What happened
During the 2008 US presidential campaign, David C. Kernell gained unauthorized access to then-Governor Sarah Palin's personal Yahoo email account by resetting its password. Screenshots of the contents were posted publicly. Kernell was convicted and, on 12 November 2010, sentenced to one year and one day in prison plus three years of supervised release.
How the deception worked
Kernell did not exploit a software flaw. He used the provider's self-service password reset flow, which authenticated the requester by asking knowledge-based security questions such as birth date, postal code and where the account holder met her spouse. Because the account holder was a sitting governor and national candidate, all of those answers were recoverable from publicly published biography and news coverage. Supplying them let him set a new password and read the mailbox, and he then published screenshots, turning a consumer account recovery convenience into a national political disclosure.
AI involvement · No AI reported
No AI involvement; the attack relied on publicly available biographical facts.
The control that would have caught it· our reading, not a claim from the sources
Knowledge-based authentication is unusable for public figures whose life details are published; account recovery should use possession-based factors such as a registered device or hardware key.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.