Cybersecurity used to feel like something handled by the IT department. Not anymore! Today, a scam can show up as a text from your bank, a phone call from someone who sounds exactly like a family member, or an email that looks like it came from your employer. Artificial Intelligence (AI) is making those scams faster and more convincing, and criminals don’t need to be technology experts to take advantage of it.
The numbers tell the story. The FBI received more than 1 million internet crime complaints in 2025, with losses exceeding $20 billion. That was a 26% increase in reported losses from 2024.
So, what can you actually do about it? Start with these five habits.
1. Turn on multifactor authentication
A password isn’t always enough. Multifactor authentication, or MFA, adds another layer of security by requiring a code, authentication app, fingerprint, or other verification before allowing access.
The 2026 Verizon Data Breach Investigations Report found that credential abuse accounted for 13% of breaches, while exploitation of software vulnerabilities had become the leading way attackers gained access.
Do this: Turn on MFA for your email, financial, banking, shopping, and social media accounts. Start with the accounts that would cause the most trouble if someone else gained access to them.
2. Slow down when something feels urgent
A sense of urgency is one of a scammer’s favorite tools. “Your account will be closed.” “You have an unpaid bill.” “I need you to send money right now.”
AI is making these messages harder to spot. The FBI’s 2025 Internet Crime Report documented 22,364 complaints involving AI-related information and more than $893 billion in reported losses. The FBI also reported that businesses lost more than $30 million to AI-related business email compromise scams.
Do This: Don’t click, reply, or send money simply because a message looks legitimate. Verify it independently. If someone asks for money or sensitive information, contact them using a phone number or website that you already know is legitimate.
And remember: a familiar voice isn’t proof of identity. Voice cloning can make a scammer sound like someone you know.
3. Give your passwords a fresh start
Using the same password everywhere is convenient, but it can also give criminals a shortcut into multiple accounts.
Use a different, strong password for each important account. Strong passwords often include uppercase and lowercase letters, numbers, and symbols and are not easily guessed. Avoid repeating letters or sequential characters like “abc” or “123” when creating a strong password.
Do this: If you haven’t changed or reused a password in a while, start with your email and financial accounts. Never share passwords or give your password to someone who contacts you unexpectedly.
4. Be thoughtful about what you put into AI tools
AI can help us write, research, summarize, and solve problems. But convenience can come with a privacy cost.
The 2026 DBIR found that 45% of employees were regular users of AI on corporate devices, up 15% from the previous year. The report also found that unauthorized “shadow AI” use had become a growing data-loss concern, with sensitive information (including source code and other structured data) being entered into unapproved AI services.
Do this: Before putting information into an AI tool, stop and consider whether it contains anything private, confidential, or sensitive. If it does, don’t upload it unless you know the tool is approved for that type of information.
5. Update your devices, and don’t ignore the warning signs
Those software update reminders may be annoying, but they’re important.
According to the 2026 DBIR, 31% of breaches began with exploitation of vulnerabilities, making it the leading initial access method. Even more concerning, organizations fully remediated only 26% of critical vulnerabilities tracked by CISA in 2025.
Do this: Install updates promptly and replace devices that no longer receive security updates. If you notice an unfamiliar transaction, compromised account, or suspicious activity, act quickly. Contact your financial institution, change affected passwords, and report suspected fraud.
Cybersecurity Quick Check
Take five minutes to ask yourself:
- Do I use MFA on my most important accounts?
- Do I use unique passwords?
- Did I verify that unexpected messages are legitimate before clicking?
- Have I limited the personal or confidential information that I share with AI tools?
- Are my phone, computer, and apps up to date?
If you answered “Yes” for all five, you’re off to a good start! If you don’t, October is a good time to make a few changes.
Helpful Resources
For practical guidance, visit CISA (the Cybersecurity & Infrastructure Security Agency), the FBI’s Internet Crime Complaint Center, and Verizon’s 2026 Data Breach Investigations Report.
Cybersecurity isn’t about being perfect. It’s about making it harder for someone else to get through the door and knowing what to do if they try.
And remember, even when you follow all these steps to help protect yourself against cybersecurity threats, you are not immune to identity fraud. If you feel your personal information has fallen into the hands of a thief, contact us. Quickly recognizing and addressing the issue will minimize damage to your accounts and your identity.
As a Power Checking account holder, you will have access to a team of Identity Theft Recovery Advocates who can answer your questions, address your concerns, and help you get back on track as quickly as possible. These advocates work on your behalf to help you recover and reverse any damage caused by identity theft. Contact us or find out more about identity theft resolution services and other benefits of Power Checking by visiting our website.