Insights on digital risk and
personal security

Digital risk is evolving quickly. For individuals and families with greater public presence, professional responsibility, or complex personal lives, digital exposure is often higher. The impact of a security incident can extend beyond inconvenience to affect privacy, reputation, and financial well-being.

Disclaimer icon
The articles below share insights from the Richter Guardian team, including security advisories, real-world case examples, and practical guidance intended for people whose roles, visibility, or circumstances place them at elevated risk.
Insights on digital risk and personal security

Browse by topic

Explore articles based on areas of risk and responsibility.

A secure app showing assets, alerts, and overall risk level

Digital protection tips

Guidance and tips for high-net-worth individuals, executives and their families to stay safe online.

A secure app showing assets, alerts, and overall risk level

Digital executive protection

Articles about identifying, reducing, and fixing cybersecurity and online privacy risks in the personal lives of high-net-worth executives and their families.

A secure app showing assets, alerts, and overall risk level

Security advisories

Covers personal devices, accounts, and online presence.

A secure app showing assets, alerts, and overall risk level

Family and personal risk

Articles with guidance and tips for managing family and personal digital risk.

A secure app showing assets, alerts, and overall risk level

Case studies

Real-world examples that illustrate how digital incidents occur and how they are managed.

Latest articles

New articles and updates from the Richter Guardian team.

Article illustration: Regular Software Updates for Cybersecurity

Why Regular Software Updates Are Essential for Strengthening Cybersecurity

Software updates are a critical defense against cyber threats. We explain why they matter and how to check for updates on Apple, Android, Windows, and macOS—and when to turn on automatic updates.

Introduction​

As technology rapidly advances, so do the threats to business security, underscoring the critical importance of regular software updates. Cyber-attacks are becoming increasingly sophisticated and widespread, posing significant risks to organizations of all sizes. To defend against these malicious threats, businesses must prioritize keeping their software up to date.​

Software updates not only introduce new features but also provide essential security patches to address potential vulnerabilities. Failing to update can leave individuals and businesses exposed to cyber breaches, data theft, and financial loss. Given the growing reliance on technology for daily operations, maintaining strong security measures is more important than ever.​

Regular software updates are a crucial line of defense against cyber threats, making it imperative for businesses to stay current to protect their data, customers, and reputation. ​

How can I check if my software is up-to-date?

You can check if your device’s software is up to date by going into the device’s settings and looking for the “software update” option. Here’s how to do it on different types of devices:

  • On Apple devices (iPhone, iPad): Go to Settings > General > Software Update to see if any updates are available.
  • On Android devices (like Samsung Galaxy): Go to Settings and tap on Software Update or System Update. The exact location may vary depending on the model, but it’s usually found in the main settings menu.
  • On Windows devices: Go to Settings and find the Windows Update section. From there, click Check for updates to see if your system needs an update.
  • On macOS (iMac, MacBook): From the Apple menu n the corner of your screen, choose System Settings. Click General in the sidebar of the window that opens, then click Software Update on the right.

Whenever possible, activate automatic updates to receive the latest patches immediately upon release.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: Apple's NameDrop feature

Potential Concern with Apple's New NameDrop Feature

Apple’s NameDrop feature in iOS 17.1 shares contacts when iPhones are held close. Law enforcement recommends turning it off for children. We explain the feature and how Richter Guardian can help with device safety.

Introduction

In Early November, Apple released ‘NameDrop’ as part of the iOS 17.1 operating system update. NameDrop allows users to share saved contacts between other newer iPhones or Apple Watches within an inch of each other. While the prompt must be accepted to share contact information, several law enforcement agencies recommend parents to change this feature for children.  

Summary of the incident

The ‘NameDrop’ feature is similar to Apple’s AirDrop functionality. When NameDrop is enabled, two iPhone users can activate the feature by holding the top ends of their iPhones together. After that, the users can tap ‘Share’ or ‘Receive Only’. The NameDrop feature is automatically enabled once a user updates to iOS 17.1.  

While the feature itself is not a threat, law enforcement agencies are concerned that the feature puts children at a bigger risk with connecting to strangers. Children may not be completely aware when accepting a new ‘Share’ or ‘Receive Only’ prompt. Police recommend turning the feature off for children once they upgrade to iOS 17.1.  

Recommendations

  1. Turn the ‘NameDrop’ Feature Off for Children – It is good practice to upgrade your iPhone devices to the latest operating system update. The latest operating system update will include ‘NameDrop’ and automatically enable the feature. To turn off the NameDrop feature, complete the following:
    Navigate to iPhone Settings > General > Airdrop > Bringing Devices Together > Off.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: FBI Notice on Compromised Government Emails and Fake EDRs

FBI Notice Spike in Compromised Government Emails Conducting Fake EDRs

The FBI warned that compromised government emails are being used to send fraudulent Emergency Data Requests to service providers. We explain EDRs, how threat actors obtain access, and how to improve cyber hygiene with Richter Guardian.

Introduction

In early November, the Federal Bureau of Investigation (FBI) issued a warning regarding the abuse of compromised email accounts from U.S. and foreign government entities. These compromised accounts are being exploited to execute fraudulent Emergency Data Requests (EDRs) aimed at U.S.-based service providers.  

What is an EDR?

An EDR is a legal mechanism enabling U.S. law enforcement agencies to urgently request confidential data from service providers without a subpoena. Threat actors would take advantage of the procedure by using compromised government email addresses to submit fraudulent EDRs and obtain customer data.

For example, Verizon disclosed that it received over 127,000 law enforcement requests for customer data during the second half of 2023, with more than 36,000 classified as EDRs. The company reported fulfilling approximately 90% of these requests.

How do threat actors execute these schemes?

Investigations into cybercrime forums reveal multiple methods used by threat actors to submit fraudulent EDRs. Some fake EDR vendors sell the capability to generate fake EDRs by targeting specific platforms, complete with counterfeit court documents. Other fake EDR vendors simply sell access to compromised government or law enforcement email accounts.

Key tactics used to compromise government or law enforcement email accounts include:

  • Phishing and malware campaigns targeting email users.
  • Purchase of stolen credentials from dark web marketplaces.
  • Exploitation of poor cyber practices among government employees.

Key lessons

The notice serves as a reminder of the dangers posed by the sophistication of scams threat actors can orchestrate once they have access to compromised credentials.  

To mitigate risks, organizations and individuals must prioritize cybersecurity hygiene:

  • Establish a procedure on handling sensitive emails to avoid getting phished; approach urgent emails or emails with attachments with caution.  
  • Employ unique and strong passwords for every account and use multi-factor authentication when possible. Data breaches happen often, and threat actors like to take the compromised credentials from these breaches to re-use on other websites.  

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Article illustration: Authenticator Apps vs SMS for Login Security

Why Authenticator Apps Are Safer Than SMS for Login Security

Authenticator apps are more secure than SMS for two-factor authentication. We compare both methods, explain SIM swapping and interception risks, and recommend using an authenticator app for important accounts.

Introduction

One of the best ways to add extra security to your accounts is through Multi-Factor Authentication (MFA) – this means you need more than just a user ID and password to log in. We strongly recommend using MFA for your important accounts.

However, not all MFA methods are equally secure. Authenticator apps are a safer option than SMS authentication methods because they generate security codes directly on your device. SMS authentication codes, on the other hand, can be intercepted by hackers.

What is Multi-Factor Authentication and what is the benefit?

MFA adds an extra step to logging in. Instead of just entering a user ID and password, you must also provide another piece of information, like a code from an app or a text message. This extra step makes it much harder for hackers to break into your account, even if they steal your password.

MFA method #1: What is an authenticator application?

An authenticator app is a mobile app that generates security codes for logging in. These codes are called Time-Based One-Time Passwords (TOTP) and change every 30 to 60 seconds.

When you set up an authenticator app for an account, you scan a QR code or enter a secret key. This links the authenticator app to your account and allows it to generate matching codes.

To log in, you enter your username, password, and the current code displayed on your authenticator app. If the code matches the one your account server expects, you get access.

Some popular authenticator applications include:  

  • Google Authenticator
  • Microsoft Authenticator
  • Authy
  • Duo Mobile

MFA method #2: What is SMS authentication?

SMS authentication is when a security code is sent to your phone via text message. You enter this code along with your user ID and password to log in. These codes are One-Time Passwords (OTP) which are generated for one-time use. OTPs can last for a specified amount of time – users will need to generate a new OTP if they exceed the time limit.  

Sometimes, websites may also send security codes via email instead of SMS, but the process is the same.

Why authenticator applications are preferred over SMS authentication

Authenticator apps provide better security than SMS codes for several reasons:

  • Less chance of being hacked: Authenticator apps generate codes directly on your device, while SMS codes are sent over the internet and can be stolen.
  • No risk of SIM swapping: Hackers can trick your phone provider into transferring your number to a new SIM card, allowing them to receive your SMS codes.
  • No risk of interception: SMS codes can be stolen using man-in-the-middle attacks, where hackers eavesdrop on internet traffic.
  • Codes change frequently: Authenticator apps refresh their codes every 30 to 60 seconds, making them harder to steal and use.

How hackers can steal SMS codes

Here are two common ways cybercriminals can steal SMS codes:

  • Man-in-the-Middle Attacks – Hackers intercept your internet traffic when you connect to an unprotected Wi-Fi network (like public Wi-Fi at a coffee shop). This can let them steal SMS codes.
  • SIM Swapping – A hacker contacts your mobile provider pretending to be you and tricks them into activating a new SIM card with your phone number. Now, they receive all your text messages, including your security codes.

How to keep your accounts safe

  • Use an authenticator app instead of SMS authentication whenever possible.
  • Protect your phone with a strong PIN or password.
  • Avoid using public Wi-Fi when entering security codes.
  • Never share your security codes with anyone.
  • Be cautious of phishing scams that try to trick you into revealing your codes.

Ready to stay protected from digital threats, with experienced professionals overseeing your security?

Request a private consultation to find out whether Richter Guardian is a good fit for you.

Have questions after reading?

If something you’ve read raises a concern, our team can help you understand how it applies to you. Richter Guardian provides ongoing monitoring and expert support for individuals, families, and leadership teams.

  • Clear visibility into personal digital risk
  • Guidance from experienced cybersecurity professionals
  • Support designed for both private clients and enterprise leadership
Have questions after reading?