Skip to content
NetarxImpact Database
Physical PretextingNo AI reportedConfirmed

Sarah Palin Yahoo email account taken over via password-reset questions

Sarah Palin (then Governor of Alaska and vice-presidential candidate) · Government · United States · September 2008

What happened

During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.

How the deception worked

Kernell did not exploit a software flaw. He used the provider's self-service password reset flow, which authenticated the requester by asking knowledge-based security questions such as birth date, postal code and where the account holder met her spouse. Because the account holder was a sitting governor and national candidate, all of those answers were recoverable from publicly published biography and news coverage. Supplying them let him set a new password and read the mailbox, and he then published screenshots, turning a consumer account recovery convenience into a national political disclosure.

AI involvement · No AI reported

No AI involvement; the attack relied on publicly available biographical facts.

The control that would have caught it· our reading, not a claim from the sources

Knowledge-based authentication is unusable for public figures whose life details are published; account recovery should use possession-based factors such as a registered device or hardware key.

Sources (1)

  1. Tennessee Man Sentenced for Illegally Accessing Former Governor Sarah Palin's E-mail Account
    U.S. Department of Justice·justice.govOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.