Bay Geeks logoTampa Bay IT Support ยท Since 2004
Bay Geeks Guide · Security Which Layer Is It?

Am I Being Hacked? The Three Layers of Cyber Threats

Most people worry about the wrong kind of hack. Here's how to tell what's really going on with your accounts and devices — and what to do about it.

You get a login alert from a city you've never visited. Your phone battery is draining faster than usual. A friend swears their phone is full of spyware and someone is watching everything they do.

Your brain goes straight to the worst case: someone is after me.

Bay Geeks has been taking these calls since 2004, and the pattern is consistent. The fear is real, but it's almost always aimed at the wrong target. People spend energy defending against a Hollywood-style attack while leaving the front door open to the cheap, boring attacks that actually get people.

A useful way to think about this comes from privacy educator Rob Braxman: digital threats come in three layers, and each one has a completely different cost, likelihood, and defense. Once you know which layer you're dealing with, the anxiety drops and the fix becomes obvious. We've adapted his framework to what we see every week with home users and small businesses across Tampa Bay.

The Short Version

The goal isn't to lock your life down like a spy. It's to defend hard against Layer 2, trim your exposure to Layer 3, and stop losing sleep over Layer 1.

Layer 1: TargetedLayer 2: Mass-volumeLayer 3: Data collection
Who's behind itGovernments, well-funded adversariesCriminal crews running scams at scalePlatforms, apps, data brokers
Cost to attack youThousands to millions of dollarsClose to zeroZero (you agreed to it)
Likelihood for most peopleVery rareVery likelyConstant
Best defenseProfessional monitoring if you're truly a targetUnique passwords, MFA, skepticism, updates, backupsPrivacy settings, fewer permanent identifiers

Layer 1: Targeted Attacks (the One You're Probably Overestimating)

This is the layer with the scary headlines: commercial spyware sold to governments for millions of dollars, custom malware, someone with prolonged access to your device. It exists. It's also expensive, and attackers are rational. They compare what it costs to get in against what they'll get out.

For someone with a normal bank balance and a normal social media presence, that math almost never works. A real targeted effort costs thousands of dollars at the low end, and most “hire a hacker” offers on the dark web are scams themselves.

The math only changes if there's a lot of money that's easy to drain, you're a path to something bigger (a company network, a wealthy relative), or you have a motivated personal enemy willing to spend real money. If none of that describes you, hardening your phone against a nation-state is solving the wrong problem.

Layer 2: Mass-Volume Attacks (the One That Actually Gets People)

This is where nearly every “I got hacked” story we hear actually lives:

It feels personal because it happened to your account. Usually, it wasn't. You were on a list of millions, and the marginal cost of trying you was nothing.

The reassuring part: every item on this list is defeated by basic hygiene, not exotic hardware.

Layer 3: Mass Data Collection (the One That Never Stops)

Nobody has to break into your phone to know where you sleep, where you work, who you text, and what you searched at 2 a.m. You agreed to that in a terms-of-service screen. Platforms and apps collect location patterns, contacts, identifiers, and behavior at population scale, and data brokers package and resell it.

Two reasons this matters even if you have “nothing to hide”:

  1. That data shapes what you see: recommendations, ads, and which information reaches you first.
  2. It's the supply chain for Layer 2. Breach dumps, broker profiles, and public records are what make doxxing and convincing phishing cheap.

Your phone number is the biggest permanent identifier you hand out. It follows you across accounts for decades and is exactly why so many services insist on it. Reducing how many places your real number, real name, and home address are linked together is a proportional, realistic goal — and a very different one from trying to stop a sophisticated remote exploit.

Which Layer Is Your Problem?

Before you assume the worst, run through this list:

If you answered yes to any of these, you're looking at a Layer 2 or Layer 3 problem. That's good news, because those are fixable in an afternoon.

What Bay Geeks Actually Recommends

Home users and small businesses get most of the benefit from a short list:

  1. Use a password manager and stop reusing passwords. For the few you have to type, use a long passphrase of four or five random words. Length beats complexity.
  2. Turn on multi-factor authentication, starting with email. Your email account is the master key to every password reset you own. Use an authenticator app or a security key instead of text messages wherever that's an option.
  3. Slow down on anything unexpected. Don't click links in surprise emails or texts. Go to the site directly or call a number you already know. No legitimate company calls to tell you your computer has a virus.
  4. Keep devices updated and backed up. Commodity malware lives on old software. A good backup turns ransomware from a catastrophe into an inconvenience.
  5. Shrink your public footprint. Tighten privacy settings, skip the public “leaving for Spain next week” post, review app permissions and location history, and consider a separate number for sign-ups.
  6. After a breakup, a firing, or a falling-out, change passwords, check your recovery email and phone numbers, and sign out of every session.

If You Think You've Been Hacked Right Now

  1. From a device you trust, change your email password first.
  2. Turn on MFA and sign out of all other sessions.
  3. Check your recovery email, recovery phone, and any forwarding rules for entries you didn't add.
  4. Work outward from there: banking, then everything else.
  5. If money has moved, you can't get back in, or you're not sure the machine is clean, that's a good use of a technician's hour. Call us.

When You Actually Need More

Some people are legitimately worth targeting: business owners who approve large wire transfers, anyone with admin access to large systems, people in public-facing roles. If a successful attack on you would pay off in a big way, plan for all three layers: managed updates, monitored endpoints, and someone watching for trouble around the clock. That's what our Advanced Maintenance Plan with Bay Geeks SOC 24/7 monitoring is built for.

FIXED ✓

Book a Security Checkup

We'll go through your passwords, MFA, backups, and exposure with you — remotely or on-site across St. Petersburg, Clearwater, and Tampa Bay. Most checkups fit in a single hour.

Frequently Asked Questions

My phone battery is draining fast. Is it hacked?

Almost never. Fast battery drain is usually a misbehaving app, an aging battery, or a recent OS update. Check battery usage by app before assuming spyware.

Someone logged into my account from another country. Was I targeted?

Almost certainly not personally. Your email and password were most likely in a breach and tried automatically against many sites. Change the password, turn on MFA, and sign out everywhere.

Do I need a “hardened” or de-Googled phone?

For most people, no. Unique passwords and MFA prevent far more real-world damage. Reducing what platforms collect is a reasonable next step once the basics are covered.

What is doxxing?

Publishing someone's private identifying information: home address, phone number, workplace, family details. It's usually assembled from data that's already public or for sale, which is why limiting your permanent identifiers helps.

The Takeaway

The next time the anxiety spikes, don't ask “is someone after me?” Ask “which layer is this?” Reused password, no MFA, exposed phone number, someone you know with access: that's Layer 2 and Layer 3, and it's fixable.

If you'd rather have someone walk through it with you, Bay Geeks offers security checkups remotely or on-site across St. Petersburg, Clearwater, and Tampa Bay. Schedule a technician, call 727-579-4335, or email [email protected].

This post was inspired by this Rob Braxman Tech video. The three-layer framework is his; the recommendations reflect what Bay Geeks sees with home and business clients in Tampa Bay.

Common Computer Problems

The issues we see most often in Tampa Bay homes โ€” and what to try first.

Remote vs. On-Site Repair

How to know which type of service gets you fixed faster.

Managed vs. Break-Fix

What proactive support actually saves you compared to calling only when something breaks.

Maintenance Plan ROI

How a monthly maintenance plan pays for itself in prevented downtime.

Ransomware Checklist

The proactive steps that keep your business off the list of ransomware victims.

Signs You Need a SOC

How to tell when antivirus alone isn't covering you anymore.

MDR vs. Antivirus

What managed detection & response catches that antivirus can't.

Identity Threats 101

Why a stolen password is now the most common way in โ€” and how it's stopped.

One-Click Compliance

What HIPAA, PCI DSS and NIST reporting should actually look like.

IT Spend Audit

A quick check on whether your current IT setup is costing more than it should.

How Remote Support Works

What actually happens during a remote session, step by step.

Pricing

Real, upfront rates for computer repair and managed IT services โ€” no hidden fees.

๐Ÿ“ž 727-579-4335  ยท  โœ‰๏ธ [email protected]  ยท  Privacy Policy  ยท  Terms of Service