Think Before You Click:
Five Cybersecurity Habits That Matter More Than Ever
Cybersecurity used to feel like something handled by the IT department. Not anymore! Today, a scam can show up as a text from your bank, a phone call from someone who sounds exactly like a family member, or an email that looks like it came from your employer. Artificial Intelligence (AI) is making those scams faster and more convincing, and criminals don’t need to be technology experts to take advantage of it.
The numbers tell the story. The FBI received more than 1 million internet crime complaints in 2025, with losses exceeding $20 billion. That was a 26% increase in reported losses from 2024.
So, what can you actually do about it? Start with these five habits.
1. Turn on multifactor authentication
A password isn’t always enough. Multifactor authentication, or MFA, adds another layer of security by requiring a code, authentication app, fingerprint, or other verification before allowing access.
The 2026 Verizon Data Breach Investigations Report found that credential abuse accounted for 13% of breaches, while exploitation of software vulnerabilities had become the leading way attackers gained access.
Do this: Turn on MFA for your email, financial, banking, shopping, and social media accounts. Start with the accounts that would cause the most trouble if someone else gained access to them.
2. Slow down when something feels urgent
A sense of urgency is one of a scammer’s favorite tools. “Your account will be closed.” “You have an unpaid bill.” “I need you to send money right now.”
AI is making these messages harder to spot. The FBI’s 2025 Internet Crime Report documented 22,364 complaints involving AI-related information and more than $893 billion in reported losses. The FBI also reported that businesses lost more than $30 million to AI-related business email compromise scams.
Do This: Don’t click, reply, or send money simply because a message looks legitimate. Verify it independently. If someone asks for money or sensitive information, contact them using a phone number or website that you already know is legitimate.
And remember: a familiar voice isn’t proof of identity. Voice cloning can make a scammer sound like someone you know.
3. Give your passwords a fresh start
Using the same password everywhere is convenient, but it can also give criminals a shortcut into multiple accounts.
Use a different, strong password for each important account. Strong passwords often include uppercase and lowercase letters, numbers, and symbols and are not easily guessed. Avoid repeating letters or sequential characters like “abc” or “123” when creating a strong password.
Do this: If you haven’t changed or reused a password in a while, start with your email and financial accounts. Never share passwords or give your password to someone who contacts you unexpectedly.
4. Be thoughtful about what you put into AI tools
AI can help us write, research, summarize, and solve problems. But convenience can come with a privacy cost.
The 2026 DBIR found that 45% of employees were regular users of AI on corporate devices, up 15% from the previous year. The report also found that unauthorized “shadow AI” use had become a growing data-loss concern, with sensitive information (including source code and other structured data) being entered into unapproved AI services.
Do this: Before putting information into an AI tool, stop and consider whether it contains anything private, confidential, or sensitive. If it does, don’t upload it unless you know the tool is approved for that type of information.
5. Update your devices, and don’t ignore the warning signs
Those software update reminders may be annoying, but they’re important.
According to the 2026 DBIR, 31% of breaches began with exploitation of vulnerabilities, making it the leading initial access method. Even more concerning, organizations fully remediated only 26% of critical vulnerabilities tracked by CISA in 2025.
Do this: Install updates promptly and replace devices that no longer receive security updates. If you notice an unfamiliar transaction, compromised account, or suspicious activity, act quickly. Contact your financial institution, change affected passwords, and report suspected fraud.
Cybersecurity Quick Check
Take five minutes to ask yourself:
Do I use MFA on my most important accounts?
Do I use unique passwords?
Did I verify that unexpected messages are legitimate before clicking?
Have I limited the personal or confidential information that I share with AI tools?
Are my phone, computer, and apps up to date?
If you answered “Yes” for all five, you’re off to a good start! If you don’t, October is a good time to make a few changes.
Helpful Resources
For practical guidance, visit CISA (the Cybersecurity & Infrastructure Security Agency), the FBI’s Internet Crime Complaint Center, and Verizon’s 2026 Data Breach Investigations Report.
Cybersecurity isn’t about being perfect. It’s about making it harder for someone else to get through the door and knowing what to do if they try.
And remember, even when you follow all these steps to help protect yourself against cybersecurity threats, you are not immune to identity fraud. If you feel your personal information has fallen into the hands of a thief, contact us. Quickly recognizing and addressing the issue will minimize damage to your accounts and your identity. As a NH Postal Credit Union account holder, you have access to a team of Identity Theft Recovery Advocates who can answer your questions, address your concerns, and help you get back on track as quickly as possible. These advocates work on your behalf to help you recover and reverse any damage caused by identity theft. Contact us or find out more about identity theft resolution services and other benefits of NH Postal Credit Union HERE.
Scammers hide harmful links in QR codes to steal personal information
Ever tried to pay for parking and discovered you need to scan a QR code to pay? It seems like a convenient way to pay, but it turns out scammers like using QR codes, too. People have reported scammers covering up legit QR codes on parking meters with a QR code of their own. If you scan that scammy QR code, it could take you to a fake site designed to steal your money, your personal information, or both. So, how can you protect yourself from these scams?
Follow these steps:
Inspect the URL link. Many QR readers preview the link they will send you to. Make sure there are no spelling mistakes or switched letters in the link before you click.
Protect your phone. Update your phone's operating system (OS) and apps to help prevent scammy links from turning into a hack:
Use strong passwords for your accounts. Protect your online accounts with strong passwords and multi-factor authentication.
Think you scanned a bad QR code? Follow these steps:
Don’t interact with the scammer: If you reach out to someone through the website you think is fake, they may try to get money or sensitive information out of you.
Change your password: If you entered credentials like your username or password, immediately change them wherever you use the same password for other accounts.
Review your transactions: Check your credit card and bank statements to spot transactions you didn’t make.
Then, report it to the FTC at ReportFraud.ftc.gov.
FBI warns of “Banking Spoof Call” scams.
The FBI is warning people about a believable phone scam that can cost thousands of dollars.
Fraudsters are calling people and claiming to represent banks.
Many of them can spoof caller ID, so the bank's name appears when the phone rings.
One victim said the scammer even knew her account number and exact balance.
According to the FBI, legitimate banks will never ask for your username or password over the phone.
You should ignore any request to move money or gain access to your bank account.
If in doubt, hang up and dial the bank's published phone number.
Safeguarding Your Child’s Identity In Today's World
Child identity theft isn’t something we often think about. However, it occurs more often than you might expect. According to Javelin’s Child Identity Fraud Report, child identity theft affects 1.25 million kids every year, which translates to about one in 50 children in America. When you see those numbers, it becomes apparent that we must act now to protect the children in our lives.
What Is Child Identity Theft?
According to the Federal Trade Commission, “Child identity theft happens when someone takes a child’s sensitive personal information and uses it to get services or benefits or to commit fraud. They might use your child’s Social Security number, name and address, or date of birth.”
Child identity theft happens for a multitude of reasons. The perpetrator could use this information to open a bank or credit card account, apply for government benefits, or even sign up for a utility service or rent a place to live. Much like other types of identity theft, it can be easy for this type of identity theft to remain undetected for months or even years.
How It Happens
As with adults, identity theft against children can be perpetrated through a variety of sources. Below we have listed some ways that children's personally identifiable information (PII) could be exposed and then potentially used for fraudulent purposes.
§ Data Breaches. Kids’ personal identifying information is in so many places, and nothing is completely secure. Schools, doctors’ offices, and your home can all experience security breaches. After a child's confidential information or PII is exposed, whether the data breach incident is accidental or with malicious intent, the security breach cannot be undone. Often, criminals will wait to utilize the confiscated information for their own purposes.
§ Familial Fraud. Three out of four cases of child identity theft come from those close to the victim, in what is known as familial fraud, and often occur in correlation with other forms of abuse, according to Javelin's Child Identity Fraud Report. Kids are often more trusting than adults, especially when they know the person who is asking for their information. Unscrupulous individuals at times utilize the PII of their own children, or children they know through family or friends, for their own benefit.
§ Phishing. These scams don’t just target adults. Children that use the internet without parental supervision have a higher chance of giving their sensitive information to a scammer, not realizing that they are being tricked. Kids don’t always know not to share their birth date, place of birth, and passwords with strangers or online “friends.”
§ Hacking. As more children have their own devices, and often multiple devices (computers, tablets, and phones), hacking becomes more common. Hackers can gain access to the information stored on these devices and can also log in to social media accounts, which they could use to attempt to defraud friends and family, acting as your child.
Warning Signs Of Child Identity Theft
Regardless of the way the information makes it into the hands of identity thieves, below are some warning signs that your child's identity may have been stolen:
§ Unexpected Mail. Your child begins receiving credit card offers, collection notices, or bills under their name.
§ Collection Calls. You or your family members begin to receive calls from collection agencies for unpaid bills in your child's name.
§ Government Benefits Denials. Your child is denied government benefits because they are already being claimed, when this is not the case.
§ IRS Notifications. The IRS contacts you or your child about your child owing taxes or indicates that their SSN was used on another tax return.
How You Can Help Protect Your Children
The best way to help protect your family from identity theft is to be proactive in helping to prevent it. The most effective preventative measure is education. This type of education will not only help protect them now, but it is information that will benefit them as adults.
Keep Important Documents in a Secure Location. Keep your family’s personal identifying information in a secure place in your home, be selective about what services you sign up for, and don’t give your information out unless it is absolutely necessary. Make sure that any important documents in your home, such as Social Security cards, birth certificates, or other legal documents, are stored securely to avoid compromise.
Share Personal Information with Caution. Assess the need before listing your child’s Social Security number (SSN) on forms. Schools and school break camps shouldn’t be using it as the only unique ID for each child. If an SSN is required, don't be afraid to ask if it's ok to share only the last 4 digits of your child's SSN.
Educate Your Child. Talk to your child about the importance of privacy and the dangers of sharing personal information online and offline. Ensure that your child isn't sharing personal information like their birthdate, address, or school on social media, other online platforms, or with other individuals without your permission.
Secure Your Mail. If you're sending or receiving mail with personal details, especially if those personal details pertain to your children, consider using a mailbox that locks or opt for electronic delivery. Retrieve your mail daily as soon after delivery as possible. Consider opting into the U.S. Postal Service’s “Informed Delivery” service. It’s free to sign up, and it will provide a Daily Digest email that will preview your mail and packages scheduled to arrive soon, along with an image of each of your incoming letter-sized mail pieces. This will help you stay vigilant if any missing mail never arrives.
Discard Unnecessary Documents with Care. If you have postal mail or other important documents that you no longer need to keep on file, make sure that you use a cross-cut shredder to securely destroy the paperwork. Criminals can engage in "dumpster diving" to retrieve discarded paperwork with personal information, potentially compromising you and your family.
Have you set up your internal Code Word to be used when you call the Credit Union?
We are advising all members to do so. A CODE WORD is something you and only you will know. When you call the NH Postal Credit Union for account information, we will ask you this code word for verification. Call and speak to a Member Service Representative today!
What are some classic warning signs of possible fraud and scams? *
There are several signs that indicate you might be dealing with a scammer, and several steps you can take to protect yourself and others.
Criminals and con artists use many scams to target unsuspecting people—of all ages—who have access to money. Consumer scams happen on the phone, through the mail, e-mail, or over the internet. They can occur in person, at home, or at a business.
Warning signs include contact from someone:
Claiming to be from the government, a bank, a business, or a family member, and asking you to pay money.
Asking you to pay money or taxes upfront to receive a prize or a gift.
Asking you to wire them money, send cryptocurrency, send money by courier, send money over a payment app, or put money on a prepaid card or gift card and send it to them or give them the numbers on the card.
Asking for access to your money-such as your ATM cards, bank accounts, credit cards, cryptocurrency wallet keys or access codes, or investment accounts.
Pressuring you to "act now" or else the deal will go away, or trying hard to give you a "great deal" without time to answer your questions.
Creating a sense of urgency or emergency to play on your emotions.
Here are some tips to protect yourself from scams:
Don’t share numbers or passwords for accounts, credit cards, or Social Security.
Never pay up front for a promised prize. It’s a scam if you are told that you must pay fees or taxes to receive a prize or other financial windfall.
After hearing a sales pitch, take time to compare prices. Ask for information in writing and read it carefully.
Too good to be true? Ask yourself why someone is trying so hard to give you a “great deal.” If it sounds too good to be true, it probably is.
Watch out for deals that are only “good today” and that pressure you to act quickly. Walk away from high-pressure sales tactics that don’t allow you time to read a contract or get legal advice before signing. Also, don’t fall for the sales pitch that says you need to pay immediately, for example by wiring the money, sending it by courier or over a payment app, or by sending cryptocurrency.
Beware when someone plays on your emotions or claims there’s an urgent situation. Advances in artificial intelligence make it easier for scammers to clone voices and alter images to make it seem like someone you know needs help. Contact the person yourself to verify the story. Use contact information you know is theirs. If you can’t reach them, try to get in touch with them through another trusted person, like a family member or their friends.
Don’t click on links or scan QR codes. These can take you to scammers’ malicious websites or give them access to your device.
Put your number on the National Do Not Call Registry. Go to www.donotcall.gov or call (888) 382-1222.
* Consumer Financial Protection Bureau
Report Fraud:
In October 2020 the FTC launched ReportFraud.ftc.gov a site for people to report fraud and other illegal business practices. Reports from consumers are stored in the Consumer Sentinel Network, a secure online database available only to law enforcement.
IRS Identity Theft Awareness
The IRS Identity Theft Awareness
The Internal Revenue Service (IRS) has launched its “Identity Theft Central” webpage to provide 24/7 access to online information regarding tax-related identity theft and data security protection. Tax-related identity theft occurs when someone steals personal information to commit tax fraud.
StayConnectedNH ! Sponsored by NH Credit Unions/ Better Values - Better Banking
Isolated and vulnerable, more than 3 million older Americans are victims of financial abuse every single year.
Today, a new tool is added to the arsenal to protect New Hampshire’s vulnerable populations by raising awareness of financial exploitation in the Granite State: StayConnectedNH.org.