Sam Disraelly, his wife and their 2 girls have been Westport residents for 7 years. A Navy veteran, he is on the board of the Westport Weston Chamber of Commerce. He is also a founder and CEO of Your Tech Department, a cybersecurity and IT support firm with offices in Wilton, Stamford and Westport.
Sam addresses this warning to “every neighbor still using an optonline.net email address.”
If you signed up for Optimum internet more than 5 years ago, there’s a good chance you got a free email address along with it — something ending in @optonline.net or @optimum.net.
If you’ve had it a while, you might still be using it. A lot of Westport and Fairfield County residents still are. They’re familiar. They work.
And that’s exactly the problem.
Sam Disraelly
I run a cybersecurity and IT support company in Fairfield County. People call me all the time after their optonline.net or optimum.net email gets hacked. Of everything I see in this business, it’s the one service that generates the most calls of this kind.
Three things are considered baseline in 2026 for any email provider:
Two-factor / multi-factor authentication (MFA). This is a second proof of identity beyond your password — an SMS code, an app confirmation — before anyone can log in. Microsoft’s research shows MFA blocks more than 99.2% of account compromise attempts, even when a password has already been stolen. It’s become standard on nearly every major email provider.
Session logs. The ability to see where and when your account has been accessed, so if something looks wrong (a login from a country you’ve never visited) you’d actually know.
The ability to kill an active session. If you discover you’ve been breached, the ability to remotely log out every open connection to your account.
None of these exist in Optimum’s email settings. There’s nothing to configure, because the option was never built.

Optimum notes the importance of 2-factor authentication (above). However, they do not offer it.
Changing your password isn’t enough, either.
If you call Optimum and say you think your email’s been compromised, the advice you’ll get is to change your password. What they won’t tell you — because there’s no way for them to check — is whether that actually locks the hacker out.
Without session logs or the ability to end an active session, an account that’s already open in a hacker’s session before the password change simply stays open. A new password doesn’t close an existing connection; it only stops new logins. The old session keeps receiving mail as if nothing happened.
So a compromised Optimum account can stay compromised indefinitely, silently, even after you think you’ve fixed it.

An email address isn’t just an address. It’s the recovery point for your bank, your medical portal, your retirement accounts, your kids’ school logins — nearly everything password-protected online gets reset through email. If someone controls your inbox undetected, they control the keys to reset almost anything else you own.
Why hasn’t this been fixed? Because Optimum has quietly stopped investing in this service.
Buried in Optimum’s FAQ, under a page titled “How do I check my Optimum email?”, is this: “As of May 4, 2021, Optimum no longer offers the ability for new and existing Internet customers to create new Optimum email accounts.”
This means Optimum won’t create new addresses for anyone. It’s not an announcement of a shutdown, and existing accounts still work.
But Optimum’s own residential Terms of Service go further: any email account inactive for 90 days — no login, no sent or opened mail, no active forwarding — is deemed inactive and permanently deleted, contents unrecoverable, with no obligation to notify you first.

Screenshot of Optimum’s Terms of Service.
An address you’ve had for 15 or 20 years, tied to accounts you may have forgotten about, can simply vanish if you go 3 months without opening it.
Taken together: no new accounts issued since 2021, no security features added since who knows when, and inactive accounts wiped without warning. It’s a strong signal about where Optimum’s investment in this “free feature” has gone.

You don’t have to wait for Optimum to fix this, because there’s no sign they’re going to.
Instead: Set up another email address. I recommend buying a domain. Use it to host your own email on a trusted service, so you can control your own digital identity. If you need to use a free account, there are other providers like Gmail, Outlook, or a similar provider that supports MFA, session logs and remote sign-out.
Forward your Optimum mail there in the meantime, or notify your important accounts (bank, medical, etc.) of the new address or switch them over directly.
If you’re not sure how, ask someone: a neighbor, a local IT person, your kid. This isn’t a hard switch, just an overdue one.
I’ve started gathering stories from people in the area whose Optimum.net or Optonline.net email has been hacked or compromised, as part of a push to get Optimum to bring their email security up to a basic 2026 standard. If that’s happened to you and you’re willing to share what happened, I’d like to hear from you. My email is sam@yourtech.team.
This isn’t about switching internet providers. It’s about one free feature that’s been quietly neglected for 5 years while sitting at the center of — and now endangering — a lot of digital lives.
(“06880” wants our readers to be safe. We want them to be informed. And, every once in a while, we want them to show support for this hyper-local blog. Please click here. And thank you!)
