- Pause: If a message pressures you to act fast, slow down.
- Verify: Check unusual requests through a channel you already trust.
- Report: Tell Security about anything suspicious, even if you're not sure.
Happy Cybersecurity Awareness Month! October is a great opportunity to refresh a few simple habits that help protect all of us.
Cybercriminals do not only target large companies or specific industries. Every organization is a potential target, regardless of size or industry, because attackers are looking for opportunity: an account they can access, a payment they can redirect, a person they can impersonate, or information they can steal.
The good news is that we do not need everyone to become a cybersecurity expert. We just need to recognize when something feels unusual, slow down when we are being rushed, and know when to ask for help.
Our theme this month: PAUSE. VERIFY. REPORT.
1. Phishing Is Getting Much More Convincing
Phishing is no longer limited to badly written emails. Attackers now use convincing copies of Microsoft login pages, shared-document notifications, voicemail alerts, QR codes, electronic signatures, and even legitimate Microsoft authentication pages.
- “A document has been shared with you.”
- “Your password expires today.”
- “You have a new voicemail.”
- “Scan this QR code to continue.”
- “Go to Microsoft and enter this code.”
Protect yourself: If you were not expecting the message, do not use the link or code it provides. Open Microsoft 365, Teams, SharePoint, or the application normally and check from there. Never enter a Microsoft device code that someone unexpectedly sends you.
2. Attackers May Pretend to Be IT, a Coworker, or an Executive
Attackers can learn a surprising amount from LinkedIn, company websites, conference pages, social media, and public information. That makes impersonation much more convincing.
- “Hi, this is IT. We’re having trouble with your account.”
- “I just sent you an MFA request. Please approve it.”
- “I’m boarding a flight. Can you handle this payment for me?”
The person may know your name, title, coworkers, or current projects. That does not mean they are legitimate.
Protect yourself: Never provide your password or approve an MFA request you did not initiate. Verify unusual requests using a communication method you already trust. Call a known number or contact IT through the normal company channel. Verification is not rude — it is good security.
3. Unexpected MFA Prompts Are a Warning Sign
If your phone suddenly asks “Approve sign-in?” and you are not signing in, do not approve it. Repeated MFA requests may mean someone already has your password and is hoping you will eventually click approve.
- Decline the request.
- Report it to Security.
4. Be Careful With AI Tools, Downloads, and Browser Extensions
Attackers follow trends, and AI is currently one of their favorite themes. Malicious websites and downloads may advertise AI desktop applications, ChatGPT or Claude plugins, coding assistants, new AI models, or browser extensions.
Protect yourself: Install software only from approved or official sources. Appearing in Google, Bing, GitHub, or an app marketplace does not automatically make something safe. If you are not sure, ask IT.
5. Never Run a Command Because a Website Tells You To
One increasingly common attack displays a fake CAPTCHA or security check and tells you to open PowerShell, Terminal, Command Prompt, or the Run box, then paste or execute a command. This is sometimes called ClickFix.
The rule is simple: No legitimate CAPTCHA needs you to run PowerShell, Terminal, Command Prompt, or a pasted command. Close the page.
6. Watch for Payment and Vendor Fraud
One of the most damaging scams is also one of the simplest. A vendor appears to say, “Our bank information has changed,” or an executive appears to request an urgent payment. Attackers may even compromise a real email account and insert themselves into an existing conversation.
Changes involving the following should always be independently verified:
- Bank accounts or wire instructions
- Payments or payroll
- Gift cards
- Vendor contact or payment information
Protect yourself: Call a phone number you already know. Do not rely on contact information included in the suspicious message.
7. Voice and Video Are No Longer Proof of Identity
AI can imitate voices and faces surprisingly well. Even if something sounds or looks like someone you know, unusual requests involving money, credentials, or sensitive information should still be verified.
“No problem — I’ll call you back on the number I already have.”
That small step can defeat a very sophisticated attack.
8. Be Cautious With Unexpected Shared Documents
Organizations like ours work with speaker materials, vendor and sponsor documents, spreadsheets, contracts, RFPs, invoices, and marketing assets. Attackers understand that, so malicious messages often look completely normal.
- “Updated sponsor list.”
- “Please review this RFP.”
- “New presentation attached.”
Ask one simple question: Was I expecting this? If not, verify before opening unusual attachments, signing in, or downloading anything.
9. Take Extra Care When Traveling
Airports, hotels, conferences, and public Wi-Fi create additional opportunities for attackers. Be suspicious if public Wi-Fi unexpectedly asks you to verify your Microsoft account, install an application or certificate, or enter a device code.
Protect yourself: Use approved connectivity and VPN options when required. If something feels strange, your phone hotspot may be a safer choice.
One Pattern Connects Almost Every Scam
Attackers often try to create an emotional reaction:
- Fear: “Suspicious activity detected!”
- Urgency: “Do this in the next 10 minutes!”
- Authority: “The CEO needs this now.”
- Secrecy: “Don’t tell anyone else.”
- Curiosity: “Confidential information attached.&rdquo
If something makes you feel like you need to act immediately, that is often exactly when you should slow down.
Reporting Is a Win
If you clicked something suspicious, entered a password, approved an MFA request, downloaded something, or simply are not sure — tell us.
Security would much rather investigate something harmless than miss the one message that matters. Reporting something that turns out to be safe is not a mistake. It means the process worked. And if something really did happen, early reporting gives us the best chance to protect you and the organization.
REMEMBER THREE THINGS
|
PAUSE |
VERIFY |
REPORT |
| Urgency is one of an attacker's favorite tools. | Use a trusted second method when something seems unusual. | If something does not feel right, tell Security. |
EVERYONE IS A TARGET. EVERYONE IS PART OF THE DEFENSE.
Attackers will keep changing their tools and tactics, but most attacks still need one thing: our trust. PAUSE. VERIFY. REPORT.
We protect one another. We’ve got this.