Ms. Yeung, a 70-year-old retired real estate executive, had spent a lifetime building a $1.1 million portfolio at Interactive Brokers. In December 2025, while she was on vacation, someone drained it to $34k in a single afternoon, without ever logging a withdrawal.

No wire or outgoing transfer. Nothing sitting in a pending queue for her to cancel. By the time she noticed, roughly $1.1 million was gone, and the only fingerprints were trades she never placed.
This happened at Interactive Brokers. If it could happen there, it can happen anywhere.
The heist
According to the Sing Tao News video, Ms. Yeung's account was emptied with more than 30 purchases of Beyond Meat 0DTE call options, $1.50 strike, totaling $1.1M, over a 1.5-hour stretch on December 19, 2025.
That day BYND traded from $1.03 to $1.261 and the stock was up almost 12%. The $1.50 calls stayed out of the money and expired worthless at 4pm Eastern Time, when the US stock market closed.
$1.1 million of life savings, gone.
On paper, the account was not robbed. It was traded. And trading is the very purpose of brokerage accounts.
Withdrawals are where the brokerage puts up walls: holding periods, callbacks, reversal windows, a fraud desk that treats a wire as their problem. A trade has none of that. It executes in seconds and is irreversible.
The preferred trade for hackers are thinly traded, illiquid options that expire the same day. The hacker needs to sell the options they already hold, at an inflated price, to the victim’s account.
With highly liquid and heavily traded option contracts, market makers will fill the victim’s buy order with the market maker’s own options at a reasonable price, so the hacker never gets to sell at their preferred inflated price.
Beyond Meat 0DTE call options, the ones used to empty Ms. Yeung’s account, barely trade. A hacker can rest a sell limit order on the market and wait. When the victim’s account buys those contracts, the seller is the hacker. Once it rolls around to 4pm Eastern Time, those call options expire worthless, and the hacker keeps the premium. The record makes it look like an elderly former corporate executive bet too big on Beyond Meat on a Friday.
This hack can be executed with any obscure stock, warrant, or bond, but options are just the fastest way to do it.
The heist starts with one link
The question of course is how the hacker got into the victim’s brokerage account in the first place.
A text could have asked the brokerage account holder to update a tax form on the account or risk account suspension otherwise.

The phishing email that fooled Hillary Clinton’s campaign manager John Podesta into exposing over 20,000 emails in 2016 arrived masqueraded as a Google security alert.
Hackers even buy ads on Google Search linking directly to pixel-perfect copies of login pages.
The victim then
clicks the phishing link
lands on an exact copy of the brokerage login, on a URL like ibkrlogc.top2
types their username and password
approves the two-factor authentication on their phone.
That is the moment it is over.3
The victim did nothing stupid. Two-factor authentication, the system we’ve all been told would save us, worked exactly as designed...for the wrong person.
2FA doesn’t protect you anymore
For years, the advice was earnest enough. Turn on 2FA. Hackers can steal your password, but they cannot steal the code on your phone. This is what Ms. Yeung herself was told, so she was astonished to find that 2FA had become useless.
Ms. Yeung had been correctly informed. Old phishing was a web form that saved your username and password for later, so 2FA would stop future attacks.
But new phishing uses fully functional sites that sit live between you and the real login and pass through whatever you type in real time: username, password, 2FA code. The brokerage, believing it has authenticated you, issues a session cookie, which says this person is logged in and verified, to the hacker, and your phone gets no new notifications.
"Just turn on 2FA" assumed the hacker had to beat the second factor, not that it could just be collected by the hacker.
Phishing-enabled trading is “authorized activity”
Brokers will monitor accounts for suspicious transactions, but that doesn’t stop trades.
With Ms. Yeung specifically, Interactive Brokers detected suspicious logins from new IP addresses between December 15-19, 2025.
Despite detecting suspicious logins, IBKR did not stop the options trades that took place on Dec 19, 2025, ask for additional verification before processing them, or accept responsibility for the losses.
As for why they refused responsibility, Interactive Brokers was clear:
If you used your own username and password to log in to place these trades, then this is the client’s responsibility. We will not accept this compensation request.
The victim did the login and tapped approve. The intrusion wears their fingerprints. If the hacker sends a wire, the broker has a problem. If they trade it away instead, it’s the victim’s nightmare.
The part that should anger you
Try to wire $1 million out of your brokerage, and you’ll get delays, emails, and calls to verify you from your brokerage.
Trade the same account into the ground with options the account holder has never bought, and none of that shows up. No second 2FA prompt to verify the action. No setting that makes you confirm an unusual order in the app before it executes. A trade is a trade, and it clears in seconds.
The brokerage could make you confirm the trade on your phone. A 70-year-old account holder who has never bought an option, whose account has had several suspicious logins in the past few days, buying $1 million of same-day-expiration BYND call options within 90 minutes should have been a fire alarm for the broker’s internal systems, but no major retail broker has an option to send a push notification confirmation for suspicious trades in their app.
Follow the money
This is not a technical limitation. Brokers make way more money from trading in options than stocks and ETFs, whether they charge payment for order flow (PFOF) or commissions.
Payment for order flow
An example from a 2022 UW study pointed out that there would be a 10x difference in PFOF revenue between an options and stock order of the same amount.
A nominal investment of $1,000 in a $25 stock would generate a 40-share equity order, worth 8 cents in equity PFOF, while a nominal investment of $1,000 in a $5 option would generate a 200-share options order, worth 80 cents in option PFOF. In other words, the same nominal investment in options will generate 10 times as much PFOF as the equity investment.
In reality, the difference is larger than 10 times, as share prices are routinely in the hundreds of dollars while options contracts are often a few dollars each.
Commissions
The same stock and option order as in the UW study, on a Vanguard account (the only broker without PFOF in this 2024 Cornell study):
Stocks: 40 shares * $0 commission per share = $0 commission.
Options: 2 options contracts * $1 commission per contract = $2 commission

Whether brokerages charge commissions or payment for order flow, it’s clear they make much more money from options trading.
Trading revenue from options dwarfs stocks and ETFs
For brokerages, “options are by far the largest share of PFOF, with around 65% of all PFOF.”
This is in spite of the fact that the premiums for options accounted for an equivalent of just 2.75% of total equities value traded in 2023.
Needless to say, brokerages love options trading
Brokerages are directly incentivized to get customers doing the sort of risky options trades that depleted Ms. Yeung’s account. That’s how they make the most money. Brokers make much less money off of customers who buy and hold. They would much rather you do frequent options trades.
So they don’t stop the options order at the time of execution because to the brokerage, an options order means lots of revenue.
What’s more, brokerages put almost no speed bumps on turning that options permission on. There is no second 2FA. The signature is typing a name in a Sign Here box. The review period can be as short as overnight, and the only reason it exists is because regulators require an approval delay, not because the broker wants friction.
A wire out of the account has delays, emails, and calls. Both the enabling of the options trading functionality and the options trades themselves that let a hacker drain the account have no such roadblocks.
How to stop the hack
Given that your brokerage will not protect you, you must protect yourself. The easiest way to do so is to never type in your username and password to log in. Instead:
1. Use passkeys if your broker offers them
A passkey is tied to the broker's real domain. On ibkrlogc.top, the passkey simply will not show up, so this hack stops at login. If your broker offers passkeys, turn them on. That is the one step that actually kills this attack.
Hong Kong now requires passkeys or hardware keys for brokerage logins. If you live nearly anywhere else, it is on you.
2. Use a password manager like Google or Apple Passwords to autofill usernames and passwords
The saved-password autofill on your browser or operating system is tied to the real URL.

On a phishing domain, your browser won’t offer to fill anything. Let that silence be your warning: check the URL, and don’t log in.
3. Use the official mobile app
Better yet, only check your account through the official mobile app, never a browser.
The bottom line
Passkeys are the only solid line of defense.
It used to be relatively easy to recognize a phishing link before clicking, but now, the most common phishing links are very legitimate looking security and account alerts. If you end up clicking through, the login page will look exactly the same as the one you’re used to. You can do everything right and still click the wrong thing after a tiring day.
The second line of defense should belong to the brokerage: a setting that flags a trade that looks nothing like you and makes you confirm it in the app before it executes. No major retail broker we know of offers that as a standard opt-in.
Until one of them does, all a hacker needs to do is get into your brokerage account. When you look back and figure out what went wrong later, all the record will say is that you, the account holder, made some very bad bets on 0DTE options. No theft. Just a bad day in the market that you never had.
Stay safe out there.
About
Inverteum Limited (HK) is a trading firm that specializes in long-short algorithmic strategies to generate returns in both bull and bear markets. Inverteum has generated 50%+ annualized returns since inception.
How We Invest
Minimize allocation to individual stocks due to their unpredictability
Build a strategy designed to harness the market’s momentum, with the tactical agility to pivot and capitalize on downward trends when necessary.
Be prepared for bear markets and ensure profitability during bad times by implementing a short selling component to the strategy
BYND stock underwent a 1-for-30 reverse split in Aug 2026, so the sub-$2 prices quoted here are pre-split.
Attackers register addresses built to survive a quick glance: a lowercase “rn” that reads as an “m” (rnicrosoft.com), a numeral “1” standing in for the letter “l” (paypa1.com), or the real brand name buried as a subdomain of a domain they control, as in interactivebrokers.com.secure-login.top, where the actual domain is secure-login.top, not Interactive Brokers.
In June 2025, cybersecurity experts at Dark Lab documented this exact technique against Interactive Brokers users: the victim, seeing a 2FA prompt, “clicks to verify the login, assuming the notification is intended for their own login attempt,” and in doing so hands the attacker a fully authenticated session.







