Newsletter

March 2026 News & Tips | Old Electronics, Data Breaches, and Better Passwords

March 12, 2026|

March 2026 News & Tips | Old Electronics, Data Breaches, and Better Passwords
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing! 
This Month's News in Review

Welcome back to another action-packed month of cybersecurity news! We had some pretty heavy topics to cover the last two months, so let’s get back on track with the usual TCE Strategy tone that makes cybersecurity fun. From the magic of password keepers to the dangers of selling your old electronics, let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.

 

Disposing of electronics

Yes, I still have a house phone. It’s a dying breed, but it still serves a purpose worth keeping in our household. However, a lightning strike power surge took out my wireless handsets that plug into the house phone, and, well, wireless house phones aren't flying off the shelves these days, making them more difficult to purchase. So, I was excited to find a matching set of 6 used handsets on eBay, and they arrived in great shape. Terrific! It was when I plugged them in that things got interesting...The previous owner had taken the time to program in the phone numbers of LOTS of friends and family, but didn’t delete them when they sold the phones. I'm not sure who Audrey or Barb or Bob or Margaret or Shayna or Steve are, but I had all of their phone numbers and first names. Here is a redacted partial list:

AUDREY XXX-XXX-X815

BARB CELL XXX-XXX-X315

BOB&MARGAR XXX-XXX-X940

CHAD XXX-XXX-X330

DANNY CELL XXX-XXX-X380

DANNY HOME XXX-XXX-X293

DAVID CELL XXX-XXX-X569

EILEEN CELL XXX-XXX-X483

ERIN CELL XXX-XXX-X047

GARY CELL XXX-XXX-X803

JESSICA XXX-XXX-X834

JESSICA CELL XXX-XXX-X565

LARRY CELL XXX-XXX-X337

MARJORIE CELL XXX-XXX-X793

MARJORIE XXXXX XXX-XXX-X339

MARV XXX-X117

MAXINE XXX-XXX-X092

MIKE CELL XXX-XXX-X931

ROBERTA CELL XXX-XXX-X822

ROBERTA HOME XXX-XXX-X763

RON CELL XXX-XXX-X413

ROSS CELL XXX-XXX-X074

SARAH CELL XXX-XXX-X883

SASHA CELL XXX-XXX-X989

SD POLICE SERVIE XXX-XXX-X154

SHAYNA XXX-XXX-X084

SHAYNA CELL XXX-XXX-X225

STEVE CELL XXX-XXX-X305

WARRIOR XXX-XXX-X238

YELLOW PAGES 800-935-5697

 

Takeaway: Imagine how useful this information would be for me to impersonate these people. I could call Ross while I pretend to be a police officer and tell him that Shayna was in a car accident and she's being held in jail on a DUI charge. She needs $5000 wired for bail or she is going to spend the weekend in jail. I can even spoof caller ID and call Ross from Shayna's phone number and say that I took her phone from her while she's sitting in a jail cell. Malicious calls like this happen all the time, and it's information like this that gives the bad guys an advantage. It's critical to wipe your electronics before reselling them, or even disposing of them.

 

Wired data breach

I'm a big fan of the magazine WIRED because they cover a lot of terrific cybersecurity topics, but they have some egg on their face because of a data breach a few months ago. A hacker called "Lovely" stole 2.3 million WIRED customer records that included "full names, email addresses, user ID, display names, account creation and update timestamps, and in some cases, last session dates." Thankfully in this case passwords were not stolen, but in many other breaches, passwords are part of the exposed data. This breach underscores a very important point: if you are using the same password everywhere in your online life, when any website gets breached, it could expose the password you use for your email account, your banking accounts and so on. A password keeper solves this problem, in that it will make very complex passwords for every online service you need, they will all be different, and the magic lies in where you only need to remember one password to open your password keeper. I'm a fan. Unfortunately, I can't recommend LastPass because they have had some very notable breaches themselves, but most of their competitors have not. If using a password keeper isn't something you are likely to do, at a minimum use a completely unique and complex password to protect your email account(s) and enable Multi-Factor Authentication (MFA), as your email account holds the keys to your cyber kingdom: if you can't remember a password for some website, you click "forgot password" and then it will send a password reset email to your email account on file. If a cybercriminal can compromise your email account, they can compromise many other online accounts you have. 
 

Until next month, please stay safe!

Upcoming Speaking Events

Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!

March 23-30, Cozumel, Mexico

April 24-26, Brainerd, MN

May 25-29, Las Vegas, NV

June 19-26, Hayward, WI

July 23-28, Austin, TX

Nov 30-Dec 4th, Key West, FL

Dec 10-13, San Diego, CA

TCE Strategy in the News

Thank you to Paul Zyla for the opportunity to be on his podcast “Under the Surface” to talk about Defending the Digital Front Line!

Interesting Articles

In my opinion, the failure to change default passwords is always going to be a problem. The answer is to do away with default passwords. Devices (and software) need randomized initial passwords so that there isn't a "default" password that cybercriminals around the world will know to try. Our current methodology is the problem.
So someone tried to extort the extortionists. I love it. Seems odd that the Russian government can find someone trying to extort the Conti ransomware gang, but they can't shut down the Conti ransomware gang. Hmmm...
Cybersecurity Tip of the Month

Spring Cleaning: Safely Disposing of External Hard Drives and USB Drives

Spring has arrived, and many of us will soon catch the annual “spring cleaning” bug. As you clean out drawers and old tech, you may come across USB drives, external hard drives, or other storage devices you no longer need. If you decide to sell, donate, or recycle them, remember that the data you leave behind may still be recoverable.

Earlier in this newsletter I shared a story about used electronics that still contained personal information from the previous owner. While that example involved phone contacts, the same risk applies to storage devices. Many people assume that simply deleting files from a USB drive or external hard drive permanently removes them. In reality, data recovery tools can often restore deleted files, meaning sensitive documents or personal information could still be accessed by someone else.

There are several ways to securely wipe these devices before getting rid of them:


Formatting an external device:
Both Windows and Mac operating systems include built-in formatting tools that can erase drive data. Performing a format with a write-zero pass fills the storage space with zeros, making previously stored data much harder to recover. To see more detailed step-by-steps for Windows and MacOS, visit this article.


Using data erasure apps:
Many apps, both free and paid, can securely overwrite the data on external drives. Some of these are described more in depth here and include:

  • Android: Secure Eraser, Shreddit

  • Windows: CCleaner, Eassos PartitionGuru, MiniTool Drive Wipe

  • MacOS: StellarWipe Mac, Mac Washing Machine Secure X9

  • Windows and MacOS: AweEraser, Super Eraser

  • Windows, MacOS, and Linux: WipeDrive


Using Darik’s Boot-and-Nuke (DBAN):
DBAN is a free program designed to completely erase a hard drive. It permanently deletes everything on the drive—including files, applications, and operating systems—so it should be used carefully and intentionally. These articles give some very helpful tips and steps for using DBAN:
 
https://www.lifewire.com/dban-dariks-boot-and-nuke-review-2619130
https://www.lifewire.com/how-to-erase-a-hard-drive-using-dban-2619148


Using the cipher command (Windows):
Cipher.exe is a built-in Windows command line tool that can securely overwrite free space on a drive after it has been formatted, helping ensure previously deleted data cannot be recovered. A short tutorial on using cipher can be found here.
 

Before disposing of a USB drive or external hard drive, take a moment to check what data might still be on it and choose a method to erase it securely. And if you want the most definitive solution of all, a good old-fashioned hammer can still get the job done.

 

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2026 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp