On a Friday afternoon in August 2012, a technology journalist named Mat Honan sat down with his phone and lost his entire digital life in one hour.
It started with small, confusing signs. His iPhone rebooted and came back to the setup screen you see on a brand-new device. His MacBook restarted and asked him to set it up like a machine that had never been used. Then his Gmail account was gone - deleted. His Twitter account was posting racist and homophobic messages under his name. And his Apple ID had been broken into, with Find My iPhone used to remotely erase everything on his iPhone, his iPad, and his MacBook.
The MacBook wipe was the part that hurt most. On it lived more than a year of photos of his infant daughter - her entire life so far. Documents and emails that existed nowhere else went with them.
The realization came in pieces. He tried to log back into Gmail: gone. He checked Twitter: strangers were posting garbage under his name. His phone, his tablet, his laptop - all erased, all at once, in the space of an hour. One moment his whole digital life was there, and then it was not.
Here is the part that should make you sit up: the hackers never guessed a single password. Not one. They did not use clever code or brute force. They walked through the front doors that customer service and account recovery left open, and every door led to the next one.
And the strangest part: Honan was never really the target. The hackers wanted his Twitter username - a three-character handle, @mat. The photos, the documents, the emails - all of it was collateral damage, erased to stop him from taking his accounts back.
He wrote the whole story down for Wired. It is one of the clearest explanations of how accounts actually get broken into that I have ever read. And every lesson in it matters more in 2026 than it did in 2012.
How the Chain Clicked Together
The hack was not one big break-in. It was a chain of small, ordinary steps - each one reasonable on its own, each one leading to the next. Here is how it clicked together.
Link 1: A public hint from Google. His Twitter account was linked to his personal website, and the website listed his Gmail address. That was the starting point. One of the hackers - a 19-year-old going by the name Phobia - typed the Gmail address into Google’s account recovery page. Recovery pages are designed to help you prove you own an account, and they drop hints to nudge you along. Because Honan had not turned on two-factor authentication, Google partially revealed the alternate recovery email on the account: his me.com address, an Apple address. That one hint was the first domino.
Link 2: A public directory gave up the billing address. The hackers looked up the whois record for Honan’s personal website. Whois is a public directory of who owns a website - anyone can look it up, no login required. It showed his billing address. Public information, freely available. Now they had an email and an address.
Link 3: Amazon handed over the card digits. They called Amazon and claimed to be the account holder, asking to add a new card to the account. Amazon asked for only three things: the name on the account, the email, and the billing address. They had all three. They called back, said they had lost access, and provided the new card number as proof. Amazon let them add a new email address to the account. From there they reset the Amazon password using that email, logged in, and viewed the last four digits of every card on file.
Link 4: AppleCare finished it. At 4:33 pm they called AppleCare claiming to be Honan, saying he could not get into his me.com email. Apple issued a temporary password after they supplied only the billing address and the last four digits of the credit card. They even failed the security questions - it did not matter. Wired later verified this technique themselves and got into an account twice, in minutes.
Link 5: The wipe. At 5:00 pm Find My wiped the iPhone. At 5:01, the iPad. At 5:05, the MacBook. Gmail was deleted. Twitter was taken at 5:02. The password reset emails that would have warned Honan were sent to the me.com inbox and immediately moved to the trash, so he never saw them. One hour. Everything gone.
Notice what the chain has in common: no password guessing, no malware, no dark web. Every link was a company’s legitimate process working exactly as designed - for the wrong person. That is what makes this story so important. You cannot patch customer service with a software update. You have to change the way you set up your own accounts.
One more thing: Find My is still a great feature - it is still the fastest way to protect a lost phone. But it is also a remote wipe button, and it is protected only by the account it is attached to. The feature is not the problem. The account security around it is.
Lesson 1: Your Email Is the Master Key
Every account you own - bank, phone, streaming, tax - has a “forgot password” link. Every one of those links sends the reset email to one place: your email inbox. Whoever controls your email can reset everything else. That is the architecture of the modern internet.
Honan’s Gmail was linked to his Apple account, which was linked to his devices, which were linked to his Amazon account. One master key opened every door. He also used the same email prefix across multiple accounts, which meant one name unlocked the whole trail.
If you only do one thing after reading this, protect the email account that all your other accounts point to. Give it a long, unique password, and set up everything else in this article around it.
Lesson 2: Turn On Two-Factor Authentication, Starting With Your Email
Two-factor authentication (2FA) means logging in needs two things instead of one: something you know (your password) and something you have (usually your phone). When a login happens on a new device, the service sends a code to your phone or asks you to confirm in an app. A hacker with your password still cannot get in without your phone - and a hacker halfway around the world does not have your phone. Some services also let you use an authenticator app, which generates the code on your device instead of sending a text. Either way, the idea is the same: one stolen password is no longer enough.
Honan’s own words: “Had I used two-factor authentication for my Google account, it’s possible that none of this would have happened.” The first domino - Google revealing the recovery email - only fell because 2FA was off.
The order matters. Turn it on for your email first, because email is the master key. Then your banking. Then everything else. Most services have it in Settings, and it takes about two minutes. The modern version is passkeys, which replace passwords with a login tied to a device you already own - if a service offers passkeys, they are even easier to use.
Lesson 3: Make Your Recovery Address a Dead End
Here is a mistake you are probably making right now: your recovery email is probably one of your normal, everyday accounts. Honan’s me.com address was both his recovery address AND an Apple service he used constantly. One key opened both doors. When the hackers got into the recovery address, they got into the heart of his Apple account at the same time.
A recovery address should be a dead end. Create a separate email account that is used for nothing except receiving reset links. Do not log into it every day. Do not connect it to any other service. Do not use it as a login anywhere. It exists for one job: to catch “reset your password” emails, so that if someone ever takes it over, they get a mailbox full of reset links - and nothing else.
Lesson 4: Back Up, Because Wipes Happen
The tragedy of this story was not the hack. Hacks happen. The tragedy was that the photos existed nowhere else. More than a year of his daughter’s life lived on one laptop, and when the laptop was wiped, it was gone.
A backup changes everything. An external drive, or a backup service that runs automatically, means a wiped device is an inconvenience, not a loss. You buy a new computer, log back in, and your photos come back with you. The photos of a first birthday, a first step, a first word - they exist in two places, so no single failure can take them. If you have a home network, What Is a NAS? walks through turning a hard drive on your network into your own private backup cloud - a middle ground between an external drive and a paid cloud service.
The rule is simple: if losing a file would hurt, it should exist in at least two places. And make the backup run automatically - automatic matters, because manual backups are the ones that quietly stop happening.
Lesson 5: The Support Call Is the Attack
Look back at the chain and find the weakest link. It was not Google’s software or Apple’s encryption. It was the human being on the other end of the phone. A billing address and four digits got the hackers past AppleCare. That was 2012.
The same trick still works today, just with new costumes. SIM-swap attacks convince a phone company to move your number to a criminal’s SIM card, which lets them receive your text-message codes. AI voice cloning now lets a caller sound exactly like someone you trust. The support call is still the attack - it just wears a better disguise.
The rule is simple, and it will protect you for the rest of your life: never give account-verifying details to someone who called you. No matter who they say they are. Hang up, find the official number yourself - from the app or the official website, never from the caller - and call back. A real company will be happy to wait. A scammer will not.
Your Five-Step Checklist
None of this requires technical skill. Every item takes less than an afternoon:
- Turn on two-factor authentication for your email. Start there - it is the master key.
- Get a password manager. Let it create long, unique passwords for every account. It remembers them, so you do not have to.
- Create a separate recovery email used for nothing else. Make it a dead end.
- Set up a backup that runs automatically. An external drive or a cloud backup service - your photos should exist in at least two places.
- Hang up and call back. Anyone who calls asking you to verify account details gets a dial tone, and you call the official number yourself.
That is it. Five small habits, and the whole chain falls apart.
The goal is not paranoia. Paranoia is exhausting, and it is not the point. The point is that a bad day online should never become a lost year of your life. The hackers in this story were not geniuses - they just found accounts that were connected, unprotected, and unbacked-up. Fix those three things, and you are no longer an easy target. That is the whole game.