Total Defense

Security & Safety Resource Center

Learn about today's current internet threats and how to stay safe and secure.

Security Tip of the Day

Daily tips to create awareness of cyber threats and empower Total Defense users to be safer and more secure online with our security tips and resources..


August 2026
08.09.26

Why cybercriminals love dormant online accounts and how to lock them down

Old online accounts are easy to forget. You may still have accounts for shopping sites, old email providers, gaming platforms, job boards, social apps, travel sites, forums, cloud tools, or services you tried once and never used again. Cybercriminals love those dormant accounts because nobody is watching them.

A dormant account can still hold personal data, saved payment details, old messages, reused passwords, recovery email links, and access to connected apps. If attackers break in, they may use that account to steal information, impersonate you, or reset passwords elsewhere.

What is a dormant online account?

A dormant online account is an account you no longer use but that still exists. That could mean you have not logged in for months or years, but the account still has your username, email address, password, profile data, purchase history, or saved files.

Google’s Inactive Google Account Policy defines an inactive Google Account as one that has not been used within a two-year period, and Google says inactive personal accounts and their data may be deleted after that period. Google also explains in its inactive account policy update that accounts unused for long periods are more likely to be compromised because they often rely on old or reused passwords and receive fewer security checks from the user.

Why do hackers target old accounts?

Hackers target dormant accounts because old accounts often have weak security and low visibility. You are less likely to notice a suspicious login if you never check the account.

Cybercriminals may use dormant accounts to:

  • Test stolen passwords from old data breaches
  • Send scams from a trusted-looking profile
  • Access saved addresses, payment details, or documents
  • Reset passwords on connected accounts
  • Recover access to other services
  • Bypass suspicion because the account looks legitimate
  • Hide activity for weeks or months

Microsoft says stale accounts pose a security risk because attackers can use compromised inactive accounts to gain unauthorized access, move laterally, or escalate privileges. While that Microsoft guidance focuses on organizational accounts, the same basic idea applies to personal accounts: unused access still creates risk.

How big is the account takeover risk?

Dormant accounts become especially risky when you reuse passwords. Verizon’s 2025 Data Breach Investigations Report is summarized in MojoAuth’s account takeover and credential stuffing analysis, which says credential stuffing accounted for a median 19% of all authentication attempts in single sign-on provider logs. That means a large share of login attempts on typical services may be attackers testing stolen credentials.

If an old password leaked years ago and you reused it across accounts, a criminal can try that same email-and-password combination on shopping, banking, email, cloud, and social platforms.

How does deleting dormant accounts help someone become safer online?

Cleaning up dormant accounts helps someone become safer online because it reduces the number of doors criminals can try. Every forgotten account is another place where your email, password, personal data, or payment history might sit unprotected.

This habit helps you:

  • Reduce your digital footprint
  • Remove accounts you no longer monitor
  • Limit damage from old breach data
  • Stop password reuse from spreading risk
  • Cut down on scam and spam exposure
  • Protect old messages, resumes, addresses, and files
  • Make account recovery easier during a real emergency

Think of dormant accounts like old house keys. If you do not need them, do not leave them floating around.

How to find dormant accounts

Start with places where old accounts usually hide.

Check:

  • Password manager entries
  • Saved browser passwords
  • Old email inboxes for “welcome,” “verify,” or “receipt”
  • App store subscriptions
  • Social login permissions such as “Sign in with Google”
  • Banking and credit card statements
  • Old resumes and job board profiles
  • Cloud storage folders
  • Gaming and ecommerce accounts

Google says account activity can include actions like reading email, using Drive, watching YouTube, downloading an app, or using “Sign in with Google” for a third-party service in its inactive account policy, so checking connected sign-ins can reveal accounts you forgot existed.

What should you do with old accounts?

Use this simple cleanup process:

  1. Make a list of old accounts
    Start with your password manager, inbox, and saved browser logins.
  2. Decide what to keep
    Keep accounts tied to taxes, banking, medical records, active purchases, subscriptions, or important files.
  3. Download anything important
    Save photos, receipts, documents, or messages before deleting.
  4. Delete accounts you no longer need
    Use the official account deletion page or privacy settings.
  5. Change passwords on accounts you keep
    Use long, unique passwords for every account.
  6. Turn on multifactor authentication
    Add MFA to email, banking, cloud, social, and shopping accounts.
  7. Remove connected apps
    Revoke access for apps and websites you no longer use.
  8. Set a reminder
    Review old accounts every six months.

Cybercriminals love dormant accounts because people forget them, reuse passwords on them, and rarely monitor them. Delete what you do not need, secure what you keep, and reduce your online attack surface one old login at a time.

08.08.26

What is ClickFix malware? A new social engineering threat explained

ClickFix malware is one of the sneakiest new social engineering threats because it tricks people into infecting their own devices. Instead of asking you to download a suspicious file, a fake website, CAPTCHA, error message, or “security check” tells you to copy and paste a command into your computer.

That command may look like a quick fix. In reality, it can install malware, steal passwords, or give hackers remote access.

What is ClickFix malware?

ClickFix is not a single malware family. It is a social engineering technique that convinces users to run malicious commands on their own devices. In Microsoft’s analysis of the ClickFix social engineering technique, attackers used fake prompts that instructed victims to copy, paste, and run commands in Windows Run, Windows Terminal, or PowerShell.

A ClickFix scam may appear as:

  • A fake CAPTCHA check
  • A fake browser error
  • A fake document verification page
  • A “connection problem” alert
  • A fake software update
  • A fake security certificate issue
  • A fake job portal or travel booking message

The scam works because the page makes the instructions feel routine and helpful.

How does a ClickFix attack work?

Most ClickFix attacks follow a simple pattern:

  1. You click a link or visit a compromised page
    The page may come from phishing emails, malicious ads, fake job posts, hacked websites, or search results.
  2. The page shows a fake problem
    The message may say your browser failed verification, your session expired, or your system needs a quick fix.
  3. The page tells you to copy and run a command
    The command may already be copied to your clipboard.
  4. You paste the command into Run, PowerShell, Terminal, or Command Prompt
    This step can download malware without you realizing it.
  5. The malware steals information or gives attackers access
    Microsoft reported that ClickFix campaigns have delivered payloads such as Lumma Stealer, which can lead to information theft and data exfiltration in its ClickFix threat research.

Why is ClickFix dangerous?

ClickFix is dangerous because it abuses human problem-solving. Most people want to fix small tech issues quickly. Scammers exploit that instinct.

A ClickFix attack can lead to:

  • Stolen passwords
  • Stolen browser cookies
  • Remote access malware
  • Infostealer infections
  • Account takeover
  • Banking fraud
  • Work account compromise
  • Identity theft
  • More malware downloads

In Microsoft’s report on a Booking.com impersonation campaign, attackers used ClickFix prompts to trick hospitality workers into launching commands that delivered credential-stealing malware.

How big is the ClickFix and phishing risk?

ClickFix usually starts with the same ingredients as phishing: trust, urgency, and a fake instruction. CISA’s phishing guidance notes that phishing topped the FBI’s 2024 list of the five most reported cybercrimes, with 193,407 complaints, in its advice on helping people avoid phishing scams.

That number matters because ClickFix does not need advanced hacking skills to succeed. It only needs one person to trust the wrong prompt.

How does this help someone become safer online?

Understanding ClickFix helps someone become safer online because it teaches one memorable rule:

Never paste commands from a website into your computer.

That habit protects you from fake CAPTCHA scams, malware downloads, password theft, fake browser fixes, and job-search scams. If a website asks you to open Run, PowerShell, Terminal, or Command Prompt, treat the request as suspicious until verified by a trusted expert.

How can you spot a ClickFix scam?

Look for these red flags:

  • A website asks you to press Windows + R
  • A page tells you to paste a command
  • A CAPTCHA requires more than clicking or selecting images
  • A “fix” asks you to open PowerShell or Terminal
  • The prompt appears after clicking an ad or email link
  • The message creates urgency
  • The website impersonates a trusted brand
  • The instructions feel too technical for a normal webpage

What should you do instead?

Use this quick safety checklist:

  • Do not paste commands from websites
  • Close the suspicious page
  • Do not call numbers shown in pop-ups
  • Update browsers from the official browser menu
  • Use official apps and websites directly
  • Run a trusted security scan
  • Ask IT or a trusted expert before running commands
  • Report phishing emails or malicious pages

If you already pasted a command, disconnect from the internet, run a full security scan, change passwords from a clean device, and turn on multifactor authentication.

ClickFix malware succeeds because it makes dangerous commands look like helpful troubleshooting. Slow down, question the prompt, and never run commands from a webpage unless you fully understand and trust the source.

08.07.26

The new face of tech support scams: How AI-powered fraud targets your money and devices

Tech support scams used to feel obvious. A random pop-up said your computer had “1,000 viruses,” a fake technician demanded payment, and the whole thing looked suspicious. Now scammers use AI-generated scripts, realistic voices, polished emails, fake websites, and convincing chat messages to make the same old scam feel official.

The goal has not changed: scammers want your money, remote access to your device, or personal information. AI just helps them move faster and sound more believable.

What is an AI-powered tech support scam?

An AI-powered tech support scam happens when criminals use artificial intelligence to impersonate a trusted company, create convincing messages, or guide victims through fake “support” steps. These scams may pretend to come from Microsoft, Apple, Google, Amazon, Geek Squad, your bank, your internet provider, or a cybersecurity company.

The FTC warns that tech support scams often begin with urgent pop-ups or messages claiming your computer has malware or another problem, then pressure you to pay for support you do not need for a problem that does not exist through its tech support scam guidance.

Why are AI tech support scams more convincing?

AI helps scammers remove the awkward signs people used to notice. A scammer can now generate better grammar, create realistic fake support pages, translate messages into clean English, customize scripts, and even imitate professional customer service language.

AI-powered scams may include:

  • Fake security pop-ups with official-looking branding
  • AI-written emails that sound polished and calm
  • Chatbots pretending to be support agents
  • Voice calls that sound more natural
  • Fake invoices for antivirus or device protection
  • Remote access requests disguised as “diagnostics”
  • Payment demands through gift cards, crypto, wire transfers, or payment apps

The FTC reported that many tech support scams trick people into calling by using pop-up alerts and other tactics that claim a device is infected with malware, according to the agency’s Telemarketing Sales Rule update.

How big is the tech support scam problem?

Tech support scams cause real financial harm, especially for older adults. The FTC said consumers age 60 and older reported more than $175 million in losses to tech support scams last year, and that older consumers were five times more likely than younger people to report losing money to this type of scam in its November 2024 enforcement update.

That number matters because these scams do not always look like “hacking.” Many victims willingly call the fake number, install remote access software, or pay the scammer because the warning looks urgent and legitimate.

How does this help someone become safer online?

Understanding AI-powered tech support scams helps someone become safer online because it teaches one essential habit: verify before you trust urgent support messages.

This habit protects you from:

  • Fake virus warnings
  • Remote access scams
  • Stolen passwords
  • Banking fraud
  • Identity theft
  • Malware downloads
  • Fake refund scams
  • Subscription renewal scams

The safer mindset is simple: real tech companies do not need a scary pop-up to make you call immediately, and legitimate support teams do not ask for gift cards, crypto, or remote access out of nowhere.

How can you spot a fake tech support message?

Watch for these warning signs:

  • The message says your device is infected and demands immediate action
  • The alert tells you not to close the window
  • The pop-up includes a phone number to call
  • The caller asks to remotely control your computer
  • The “technician” asks for banking access
  • The company demands gift cards, crypto, wire transfers, or payment apps
  • The message threatens account suspension or legal action
  • The support website has a strange or misspelled address
  • The caller asks for passwords, verification codes, or security questions

The FTC’s Top scams of 2024 report explains that people lost more money per person when they interacted with scammers by phone, with a median reported loss of $1,500.

What should you do if a tech support warning appears?

Use this simple response plan:

  1. Do not call the number in the pop-up.
    Close the browser tab or restart the device if needed.
  2. Do not click links inside the warning.
    Go directly to the official company website or app.
  3. Do not give remote access.
    Never let an unknown caller control your device.
  4. Run a trusted security scan.
    Use your installed antivirus or built-in security tools.
  5. Call support using a verified number.
    Use the number on the company’s official website, your account portal, or the back of your card.
  6. Report the scam.
    The FTC encourages people to report scams through ReportFraud.ftc.gov.

What if you already gave access or paid?

Act quickly:

  • Disconnect your device from the internet
  • Run a full security scan
  • Uninstall remote access apps you do not recognize
  • Change passwords from a clean device
  • Turn on multifactor authentication
  • Contact your bank or credit card company
  • Watch for new accounts or suspicious charges
  • Report the incident to the FTC

AI makes tech support scams look cleaner, sound smarter, and move faster. You can still beat them by slowing down, refusing remote access, verifying through official channels, and never paying through unusual methods.

08.06.26

How hackers exploit trusted brands to steal your information

Trusted brands make life easier. You recognize your bank, delivery company, streaming service, phone carrier, employer, favorite retailer, or job board, so you react quickly when a message appears to come from one of them. Hackers know that, and they use familiar logos, names, colors, and urgent language to trick people into clicking fake links or sharing sensitive information.

This tactic is called brand impersonation, and it powers many phishing, smishing, fake login, and malware scams.

What is brand impersonation in cybersecurity?

Brand impersonation happens when a scammer pretends to be a real company, government agency, bank, retailer, shipping service, or tech platform. The FBI explains that spoofing can disguise an email address, sender name, phone number, or website URL, often by changing one letter, symbol, or number to make the message look like it came from a trusted source.

A fake message might say:

  • “Your package could not be delivered”
  • “Your account will be suspended”
  • “Your payment failed”
  • “You have a new secure document”
  • “Your password expires today”
  • “Your job application needs verification”
  • “Unusual login detected”

These messages push you to act fast, and that is the point.

Why do hackers use trusted brands?

Hackers use trusted brands because familiar names lower your guard. A fake email from a random company may look suspicious. A fake alert from your bank, Amazon, Microsoft, Apple, PayPal, FedEx, UPS, Netflix, or LinkedIn may feel believable.

The FTC said consumers reported losing more than $12.5 billion to fraud in 2024, and imposter scams were the most commonly reported scam category that year. That statistic shows why impersonation works: criminals do not need you to trust them, they need you to trust the brand they are pretending to be.

How do fake brand messages steal your information?

Most brand impersonation scams follow a simple pattern:

  1. The scammer creates urgency
    The message says your account, money, delivery, job, or subscription has a problem.
  2. The scammer gives you a link
    The link sends you to a fake website that looks like the real brand.
  3. The scammer asks for sensitive data
    The fake page may request your username, password, credit card, verification code, Social Security number, or banking details.
  4. The scammer uses or sells your information
    Criminals may access your accounts, steal money, commit identity theft, or send more scams.

CISA warns that phishing tricks people into clicking harmful links, opening fake emails, or downloading malicious attachments, which can expose sensitive information or install malware. [cisa.gov]

How does this help someone become safer online?

Learning how hackers exploit trusted brands helps someone become safer online because it builds a “verify before you trust” habit. Instead of reacting to a logo, you learn to check the sender, inspect the link, and go directly to the official website or app.

That habit protects you from:

  • Stolen passwords
  • Fake payment pages
  • Malware downloads
  • Account takeover
  • Identity theft
  • Job scams
  • Banking fraud
  • Fake delivery alerts

The safer mindset is simple: a familiar logo does not prove a message is real.

How can you spot a fake brand message?

Look for these warning signs before clicking:

  • The message creates panic or urgency
  • The sender address has extra letters, numbers, or misspellings
  • The link does not match the brand’s official domain
  • The message asks for passwords or verification codes
  • The greeting feels generic
  • The logo looks slightly blurry or stretched
  • The message includes unexpected attachments
  • The offer sounds too good to be true
  • The phone number or link appears only inside the message

The FBI recommends carefully examining email addresses, URLs, and spelling because scammers use slight differences to trick your eye and gain your trust. [fbi.gov]

What should you do instead of clicking?

Use this quick safety checklist:

  • Go directly to the official website by typing the address yourself.
  • Open the company’s official app instead of using a link in a message.
  • Call the company using a verified number from the official website or back of your card.
  • Do not share one-time codes with anyone who contacts you.
  • Turn on multifactor authentication for email, banking, shopping, and work accounts.
  • Use a password manager to avoid entering passwords on fake domains.
  • Report phishing emails and texts to the company being impersonated and to the proper reporting channels.
  • Delete the message if you cannot verify it.

CISA advises people to verify suspicious requests through a known contact method instead of replying or using the phone number or link inside the message.

Hackers exploit trusted brands because trust creates shortcuts. Slow down before clicking, check the sender, inspect the link, and go directly to the official source. A few extra seconds can protect your passwords, money, identity, and devices.

08.05.26

Why infostealer malware is one of the fastest-growing cyber threats

Infostealer malware is one of today’s most dangerous digital threats because it does not need to “break” your computer to hurt you. It quietly grabs the information you already use every day, including saved passwords, browser cookies, autofill data, crypto wallet details, and login tokens.

What is infostealer malware?

Infostealer malware is malicious software designed to steal sensitive information from a phone, laptop, browser, or online account. Unlike ransomware, which loudly locks files and demands payment, infostealers usually work silently.

Cybercriminals use infostealers to collect:

  • Saved browser passwords
  • Session cookies that keep you logged in
  • Credit card details stored in browsers
  • Autofill names, addresses, and phone numbers
  • Email and cloud account logins
  • Cryptocurrency wallet keys
  • Screenshots and system information
  • Work account credentials from personal devices

That stolen data often gets packaged into “stealer logs” and sold through criminal marketplaces. Recorded Future’s 2025 Identity Threat Landscape Report found that each compromised device exposed an average of 87 stolen credentials, which shows how one infected computer can unlock many accounts at once.

Why is infostealer malware growing so fast?

Infostealers are growing because they are cheap, fast, and useful to criminals. Attackers do not always need to hack a company directly if they can steal a real user’s login first.

Infostealers commonly spread through:

  • Fake browser updates
  • Malicious ads
  • Cracked software and pirated games
  • Fake installers
  • Phishing emails
  • Malicious browser extensions
  • “Copy and paste this command” scams
  • Search results poisoned with malware links

AhnLab’s May 2025 Infostealer Trend Report described infostealers disguised as illegal programs such as cracks and keygens, often promoted through search engine poisoning. AhnLab’s December 2025 Infostealer Trend Report also noted that attackers post malware distribution links on legitimate websites, forums, Q&A pages, and comments to make the downloads appear trustworthy.

Why are stolen cookies and session tokens so dangerous?

Stealing a password is bad. Stealing a session cookie can be worse.

A session cookie can prove to a website that you already logged in. If a criminal steals that cookie, the criminal may bypass normal login steps and sometimes get around multifactor authentication. Recorded Future reported that 276 million malware-sourced credentials indexed in 2025 included active session cookies, representing 31% of malware-sourced credentials in its dataset. [recordedfuture.com]

That is why “I use MFA” should not be your only defense. MFA helps a lot, but malware on your device can still steal active login sessions, browser data, and other account details.

How does this help someone become safer online?

Understanding infostealer malware helps someone become safer online because it changes how individuals treat downloads, browser storage, and account security.

The safer mindset is simple: do not let unknown software near your saved logins.

Once you know infostealers target the data sitting inside browsers and apps, you become more careful about:

  • Downloading free tools from random websites
  • Saving every password in a browser
  • Ignoring software updates
  • Clicking fake browser update pop-ups
  • Installing extensions without checking reviews
  • Using the same password across accounts
  • Logging into work accounts from risky personal devices

Microsoft’s Digital Defense Report 2025 says Microsoft blocks 4.5 million net new malware files every day, which makes smart download habits essential for everyday users.

How can you spot infostealer malware before it infects your device?

Look for these warning signs before installing anything:

  • The download comes from an ad, pop-up, or unfamiliar website
  • The file claims to be a browser update
  • The app promises a free paid tool, game cheat, or premium software crack
  • The site pressures you with “urgent” language
  • The installer asks for admin permission immediately
  • The browser warns that the file may be unsafe
  • The download page has misspellings or strange domain names
  • A tutorial tells you to paste a command into Terminal or PowerShell

If something feels rushed, free, or too convenient, pause and verify the source.

How to protect yourself from infostealer malware

Use layered protection. One setting will not stop every scam.

Step-by-step infostealer defense checklist

  • Use a password manager instead of saving all passwords in your browser.
  • Turn on multifactor authentication for email, banking, cloud storage, and social accounts.
  • Avoid cracked software, pirated games, and cheat tools because attackers often hide malware inside them.
  • Update browsers from the official browser menu, not from pop-ups.
  • Install apps only from trusted sources such as official app stores or vendor websites.
  • Remove browser extensions you do not use and review extension permissions.
  • Use security software that can detect malware, suspicious downloads, and credential theft behavior like Total Defense Internet Security.
  • Separate work and personal activity when possible, especially on shared or family devices.
  • Check account activity regularly for unfamiliar logins.
  • Change passwords from a clean device if you suspect infection.

What should you do if you think an infostealer infected your device?

Act fast. Infostealers move quickly.

  1. Disconnect the device from the internet.
  2. Run a full security scan.
  3. Remove suspicious apps and browser extensions.
  4. Change important passwords from a clean device.
  5. Sign out of all sessions for email, banking, cloud, and social accounts.
  6. Turn on MFA or reset MFA settings if needed.
  7. Check financial accounts for unusual activity.
  8. Restore the device from a clean backup if malware remains.

Infostealer malware is growing because stolen logins are valuable, easy to sell, and useful for bigger attacks. Protect yourself by avoiding risky downloads, using a password manager, limiting browser-stored secrets, and treating fake updates like scams.

08.04.26

Fake browser updates are back: How to spot malware before you install it

Fake browser update scams are making the rounds again, and they look more believable than ever. You visit a familiar website, a pop-up says your browser is outdated, and the message pushes you to click “Update now.” It feels helpful, but it may be malware.

Real browser updates protect you. Fake browser updates infect you.

What is a fake browser update scam?

A fake browser update scam is a malicious pop-up, banner, or webpage that pretends to be a Chrome, Edge, Firefox, or Safari update. Instead of installing a real browser patch, the download can install malware, spyware, remote access tools, password stealers, or ransomware loaders.

The Center for Internet Security warned in its analysis of fake browser update malware campaigns that attackers use compromised websites to generate fake browser update prompts tailored to the browser a visitor uses. That detail matters because the scam may look customized and convincing.

Why are fake browser updates dangerous?

Fake browser updates work because they abuse a good security habit. Most people have heard, “Keep your software updated.” Scammers twist that advice into a trap.

Once someone installs the fake update, malware may:

  • Steal saved passwords
  • Track keystrokes
  • Install remote access tools
  • Download more malware
  • Disable security protections
  • Redirect browser traffic
  • Help attackers take over accounts
  • Open the door to ransomware

Research reported that FakeUpdates, also known as SocGholish, remained a top global malware threat in March 2025 and used fake browser update lures on compromised websites to trick users into downloading malware.

How big is the malware problem?

Malware arrives at massive scale. Microsoft says in its Digital Defense Report 2025 that it blocks 4.5 million net new malware files every day. That statistic shows why one bad click can matter. Attackers constantly create new files, new lures, and new fake download pages to get around defenses.

How can you tell if a browser update is fake?

Fake browser updates often create urgency. They want you to click before you think.

Watch for these red flags:

  • A random website says your browser is outdated
  • A pop-up uses words like “critical,” “urgent,” or “required”
  • The update downloads as a strange file
  • The page does not come from the browser maker
  • The message blocks you from closing the tab
  • The site asks you to run a script or installer
  • The URL looks suspicious or misspelled
  • The download starts automatically
  • The page asks for admin permission right away

Real browser updates usually happen inside the browser itself, not through a random pop-up on a website.

How does this help someone become safer online?

Learning to spot fake browser updates helps someone become safer online because it builds a simple habit: update from the official source, not from a pop-up.

That one habit helps protect against:

  • Malware infections
  • Password theft
  • Account takeover
  • Banking fraud
  • Spyware
  • Ransomware
  • Fake tech support scams

It also teaches a broader cybersecurity rule: when a message creates urgency and asks you to install something, slow down and verify it first.

How should you update your browser safely?

Use the browser’s built-in update tool instead of clicking a pop-up.

Safe browser update checklist

  • Chrome: Open Chrome, select the three-dot menu, choose Help, then About Google Chrome.
  • Edge: Open Edge, select the three-dot menu, choose Help and feedback, then About Microsoft Edge.
  • Firefox: Open Firefox, select the menu, choose Help, then About Firefox.
  • Safari: Update Safari through macOS or iOS software updates.

If a webpage says your browser needs an update, close the tab and check the update status from your browser menu.

What should you do if you clicked a fake update?

If you downloaded or ran a suspicious browser update, act quickly.

  1. Disconnect from the internet.
  2. Do not log in to banking, email, or work accounts from that device.
  3. Run a full antivirus or security scan.
  4. Remove unknown browser extensions.
  5. Check installed apps for anything unfamiliar.
  6. Change important passwords from a clean device.
  7. Turn on multifactor authentication.
  8. Review bank, email, and cloud account activity.
  9. Restore from a clean backup if malware remains.

CISA recommends strong defenses such as phishing-resistant multifactor authentication, tested offline backups, and application controls to reduce the impact of malicious cyber activity.

Browser updates are important, but fake update pop-ups are dangerous. Do not trust a random website that tells you to install an update. Close the page, open your browser settings, and update from the official menu.

08.03.26

What is a rootkit? How hidden malware can give hackers backdoor access to your device

A rootkit is one of the sneakier types of malware because it tries to hide while giving an attacker deep access to your computer. If regular malware is like a burglar breaking a window, a rootkit is like someone secretly copying your house key, hiding in the walls, and letting other criminals come in later.

The NIST rootkit glossary defines a rootkit as tools an attacker uses after gaining root-level access to conceal activity and maintain access through covert means. In plain English: a rootkit helps a hacker stay hidden while keeping control.

What does a rootkit do?

A rootkit can help an attacker control a device without showing obvious signs. Once installed, a rootkit may hide files, disguise running processes, disable security tools, open a backdoor, or help install other malware.

A rootkit may allow criminals to:

  • Spy on your activity
  • Steal passwords and account tokens
  • Hide viruses from security scans
  • Disable antivirus software
  • Log keystrokes
  • Give remote access to attackers
  • Install ransomware, bots, or data-stealing malware

Why are rootkits dangerous?

Rootkits are dangerous because they focus on stealth. You may not see pop-ups, strange apps, or obvious warnings. Your device might look normal while an attacker quietly maintains access.

That hidden access matters because modern malware arrives at massive scale. Microsoft reports in its 2025 Digital Defense Report that it blocks 4.5 million net new malware files every day, showing how aggressively attackers push new malicious files into the world.

Rootkits are not the most common threat most consumers will face every day, but they are serious because they can make infections harder to detect and remove.

How does a rootkit get on a device?

A rootkit usually needs a way in first. Attackers often rely on the same tricks used in other malware attacks.

Common rootkit infection paths include:

  • Clicking a malicious email attachment
  • Downloading cracked software or pirated games
  • Installing fake security tools
  • Using outdated operating systems
  • Plugging in unknown USB drives
  • Visiting compromised websites
  • Ignoring software updates
  • Giving admin permission to an unsafe app

Rootkits often target vulnerabilities in an operating system or application and can also spread through infected USB drives.

How can you tell if you have a rootkit?

Rootkits try to avoid detection, so symptoms can be subtle. Still, you should investigate if your device acts strangely.

Watch for these warning signs:

  • Security software turns off by itself
  • System settings change without explanation
  • Your device slows down dramatically
  • Unknown programs request admin access
  • Browser redirects happen repeatedly
  • Files disappear or reappear
  • Your device overheats when idle
  • Antivirus scans fail or crash
  • You see suspicious network activity

One warning sign does not prove a rootkit infection, but several signs together deserve attention.

How does learning about rootkits help someone become safer online?

Understanding rootkits helps someone become safer online because it reinforces one important habit: do not give unknown software deep access to your device.

Rootkits often depend on trust mistakes. Someone clicks a fake update, installs a shady download, ignores a security patch, or approves admin access without thinking. When you understand that malware can hide after gaining privileged access, you become more careful with every download, update, and permission request.

That mindset helps prevent:

  • Malware infections
  • Account theft
  • Device takeover
  • Data theft
  • Ransomware attacks
  • Fake tech support scams

How to protect yourself from rootkits

Use layered protection. No single tool catches everything.

Step-by-step rootkit prevention checklist

  • Keep your operating system updated
    Install Windows, macOS, Android, iOS, and browser updates quickly.
  • Use reputable security software
    Choose trusted antivirus or endpoint protection and keep it updated.
  • Avoid pirated software
    Cracked apps often carry hidden malware.
  • Do not click fake update pop-ups
    Update apps from official app stores or the software maker’s website.
  • Use a standard user account
    Avoid using an admin account for everyday browsing.
  • Turn on multifactor authentication
    MFA protects accounts even if malware steals a password.
  • Scan external drives
    Do not trust random USB drives or unknown storage devices.
  • Back up important files
    Keep backups offline or in a secured cloud account.
  • Review app permissions
    Remove apps that ask for more access than they need.

What should you do if you suspect a rootkit?

Act quickly and avoid logging into sensitive accounts from the infected device.

Take these steps:

  1. Disconnect the device from the internet.
  2. Run a full offline malware scan if available.
  3. Use a trusted rescue scanner from a known security vendor.
  4. Change passwords from a clean device.
  5. Check bank, email, and cloud accounts for suspicious activity.
  6. Restore the device from a clean backup if needed.
  7. Reinstall the operating system if security tools cannot remove the infection.

A rootkit is hidden malware that helps attackers maintain backdoor access to a device. You can reduce the risk by updating software, avoiding sketchy downloads, using trusted security tools, and thinking twice before granting admin access.

08.02.26

Talk to your child about in-game currency before the next accidental purchase

Online games make it easy for kids to play, compete, customize characters, and unlock new items. Many games also make it very easy to spend real money through premium currency, battle passes, loot boxes, skins, upgrades, and limited-time offers.

Before your child starts a new game, have one simple conversation: some game money is pretend, and some game money costs real money.

That talk can prevent surprise charges, reduce pressure to buy digital items, and help your child build safer online habits.

What is in-game currency?

In-game currency is money used inside a video game. Some games give players free currency for completing challenges, leveling up, or logging in. Other games sell premium currency that costs real money.

Common examples include:

  • Coins
  • Gems
  • V-Bucks
  • Robux
  • Tokens
  • Credits
  • Crystals
  • Battle pass points

The tricky part? Games often make both types of currency look similar. A child may not immediately understand that clicking “buy” can charge a parent’s credit card, gift card balance, mobile wallet, or console account.

Why should parents talk about premium currency?

Parents should talk about premium currency because many games encourage fast decisions. A game might show a countdown timer, a rare character skin, a “limited offer,” or a bundle that looks like a deal. That design can make kids feel rushed.

The FTC’s Kids and Video Games guidance specifically recommends parents ask whether a game manipulates kids into buying in-game purchases to succeed or avoid something bad happening in the game. The FTC also says parental controls can limit the amount of time and money a child spends playing a video game. [consumer.ftc.gov]

That is exactly why the conversation matters. You are not only preventing a purchase. You are teaching your child to pause before clicking.

How does this help someone become safer online?

This tip helps someone become safer online because it builds a key cybersecurity habit: stop, think, and verify before acting.

Kids who learn to question digital purchases also learn to question:

  • Pop-ups that demand quick action
  • “Free reward” links
  • Fake giveaways
  • In-game scams
  • Pressure from strangers
  • Requests to move chats off-platform
  • Offers that sound too good to be true

The same skill that prevents an accidental currency purchase can also help a child avoid phishing, account theft, and social engineering later.

How big is the risk?

Accidental and unwanted game purchases are not rare. The FTC announced that it was sending more than $126 million in refunds to Fortnite players who were charged for unwanted purchases while playing the game, according to the agency’s FTC gaming enforcement update.

That statistic shows why families should treat in-game spending like a real financial safety issue, not just a gaming annoyance.

What should you say to your child before they play?

Keep the conversation short, calm, and specific.

Try this:

“Some games use fake money and real-money currency. If a button says buy, unlock, upgrade, bundle, pass, gems, coins, or limited offer, stop and ask me first. We will decide together.”

Then explain:

  • Free rewards do not need a payment method
  • Premium currency costs real money
  • A saved card can be charged quickly
  • Limited-time offers can pressure players
  • No game item is worth hiding a purchase
  • Asking first will never get them in trouble

How to prevent accidental in-game purchases

Use both conversation and controls. Do not rely on only one.

Step-by-step parent checklist

  • Remove saved payment methods from gaming accounts when possible.
  • Require a password or PIN for every purchase.
  • Turn on spending limits for consoles, phones, tablets, and game accounts.
  • Use child profiles instead of letting kids play on adult accounts.
  • Review purchase history weekly for small charges.
  • Use gift cards instead of credit cards for gaming budgets.
  • Disable one-click purchases anywhere you can.
  • Check each new game separately because every game handles currency differently.

The ESRB says parental controls are available for every device and can help parents block games by rating, set time limits, manage in-game purchases, and restrict internet access through its tools for parents. The ESRB also explains that parental controls can help manage what kids play, when they play, who they communicate with, and whether they can spend money. [esrb.org]

Why should you repeat this conversation for every game?

You should repeat this conversation for every game because each game uses different words, icons, stores, currencies, and pressure tactics. One game may call premium money “gems,” while another calls it “credits” or “tokens.”

Make this part of your family’s new-game routine:

  1. Look up the game rating.
  2. Check whether the game has in-game purchases.
  3. Review the store page together.
  4. Explain which currency costs real money.
  5. Set purchase controls before play starts.
  6. Agree on a monthly gaming budget, if any.

Talking to your child about in-game currency protects your wallet and teaches digital decision-making. Set clear rules, turn on purchase controls, and remind your child that asking before clicking is part of being smart online.

08.01.26

Use multiple email addresses to stay safer online and protect your job search

Your email address acts like a digital home base. You use it to shop, apply for jobs, reset passwords, receive banking alerts, subscribe to newsletters, and sign in to apps. That makes your inbox valuable to scammers, advertisers, and cybercriminals.

A simple fix can make your digital life cleaner and safer: use multiple email addresses for different parts of your life. At minimum, keep one email for shopping and newsletters, and another for professional correspondence, job applications, and important accounts.

Why should you use more than one email address?

Using one email for everything creates clutter and risk. When every store receipt, coupon, job alert, shipping update, social media login, and recruiter message lands in the same place, important emails get buried.

It also gives scammers more room to work. The FBI’s 2024 Internet Crime Report says phishing and spoofing ranked among the top three cybercrime complaint categories in 2024, which means attackers continue to rely heavily on deceptive messages that look legitimate.

When you separate your inboxes, you make scams easier to spot. If a “bank alert” lands in your shopping-only email, that looks suspicious right away. If a fake recruiter contacts the email you never use for job applications, you know to slow down.

How does this help someone become safer online?

Multiple email addresses help you become safer online because they reduce exposure, improve focus, and limit damage.

Here is the practical security benefit:

  • Less confusion: You can quickly tell whether an email belongs in that inbox.
  • Less spam around important messages: Recruiter emails and password alerts do not get buried under coupons.
  • Better phishing detection: Messages sent to the wrong email category stand out.
  • Damage control: If one email appears in a breach or spam list, your other inboxes stay cleaner.
  • Stronger privacy: You do not hand the same address to every store, app, newsletter, and job board.

The [FTC’s job scam guidance] warns that scammers post fake jobs online and try to get personal information or money from applicants, so a dedicated job-search email gives you a cleaner way to track legitimate employer communication.

What email addresses should you create?

You do not need ten inboxes. Start with two or three.

1. Professional and job-search email

Use this for resumes, recruiter outreach, interviews, networking, LinkedIn, portfolio sites, and job boards.

Best format:

Avoid funny nicknames, birth years, or personal details.

2. Shopping and newsletter email

Use this for ecommerce, coupons, loyalty programs, webinars, downloads, promotions, and one-time signups.

This inbox will attract more marketing and spam, and that is the point. You keep the noise away from your professional inbox.

3. High-security email

Use this for banking, password managers, healthcare portals, tax accounts, cloud storage, and primary account recovery. Do not post this email publicly.

The [CISA privacy guidance] explains that social engineering becomes more convincing when attackers can use personal information that is publicly available online, so keeping your most sensitive email private reduces useful clues.

How big is the risk?

Email remains one of the easiest ways for scammers to reach people. The FTC reported that Consumer Sentinel received 6.5 million consumer reports in 2024 across fraud, identity theft, and other consumer protection categories.

That number shows why inbox hygiene matters. You cannot stop every scam from arriving, but you can make your inbox easier to defend.

How to set up multiple emails safely

Follow this simple setup:

  1. Create a professional email address
    Use it only for work, job hunting, recruiters, and professional accounts.
  2. Create a shopping email address
    Use it for newsletters, ecommerce, coupons, and loyalty programs.
  3. Protect your sensitive email
    Use a private email for banks, healthcare, taxes, and password recovery.
  4. Turn on multifactor authentication
    Add MFA to every email account, especially the professional and sensitive ones.
  5. Use a password manager
    Give every email account a unique, strong password.
  6. Add filters and labels
    Create folders for recruiters, applications, receipts, shipping, and alerts.
  7. Review forwarding rules monthly
    Attackers sometimes add hidden forwarding rules after account compromise.
  8. Unsubscribe carefully
    Use built-in unsubscribe options only for brands you recognize. Mark suspicious emails as spam instead.

What should job seekers do differently?

Job seekers should treat their email like part of their personal security plan.

Use your professional email for:

  • Resume submissions
  • Job boards
  • Recruiter outreach
  • Interview scheduling
  • Portfolio contact forms
  • Professional networking

Avoid using your job-search email for:

  • Online shopping
  • Streaming trials
  • Sweepstakes
  • Random downloads
  • Public comment sections

This keeps recruiter messages visible and makes fake job emails easier to identify.

Using multiple email addresses does not make you paranoid. It makes you organized, searchable, and safer. Start with one professional email and one shopping email today. Then protect your most sensitive accounts with a private email, strong passwords, and multifactor authentication.