Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Sarah Palin’s personal Yahoo email account was accessed in September 2008 after the password was reset using answers to account security questions. The Justice Department’s account describes no password-cracking tool, malware, or software exploit: the documented route was the account-recovery process.

How was Sarah Palin’s email hacked?

On or about September 16, 2008, David Kernell reset the password to Palin’s personal email account after answering its security questions, according to the Justice Department. The department’s October 8, 2008 indictment announcement alleged that he then accessed the account, read its contents, captured screenshots, and posted screenshots and the new password publicly.

Those details in the 2008 announcement were allegations at the indictment stage, not findings of guilt. The DOJ noted the presumption of innocence. Its later account of the case says Kernell viewed the emails and personal information and posted screenshots and the reset password online.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened in the case?

Date Event What the record says
September 16, 2008 Account access DOJ says the unauthorized access occurred on or about this date, using a password reset enabled by answers to security questions.
October 8, 2008 Indictment announced The DOJ announcement described allegations that the account was accessed, its contents read, and screenshots and the new password posted.
April 30, 2010 Jury verdict DOJ reported a conviction for misdemeanor unauthorized access and obstruction of justice, an acquittal on wire fraud, and no verdict on identity theft.

In its April 30, 2010 verdict announcement, the Justice Department stated: “The jury found Kernell not guilty of wire fraud.” The jury convicted him of misdemeanor unauthorized access and obstruction of justice, acquitted him of wire fraud, and did not reach a verdict on identity theft.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why account recovery matters to security

A strong password is not the only way into an account if the provider offers a recovery route that can reset it. In this case, the described entry point was password recovery, not a demonstrated failure to guess Palin’s existing password. The practical lesson is that recovery answers based on personal facts may be vulnerable when those facts can be found or inferred. That is a lesson drawn from the documented mechanism, not a finding about every provider’s recovery system or a current assessment of Yahoo.

The aftermath also shows why mailbox access has consequences beyond the ability to send messages. DOJ’s account describes emails and personal information being viewed, then screenshots and the new password being made public. Stored correspondence and personal details can themselves be exposed when an account is compromised.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What users can do now

Use multifactor authentication where available

The Cybersecurity and Infrastructure Security Agency (CISA) explains that multifactor authentication (MFA) requires two or more types of authenticator. That extra factor can make access harder when a password or PIN alone is compromised. CISA advises businesses to aim for phishing-resistant MFA; a physical security key is one option it identifies. Support depends on the service, and adding MFA does not by itself fix weaknesses in an account’s recovery process. See CISA’s guidance on MFA and its phishing-resistant MFA guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Review recovery settings as carefully as sign-in settings

  • Choose recovery answers that cannot be readily discovered or inferred from public information, when a service permits custom answers.
  • Keep recovery email addresses and phone numbers current and secured with their own strong authentication.
  • Review the provider’s available recovery protections and account-activity controls; these vary by service.
  • Do not treat a security key as a complete solution: it is an MFA option, not a substitute for securing password-reset and recovery routes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.