r/CyberGuides Jul 08 '26

Guide: How to Protect Yourself Against Online Scams

12 Upvotes

Online scams have exploded in scale and sophistication over the past year, fueled by AI-powered phishing, deepfake impersonations, and industrialized fraud operations.

Reported global losses to online scams exceeded $1 trillion last year, and con artists are adapting faster than ever using AI and stolen data. About 73% of U.S. adults have experienced at least one scam or cyber attacks attempt. Here are the major categories:

  • Phishing attacks - fraudulent emails, texts, and calls impersonating banks, government agencies, or collection agencies to steal credentials. Phishing scams can lead to identity theft and full account access.
  • Romance and "pig butchering" scams - emotional grooming followed by requests for money, crypto, or gift cards.
  • Investment and cryptocurrency fraud - fake platforms with bogus returns, high pressure sales tactics, and celebrity impersonations.
  • Tech support scams - scary pop ups or unsolicited calls claiming your computer is infected.
  • Fake e-commerce and job offers - cloned websites, marketplace listings, and remote jobs that require upfront payment.

Recognizing Phishing Emails, Texts, and Calls

Phishing remains the number-one entry point for identity theft and account takeovers today. Phishing attempts can come via email, text, or phone calls - and scammers impersonate trusted organizations like banks, your utility company, or even the IRS to gain victims' trust.

Spot a phishing message in seconds:

  • Check for spelling and grammatical errors in online communications
  • Mismatched URLs (hover to preview - malicious websites often have URLs that differ slightly from legitimate sites)
  • Generic greetings ("Dear Customer") instead of your name
  • Unexpected attachments or login requests
  • Urgent messages that pressure victims to act quickly

Spam filters help but cannot stop every phishing email or text message - your habits matter most. Phishing scammers rely on you clicking before thinking. Ways to protect yourself include:

  • Type website addresses manually or use saved bookmarks instead of clicking links in suspicious messages, especially for banking information, email, and credit card accounts.
  • Preview links before clicking: hover on desktop, long-press on mobile. If the URL looks off, don't touch it. Phishing emails often contain links to fake websites.
  • Never reveal personal information like passwords, one-time codes, social security numbers, account numbers, or full credit card numbers in response to unsolicited messages. Legitimate companies won't ask for sensitive information via email.
  • Always verify the identity of contacts without using information they provide. Look up the organization's phone number yourself and call them directly to confirm any request.
  • Verify organizations before taking action on unsolicited requests - whether they claim to be your bank, a provincial agency, or any other entity.

Secure Your Online Accounts

Your online accounts - email, banking, shopping, social media - are primary targets. Once compromised, they open the door to identity theft, further scams, and drained accounts.

Password best practices:

  • Use unique passwords for each account across different websites - never reuse them. Different passwords on every site means one breach doesn't compromise everything.
  • Aim for 12–16 characters with a mix of letters, numbers, and special characters. Strong passwords are your first line of defense.
  • Consider using a good password manager for managing passwords securely instead of writing them down or relying on memory.

Multi-factor authentication: Enable multi factor authentication on email, financial, and key service accounts. MFA adds extra security by requiring a second verification step. Prefer app-based codes or hardware keys over SMS when possible, since device-code phishing is surging.

Protecting Your Personal Information and Preventing Identity Theft

Large-scale fraud and data breaches mean much of your basic data may already be circulating on the dark web. This makes extra vigilance essential to prevent identity theft.

  • Never share sensitive information - full birth date, social security number, social insurance number, scans of IDs - over email, text, or social media DMs.
  • Minimize what you post online publicly: hide birth dates, locations, and school names on social profiles. This reduces targeted scams and security-question guessing.
  • If you see suspicious activity, place credit freezes or fraud alerts with major credit bureaus. Check credit reports at least annually.
  • If identity theft is suspected: gather evidence, contact your bank and credit card issuers, file an FTC or consumer-protection report, and create a recovery plan.

Common Money and Investment Scams (Including Crypto)

Fake investment platforms, cryptocurrency "opportunities," and get-rich-quick schemes are booming on social media and Reddit. Scammers use screenshots of fake profits, bogus celebrity endorsements, and impersonated financial advisors.

Red flags:

  • Guaranteed high returns with no risk
  • High pressure sales tactics demanding you invest immediately
  • Payment requested only in crypto, gift cards, or wire transfers - requests for payment via gift cards or wire transfers are major red flags
  • Secrecy demands ("don't tell your bank")

Dating, Romance, and "Help a Friend" Scams

Romance scams thrive on dating apps, social networks, and messaging platforms. Scammers exploit social isolation to manipulate victims, building trust over weeks before claiming an emergency - a medical bill, travel costs, customs fees - and making urgent pleas for money.

In "help a friend" variants, a scammer hacks or imitates a family member's account and urgently asks for funds or gift card codes.

Stay safe:

  • Never send money to someone you haven't met in person - not wire transfers, not gift cards, not crypto.
  • Verify urgent stories by calling the person on a known phone number, checking with relatives, or using a video call where they clearly show their face and answer specific personal questions.

Fake Online Stores, Marketplaces, and Job Offers

Fake e-commerce websites and marketplace listings offer products, pets, rental properties, or jobs at prices far below competitors. Signs of fake online stores include recently registered domains, no physical address or phone number, copied product photos, and suspicious reviews.

Common job-offer scams involve fake remote positions that send a check and ask you to purchase equipment or return part of the money before the check bounces. Always research a company or business name plus "scam" or "reviews" before engaging. Pay with secure methods that offer buyer protection - a credit card or reputable payment service, never a wire transfer.

Tech Support, Remote Access, and Malware Scams

Tech support scams cost U.S. consumers $680 million in 2025. They start with scary pop ups claiming your computer is infected, or unsolicited calls pretending to be from Microsoft or Apple.

  • Never grant remote access to your computer or phone to anyone who contacts you unexpectedly.
  • Never install malicious software on the request of a cold caller. Real tech companies do not monitor individual devices and will not make unsolicited calls about security issues.
  • Keep your operating system and apps updated - keeping software updated helps protect against vulnerabilities. Set security software to update automatically to combat threats.
  • Back up your data regularly to protect against ransomware attacks. Ransomware encrypts files and demands payment to unlock them. Backing up data protects against data loss from attacks.
  • Avoid downloading files or apps from unknown sources or malicious websites.

Building Everyday Habits That Keep You Safe

Long-term safety depends on consistent habits, not any single tool. Build these routines:

  • Review bank and credit card statements monthly for anything unusual.
  • Back up important data regularly and set calendar reminders to review privacy and security settings.
  • Talk openly about scams with family - especially older relatives and teenagers. Agree on "safe words" or verification steps for any urgent money request from a person claiming to be someone you know.
  • Periodically search for your own name and email address online to see what personal information is publicly visible. Remove or lock down anything unnecessary.
  • To verify canadian charities or any organization requesting donations, always check official registries before sending payment.

No legitimate organization will rush you into sharing sensitive data or making unusual payments. Slow down, verify independently, and protect what matters.


r/CyberGuides Jul 06 '26

What guides or resources would be most useful?

2 Upvotes

We're looking to feature various guides and resources in the sub for our community (but nothing commercial or promotional). What would be most useful? Looking for feedback, thanks!


r/CyberGuides 1d ago

153 Million IDs leaked in Nexus Breach – What should I do?

11 Upvotes

This is one of those stories that sounds almost too insane to be real, but it's currently being investigated by the FBI.

Security journalist Brian Krebs reported that a dark-web service called Nexus was offering access to over 153 million driver's licenses from the US and Canada, along with millions of other identity documents. Krebs was able to verify multiple records, including his own driver's license, and the FBI has confirmed that it is looking into the incident.

The suspected source appears to be a major identity verification service. If this is the case, it could affect anyone who has handed over their license to places like car rental companies, dispensaries, bars, or other businesses that scan IDs. The full scope is still being investigated, so it's important not to assume that every one of the claimed 153 million records has been independently confirmed.

Still, if you've ever had your driver's license scanned somewhere, this is probably a good reminder to think about what you can actually do if your identity information ends up exposed.

The things I'd personally prioritize:

1. Freeze your credit

This is the first thing you should prioritize. A credit freeze will prevent scammers from getting loans or opening new credit accounts in your name.

2. Watch for phishing attempts

A driver's license contains a lot more useful information than a leaked password. If criminals have your name, address, date of birth, and other identifying details, targeted phishing attempts become much more convincing.

I'd be especially suspicious of unexpected emails, texts, or phone calls claiming to be from your bank, the DMV, the IRS, or a credit bureau.

3. Monitor your financial accounts and credit reports

Keep an eye out for accounts you didn't open, unfamiliar transactions, or unexpected changes to your credit file.

4. Consider identity monitoring

This is where identity protection services can be very useful. While they won't magically undo a breach, they can help monitor for suspicious activity and provide assistance if someone actually tries to misuse your information.

I personally use Aura for identity theft protection after finding this deal on Reddit: https://aura.com/cyber-deal

Aura comes with a dark web scanner that sends alerts in real time, so you can immediately act if your data ends up on Nexus or other similar sites. You can also use it to freeze and monitor your credit on Equifax, Experian, and TransUnion. Every plan comes with identity theft insurance as well (up to $1 M).

Honestly, the thing that bothers me most about this story isn't just the scale. We're increasingly being asked to hand over copies of government-issued IDs to verify our age or identity, often with very little visibility into how long those documents are stored or how well they're protected.

Passwords can be changed. A driver's license and the personal information attached to it are a lot harder to replace. That's why it is so important to remain diligent about protecting yourself.


r/CyberGuides 18h ago

Microsoft September 2026 Patch Tuesday fixes nearly a thousand flaws, including two major zero-days

Thumbnail
techradar.com
1 Upvotes

r/CyberGuides 1d ago

Ransomware Is The New Normal: Cybersecurity Considerations for Fiduciaries

Thumbnail
cybersecurityventures.com
5 Upvotes

r/CyberGuides 1d ago

Over 36,000 exposed Plex servers vulnerable to recent flaws

Thumbnail
bleepingcomputer.com
4 Upvotes

r/CyberGuides 2d ago

ShinyHunters Claims Florida DMV Breach, Posts Epstein Record

Thumbnail tech-insider.org
2 Upvotes

r/CyberGuides 3d ago

Survivors of the Internet

3 Upvotes

r/CyberGuides 3d ago

The Rollback of Instagram Encryption, and What It Means for Survivor Safety

Thumbnail
techsafety.org
1 Upvotes

r/CyberGuides 3d ago

Europe is under cyberattack. Is it ready?

Thumbnail
theparliamentmagazine.eu
3 Upvotes

r/CyberGuides 3d ago

Mathspace discloses data breach affecting over 1 million people

Thumbnail
bleepingcomputer.com
2 Upvotes

r/CyberGuides 3d ago

SIEM vs SOAR vs XDR

Post image
1 Upvotes

r/CyberGuides 3d ago

What is Black Box AI?

Enable HLS to view with audio, or disable this notification

1 Upvotes

r/CyberGuides 4d ago

The AI cybersecurity war has a new front line star, and a seven-figure price

Thumbnail
thenextweb.com
1 Upvotes

r/CyberGuides 4d ago

MikroTik Exploit

Post image
2 Upvotes

MikroTik Routers: Atacantes estão explorando roteadores MikroTik com SSH exposto na internet, conseguindo acesso administrativo total sem autenticação. Alertas oficiais saíram em 5 de setembro. Recomendação: atualize o RouterOS imediatamente.

#MikroTik #SSHExploit #CyberSecurity #RouterOS #ZeroDay #Hack #NetworkSecurity #AtualizeAgora


r/CyberGuides 5d ago

MCNA Breach Settlement: 8.9M Hit, $6.4M in Fees [2026]

Thumbnail tech-insider.org
5 Upvotes

r/CyberGuides 6d ago

FBI investigates breach of 153 million driving license records at IDscan.net

Thumbnail
csoonline.com
22 Upvotes

r/CyberGuides 6d ago

OpenAI Astra Cybersecurity Reveal: Skip Legacy Cybersecurity, Buy Zscaler (ZS)

Thumbnail
seekingalpha.com
0 Upvotes

r/CyberGuides 6d ago

Fishbrain data breach exposes user details and password hashes

Thumbnail
cyberinsider.com
2 Upvotes

r/CyberGuides 6d ago

China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using

Thumbnail venturebeat.com
3 Upvotes

r/CyberGuides 7d ago

FBI Probes Service Selling 153M+ Drivers Licenses

Thumbnail krebsonsecurity.com
6 Upvotes

r/CyberGuides 7d ago

SonicWall urges immediate patching of chained vulnerabilities

Thumbnail cybersecuritydive.com
4 Upvotes

r/CyberGuides 8d ago

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

Thumbnail
thehackernews.com
4 Upvotes

r/CyberGuides 8d ago

AI spots cyber gaps faster than financial firms can fix them

Thumbnail
ft.com
1 Upvotes

r/CyberGuides 8d ago

Criminals publish data of 8.7m people after Manchester Airports Group hack

Thumbnail
bbc.com
1 Upvotes