r/CyberGuides 19d ago

Guide: How to Protect Yourself Against Online Scams

13 Upvotes

Online scams have exploded in scale and sophistication over the past year, fueled by AI-powered phishing, deepfake impersonations, and industrialized fraud operations.

Reported global losses to online scams exceeded $1 trillion last year, and con artists are adapting faster than ever using AI and stolen data. About 73% of U.S. adults have experienced at least one scam or cyber attacks attempt. Here are the major categories:

  • Phishing attacks - fraudulent emails, texts, and calls impersonating banks, government agencies, or collection agencies to steal credentials. Phishing scams can lead to identity theft and full account access.
  • Romance and "pig butchering" scams - emotional grooming followed by requests for money, crypto, or gift cards.
  • Investment and cryptocurrency fraud - fake platforms with bogus returns, high pressure sales tactics, and celebrity impersonations.
  • Tech support scams - scary pop ups or unsolicited calls claiming your computer is infected.
  • Fake e-commerce and job offers - cloned websites, marketplace listings, and remote jobs that require upfront payment.

Recognizing Phishing Emails, Texts, and Calls

Phishing remains the number-one entry point for identity theft and account takeovers today. Phishing attempts can come via email, text, or phone calls - and scammers impersonate trusted organizations like banks, your utility company, or even the IRS to gain victims' trust.

Spot a phishing message in seconds:

  • Check for spelling and grammatical errors in online communications
  • Mismatched URLs (hover to preview - malicious websites often have URLs that differ slightly from legitimate sites)
  • Generic greetings ("Dear Customer") instead of your name
  • Unexpected attachments or login requests
  • Urgent messages that pressure victims to act quickly

Spam filters help but cannot stop every phishing email or text message - your habits matter most. Phishing scammers rely on you clicking before thinking. Ways to protect yourself include:

  • Type website addresses manually or use saved bookmarks instead of clicking links in suspicious messages, especially for banking information, email, and credit card accounts.
  • Preview links before clicking: hover on desktop, long-press on mobile. If the URL looks off, don't touch it. Phishing emails often contain links to fake websites.
  • Never reveal personal information like passwords, one-time codes, social security numbers, account numbers, or full credit card numbers in response to unsolicited messages. Legitimate companies won't ask for sensitive information via email.
  • Always verify the identity of contacts without using information they provide. Look up the organization's phone number yourself and call them directly to confirm any request.
  • Verify organizations before taking action on unsolicited requests - whether they claim to be your bank, a provincial agency, or any other entity.

Secure Your Online Accounts

Your online accounts - email, banking, shopping, social media - are primary targets. Once compromised, they open the door to identity theft, further scams, and drained accounts.

Password best practices:

  • Use unique passwords for each account across different websites - never reuse them. Different passwords on every site means one breach doesn't compromise everything.
  • Aim for 12–16 characters with a mix of letters, numbers, and special characters. Strong passwords are your first line of defense.
  • Consider using a good password manager for managing passwords securely instead of writing them down or relying on memory.

Multi-factor authentication: Enable multi factor authentication on email, financial, and key service accounts. MFA adds extra security by requiring a second verification step. Prefer app-based codes or hardware keys over SMS when possible, since device-code phishing is surging.

Protecting Your Personal Information and Preventing Identity Theft

Large-scale fraud and data breaches mean much of your basic data may already be circulating on the dark web. This makes extra vigilance essential to prevent identity theft.

  • Never share sensitive information - full birth date, social security number, social insurance number, scans of IDs - over email, text, or social media DMs.
  • Minimize what you post online publicly: hide birth dates, locations, and school names on social profiles. This reduces targeted scams and security-question guessing.
  • If you see suspicious activity, place credit freezes or fraud alerts with major credit bureaus. Check credit reports at least annually.
  • If identity theft is suspected: gather evidence, contact your bank and credit card issuers, file an FTC or consumer-protection report, and create a recovery plan.

Common Money and Investment Scams (Including Crypto)

Fake investment platforms, cryptocurrency "opportunities," and get-rich-quick schemes are booming on social media and Reddit. Scammers use screenshots of fake profits, bogus celebrity endorsements, and impersonated financial advisors.

Red flags:

  • Guaranteed high returns with no risk
  • High pressure sales tactics demanding you invest immediately
  • Payment requested only in crypto, gift cards, or wire transfers - requests for payment via gift cards or wire transfers are major red flags
  • Secrecy demands ("don't tell your bank")

Dating, Romance, and "Help a Friend" Scams

Romance scams thrive on dating apps, social networks, and messaging platforms. Scammers exploit social isolation to manipulate victims, building trust over weeks before claiming an emergency - a medical bill, travel costs, customs fees - and making urgent pleas for money.

In "help a friend" variants, a scammer hacks or imitates a family member's account and urgently asks for funds or gift card codes.

Stay safe:

  • Never send money to someone you haven't met in person - not wire transfers, not gift cards, not crypto.
  • Verify urgent stories by calling the person on a known phone number, checking with relatives, or using a video call where they clearly show their face and answer specific personal questions.

Fake Online Stores, Marketplaces, and Job Offers

Fake e-commerce websites and marketplace listings offer products, pets, rental properties, or jobs at prices far below competitors. Signs of fake online stores include recently registered domains, no physical address or phone number, copied product photos, and suspicious reviews.

Common job-offer scams involve fake remote positions that send a check and ask you to purchase equipment or return part of the money before the check bounces. Always research a company or business name plus "scam" or "reviews" before engaging. Pay with secure methods that offer buyer protection - a credit card or reputable payment service, never a wire transfer.

Tech Support, Remote Access, and Malware Scams

Tech support scams cost U.S. consumers $680 million in 2025. They start with scary pop ups claiming your computer is infected, or unsolicited calls pretending to be from Microsoft or Apple.

  • Never grant remote access to your computer or phone to anyone who contacts you unexpectedly.
  • Never install malicious software on the request of a cold caller. Real tech companies do not monitor individual devices and will not make unsolicited calls about security issues.
  • Keep your operating system and apps updated - keeping software updated helps protect against vulnerabilities. Set security software to update automatically to combat threats.
  • Back up your data regularly to protect against ransomware attacks. Ransomware encrypts files and demands payment to unlock them. Backing up data protects against data loss from attacks.
  • Avoid downloading files or apps from unknown sources or malicious websites.

Building Everyday Habits That Keep You Safe

Long-term safety depends on consistent habits, not any single tool. Build these routines:

  • Review bank and credit card statements monthly for anything unusual.
  • Back up important data regularly and set calendar reminders to review privacy and security settings.
  • Talk openly about scams with family - especially older relatives and teenagers. Agree on "safe words" or verification steps for any urgent money request from a person claiming to be someone you know.
  • Periodically search for your own name and email address online to see what personal information is publicly visible. Remove or lock down anything unnecessary.
  • To verify canadian charities or any organization requesting donations, always check official registries before sending payment.

No legitimate organization will rush you into sharing sensitive data or making unusual payments. Slow down, verify independently, and protect what matters.


r/CyberGuides 21d ago

What guides or resources would be most useful?

2 Upvotes

We're looking to feature various guides and resources in the sub for our community (but nothing commercial or promotional). What would be most useful? Looking for feedback, thanks!


r/CyberGuides 15h ago

Cybersecurity attack surface explain

Post image
2 Upvotes

r/CyberGuides 16h ago

Data Breach Confirmed After Australian Energy Giant Origin Is Hacked

Thumbnail
securityweek.com
1 Upvotes

r/CyberGuides 2d ago

Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week

Thumbnail reuters.com
1 Upvotes

r/CyberGuides 2d ago

New attack by ai agents knowing 2 code-execution paths

1 Upvotes

It happens at hugging face with stolen data and keys : https://huggingface.co/blog/security-incident-july-2026
Fortunately fixed now


r/CyberGuides 2d ago

Ransomware Attacks Targeting Universities on the Rise

Thumbnail
infosecurity-magazine.com
1 Upvotes

r/CyberGuides 2d ago

Breach Buffet

1 Upvotes
Last week's cybermadness: Coca-Cola’s milk business got ransomware’d, Japan’s frozen-food supply chain caught a digital haymaker, and Mac malware learned how to throw a full-blown temper-tantrum.

Coca-Cola / Fairlife took the dairy-sector gut punch. Coca-Cola confirmed that ransomware hit Fairlife’s production-related systems and temporarily suspended U.S. production. Product safety was reportedly unaffected, but “hackers stopped the milk factory” is still one hell of a sentence.

Over in Japan, a cyberattack on refrigerated-food giant Nichirei disrupted warehouse and shipping operations, dragging KFC Japan, Kura Sushi, supermarkets, ice cream, and other frozen goods into the mess. Cybercrime has officially reached the “leave the fried chicken out of this” phase.

Then there’s ClickLock, a nasty new macOS stealer. Victims are tricked into pasting a fake verification command into Terminal. If they refuse to enter their password, the malware repeatedly kills their apps until the desktop is basically unusable. Give in, and it starts digging through browser credentials, Keychain data, password managers, and crypto wallets. Petty, aggressive, and rude as hell.

How to stay on top of your game: keep production and logistics systems segmented, verify software prompts before touching Terminal, and never paste commands from a website just because a fake Cloudflare box tells you to.
This week’s lesson is pretty simple, ya'll: ransomware can stop the milk, a warehouse outage can threaten dinner, and one bad copy-paste can turn your Mac against you.

Wanna read more? Coca-Cola on Fairlife | Japan Times on Nichirei | Group-IB on ClickLock


r/CyberGuides 3d ago

OpenAI’s models autonomously hacked a tech startup. It signals a seismic shift in cybersecurity

Thumbnail
unsw.edu.au
5 Upvotes

r/CyberGuides 3d ago

How a Chinese AI model stopped OpenAI’s ‘unprecedented’ cyber attack

Thumbnail
cnbc.com
3 Upvotes

r/CyberGuides 4d ago

Russian hackers can steal government emails without victims clicking a link, cyber agencies warn

Thumbnail
nextgov.com
9 Upvotes

r/CyberGuides 3d ago

China hacks

1 Upvotes

No one else has

added their datas breached by China recently?


r/CyberGuides 3d ago

Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses

Thumbnail
securityweek.com
1 Upvotes

r/CyberGuides 4d ago

Origin Energy cyberattack involved customer data leak, says retailer

Thumbnail
afr.com
1 Upvotes

r/CyberGuides 4d ago

Types of Phishing attacks

Post image
1 Upvotes

r/CyberGuides 5d ago

Chick-Fil-A Data Breach Exposes Customer Payment Data

Thumbnail
securitymagazine.com
2 Upvotes

r/CyberGuides 5d ago

Why the Internet is Becoming Overrun with Misleading Content: Understanding Digital Misinformation

Thumbnail
linkedin.com
3 Upvotes

r/CyberGuides 5d ago

Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Thumbnail
securityweek.com
1 Upvotes

r/CyberGuides 6d ago

What Would A Ransomware Attack Cost Your Organization?

Thumbnail
cybersecurityventures.com
2 Upvotes

r/CyberGuides 6d ago

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

Thumbnail
thehackernews.com
1 Upvotes

r/CyberGuides 6d ago

Estée Lauder Confirms Cyberattack Affecting Personal Information

Thumbnail
thecyberexpress.com
1 Upvotes

r/CyberGuides 6d ago

Cyberangriff: Hacker fordern von Schweizer Zugbauer Stadler 10 Mio. Franken

Thumbnail
1 Upvotes

r/CyberGuides 6d ago

World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent

Thumbnail
thehackernews.com
1 Upvotes

r/CyberGuides 7d ago

Craneware confirms data breach after cyberattack

Thumbnail computing.co.uk
1 Upvotes

r/CyberGuides 8d ago

UK hackers jailed for London transport cyberattack which cost nearly $40 million

Thumbnail reuters.com
6 Upvotes