She googled something like 'mail new social security card' - clicked the first result and started entering information.
About 4 screens in she asked me to look at it - and we could both tell that it was likely not an official gov site at that point.
was first result in google so she trusted it - it looked similar enough to a gov site to go with the easy onboarding flow.. a few details like name and addy - then submit - next screen a few more bits of info.. submit next screen - real gold like maiden name, name of dog, - they already captured the social on the first screen..
some months later the irs is telling her she needs a pin code and that her identity appears to be hacked or whatever.. no surprise.
I long for the day when the faint piss-yellow box surrounded paid listings.. the engineers that came up with that perfect yellow that may show on a good desktop monitor / and in a presentation to the ftc/cpb/congress - whatever.. yet faded out on a laptop screen - and when the sun hits.. and yet as great as that was at being essentially invisible to most users - they still did away it - lets assume because it caused more clicks.. a/b testing and all the s valley bs.
I had forgotten about that incident until I saw this headline - might be time enough to still ad a note about this on a reply to a different HN article a week ago - where someone said "I've never seen any evidence of anyone hurt by the large scale collection of personal data by Google and FB." - ( https://news.ycombinator.com/item?id=27064382 )
( Part of the discussion in regards to the article Why I Work on Ads - https://news.ycombinator.com/item?id=27060898 )
This is indeed another good example of damage done by the ad selling overlords.
Now remembering stopping people from clicking the 'first result' for "flash player" - on so many devices, so many times - that ad was a two click malware install - of course it was a paid ad - sigh - people just don't know and google's been exploiting that for a long time.