Recently, the tech world has been abuzz over news that Microsoft had to patch hundreds of security vulnerabilities in a single update, including at least one that was already being exploited in the wild. To the average user, this might sound distant, like something that only affects big companies. However, each vulnerability is a door through which bad actors can slip in to steal personal information from anyone using a computer or phone—from social security numbers to bank passwords. This is a good time to pause and review personal data protection habits that everyone should have, regardless of whether tech news is making headlines or not.
Protecting personal data is not a one-time task but a habit to maintain, like locking your door every night.
Why Personal Data Is So Valuable
Think of personal data like a house key. Your social security number, date of birth, address, phone number, online shopping habits—all are small pieces that, when assembled, allow criminals to create a "copy" of you to take out loans, open credit cards, or apply for government benefits. Unlike a house key, you cannot easily change your social security number if it gets exposed.
Tech companies, social media platforms, and even free apps on phones collect data to sell to advertising companies. That's why after searching for flights back to Vietnam, you suddenly see flight advertisements everywhere. This kind of tracking is mostly legal, but it creates a massive amount of data about you—and that data becomes the target when cybersecurity incidents happen, like the recent Microsoft vulnerability.
Passwords: The First Line of Defense and the Most Overlooked
Many people still use the same password for every account, from email to banking to Facebook. This is like using a single key for your house, car, and safe. If a criminal gets that key from one place, they can open everything else.
The simple solution is to use a password manager (like Bitwarden or 1Password) to create and remember long, complex, unique passwords for each account. Additionally, most banks, email providers, and social media platforms allow you to enable two-factor authentication, which means that after entering your password, the system sends an additional code to your phone to confirm you are logging in. This step takes only a few extra seconds, but according to the Federal Trade Commission (FTC), it is one of the most effective ways to prevent criminals from taking over accounts even if they have your password.
Identifying Fake Emails and Text Messages
Phishing (fraud through fake emails or text messages) is the most common way personal data gets stolen. Criminals often impersonate banks, the IRS, or even U.S. immigration authorities, sending emails saying your account has a problem and asking you to click a link and enter your login information.
A red flag: U.S. government agencies like the IRS never contact you demanding money via sudden email or phone calls. If you receive a message creating a sense of urgency, threatening to close your account if you don't act immediately, that's usually a psychological trick to keep you from thinking clearly. The safest approach is not to click links in unfamiliar emails, but instead to open your browser, type the official website address of your bank or relevant agency directly to verify.
Social Media: Share Less, Stay Safer
Social media is where many people accidentally expose the most data without realizing it. Posting photos from your vacation while you're away tells criminals your house is empty. Answering fun Facebook quizzes like "What was your first pet's name" accidentally reveals the answer to a security question that your own bank might be using to verify your identity.
The simple solution is to go to the privacy settings of each platform, limit who can see your posts, and avoid publicly posting your full birth date, phone number, or home address on your public profile.
Public WiFi and Phone Apps
Free WiFi at coffee shops and airports is convenient, but it's also a place where criminals can easily "eavesdrop" on data being transmitted over the network if you log into your bank or enter credit card information while using it. If you need to do important work like that, use your phone's data network (4G, 5G) or use a VPN app (a virtual private network that encrypts data as it's transmitted) for added security.
With phones, each app typically requests access to location, contacts, camera, even if unrelated to its main function. A flashlight app doesn't need to know where you are. Every few months, go to settings to review and disable unnecessary permissions.
Comparison of Common Data Protection Measures
| Measure | Difficulty Level | Protection Effectiveness |
|---|---|---|
| Strong, unique passwords for each account | Easy, use password manager app | High |
| Two-factor authentication | Easy, takes a few seconds per login | Very high |
| Caution with unfamiliar emails and texts | Easy, just requires a habit | High |
| Limit sharing on social media | Medium, requires adjusting settings | Medium |
| Use VPN when out on public WiFi | Medium, requires installing an app | Medium to high |
| Monitor credit reports regularly | Easy, free from three major companies | Helps detect fraud early |
For Vietnamese Americans: Important Considerations
The Vietnamese community in America, especially those who arrived before or right after 1975, often has less familiarity with technology procedures and English-language cybersecurity notifications, according to the Consumer Financial Protection Bureau (CFPB) which noted language barriers in accessing financial information. This makes many seniors vulnerable to scams like IRS impersonation calls, fake calls from relatives claiming to be in trouble and needing money urgently, or Social Security Administration (SSA) calls demanding verification of social security numbers.
One notable fact is that nail salon owners, restaurant owners, and laundry shop owners often store customer and employee information (including social security numbers for tax purposes) on shared computers or unprotected personal email accounts. If that computer gets infected with malware, not only the owner but all customers and employees risk having their information exposed. For small businesses, it's important to keep accounting and tax computers separate from machines used for social media or entertainment.
What to Do If You Suspect Your Data Has Been Exposed
If you receive a notification from your bank, credit card company, or the tech company itself saying your data may have been affected by a cyber attack, don't panic but don't ignore it either. First, immediately change the password for that account and any other accounts using the same password. Then check your credit report (free from the three major companies: Equifax, Experian, and TransUnion) to see if any unfamiliar accounts have been opened in your name.
If you detect signs of identity theft, you can report directly to the FTC through IdentityTheft.gov, and the agency will guide you step-by-step through locking fraudulent accounts and restoring your identity.
Protecting personal data is not a one-time task but an ongoing habit, like locking your front door each night. Security vulnerabilities like the Microsoft incident can happen at any company, but most real damage comes from small, preventable oversights in each person's daily habits.
Bảo Nguyễn
Bảo Nguyễn founded Saigon Sentinel to give the Vietnamese diaspora truly independent, in-depth community coverage at a time when misinformation moves faster than fact-checks and the language barrier makes verification harder than it should be. He sets the editorial standards and quality controls that govern the reporting, chooses the subjects, writes and edits each article, reads it against its sources before publication, audits published output, and handles corrections.