scams are increasingly common and often involve fake trading platforms, phishing attacks, and misleading investment opportunities. In my desperation, a friend from the crypto community recommended SEFTYHUB Recovery Service, known for helping victims recover lost or stolen funds. After doing some research and reading multiple positive reviews, I reached out to SEFTYHUB Recovery. I provided all the necessary information—wallet addresses, transaction history, and communication logs. Their expert team responded immediately and began investigating. Using advanced blockchain tracking techniques, they were able to trace the stolen Dogecoin, identify the scammer’s wallet, and coordinate with relevant authorities to freeze the funds before they could be moved. Incredibly, within 6 hours, SEFTYHUB Recovery successfully recovered the majority of my stolen crypto assets. I was beyond relieved and truly grateful. Their professionalism, transparency, and constant communication throughout the process gave me hope during a very difficult time. If you’ve been a victim of a crypto scam, I highly recommend them with full confidence contacting:
Email:
SEFTYHUB@GMAIL.COM
TELEGRAM@SEFTYHUB
I was recently scammed out of $53,000 by a fraudulent Bitcoin investment scheme, which added significant stress to my already difficult health issues, as I was also facing cancer surgery expenses. Desperate to recover my funds, I spent hours researching and consulting other victims, which led me to discover the excellent reputation of SEFTYHUB Crypto Recover, I came across a Google post It was only after spending many hours researching and asking other victims for advice that I discovered SEFTYHUB Crypto Recovery’s stellar reputation. I decided to contact them because of their successful recovery record and encouraging client testimonials. I had no idea that this would be the pivotal moment in my fight against cryptocurrency theft. Thanks to their expert team, I was able to recover my lost cryptocurrency back. The process was intricate, but SEFTYHUB Crypto Recovery’s commitment to utilizing the latest technology ensured a successful outcome. I highly recommend their services to anyone who has fallen victim to cryptocurrency fraud. For assistance, contact.
EMAIL /:
SEFTYHUB@GMAIL.COM
TELEGRAM@SEFTYHUB
Excellent advice! That news article finally made me switch over to using an authenticator app with Questrade. Our banks are so far behind too; only allow SMS 2FA and just recently enabled password logins instead of the 6 digit pins. Looking at you Tangerine…
Ugh, Tangerine is specifically one of the banks that I just don’t take security seriously at all. A 6 digit numeric pin would take less than a second to break into. I’m amazed their clients haven’t been robbed blind already.
Is 2FA via e-mail address better than cell phone number?
hackers can find out your email address just as they can find out your phone number.
If your email is protected with a Yubikey, yes. Gmail supports this, so make sure you turn this on.
Thank you for this very helpful article! Do you have a list of institutions that only support SMS-based 2FA?
U.S. – Discover and PNC Bank
Canada – Tangerine, TD Bank , RBC
You can find a more comprehensive list of companies across different sectors and what kind of 2FA they support here -> https://2fa.directory/us/
TD Bank has MFA Via their own app called “TD Authenticate” I used to use it when I was a client.
” hackers logged into one of her self-directed investment accounts, cashed in all her holdings and briefly bought and sold tens of thousands of dollars worth of two Chinese stocks.”
She should have received email notifications of all those activities/transactions on her account. Did she ignore all of those?
It believe yes, she did receive them but ignored them.
Okay, that’s helpful to know that she at least got the warning emails but failed to alert her bank. Any changes that a hacker might make to your account (i.e., change a password, turn off trading PIN, make a trade), would usually result in the bank sending you a text message AND an email. In this case it sounds like she should have paid better attention to her email and alerted her bank (but I don’t want to blame the victim here…).
If hackers have access my SMS messages through SS7 attack, Sim Swap or Sim Porting, they could arguably delete the bank’s text message before I even get a chance to see it. However, the only way they could hack into my Gmail and also delete the notification email would be if they knew my email password, or used SMS 2FA to reset the password, again doing all this by intercepting my text messages without me realizing it.
For those of us who bank at the Big 5 and don’t currently have the option to use a Yubikey, I think it would make sense to at least authenticate our Gmail accounts with a Yubikey. That way, if any suspicious activity does happen to our bank accounts, we will at least get the emails even if the hackers manage to intercept our text messages. We just need to make sure to monitor our Gmail accounts regularly and alert our bank if we see a change that we didn’t initiate.
While we can’t avoid SIM swapping altogether, you can call your mobile service provider and ask that your SIM be protected with a PIN. Luckily mobile providers are starting to catch on and taking steps to reduce SIM fraud, for example by sending you a text for your permission (before your SIM has been compromised). It still leaves some back doors open though.
Lastly, it it is important that we also legally protect ourselves in the event of a breach. Most banks have a page on their website where they state that they will cover losses provided the client also does their part by changing passwords frequently, not using the same passwords for different accounts etc. You don’t want to be in a situation where you’re up against a bank’s team of lawyers trying to prove that your banking password is different from your low-security Netflix account.
If a hacker intercepts my SMS, would I still receive the message on my phone? Or would I just have no idea that the text was sent to me?
You would still get the message but have no idea it was intercepted. Then can read any SMS without interfering with its normal delivery.
Wow, this was amazing, thank you SO much for all this info! I had never heard of a Yubikey…. 🙁 I have accounts with Vanguard, Schwab and Fidelity, and anytime I need to do a transaction, I log in via their app (or if I access via the web, the 2FA will be an app login). Also, my password is basically Face ID. But now I wonder if I should add a physical token as well? Yikes 🫠
For any accounts worth over $100k, yes I would. Face ID is misleading as it makes it easier to log in from specific devices, but if you log in from another device and it allows you in with SMS or something, then Face ID doesn’t protect you. You are only as secure as your least secure login method.
What if you lose the Yubikey? Does it use SMS as a backup? If so, what’s to stop the hacker from using SMS and saying they lost the Yubikey key when hacking into your account?
A hardware token should be used as the only 2FA method. SMS should not be allowed as a backup login method. You are only as secure as your least secure login method.
When you set up a hardware token, your bank/brokerage should provide you with a set of backup codes that you can use to login should you lose your key. Print these out and store them in a secure location that you can access, like a safety deposit box.
Thanks for the excellent overview. What are your thoughts on banking apps and using your iPhone?
They’re fine with a hardware token. I operate under the assumption that my phone has already been hacked and all my passwords are already stolen. But my password is useless without my physical key.
Great info, please continue update this on the future.
Quick question – Is using Chrome’s built-in password manager safe? If so, how does it compare to password manager like LastPass or 1Password.
Chrome’s password manager is fine, I’ve used it before. That is, until I accidentally deleted all my passwords when I was trying to clear my browsing history because I had the wrong checkbox checked off. Arg. Never again.
Any concerns about password managers getting hacked (especially if stored in the cloud)? Seems like that would be the real jackpot for hackers.
Lastpass had a major issue with millions of password being stolen last year. They were hacked.
Don’t use them!
Use Bitwarden. Among the free ones, it’s the most secure w/ unlimited devices. Install their app in your phone and the chrome extension.
Chrome’s built-in password manager is reasonably safe for most everyday users, but if you want stronger security, more control, and features (especially for multiple devices, sharing, or long-term vault management), Bitwarden is superior, even the free version.
to add, Chrome’s passwords are synced directly to Google’s ecosystem; your cloud copy is only protected by your Google credentials.
Bitwarden is designed end-to-end encrypted; even the company can’t read your passwords. You have the option to keep everything local if you want, but it could be a problem in some cases.
Chrome = cloud-first, tied to Google. Bitwarden = cloud or local, encrypted end-to-end.
This is all great info. I deliberately didn’t name the password manager I personally use because that would open up a vector of attack, but I really like Bitwarden for the exact reason you describe.
When looking for a password manager, look for the terms “end-to-end encryption” and/or “Zero-knowledge encryption.” These terms mean that even if the FBI flashed their badge at the company’s offices and demanded your passwords, the company can’t give it to them because it’s encrypted in such a way that even they can’t see them. That’s the gold standard for password managers.
Something doesn’t add up about this questrade client. They tried to contact her multiple times and she ignored all their attempts. And she has some cyber security training as a financial professional. Is she an accomplice?
Also an interesting script from the comments to the article regarding how the funds could have been withdrawn from her account:
Here is a possible script: Accomplice A buys the thinly traded XYZ shares for $1/share, sets up a limit sell order for $50/share that no one bites at, Accomplice B hacks the account and buys those shares for $50/share; voila, Accomplice A has essentially 50x their money and the hacked account shares plummet back to their original value once the trade is complete. Accomplice A closes their account and takes the cash. It certainly keeps under the anti-laundering money transfer limits (over $10k?) since I doubt share purchases are monitored the same way.
I haven’t spoken to Ms. Tong so I don’t know anything more than the article says, but technically it says she lost $70k, not that she had $70k stolen. It’s possible they logged in, and just bought some shitty stock that plummeted.
Questrade only allows withdrawing to an account with the same name as you, so they may not have been able to withdraw any money.
This is a topic I find that isn’t really discuss into their the FIRE movement, yet is in my opinion critical.
I really thank you for this!
And on my to buy Yubikey.
I called Schwab to see if I should buy a Yubikey to protect my brokerage funds. Turns out they have their own hardware from Symantec that’s on a keychain and they’ll send it to their clients for free.
Oh great! That’s handy!
It is annoying that a lot of Canadian sites use phone numbers for 2FA especially tangerine and the CRA as well. I’m out of the country a lot and never use my Canadian number outside the country so its hard to access.
Another thought I’ve had with recent uptake in E-sims. There are so many different ones out there such as Airalo, Saily, GlobalYo etc etc. I’m curious because these E-sims maybe not be as well known or secure as old school regular sims, could there be possibility of being hacked through these like it is through public Wifi.
To my knowledge, an e-sim is no less secure than a regular SIM. I would definitely use that over public Wifi.
Bonus points if you combine with a VPN!
Slightly unrelated but just a warning about logging into investment accounts with a VPN while travelling: make sure you switch to your home country IP before logging in, especially with Wealthsimple.
This couple got banned from WS after their fraud department likely thought they were engaging in money laundering (WS never disclosed the reason). They were using a US VPN on a work computer:
https://www.reddit.com/r/PersonalFinanceCanada/comments/1muj2tr/accounts_closed_and_banned_from_wealthsimple_with/
Fidelity has moved away from hardware tokens and now encourages the use of authenticator apps like Google Authenticator, Microsoft Authenticator, and Authy.
Authenticator apps are generally considered more secure and convenient than hardware tokens, especially since they don’t rely on cellular networks and can be used with multiple accounts.
Of course, Fidelity’s position is about cost, UX, and adoption, not pure raw security. Nonetheless, it’s better having either one.
Instead of using Yubico key. Do you think it’s safe to use Authenticator App like google authenticator app for any accounts which hold cash, ETF etc ?
That G&M article may be behind a paywall so maybe this was already addressed there: I’m surprised that the brokerage didn’t have anomaly detection. For example, if this investor’s typical pattern was once a month login and buy the same ETF for years (i.e. typical FIRE or long term buy & hold investor behaviour), then all of a sudden one day attempt to buy 70K of an individual stock – I would have thought that would trigger an alert as to the unusual activity.
I am so very grateful for all the info and all the responses. I too have never heard of Yubikey. I will need to do some more research where I can get one in Canada. Thank you again
Yeah I laugh I when some of these webpages ask for me to setup 2FA. So you expect me to trust you to securely maintain a database containing all the information needed to take over my identity?!?
I moved to an authenticator app on my phone where possible. It has to be better than sms and its best when you go traveling and might not be able to receive sms on your home number.
Indirectly, this another benefit in keeping at least some portion of wealth in a housing.
I would bet most people are using their phones for most transactions rather than a computer.
Any specific tips for using your phone?
Before I found the contact of Vadim, my credit was in low 500s. No matter how much I tried to get my credit in good standing, It just did not work until a friend of mine from Arkansas who Vadim had helped gave me his contact. This man literally fixed my life within 7 working days my credit score was over 750 with all negative reports removed. I honestly never believed this was possible especially considering the fact there a lots of fake people online but Vadim is indeed different. If you have similar issues, his contact is: VADIMWEBHACK@ GMA1L.C0M AND WHATSAPPP: +.1..2.4.0..4.3.9..0.6.2.4.
I was able to see every message, pictures and videos on my ex’s phone with the help of this amazing hacker Alberto Vadim. I was about to make the biggest mistake of getting married to him but after reading his chats I discovered he had already been married in another country with 2 kids. This really broke my heart but I am very happy I did not end up in that marriage. All thanks to Vadimwebhack@ GmaiI,C0M for helping me see the truth.
I shouldn’t be saying this here but to be honest this hacker should be reviewed, I just used his services, and he’s the best, experience and ethical. Contact him for any hacking and recovery support via email, (wisetechhack@ gmail .com) you can tell him I referred you
Great article on keeping investments safe. Curious why you use your yubikey for 2fa instead of a passkey? I would think passkeys are more secure than password + 2fa even if the 2fa is through a yubikey.
CRYPTO SCAM LOSS AND RECOVERY WITH SEFTYHUB SOLUTIONS My name is Isabel Abdi, and sharing this is not easy for me, but I believe it might help someone avoid the pain I went through. I lost $637,000.00 to an online scam, and it’s something I never imagined could happen to me. It started very simply. I met a man while scrolling online. At first, it was just normal conversation nothing suspicious. He was calm, respectful, and seemed genuinely interested in my life. Over time, we spoke more often, and I began to trust him. Looking back now, I realize how carefully everything was planned. He later introduced me to cryptocurrency and told me how he had been making consistent profits. I didn’t rush into it at first. I asked questions, did a bit of research, and even checked reviews online. Everything looked convincing. Slowly, I allowed myself to believe it was a real opportunity. I started investing small amounts, and the platform showed profits almost immediately. That gave me confidence. Each time I invested more, the numbers kept growing. It felt exciting, like I was finally making a smart financial move. But when I tried to withdraw my money, everything changed. There were delays, then excuses, then sudden fees I had to pay before any withdrawal could be processed. At that point, I felt something was wrong, but I was already too deep in. I kept hoping it would work out, but it never did. That’s when the truth hit me I had been scammed. The emotional impact was heavy. I felt embarrassed, angry, and completely drained. Losing that amount of money is something that stays with you mentally and emotionally. While searching for help, I came across SEFTYHUB SOLUTIONS. To be honest, I was very skeptical. After what I had been through, trusting anyone again felt almost impossible. But I still decided to try. From the beginning, they treated me differently. They were clear, patient, and professional. They explained the process step by step and kept me updated. Slowly, I started to feel a bit of hope again. To my surprise and relief, they were able to recover my funds successfully. I can’t fully describe the feeling it was like getting my life back after thinking everything was lost. I’m truly grateful, and I don’t take it for granted. If you’re going through something similar, please be careful and don’t ignore red flags. And from my experience, I can honestly recommend SEFTYHUB SOLUTIONS. EMAIL SEFTYHUB @GMAIL COM