{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:19:40.630Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Sarah Palin Yahoo email account taken over via password-reset questions","date":"2008-09","date_precision":"month","victim_org":"Sarah Palin (then Governor of Alaska and vice-presidential candidate)","sector":"Government","country":"United States","primary_vector":"Physical Pretexting","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement; the attack relied on publicly available biographical facts.","outcomes":["Data Breach","Credential Theft"],"loss_usd":null,"loss_note":"No financial loss reported; the harm was disclosure of private correspondence during a national election campaign.","records_affected":null,"threat_actor":"David C. Kernell (convicted)","summary":"During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.","how_it_worked":"Kernell did not exploit a software flaw. He used the provider's self-service password reset flow, which authenticated the requester by asking knowledge-based security questions such as birth date, postal code and where the account holder met her spouse. Because the account holder was a sitting governor and national candidate, all of those answers were recoverable from publicly published biography and news coverage. Supplying them let him set a new password and read the mailbox, and he then published screenshots, turning a consumer account recovery convenience into a national political disclosure.","lessons":"Knowledge-based authentication is unusable for public figures whose life details are published; account recovery should use possession-based factors such as a registered device or hardware key.","confidence":"Confirmed","sources":[{"title":"Tennessee Man Sentenced for Illegally Accessing Former Governor Sarah Palin's E-mail Account","url":"https://www.justice.gov/archives/opa/pr/tennessee-man-sentenced-illegally-accessing-former-governor-sarah-palin-s-e-mail-account-and","publisher":"U.S. Department of Justice"}],"entry_type":"incident","slug":"2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions","year":2008,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2008-sarah-palin-yahoo-email-account-taken-over-via-password-reset-questions"}]}