Chris Chia's Blog - Posts Tagged "hacking"
Computer Hacking 101
Many of the hacking techniques used in The Apex Code — including a healthy dose of social engineering — are taken from the real thing. As basic as some of them seem, and for as long as they've been around, they're still in use today, and getting hacked has never carried more personal risk than it does now. We're all carrying the equivalent of a hand-held computer everywhere we go, in our pockets and bags, and that phone holds everything a hacker would need to take over your identity, drain your accounts, or run up your credit cards. It's not just personal risk either — companies face it just as much, made worse by the fact that lists of stolen login credentials get bought and sold on the dark web every single day.
It's close to true today that anyone can get hacked, and there's very little real defense if someone determined enough wants into your bank account or your entire social media footprint.
This Happened to Us Last Week
A friend of ours appeared to be selling a truck on their social media account, on behalf of another friend whose husband had recently passed away. It looked like a decent deal — not a steal, not "too good to be true," just something reasonably priced that we might genuinely want. So we asked about it. The "friend" answered our questions, gave details, and then suggested we send a deposit to hold the truck until we could come see it in person a couple of days later. All perfectly reasonable, for someone we knew, with mutual friends all over our social feeds. We passed for other reasons, and said we'd call ahead once we had time to actually go look at it.
The whole thing was bogus. Our friend's account had been hacked, and whoever was behind it had been running the same play on multiple people — a truck, an ATV, a car, a boat, golf clubs, whatever story fit the account they'd taken over. Nobody in that chain of victims did anything careless. They just answered a message from someone they already trusted.
The Social Engineering Problem
This is what social engineering looks like when it's actually good at its job — professional enough, and insidious enough, that you genuinely can't take anything you see or hear online at face value anymore. Even voice replication means the person calling you might not be who you think, especially if it's been a while since you last heard from them.
In The Apex Code, I kept things to well-known, conventional hacking methods — all real, all with a long history, all still very much in use. A few examples:
Credential mining — mining someone's social media and online presence for personal details, then using that information to make smart, targeted guesses at their login credentials.
Password reuse — taking one cracked password and reusing it across multiple accounts, since most people reuse the same passwords or close variations of them everywhere.
Malicious software — spyware quietly injected onto a device that mines every unprotected password and login it can find.
Email and messaging — straightforward fake messages designed to get you to hand over your login details to someone pretending to be someone else, which is really just social engineering wearing a different hat.
The Bottom Line
Use an encrypted password vault. Use the strong, random passwords a good password generator gives you — often built right into that same vault app. And stop reusing family names, pet names, birthdays, and the usual combinations of them, over and over, across everything.
This isn't exhaustive advice. Think of it more as a nudge to run a few checks and refresh your own security every so often — before someone else finds the reason to do it for you.
— Chris
It's close to true today that anyone can get hacked, and there's very little real defense if someone determined enough wants into your bank account or your entire social media footprint.
This Happened to Us Last Week
A friend of ours appeared to be selling a truck on their social media account, on behalf of another friend whose husband had recently passed away. It looked like a decent deal — not a steal, not "too good to be true," just something reasonably priced that we might genuinely want. So we asked about it. The "friend" answered our questions, gave details, and then suggested we send a deposit to hold the truck until we could come see it in person a couple of days later. All perfectly reasonable, for someone we knew, with mutual friends all over our social feeds. We passed for other reasons, and said we'd call ahead once we had time to actually go look at it.
The whole thing was bogus. Our friend's account had been hacked, and whoever was behind it had been running the same play on multiple people — a truck, an ATV, a car, a boat, golf clubs, whatever story fit the account they'd taken over. Nobody in that chain of victims did anything careless. They just answered a message from someone they already trusted.
The Social Engineering Problem
This is what social engineering looks like when it's actually good at its job — professional enough, and insidious enough, that you genuinely can't take anything you see or hear online at face value anymore. Even voice replication means the person calling you might not be who you think, especially if it's been a while since you last heard from them.
In The Apex Code, I kept things to well-known, conventional hacking methods — all real, all with a long history, all still very much in use. A few examples:
Credential mining — mining someone's social media and online presence for personal details, then using that information to make smart, targeted guesses at their login credentials.
Password reuse — taking one cracked password and reusing it across multiple accounts, since most people reuse the same passwords or close variations of them everywhere.
Malicious software — spyware quietly injected onto a device that mines every unprotected password and login it can find.
Email and messaging — straightforward fake messages designed to get you to hand over your login details to someone pretending to be someone else, which is really just social engineering wearing a different hat.
The Bottom Line
Use an encrypted password vault. Use the strong, random passwords a good password generator gives you — often built right into that same vault app. And stop reusing family names, pet names, birthdays, and the usual combinations of them, over and over, across everything.
This isn't exhaustive advice. Think of it more as a nudge to run a few checks and refresh your own security every so often — before someone else finds the reason to do it for you.
— Chris
Published on August 08, 2026 10:37
•
Tags:
behind-the-scenes, cybersecurity, hacking, social-engineering, techno-thriller, the-apex-code


