How to Spot Internet Scams
Most internet scams rely on a handful of familiar tactics designed to make people act before they have time to think. Scammers may create urgency, fear, excitement, or curiosity by claiming an account has been compromised, a payment is overdue, a prize has been won, or immediate action is required. These messages can arrive through email, text messages, social media, websites, online advertisements, or messaging apps.
Common warning signs include unexpected requests for passwords, verification codes, personal information, money, gift cards, cryptocurrency, or unusual payment methods. Be cautious of unfamiliar links, suspicious attachments, unexpected invoices, offers that seem unusually generous, and messages pressuring you to keep a transaction secret. Scammers may also impersonate legitimate businesses, government agencies, financial institutions, friends, or family members to make their requests appear trustworthy.
If an offer or warning asks for urgent action, stop and verify it separately. Open the organization's official app or type a known address instead of following the message's link. Do not send money, install remote-access tools or provide security codes to an unexpected contact. Ask a trusted person for a second opinion if pressure is making it hard to decide.
Back to topic listCommon Email and Tech Support Scams
Email scams often impersonate trusted companies, financial institutions, delivery services, coworkers, or government agencies to convince recipients that a message is legitimate. They may claim that an account has been locked, a package cannot be delivered, an invoice is overdue, or suspicious activity has been detected. The goal is usually to make you click a malicious link, open an attachment, provide login credentials, or send money.
Tech support scams use similar tactics but often claim there is an urgent problem with your computer. Scammers may use fake security warnings, browser pop-ups, emails, or unsolicited phone calls claiming that your device contains viruses or has been compromised. They may then request payment, ask you to install remote-access software, or attempt to gain control of the computer. Unexpected warnings that include a phone number and demand immediate action are a major red flag.
A webpage cannot reliably diagnose your computer simply by showing a dramatic virus alert. Do not call the number or install the suggested tool. Close the tab; if it will not close, quit the browser using your device's normal controls. If you already installed remote-access software, paid money or shared credentials, treat that as an incident rather than just dismissing the warning.
Back to topic listSocial Media and Marketplace Scams
Social media platforms and online marketplaces give scammers easy ways to create convincing profiles, listings, advertisements, and messages. Fake accounts may use stolen photographs and personal information, while fraudulent marketplace listings can copy images and descriptions from legitimate sellers. Scammers may also compromise real accounts, making suspicious messages or offers appear to come from someone you already know.
Common warning signs include prices that seem unusually low, requests to move conversations outside the platform, pressure to act quickly, unusual payment methods, and requests for verification codes or personal information. Marketplace scammers may request deposits for items that do not exist, send fake payment confirmations, or claim that additional fees must be paid before money can be released.
Verify payment inside your bank or the platform's official account, not through a screenshot or emailed receipt. Be cautious of overpayments followed by a request to return money, unexpected shipping fees and requests for sign-in codes. A familiar profile can be hijacked. Check platform protections before agreeing to a transaction, and independently contact friends who make unusual requests.
Back to topic listHow Scammers Use Fear and Urgency
Scammers frequently use fear, urgency, and emotional pressure to convince people to act before they have time to question what is happening. A message might claim that your bank account has been compromised, your computer is infected, a payment is overdue, or legal action is imminent. Others create artificial urgency around prizes, purchases, investments, or limited-time opportunities.
These tactics work because strong emotions can interfere with careful decision-making. Scammers may demand immediate payment, passwords, verification codes, remote access, or personal information while warning that something terrible will happen if you hesitate. They may also discourage you from contacting family members, your bank, or another trusted person who could recognize the scam.
Pause the conversation and contact the organization independently. A caller who claims you must move money to a 'safe account,' buy gift cards, or remain on the phone while transferring funds is giving you reasons to stop. If someone claims to be a family member in trouble, verify through a known number. Do not let threats or secrecy prevent you from checking.
Back to topic listWhat to Do If You’ve Been Scammed
If you believe you've been scammed, acting quickly can help limit the damage. Stop communicating with the scammer, save relevant emails, messages, receipts, phone numbers, and screenshots, and identify what information or access may have been compromised. If you provided a password, change it immediately and update any other accounts where the same password was used.
If money or financial information was involved, contact your bank, credit card company, or payment provider as soon as possible. They may be able to stop a transaction, replace compromised cards, or help protect affected accounts. If a scammer gained remote access to your computer, disconnect the device from the internet and have it checked for unwanted software or changes before using it for sensitive activities.
Use a trusted device to change exposed passwords and protect the email account used for account recovery. Contact your bank or payment provider promptly if money was sent, and preserve receipts and messages. Report fraud through official channels. If identity information was exposed, use the official identity-theft recovery resources. Be alert for recovery scammers who promise to retrieve losses in exchange for a fee.
Back to topic listHow to Secure Accounts After a Compromise
If you believe an online account has been compromised, changing the password is an important first step, but it may not be enough. Create a new, unique password and review recent login activity, connected devices, active sessions, and account settings for anything unfamiliar. If available, sign out of other devices or sessions to remove access that an unauthorized user may still have.
Next, enable multi-factor authentication (MFA) and carefully review recovery information such as backup email addresses and phone numbers. Attackers sometimes change these settings so they can regain access later. Also check for unfamiliar forwarding rules, connected applications, security keys, or other changes, particularly with email accounts that can be used to reset passwords for other services.
Secure the email account that can reset your other passwords, then review affected accounts. Remove unfamiliar sessions, recovery contacts, forwarding rules and connected apps where the service provides those controls. Save recovery codes securely and check recent transactions. If you cannot sign in, use the provider's official recovery process; CCS can assist with the steps but cannot bypass provider identity checks or guarantee recovery.
Back to topic listA Basic Home Cybersecurity Checklist
Good home cybersecurity starts with a few simple habits that work together to reduce risk. Keep computers, phones, web browsers, and other connected devices updated so known security vulnerabilities are patched. Use reputable security software where appropriate, secure your home Wi-Fi with a strong password, and remove programs or accounts you no longer use.
Protect online accounts with strong, unique passwords and multi-factor authentication (MFA) whenever available. Avoid reusing passwords between important accounts, and consider using a password manager to keep track of them. Be cautious with unexpected emails, text messages, attachments, downloads, and links, especially when they request personal information, payment, passwords, or immediate action.
Check updates, account protection, router security and a backup you have actually tested. Review device and app permissions, and keep recovery information accessible to the authorized owner. Include household members in the plan so they know how to verify unexpected requests. Repeat these checks when devices change or account settings are updated, rather than relying on a one-time setup.
Back to topic listNew Computer Setup Checklist
Setting up a new computer properly can improve its security, performance, reliability, and usability from the start. Begin by installing all available Windows or macOS updates, updating important applications and drivers, and removing unnecessary trial software or preinstalled programs. Configure your preferred web browser, email, printer, and other devices you regularly use.
Next, enable automatic updates, strong device sign-in protection and appropriate account security. Check whether device encryption is available and save its recovery information securely before relying on it. Use multifactor authentication or suitable passkeys for important online accounts. Install software only from trusted sources and confirm the device's security protections are enabled.
Before moving files, verify what is on the old computer and what is already stored in cloud accounts. Install required applications from trusted sources and sign in to the intended accounts. Test your printer and other essential devices. Save disk-encryption recovery information securely and confirm a backup can restore files. Synchronization and a separate backup serve different purposes.
Back to topic listWhat to Do Before Selling or Donating a Computer
Before selling, donating, or giving away a computer, make sure any important files, photos, documents, passwords, and other personal data are safely backed up. Sign out of important accounts and services, remove the device from accounts where necessary, and confirm that anything you want to keep has been transferred before beginning the erasure process.
Simply dragging files to the Recycle Bin or Trash is not the same as securely removing your personal information. Use the appropriate Windows or macOS reset and data-erasure options to remove user accounts, applications, settings, and personal files. The correct method can vary depending on the computer and type of storage, so follow the manufacturer's recommended procedure when preparing a device for a new owner.
Verify the backup before erasing anything, then follow the manufacturer's instructions for that computer and operating-system version. Save any information needed for your replacement device and remove activation or account locks appropriately. An ordinary reset may not meet sensitive-data disposal requirements. If the computer cannot start or its drive will not erase, get advice rather than assuming the data is gone.
Back to topic listSafe Browsing and Email Safety Best Practices
Many online threats begin with malicious websites, deceptive emails, suspicious links, or unsafe downloads. Be cautious with unexpected messages, especially those asking you to sign in, download a file, provide personal information, or make an urgent payment. Before clicking a link, check where it leads and consider accessing important accounts directly through their official website or app instead.
Email attachments should also be treated carefully, even when they appear to come from someone you recognize. Compromised accounts can be used to send convincing malicious messages, while scammers frequently impersonate legitimate businesses and organizations. Unexpected attachments, unusual requests, spelling variations in email addresses, and pressure to act quickly are all reasons to verify a message before responding.
Use a trusted bookmark or official app to reach important accounts. Check an unexpected attachment with the sender through another channel before opening it. Remove unnecessary browser extensions and deny notification requests from unfamiliar sites. Do not enable document macros or ignore security warnings merely because a message tells you to. Keep software updated and report suspicious requests through the service's official process.
Back to topic listProtecting Family Members Online
Protecting family members online starts with recognizing that different people face different types of digital risks. Children may encounter inappropriate content, unsafe interactions, or misleading information, while seniors and less experienced users are frequently targeted by phishing, tech support scams, fraudulent messages, and other forms of social engineering. Understanding these differences makes it easier to put appropriate safeguards in place.
Technology can provide an additional layer of protection. Keep devices updated, use strong passwords and multi-factor authentication, enable appropriate privacy and security settings, and consider parental controls or content restrictions where appropriate. Family members should also know never to provide passwords, verification codes, financial information, or remote access to someone who unexpectedly contacts them.
Agree on a simple rule: anyone can pause an unfamiliar request and ask for help without embarrassment. Set up account recovery, appropriate device protections and age-appropriate controls together. A family verification phrase can help with unexpected calls, but it should not replace independent contact. Never send money solely because a voice or video appears to be a relative; AI can imitate both.
Back to topic listAn Everyday AI Safety Checklist
AI tools can be useful for writing, research, brainstorming, productivity, and problem-solving, but their output should not automatically be treated as accurate. AI can misunderstand questions, omit important context, or confidently generate incorrect information. Verify important facts with reliable sources, especially when using AI for financial, legal, medical, technical, or other consequential decisions.
Be careful about what information you provide to an AI service. Avoid entering passwords, financial details, confidential business information, customer data, private documents, or other sensitive information unless you understand how the service handles and protects that data. Privacy policies, account settings, and data-retention practices can vary significantly between AI providers.
Before submitting a prompt, remove passwords, identifying details and confidential records. Check whether the service is approved for the task and review its data controls. Verify important claims against original sources, and do not run generated scripts or follow risky troubleshooting instructions without review. AI can help prepare a draft or checklist; you remain responsible for the information shared and actions taken.
Back to topic list