The Mel Robbins PodcastThis Conversation Could Save You Thousands of Dollars
CHAPTERS
- 0:00 – 6:03
Meet cybersecurity educator Caitlin Sarian + why this matters now
Mel introduces Caitlin Sarian and sets the stakes: online scams are exploding and no one was taught “cyber hygiene.” Caitlin frames the episode as empowering, not scary, and previews simple routines anyone can adopt.
- •Caitlin’s mission: make cybersecurity practical for everyday life
- •Cybercrime is described as a massive economy; “when, not if” mindset
- •Cybersecurity as a routine like seatbelts/toothbrushing
- •Preview that there are a few “essential” actions to focus on
- 6:03 – 7:52
What cybersecurity really is: your digital footprint (and the incognito myth)
Caitlin defines cybersecurity as protecting your digital footprint—everything you do online. She explains that “incognito” only hides activity from your device/browser history, not from websites or trackers.
- •Digital footprint includes apps, websites, games, accounts—“everything”
- •Data is collected/recorded in many forms
- •Incognito mode doesn’t hide you from sites/trackers
- •Cookies/tags/pixels still track behavior
- 7:52 – 11:38
Give less personal data: aliases, burner numbers, and fewer accounts
Mel rapid-fires privacy habits Caitlin uses, starting with refusing to give real identifiers unless necessary. Caitlin explains why companies request data, how it’s sold, and how to reduce exposure using aliases, alternate emails, and forwarding numbers.
- •Challenge: “Why do they need your phone number/birthday?”
- •Use Google Voice/forwarding numbers and separate signup emails
- •Create fewer accounts; every account expands your footprint
- •Open-source intelligence (OSINT) makes personal info easy to assemble
- 11:38 – 13:31
Location oversharing: vacation posts, timing scams, and social engineering
Caitlin explains why posting trips in real time can increase risk beyond burglary—scammers can use your posts to impersonate you or target family during moments you’re unreachable (like flights). The fix is delaying posts and avoiding precise tags (hotels, flights).
- •Real-time travel posts can enable social engineering
- •Scammers can impersonate you with specific context (hotel, city)
- •Timing attacks: they call family when you’re in-flight/unreachable
- •Safer sharing: post later, tag general areas not exact locations
- 13:31 – 18:55
Public Wi‑Fi risks explained: HTTPS, VPNs, and what to avoid
The conversation breaks down what happens on open networks and why unencrypted Wi‑Fi can expose sensitive activity. Caitlin gives practical rules: check for HTTPS, avoid banking on public Wi‑Fi, use tethering/hotspots, and consider a VPN when needed.
- •Open Wi‑Fi can be unencrypted; others can intercept traffic
- •HTTPS “S” indicates a secure connection (baseline check)
- •Use public Wi‑Fi for low-risk tasks (maps/social) not banking
- •Safer alternatives: phone tethering/hotspot; VPN for privacy
- 18:55 – 24:05
Passwords, Notes app, and security questions: stopping the easiest hacks
Caitlin explains why storing passwords in unsecured Notes is risky (iCloud exposure) and why password managers are safer. She also warns that common security questions are easily researched via OSINT, so answers should be treated like passwords (persona-based).
- •Lock Notes (Face ID/passcode) if you must store sensitive info
- •Use a password manager (1Password, Keeper, iOS Passwords)
- •Avoid “all eggs in one basket” when possible
- •Security questions are often publicly discoverable—use fake persona answers
- 24:05 – 27:12
Auto software updates and physical-device risks (juice jacking, ‘hackers aren’t interested in me’)
Caitlin reframes software updates as security patches that close vulnerabilities hackers exploit. She also covers edge-but-real physical risks like compromised USB charging ports (“juice jacking”) and emphasizes that criminals target easy money, not just famous people.
- •Updates often patch known security holes—turn on auto-updates
- •“Juice jacking”: don’t trust random USB ports; use wall outlets
- •Myth: “hackers won’t target me” — easy targets are profitable
- •Behavior changes are small but prevent big downstream damage
- 27:12 – 29:52
How people get hacked today: reused passwords, phishing, and ‘law enforcement’ calls
Caitlin describes two primary attack paths: credential stuffing from reused passwords and social-engineering scams via calls/emails. They unpack the psychology of urgent threats (missed jury duty, arrest) and the red flag of being asked to pay in crypto.
- •Base-password reuse enables fast automated guessing variations
- •Phishing and scam calls are increasingly sophisticated with personal data
- •Common script: missed court/jury duty → fear → demand payment
- •Crypto payment request is a major warning sign
- 29:52 – 35:21
Spotting compromise: checking logins, banking alerts, and voice-scam defenses
Caitlin shares how to audit account sessions (Gmail, social apps, phone logins) to detect suspicious access. She also advises calling banks using the number on your card, avoiding unknown calls/voicemail greetings, and using a family safe word to counter voice cloning scams.
- •Check “logged-in sessions” and account activity history regularly
- •For suspicious banking texts/charges: call bank via official number
- •Avoid answering unknown calls; limit voicemail info/voice samples
- •Use a family safe word to verify identity during urgent requests
- 35:21 – 37:08
Payment-app scams (Venmo/Zelle) and safer ways to pay
A detailed walkthrough of the Venmo ‘accidental payment’ scam shows how victims lose money when the original stolen-card transfer is reversed. Caitlin recommends minimizing peer-to-peer payments when possible and prioritizing credit cards for better dispute protection.
- •Scam pattern: stranger ‘accidentally’ sends money → asks for return
- •Stolen-card payment gets reversed; your voluntary refund doesn’t
- •Avoid Venmo/Zelle when possible; treat them like cash transfers
- •Prefer credit cards over debit for stronger fraud protections
- 37:08 – 39:03
After a data breach: MFA, credit monitoring, and freezing your credit (fast identity-theft prevention)
Caitlin outlines what to do when a retailer or financial service is breached: change passwords, enable multi-factor authentication, and enroll in offered monitoring. The biggest preventative move is freezing credit with all bureaus so criminals can’t open accounts in your name.
- •Immediate steps: update password; enable MFA (prefer authenticator apps)
- •Use free credit monitoring offered after major breaches
- •Freeze credit across the three bureaus; unfreeze only when needed
- •Freezing credit is positioned as the fastest way to stop identity theft
- 39:03 – 40:46
Protecting seniors: locks on key accounts, MFA routing, and fraud helplines
Mel and Caitlin discuss why older adults are heavily targeted and how families can intervene respectfully. Caitlin recommends freezing credit, strengthening bank/retirement logins, turning on MFA, and—if appropriate—routing authentication codes to a caretaker for oversight.
- •Start with credit freeze for parents/grandparents
- •Harden bank/401k/retirement accounts with strong unique passwords
- •Enable MFA and consider caretaker receiving codes for visibility
- •Teach a simple rule: hang up and call a trusted fraud helpline/number
- 40:46 – 44:47
Kids online safety + sextortion: privacy settings, messaging limits, and where to report
Caitlin lists non-negotiables for children: use child accounts, set profiles to private, restrict DMs, and be cautious with chat in games. She explains sextortion dynamics and points listeners to the FBI’s IC3 site for reporting online crimes.
- •Use child accounts on platforms; set profiles to private
- •Limit or block direct messages; watch chat features in games
- •Open communication makes kids more likely to report uncomfortable situations
- •Sextortion is rising; report via IC3.gov (Internet Crime Complaint Center)
- 44:47 – 46:31
If your phone is stolen: pre-steps to keep it trackable
Caitlin recommends preparing before loss by removing quick access to Airplane Mode from Control Center, preventing thieves from instantly disabling tracking. She notes the importance of strong device passcodes and the reality that weak PINs are still common.
- •Remove Airplane Mode from swipe-down Control Center access
- •Thieves often enable Airplane Mode first to defeat tracking
- •Use stronger unlock codes; weak PINs remain widespread
- •Preparation reduces panic and limits downstream account exposure
- 46:31 – 54:22
Wearables and app privacy: reading policies, limiting permissions, and stopping camera-roll scanning
The conversation broadens to data collection via wearables and connected devices. Caitlin advocates a risk-based approach: summarize privacy policies with AI tools, check who data is shared with, and tighten app permissions—especially camera, mic, and precise location—to prevent background scanning (including camera roll analysis by social apps).
- •Wearables collect sensitive health/biometric data; decide via risk tolerance
- •Use AI to summarize privacy policies: what data, why, who shared with
- •Audit app permissions: camera, microphone, location (prefer ‘only while using’)
- •Social apps may scan your camera roll; limit photo access to selected items
- 54:22 – 1:04:33
Facial recognition and home cameras: what’s hackable + practical protections
Caitlin explains the tradeoffs of biometric systems (Clear/Global Entry) and why biometrics can’t be ‘changed’ like passwords if leaked. She then covers risks to laptops, doorbells, and baby monitors—often driven by reused passwords or exposed networks—and recommends simple mitigations like camera covers and unique passwords.
- •Biometrics are unique and hard to remediate if compromised
- •Opt-in vs opt-out decisions depend on convenience and risk tolerance
- •Cameras can be accessed via reused passwords or insecure setups
- •Use camera covers and strong unique passwords for IoT devices
- 1:04:33 – 1:13:42
The 5 essential online safety habits (plus data deletion services)
Caitlin closes with a prioritized checklist that reduces overwhelm: strong unique passwords, automatic updates, credit freeze, pausing before clicking links, and reducing exposed personal data. She also describes data broker opt-outs, manual removal sites, and services like Incogni to automate deletions.
- •Five essentials: passwords, auto-updates, freeze credit, 9-second link pause, limit data online
- •Identify ‘key accounts’ and protect them first; add MFA
- •Avoid clicking links; verify by calling or hovering to inspect URLs
- •Reduce data via broker opt-outs (Whitepages, TruePeopleSearch) or deletion services