Author: J. Mesa

  • The T-Mobile Data Breach of 2023: What Happened and How to Protect Yourself

    By J. Mesa

    A cyberattack can seem distant until you get the call that says your systems were breached. Many organizations don’t list a security breach among their top five operational risks. Following real incidents helps put that risk in view, because every industry depends on technology.

    The T-Mobile breach of January 2023 is a useful case. It shows how one overlooked connection exposed millions of customers.

    What happened in the T-Mobile breach?

    In January 2023, T-Mobile announced that an attacker had obtained data on about 37 million customer accounts. The attacker pulled the data through an application programming interface, or API.

    According to the company’s disclosure, the activity began in late November 2022. T-Mobile detected it in early January 2023 and shut it down within a day. The attacker had access for more than a month.

    What data was exposed?

    T-Mobile said the attacker obtained:

    • Names
    • Billing addresses
    • Email addresses
    • Phone numbers
    • Dates of birth
    • Account numbers and plan details

    The company said passwords, payment card details, and Social Security numbers were not exposed.

    That sounds mild. It isn’t. A name, phone number, birth date, and account number are what a criminal needs to pose as you to a phone carrier, or to write a phishing message that looks real.

    What is an API, and how do attackers abuse one?

    An API is a connection that lets one piece of software request data from another. When an app shows your account balance, it asks an API for it.

    APIs cause breaches when they hand over more than they should. Common weaknesses include:

    • No check that the requester is allowed to see the data
    • No limit on how many records one requester can pull
    • Old or forgotten APIs that nobody monitors

    In this case the attacker used an API to collect customer records at scale, without breaking into the core network.

    Why does this keep happening to T-Mobile?

    The 2023 breach followed several earlier ones. A breach in 2021 exposed data on tens of millions of people and led to a $350 million settlement. The company was in the middle of a large security overhaul when the API incident happened.

    It is encouraging that the company invested in security. The repeat incident shows that a large budget does not remove risk. A large company has thousands of systems, and an attacker needs one weak point.

    What should I do if my data was exposed?

    1. Set an account PIN or passcode with your carrier, and change it if you already had one.
    2. Turn on SIM protection. Carriers offer a setting that blocks someone from moving your number to a new SIM without extra verification.
    3. Move away from text-message codes for your most important accounts. Use an authenticator app or a security key where you can.
    4. Freeze your credit with Equifax, Experian, and TransUnion. It is free.
    5. Watch for phishing. Expect calls, texts, and emails that mention your carrier and your real account details.
    6. Check your accounts for charges or changes you did not make.

    What is SIM swapping?

    SIM swapping is a fraud where a criminal convinces your carrier to move your phone number to a SIM card they control. They then receive your calls and texts, including login codes from your bank and email.

    Leaked carrier data makes the con easier, because the criminal can answer the carrier’s verification questions. An account PIN and SIM protection are your defense.

    How do I spot a phishing message after a breach?

    • It mentions the breach and asks you to “verify” your account
    • It includes real details, such as your name and plan
    • It links to a login page
    • It pushes you to act within hours

    Your carrier will not ask for your password or PIN by text or email. Go to the company’s app or website yourself. Don’t use the link.

    What should businesses learn from this breach?

    • Know your APIs. Keep an inventory of every API you expose, including old versions.
    • Require authentication and authorization on every request. Confirm who is asking and what they are allowed to see.
    • Limit the rate of requests, so one account can’t pull millions of records.
    • Monitor for unusual volume. A month of bulk requests should trigger an alert on day one.
    • Encrypt sensitive data and use multi-factor authentication for staff.
    • Audit on a schedule. Regular security assessments find the forgotten connection before an attacker does.

    Does this apply to a small business?

    Yes. You may not build APIs, and you use them. Your website, your booking tool, your payment processor, and your accounting software all connect through them.

    • Ask your vendors how they secure customer data.
    • Remove integrations and plugins you no longer use.
    • Give each connected app the least access it needs.
    • Rotate API keys when staff or vendors change.

    Why does employee training matter?

    Technical controls are one half of the defense. Staff need to know the risks and how to respond. Training should cover:

    • How to identify and report suspicious emails
    • Why strong passwords and multi-factor authentication matter
    • What to do in the first minutes of a suspected breach

    What is the customer’s role?

    Customers protect their own information too. Use strong, unique passwords, check your accounts for unfamiliar activity, and report anything unusual to your provider right away.

    Should I switch carriers after a breach?

    A breach alone does not tell you which carrier is safest. Every major carrier has disclosed incidents. Judge a provider by how it responds: how fast it tells customers, what protections it offers, and whether it fixes the cause. Whichever carrier you use, set a PIN and turn on SIM protection.

    How do I know if I was part of the breach?

    T-Mobile notified affected customers directly. If you were a customer in late 2022, check your account messages and mail from that period. You can also search your email address at haveibeenpwned.com.

    Your next step

    Set a PIN on your mobile account today. It takes five minutes. If your business handles customer data, find out how your systems and vendors would hold up under the same attack. Cerberus Cybersecurity can show you with a risk and compliance assessment. Contact us to schedule one.

  • 7 Bad Cybersecurity Habits That Put You at Risk (and How to Fix Them)

    By J. Mesa

    Most security incidents don’t start with a brilliant hacker. They start with a habit: a reused password, a skipped update, a quick click. The same seven habits show up again and again, in homes and in businesses.

    Here is each one, why it puts you at risk, and how to fix it.

    1. Why are weak passwords dangerous?

    Passwords such as “password” and “123456” sit at the top of every attacker’s list. Software tries them in seconds.

    The fix: Use a long passphrase made of several unrelated words. Words from another language make it harder to guess. Something built around a phrase like “Biba Mes CHamoru” means a lot to me and nothing to a cracking tool. Don’t copy an example from a blog post, mine included. Make your own, and use a different one for every account. A password manager keeps track of them.

    2. Is it safe to share passwords?

    No. Sharing a streaming login to catch the latest episode of a show feels harmless. Once you share a password, you no longer control where it goes. The other person may reuse it, save it somewhere unsafe, or fall for a phishing email.

    The fix: Give each person their own account. For family services, use the plan’s built-in sharing feature. At work, never share a login. If several people need the same system, give each one a separate account, so you can see who did what and remove access when someone leaves.

    3. Is public Wi-Fi safe?

    Public Wi-Fi in an airport, hotel, or café is a shared network. An attacker on it can set up a fake hotspot with a similar name or try to intercept traffic that is not encrypted.

    The fix:

    • Confirm the network name with staff before you join
    • Use your phone’s hotspot for banking and work
    • Use a virtual private network (VPN) when you handle sensitive or business data while traveling
    • Turn off automatic connection to open networks

    4. What happens if I click a suspicious link?

    Phishing is a common way for attackers to get into accounts. A link can lead to a fake login page that captures your password, or it can install malware on your device.

    The fix: Check the address before you click. Don’t open attachments you did not expect. If you doubt an email, call the business or person using a phone number from their official website. Do not use the contact details in the email.

    If you already clicked, change the password for that account from a different device and tell your IT contact.

    5. Why do software updates matter?

    Updates carry security patches that fix known flaws. Skip them, and attackers can use those flaws against you. Updates take time and interrupt your day. They also close the holes that criminals are using right now.

    The fix: Turn on automatic updates for your operating system, browser, apps, and phone. Restart when asked. Replace devices that no longer receive updates.

    6. Why should I change default settings?

    Many routers, cameras, and other devices ship with a standard username and password such as “admin” and “admin.” Lists of those defaults are published online. Attackers scan the internet for devices that still use them.

    The fix: Change the default username and password on every device as soon as you set it up. Start with your home or office router. Turn off features you don’t use, such as remote management.

    7. What if I don’t back up my data?

    Without a backup, a ransomware attack, a failed drive, or a stolen laptop means the data is gone.

    The fix: Back up to an external drive or cloud storage. Follow the 3-2-1 rule: three copies, two types of storage, one offsite. Test that you can restore a file. It is better to have a backup and not need it than the alternative.

    What other bad habits should I watch for?

    • No multi-factor authentication. A second step at login blocks most attacks that use stolen passwords. Turn it on for email and banking first.
    • Oversharing online. Birthdays, pet names, and travel plans help attackers guess security answers and write convincing scams.
    • Using an administrator account for daily work. Malware runs with the rights of the account that opens it. Use a standard account for everyday tasks.
    • Ignoring old accounts. Close accounts you no longer use. Each one is a breach waiting to happen.

    Which habit should I fix first?

    Start with passwords and multi-factor authentication. Stolen and weak passwords open more accounts than any other cause. Then turn on automatic updates, which takes a few minutes and keeps working without you. Backups come third.

    How do I change habits across a whole team?

    • Make the safe way the easy way. Provide a password manager and turn on automatic updates for everyone.
    • Explain the reason behind each rule. People follow rules they understand.
    • Train in short sessions through the year.
    • Praise people who report a suspicious email or admit a mistake.
    • Write the rules into a short policy that new hires read on day one.

    How do I know if a bad habit already caused harm?

    • Search your email address at haveibeenpwned.com to see if it appears in a breach
    • Review the login history on your email and bank accounts
    • Look for email forwarding rules you did not create
    • Check that your backups ran

    If you find a problem, change the password, turn on multi-factor authentication, and tell anyone who may be affected.

    Are these habits a problem for businesses too?

    Yes, and the stakes are higher. One employee’s reused password can expose a customer database. One unpatched server can stop operations for a week. The same seven fixes apply, and a business should add written policies and regular training.

    Your next step

    Pick the habit from this list that describes you and fix it today. Cybersecurity is a priority for everyone, at home and at work. If you want your whole team to build better habits, Cerberus Cybersecurity offers cybersecurity training for every audience. Contact us to learn more.

  • How to Spot a Phishing Email: 9 Red Flags and What to Do Next

    By J. Mesa

    Each new year brings new technology and the same old threat. Phishing sounds like a tired topic. It keeps coming up because it still works, and criminals reach for it first.

    This guide shows you how to recognize a phishing message, the forms it takes, and what to do when one lands in your inbox.

    What is phishing?

    Phishing is a scam where a criminal sends a message that appears to come from a source you trust, such as a bank, a delivery service, a coworker, or a vendor. The goal is to get you to click a link, open a file, share a password, or send money.

    Why does phishing still work?

    • It targets people. Software can be patched. A busy person in a hurry can be rushed.
    • It is cheap. A criminal can send thousands of messages for almost nothing.
    • It looks better every year. Attackers copy real logos and layouts, and writing tools remove the spelling mistakes that used to give them away.
    • One click is enough. A single response out of thousands pays for the campaign.

    What are the types of phishing?

    • Email phishing. Mass messages that imitate well-known companies.
    • Spear phishing. A message written for one person, using details about their job or life.
    • Business email compromise. A message that poses as an owner, executive, or vendor and asks staff to send money or change bank details.
    • Smishing. Phishing by text message.
    • Vishing. Phishing by phone call, often with a fake caller ID.
    • QR code phishing. A code that leads to a fake login page.

    What are the red flags of a phishing email?

    1. You didn’t expect it. Be wary of any unsolicited message that asks for information or payment.
    2. It creates urgency. “Your account closes in 24 hours” is meant to stop you from thinking.
    3. It asks for personal information. Legitimate companies don’t ask for passwords or card numbers by email.
    4. The sender address is off. Look at the full address, not the display name. Watch for swapped letters and odd domains.
    5. The link doesn’t match. Hover over it to see where it goes.
    6. It has an unexpected attachment. Invoices, shipping notices, and “scanned documents” you didn’t ask for are common lures.
    7. The greeting is generic. “Dear customer” from a company that knows your name is a warning.
    8. The request is unusual. Gift cards, wire transfers, and secrecy are scam hallmarks.
    9. Something feels wrong. Odd tone, odd timing, or an odd request from someone you know deserves a second look.

    Spelling and grammar errors are still a sign. Their absence proves nothing.

    How do I verify a sender?

    Before you respond, confirm who sent the message. Contact the company or person through a phone number or address you already know to be real. Don’t use the contact details in the message, and don’t reply to it.

    For any request that involves money or a change to payment details, make a phone call. This one habit stops most business email compromise.

    What should I do if I receive a phishing email?

    1. Don’t click, reply, or open attachments.
    2. Report it with your email program’s “Report phishing” button.
    3. At work, tell your IT contact so they can warn others.
    4. Delete it.

    What should I do if I clicked a phishing link?

    Act right away. Speed matters more than embarrassment.

    1. Disconnect the device from the network if you opened a file or installed something.
    2. Change the password for the affected account from a different device, and for any account that shares it.
    3. Turn on multi-factor authentication.
    4. Tell your IT contact or manager at work.
    5. Call your bank if you entered payment details or sent money.
    6. Run a security scan on the device.
    7. Report it to the FBI at ic3.gov and to the Federal Trade Commission at reportfraud.ftc.gov.

    How do I protect my business from phishing?

    • Train your team. Use real examples. Repeat through the year.
    • Run simulated phishing tests and use the results to teach, never to punish.
    • Turn on multi-factor authentication for email. It limits the damage when a password is stolen.
    • Use email filtering and turn on the security features your email provider offers.
    • Set a payment verification rule. Any change to bank details gets a phone call to a known number.
    • Make reporting easy. One button, no blame.

    How does my online information help phishers?

    Attackers research their targets. Your social media tells them your employer, your job title, your coworkers, and where you spent the weekend. They use those details to write messages that sound real.

    • Keep your home address and phone number off public profiles
    • Limit what you share about your role and your workplace
    • Use strong, unique passwords for every account

    You would be surprised how much a criminal can learn from a public profile.

    Does multi-factor authentication stop phishing?

    It stops most of it. If you give away a password, the attacker still needs the second step. Some attacks trick people into approving a login prompt or typing a code into a fake page, so never approve a prompt you did not start. Security keys and passkeys resist phishing best, because they only work on the real website.

    Can phishing happen by phone or text?

    Yes. A text about a missed delivery or a call from “your bank’s fraud team” follows the same pattern as a phishing email. Hang up, and call the number on your card or the company’s official website.

    How do I teach my family?

    Share three rules: don’t click links in unexpected messages, never give a code or password to anyone who contacts you, and confirm any request for money with a phone call.

    What does a real example look like?

    Picture an email from “Microsoft 365 Support” that says your mailbox is full and will stop receiving mail today. A button reads “Increase storage.” The sender’s address ends in an unfamiliar domain, and the button leads to a login page that looks right and sits at the wrong web address. That one message shows urgency, a mismatched sender, and a mismatched link.

    Your next step

    Stay informed about the latest phishing methods, and teach yourself and your team how to spot them. Cerberus Cybersecurity offers training and awareness programs that use real examples and hands-on practice. Contact us to see how we can help your organization. Stay alert, stay safe, and keep your digital life secure.

  • Holiday Scams: How to Stay Cyber Safe This Christmas

    By J. Mesa

    Christmas is a time for joy and celebration. It is also the busiest season of the year for cybercriminals. More people shop online, more packages are in transit, and more of us are distracted. Scammers plan for it.

    This guide covers the scams you will see this season and how to keep your family and your business safe.

    Why do scams increase during the holidays?

    • More online shopping. More orders mean more chances to slip in a fake confirmation or a fake store.
    • More deliveries. A text about a package feels normal in December.
    • More giving. Generosity makes charity scams and gift card requests effective.
    • Less attention. People rush, travel, and check email on their phones.

    What are the most common holiday scams?

    • Fake delivery notices. A text or email says a package is delayed and asks you to click a link to reschedule or pay a small fee.
    • Fake stores and apps. Copycat websites and apps imitate real retailers to collect card numbers.
    • Phishing from “your bank” or “a retailer.” A message warns of a problem with your order or account and links to a fake login page.
    • Gift card scams. Someone posing as a boss, a relative, or a government agency asks you to buy gift cards and send the codes.
    • Charity scams. Fake charities ask for donations by phone, social media, or email.
    • Holiday e-cards. A greeting card link from a stranger installs malware.
    • Travel deals. Fake listings for flights and rentals take your payment and vanish.

    How do I spot a fake delivery text?

    • You were not expecting it, or it names no retailer
    • The link uses an odd web address
    • It asks for a fee, a card number, or personal details

    Delivery companies do not charge a redelivery fee by text. To check a package, open the retailer’s app or type the carrier’s web address yourself and enter the tracking number from your order confirmation.

    How do I protect myself from phishing?

    Scammers send emails and texts that appear to come from a retailer or a bank and ask for personal information or payment. Some carry a link or attachment that installs malware.

    • Be wary of unsolicited messages
    • Never click links or open attachments from unknown senders
    • Go to the company’s site or app directly to check your account

    How can I tell if a website or app is fake?

    • Check the web address letter by letter. Look for misspellings and extra words.
    • Look for contact details, a return policy, and a physical address.
    • Search the store’s name with the word “scam” or “reviews.”
    • Be suspicious of prices far below every other seller.
    • Download apps only from the official app store, and check the developer’s name.

    The padlock icon and “HTTPS” in the address bar mean your connection to the site is encrypted. They do not prove the site is honest. Scam sites have padlocks too.

    Should I use a VPN for holiday shopping?

    A VPN, or virtual private network, encrypts your internet connection. It helps on public Wi-Fi in airports, hotels, and cafés, where other people share the network. It does not protect you from a fake store or a phishing link. If you have no VPN, use your phone’s mobile data for purchases while you travel.

    What is the safest way to pay online?

    Credit cards and well-known payment services such as PayPal offer fraud protection and a process for disputing charges.

    • Use a credit card in place of a debit card. A fraudulent debit charge takes money straight out of your account.
    • Avoid wire transfers, cash transfer apps, cryptocurrency, and gift cards as payment to a seller you don’t know. Those payments are hard or impossible to reverse.
    • Turn on purchase alerts from your card issuer.

    A seller who insists on one of those hard-to-reverse methods is telling you it is a scam.

    How do gift card scams work?

    Someone contacts you with an urgent story. A “boss” needs gift cards for clients. A “grandchild” is in trouble. A “government office” says you owe a fine. They ask you to buy gift cards and read out the numbers.

    No legitimate business or agency takes payment in gift cards. If a coworker or relative asks, call them on a number you already have.

    How do I check a charity before I donate?

    • Look the charity up on a rating site such as Charity Navigator or the BBB Wise Giving Alliance
    • Confirm its name exactly, since scammers use names close to real ones
    • Donate through the charity’s own website, not a link in a message
    • Pay by credit card, never by gift card or wire

    How do I set up new devices safely?

    New phones, tablets, cameras, and smart speakers arrive as gifts. Before anyone uses them:

    1. Install all updates.
    2. Change any default password.
    3. Turn on a screen lock.
    4. Review privacy settings and app permissions.
    5. For children’s devices, set up parental controls.

    Why should I update my devices before the holidays?

    Attackers target flaws in older software. Updates from your operating system and app vendors fix those flaws. Turn on automatic updates on your computer and phone before the shopping season starts.

    What should I keep off social media?

    Avoid posting your home address, phone number, or travel dates. A photo of your empty living room and a caption about your trip tell a burglar what they need to know. Share the vacation photos when you get home. Use strong, unique passwords for all your accounts as well. Our post on the most hacked passwords explains how to build a good one.

    How can a business stay safe during the holidays?

    Criminals know offices run on skeleton crews in late December.

    • Remind staff about gift card and invoice scams before the break
    • Require a phone call to confirm any payment change
    • Make sure someone is monitoring alerts and knows who to call
    • Check that backups ran before everyone leaves
    • Install pending updates

    What should I do if I get scammed?

    1. Call your bank or card issuer right away and dispute the charge.
    2. Change the password on any account involved.
    3. Report it at reportfraud.ftc.gov and to the FBI at ic3.gov.
    4. If you bought gift cards, contact the card company with the receipt.
    5. Tell your family, so the same scam doesn’t reach them.

    Your next step

    Share this list with the people you will see this holiday, and help older relatives recognize the delivery and gift card scams. Knowing the threats and taking a few precautions lets you enjoy a happy and secure season. If your business wants to prepare its team, Cerberus Cybersecurity offers cybersecurity training. Contact us to learn more.

  • The 5 Most Hacked Passwords (and What to Use Instead)

    The 5 Most Hacked Passwords (and What to Use Instead)

    By J. Mesa

    Attackers don’t break into most accounts. They log in. They take a list of the passwords people use most, try each one against your email or your bank, and move on to the next person. If your password sits on that list, the attack takes seconds and needs no skill.

    This post covers the passwords attackers try first, why they work, and the stronger habit I recommend to every client: the passphrase.

    What are the most common passwords?

    NordPass publishes a yearly study built from millions of passwords exposed in data breaches. In its 2025 report, these five led the United States list:

    1. admin
    2. password
    3. 123456
    4. 12345678
    5. 123456789

    The global list looks much the same, with 123456 in first place. Older favorites such as qwerty, 111111, and abc123 still rank high every year. The names change order. The pattern holds: short, predictable, and typed by millions of people.

    Why do hackers try these passwords first?

    Attackers don’t type guesses by hand. They run software that tests thousands of passwords per second, and that software starts with wordlists built from past breaches. Three common attacks rely on those lists:

    • Dictionary attack. The tool tries every word and common password on a list against one account.
    • Password spraying. The attacker tries one common password, such as Password1, against every employee in a company. One match gives them a way in.
    • Credential stuffing. The attacker takes email and password pairs leaked from one site and tries them on other sites. This works because people reuse passwords.

    A password from the top five fails all three attacks on the first try.

    Is adding a number or symbol enough?

    No. Attackers know the tricks. Their tools swap a for @, add 1 or ! to the end, and capitalize the first letter. Password1! sits at number 16 on the 2025 list.

    A short password full of symbols, such as x7g9@k2!, is also weak. Eight characters is short enough that cracking hardware can work through every combination when a site stores passwords poorly. It is also hard for you to remember, so you write it down or reuse it.

    Length beats complexity. Each character you add multiplies the work an attacker has to do.

    How long should a password be?

    The National Institute of Standards and Technology (NIST) writes the password guidance that most US security standards follow. Its current guidance, SP 800-63B, calls for at least 15 characters on an account protected by a password alone. It also tells organizations to stop requiring mixed character types and to accept long passwords of at least 64 characters.

    Fifteen random characters are hard to remember. Fifteen characters of words are easy. That is the case for a passphrase.

    What is a passphrase, and is it safer than a password?

    A passphrase is a string of several unrelated words. It runs longer than a traditional password, so it resists guessing and brute-force attacks, and you can remember it because you know the words.

    Compare the two. The password x7g9@k2! has 8 characters. The passphrase kadu tasi ayuyu babui has 21.

    That example uses words from Chamorro, my own language. Words from a language other than English make a passphrase stronger, because many attacker wordlists focus on English and on passwords leaked from English-language sites. The phrase means something to me and reads as gibberish to a cracking tool.

    How do I create a strong passphrase?

    1. Pick four or more words that have no connection to each other.
    2. Avoid quotes, song lyrics, and famous examples. If a phrase appears in a book or a movie, it appears in a wordlist.
    3. Mix in a word from another language, a place only you know, or an invented word.
    4. Aim for 15 characters or more.
    5. Use a different passphrase for every important account.

    A personal touch helps you remember it. Keep personal facts out of it. Your pet’s name, your birth year, and your street all show up on your social media, and attackers check there first.

    Do I need to change my password every 90 days?

    No. NIST now tells organizations to stop forcing password changes on a schedule. Forced changes push people toward weak patterns, such as Summer2025 turning into Fall2025. Change a password when you have a reason: a breach notice, a phishing link you clicked, or a shared login after someone leaves the company.

    How do I know if my password was exposed?

    Search your email address at haveibeenpwned.com, a free service that tracks breached accounts. Many password managers and browsers run the same check and warn you about exposed logins. If a password shows up in a breach, change it on that site and on every site where you reused it.

    How do I remember a different passphrase for every account?

    You don’t. Use a password manager. You remember one strong passphrase, and the manager creates and stores a unique password for each account.

    Then turn on multi-factor authentication (MFA) wherever a site offers it. With MFA, a stolen password alone does not open the account.

    What should a small business do about passwords?

    • Set a minimum length of 15 characters and drop the forced 90-day change.
    • Block the common passwords listed above. Most identity systems, including Microsoft 365, can do this.
    • Give every employee a password manager.
    • Require MFA on email, banking, and remote access.
    • Train your team to spot phishing. A passphrase does not help once someone types it into a fake login page.

    What makes a password weak?

    A password is weak when an attacker can predict it. Short length, common words, keyboard patterns such as qwerty, repeated characters, and personal details all make a password easy to predict. Reuse makes a strong password weak too, because one breached site exposes every account that shares it.

    Your next step

    Check your own accounts against the list in this post today. If you run a business and want help writing a password policy or training your team, contact Cerberus Cybersecurity. We put people first, and passwords are a people problem.

    A strong passphrase is your first line of defense. Treat it that way.

  • Is Online Shopping Safe? 9 Tips for Secure Shopping

    By J. Mesa

    Shopping from home is convenient, and most of the time it is safe. The trouble comes from a small number of fake stores, stolen accounts, and scam messages. A few habits protect you from nearly all of them.

    Here are nine tips to help you shop online with confidence, in the holiday season and all year.

    Is online shopping safe?

    Yes, when you buy from retailers you can verify and pay with a method that protects you. The risk rises when you follow a link from an ad or a message, buy from a store you have never heard of, or pay in a way you can’t reverse.

    1. How do I check that a website is secure?

    Look for “HTTPS” at the start of the web address and a lock icon in the address bar. They show that the site encrypts the information you send.

    Encryption is the minimum. Scam sites use HTTPS too, so treat the lock as one check among several.

    2. How do I know an online store is legitimate?

    • Read the web address carefully for misspellings
    • Look for a physical address, a phone number, and a return policy
    • Search the store’s name with “reviews” and “scam”
    • Check how long the site has existed. A store created last month with huge discounts is a warning.
    • Be wary of sites that accept only wire transfers, payment apps, or cryptocurrency

    When in doubt, buy the item from a retailer you already know.

    3. Why should I use strong, unique passwords?

    A store account holds your address, your order history, and often a saved card. If you reuse a password and one site is breached, attackers try that password everywhere.

    Avoid passwords such as “123456” or “password.” Use a password manager to create and store a different password for each account.

    4. Should I turn on two-factor authentication for shopping accounts?

    Yes. Turn it on for your email first, since password resets go there, and then for the retailers and payment services you use most. With two-factor authentication, a stolen password alone does not open the account.

    5. How do I avoid phishing while shopping?

    Scammers send fake order confirmations, shipping notices, and “problem with your payment” alerts.

    • Don’t click links in messages about orders you don’t remember
    • Open the retailer’s app or type its address yourself to check an order
    • Never enter your password or card number on a page you reached from a link

    6. Why does the privacy policy matter?

    A privacy policy tells you what a store collects and who it shares it with. Before you buy from an unfamiliar site, skim it. Avoid stores with no policy or one that is vague about selling your data.

    7. Is a credit card safer than a debit card?

    Yes. In the United States, federal law limits your liability for fraudulent credit card charges, and most issuers set it at zero. You dispute the charge while the bank’s money is at stake.

    A debit card pulls money directly from your bank account. Your protection depends on how fast you report the fraud, and you wait for the money to come back.

    8. Should I save my card on shopping sites?

    Saving a card is convenient, and it means a breach of that store or your account exposes it. Save cards only with retailers you use often and trust. For one-time purchases, check out as a guest. Digital wallets such as Apple Pay and Google Pay add protection, because they give the store a one-time code in place of your card number.

    9. Is it safe to shop on public Wi-Fi?

    Avoid it for purchases. Public networks are shared, and an attacker can set up a fake hotspot. Use your phone’s mobile data or a VPN when you buy something away from home.

    How do I shop safely on social media and marketplaces?

    • Pay through the platform’s checkout, which carries buyer protection
    • Don’t move the conversation or the payment off the platform
    • Be wary of sellers with new accounts and stock photos
    • Meet in a public place for local pickups

    What are the signs of a scam deal?

    • A price far below every other seller
    • A countdown timer pushing you to buy now
    • A request for payment by gift card, wire, or payment app
    • A seller who avoids questions

    If a deal looks too good to be true, it is.

    How do I monitor my accounts after I shop?

    • Turn on transaction alerts from your card issuer
    • Review statements each week during heavy shopping periods
    • Check your credit reports, which are free at annualcreditreport.com
    • Keep order confirmations until the items arrive

    What should I do if I am scammed?

    1. Contact your card issuer and dispute the charge.
    2. Change the password on the affected account.
    3. Report the seller to the platform.
    4. Report the scam at reportfraud.ftc.gov and to the FBI at ic3.gov.
    5. Watch your accounts for more charges.

    Act fast. Disputes have deadlines.

    What if an order never arrives?

    Contact the seller first and keep a record of the conversation. If the seller does not respond or refuses a refund, file a dispute with your card issuer. Card networks allow a dispute for goods that were not delivered, and the issuer will ask for your order confirmation and the messages you exchanged.

    Does my business need to think about this?

    If you sell online, your customers are asking the same questions about you.

    • Use a reputable payment processor and never store card numbers yourself
    • Keep your website and plugins updated
    • Publish a clear privacy policy, return policy, and contact details
    • Follow PCI-DSS, the security standard for businesses that accept cards

    If employees buy for the company, give them a company card with alerts and a simple approval rule.

    Your next step

    Before your next purchase, turn on two-factor authentication for your email and set up transaction alerts on your card. Those two steps catch most problems early. If you run an online store and want to know how well you protect your customers, contact Cerberus Cybersecurity about a risk and compliance assessment.

  • How Much Does a Data Breach Cost a Small Business?

    By J. Mesa

    A cybersecurity breach is expensive, and the cost lasts long after the systems are back on. For a small business, one incident can decide whether the company survives the year.

    This post breaks down what a breach costs, where the money goes, and what lowers the bill.

    How much does a data breach cost a small business?

    Estimates vary with the study and the size of the company.

    • The Hiscox Cyber Readiness Report 2019 put the mean cost of a firm’s largest single cyber incident at just under $200,000, across businesses of all sizes. That figure counts recovery, lost revenue, and lost customers.
    • IBM’s yearly Cost of a Data Breach Report covers organizations of all sizes. It measured a global average of $4.24 million in 2021 and $4.35 million in 2022, and the 2024 report put it at $4.88 million.

    Your number depends on what data you hold, how long you are down, and how prepared you are. A small breach caught early may cost a few thousand dollars. A ransomware attack with no usable backup can cost far more than $200,000.

    What are the direct costs of a breach?

    • Incident response. Forensic investigators and IT specialists to find and remove the attacker
    • System recovery. Rebuilding computers, restoring data, replacing equipment
    • Legal advice. An attorney to guide notification and liability
    • Notification. Letters, a call center, and credit monitoring for the people affected
    • Regulatory fines. Penalties under rules such as HIPAA, the FTC Safeguards Rule, or state privacy laws
    • Card brand penalties. Assessments under PCI-DSS if payment card data was involved
    • Ransom. If you choose to pay, with no guarantee of results

    What are the hidden costs?

    • Downtime. Every hour your systems are down is an hour you can’t sell, bill, or serve customers.
    • Lost customers. People leave a business that loses their data, and they tell others.
    • Damaged reputation. Winning new clients gets harder.
    • Higher insurance premiums. Your cyber policy costs more after a claim.
    • Staff time. Your team spends weeks on recovery in place of their jobs.
    • Lost contracts. Larger clients may drop a vendor after an incident.

    For many small businesses, the downtime and the lost customers cost more than the technical cleanup.

    What makes a breach more expensive?

    • Sensitive data. Stolen card numbers, health records, and Social Security numbers bring notification duties and fines. A breach that touches only internal systems costs less.
    • Slow detection. The longer an attacker stays inside, the more they take.
    • No backups. Without a clean backup you rebuild from nothing or face the ransom.
    • No plan. Decisions made in a panic cost time and money.
    • Compliance gaps. Regulators penalize a business that skipped required safeguards.

    What makes a breach less expensive?

    Studies of breach costs point to the same factors each year.

    • An incident response plan that the team has practiced
    • Employee training, which reduces successful phishing
    • Multi-factor authentication and limited access
    • Encryption of sensitive data
    • Tested backups, kept offline or offsite
    • Fast detection through monitoring and alerts

    Each one shortens the incident or shrinks the amount of data exposed.

    Can a small business survive a breach?

    Many do. The ones that recover have backups, a plan, insurance, and cash reserves to cover the gap. You may have heard a claim that 60 percent of small businesses close within six months of an attack. That number circulates widely, and nobody has produced a study that supports it. The honest answer is that survival depends on preparation.

    Does cyber insurance cover the cost?

    A cyber insurance policy can pay for investigation, legal help, notification, business interruption, and sometimes extortion payments. Before you rely on one, know three things:

    • Insurers require controls such as multi-factor authentication and backups, and they can deny a claim if your application was inaccurate.
    • Policies have limits, deductibles, and exclusions. Read them.
    • Insurance pays bills. It does not restore lost customers.

    How do I estimate my own risk?

    1. List the data you hold and how many people it covers.
    2. Estimate what one day of downtime costs in lost sales and wages.
    3. Ask how long a full restore from backup would take.
    4. Check which laws and contracts apply to your data.
    5. Add the cost of outside help: IT, legal, and notification.

    That rough total shows how much prevention is worth to you.

    How much should a small business spend on cybersecurity?

    No single figure fits every company. Match your spending to your risk. Start with the low-cost basics that prevent the most common attacks, then add assessment and monitoring as your data and your contracts demand.

    Compare the cost of each measure with your estimate above. A password manager and multi-factor authentication cost a few dollars per user per month. A day of downtime costs far more.

    What steps prevent or reduce the cost of a breach?

    1. Use strong, unique passwords with a password manager.
    2. Turn on multi-factor authentication for email, banking, and remote access.
    3. Update software and security systems on a schedule.
    4. Train employees on cybersecurity best practices, and repeat the training.
    5. Back up your data and test the restore.
    6. Encrypt laptops and phones.
    7. Write an incident response plan and keep a printed copy.
    8. Limit the data you keep.
    9. Review your vendors’ security.

    What should I do in the first 24 hours of a breach?

    1. Disconnect affected systems from the network.
    2. Call your IT provider or incident response firm.
    3. Notify your cyber insurer. Many policies require prompt notice.
    4. Call your attorney.
    5. Preserve evidence. Don’t wipe systems before they are examined.
    6. Change passwords from a clean device.
    7. Document every action and the time you took it.

    Fast, orderly action in the first day lowers the final cost more than anything you do afterward.

    Your next step

    The cost of a breach is significant, and most of it is avoidable. Investing in strong cybersecurity measures protects your business from financial and reputational damage. Cerberus Cybersecurity helps small businesses find their gaps with risk and compliance assessments, write practical policies, and train their teams. Contact us to find out where you stand.

  • Black Friday and Cyber Monday Scams: How to Shop Safely

    By J. Mesa

    It’s that time again! Black Friday and Cyber Monday bring some of the best prices of the year. They also bring scammers, who know that shoppers in a hurry check fewer details.

    Here is how to get the deals and keep your money.

    Why do scammers love Black Friday?

    • Shoppers expect big discounts. A fake 80 percent discount looks plausible for one week of the year.
    • Deals have deadlines. Real time limits make fake urgency harder to spot.
    • Inboxes overflow. A scam email hides among hundreds of real promotions.
    • People try new stores. A shopper chasing a deal will buy from a site they have never used.

    What are the most common Black Friday scams?

    • Fake online stores that take payment and send nothing, or send a counterfeit
    • Phishing emails and texts that imitate real retailers
    • Fake order and delivery notices that link to malicious sites
    • Social media ads for products that don’t exist
    • Bogus coupon and gift card offers that collect personal details
    • Counterfeit apps that imitate a retailer’s shopping app

    How do I know a website is secure?

    Before you enter a card number, check that the address starts with “HTTPS” and shows a lock icon. That means the site encrypts what you send.

    The lock does not prove the store is real. Fake stores use encryption too. Use the next section to check the seller.

    How do I spot a fake store?

    • Check the address. Look for misspellings, extra words, or an unusual ending.
    • Look for contact details and a return policy.
    • Search for reviews on independent sites, not only on the store itself.
    • Compare prices. A price far below every competitor is a warning.
    • Check the payment options. A store that takes only wire transfers, payment apps, or cryptocurrency is unsafe.
    • Look at the writing and images. Copied photos and awkward text suggest a quick copy of another site.

    How do I tell a real deal from a fake one?

    If a deal seems too good to be true, it is. Be careful with offers that:

    • Last only minutes and show a countdown timer
    • Ask for personal or financial details before you can “claim” them
    • Arrive by text or direct message from an unknown sender
    • Come through an ad for a store you can’t find elsewhere

    Go to the retailer’s own website by typing its address. If the deal is real, you will find it there.

    How do I protect my accounts?

    Create a strong, unique password for each online account and use a password manager to keep track. Turn on two-factor authentication for your email and your main shopping accounts. Those steps keep a breach at one store from spreading to the rest.

    Should I click links in sale emails and texts?

    Be careful. Scammers copy the design of real promotions. Even when a message comes from a company you shop with, confirm it before you click.

    • Check the sender’s full address
    • Hover over a link to see where it leads
    • Type the store’s address yourself when you are unsure

    What is the safest way to pay?

    • Use a credit card. It gives you the strongest fraud protection and a dispute process.
    • Use a digital wallet such as Apple Pay or Google Pay where a store offers it. The store never receives your card number.
    • Avoid debit cards for online purchases. Fraud takes money straight from your account.
    • Never pay a seller by wire transfer, gift card, or cryptocurrency.

    What should I avoid posting on social media?

    Be careful about what you share during the season.

    • Don’t announce that you are out of town
    • Don’t post photos of expensive new purchases
    • Don’t share order confirmations or tracking numbers

    That information tells burglars and package thieves when and where to look.

    How do I keep my packages safe?

    • Track deliveries and bring packages in the same day
    • Use a pickup locker or ship to your workplace if nobody is home
    • Require a signature for expensive items
    • Ask a neighbor to collect packages when you travel

    How do I shop safely on my phone?

    • Download shopping apps only from the official app store
    • Check the developer’s name and the number of reviews
    • Keep your phone’s software up to date
    • Avoid making purchases on public Wi-Fi. Use mobile data.

    How do I prepare before Black Friday?

    1. Update your computer, phone, and browser.
    2. Turn on two-factor authentication for your email.
    3. Set up transaction alerts with your card issuer.
    4. Make a list of what you want and where you will buy it.
    5. Bookmark those stores, so you don’t need to follow links.

    A plan keeps you from making rushed decisions when the sales start.

    What should I do if I fall for a scam?

    1. Call your card issuer and dispute the charge.
    2. Change the password on any account you used.
    3. Report the scam at reportfraud.ftc.gov and to the FBI at ic3.gov.
    4. Report the fake store or ad to the platform where you found it.
    5. Watch your statements for further charges.

    How should a small business prepare?

    If you sell during the holiday rush, criminals target you too.

    • Update your website, shopping cart, and plugins before the season
    • Watch for unusual orders, such as many small test charges
    • Warn staff about fake supplier invoices and gift card requests
    • Tell customers how you will contact them, so they can spot impostors

    Are buy now, pay later plans safe?

    They are legitimate services, and they carry weaker dispute rights than a credit card in some cases. Read the terms before you use one, and sign up through the retailer’s checkout or the provider’s own app. Scammers send fake “payment overdue” messages in the names of these services, so check your balance in the app, not through a link.

    Your next step

    Bookmark your favorite stores and set up card alerts before the sales begin. With those two steps and the checks above, you protect yourself and your loved ones from scammers this season. Happy shopping! If your business wants its team ready for the holiday rush, contact Cerberus Cybersecurity about our cybersecurity training.

  • How to Secure Your Small Business Online: 10 Expert Tips

    By J. Mesa

    Your online presence is your storefront. Your website, email, domain name, social media, and business listings are how customers find and trust you. An attacker who takes over any one of them can steal from you, pose as you, or shut you down.

    Cyberattacks can bring financial loss, damage to your reputation, and legal penalties. These ten tips protect the accounts and systems your business shows to the world.

    What is an online presence, and why protect it?

    Your online presence includes every account and service that represents your business:

    • Your domain name and website
    • Business email
    • Social media profiles
    • Business listings, such as your Google Business Profile
    • Online banking and payment accounts
    • Cloud storage and business applications

    Each one is a way in. Losing your domain or email account can take the others with it, because password resets flow through them.

    1. How do I create strong passwords for business accounts?

    Weak or easy-to-guess passwords are among the most common ways criminals get into accounts.

    • Use a long, unique password for every account
    • Never reuse a password
    • Use a password manager to create and store them
    • Give each employee their own login. Don’t share accounts.

    2. What is two-factor authentication, and should I use it?

    Two-factor authentication (2FA) adds a second proof of identity at login, such as a code from an app on your phone. With it on, a stolen password is not enough.

    Turn it on for every account that offers it. Start with email, your domain registrar, banking, and social media. An authenticator app or a security key is stronger than a text-message code.

    3. Why do updates matter?

    Criminals exploit flaws in outdated software and devices. Updates fix those flaws.

    • Turn on automatic updates for computers and phones
    • Update your website platform, themes, and plugins
    • Update routers, firewalls, and other network devices
    • Replace equipment that no longer receives security updates

    4. How do I handle emails and attachments safely?

    Phishing emails imitate people and companies you trust.

    • Check the sender’s full email address
    • Don’t click links or download attachments from unknown or unexpected senders
    • Confirm any request for money or a change in payment details by phone
    • Report suspicious messages to your IT contact

    5. How do I know a connection is secure?

    When you open financial accounts or enter personal information, check that the web address begins with “HTTPS” and shows a padlock icon. That means the site encrypts the data you send and receive.

    Your own website needs HTTPS as well. Browsers warn visitors away from sites without it, and search engines favor sites that have it.

    6. How do I monitor my accounts?

    • Review bank and card statements for transactions you don’t recognize
    • Check your business credit reports
    • Turn on login and transaction alerts
    • Look at the login history on your email and social accounts

    If you see something suspicious, contact your bank or card company right away and change the affected passwords.

    7. How do I protect my website?

    • Keep the platform and plugins updated, and remove the ones you don’t use
    • Use strong passwords and 2FA for every administrator
    • Limit the number of administrator accounts
    • Back up the site and store the backup somewhere else
    • Use a web application firewall, which many hosting and DNS providers include

    8. How do I protect my domain name?

    Your domain is the root of your online identity. If someone takes it, they control your website and your email.

    • Turn on 2FA at your domain registrar
    • Turn on the registrar lock, which blocks unauthorized transfers
    • Keep the contact email on the account current
    • Set the domain to renew automatically, so it never lapses

    9. How do I stop criminals from spoofing my email?

    Attackers send email that appears to come from your domain to trick your customers and staff. Three DNS records help prevent it:

    • SPF lists the servers allowed to send mail for your domain
    • DKIM adds a signature that proves a message was not altered
    • DMARC tells receiving mail servers what to do with messages that fail those checks

    Your email provider or IT contact can set these up. A DMARC policy of “quarantine” or “reject” gives the strongest protection.

    10. How do I secure my social media and business listings?

    • Use a unique password and 2FA on every profile
    • Assign roles to staff through the platform’s business tools. Don’t share one login.
    • Remove access when an employee or agency leaves
    • Claim your business listings, so nobody else does
    • Watch for fake profiles that copy your name and logo, and report them

    What should I do if an account is hacked?

    1. Change the password from a clean device.
    2. Sign out of all other sessions.
    3. Turn on 2FA.
    4. Check for changes: forwarding rules, new administrators, new payment details.
    5. Tell customers and partners if the attacker sent messages as you.
    6. Use the platform’s recovery process if you are locked out.
    7. Report fraud to your bank and at ic3.gov.

    How often should I review my online security?

    Review it every quarter. Check who has access, confirm that updates and backups ran, and test that you can recover an account. Review again whenever an employee or vendor leaves.

    Are these steps enough?

    No security measure is foolproof. These practices cut your risk sharply and help keep your business and your customers’ information safe. Businesses that hold regulated data or serve larger clients should add written policies, employee training, and a regular risk assessment.

    What is the most common way a small business loses an account?

    A reused password and no second step at login. An employee uses the same password for a business account and a personal one. The personal site is breached, criminals try the leaked password on the business account, and it works. A password manager and two-factor authentication close that route, which is why they come first on this list.

    Your next step

    Turn on two-factor authentication for your email and your domain registrar today. Those two accounts protect all the others. To see how we can help with your cybersecurity goals, contact us or write to [email protected]. At Cerberus Cybersecurity, we believe in people first.

  • 5 Cybersecurity Mistakes Small Businesses Make (and How to Fix Them)

    By J. Mesa

    Small businesses are frequent targets for cyberattacks, and many fall victim to data breaches and other threats. In my work, the cause is seldom a clever attacker. It is one of five common mistakes.

    This post covers each mistake, why it matters, and how to fix it.

    Why are small businesses targeted?

    • They hold data worth stealing: customer records, payment details, and bank access.
    • They have fewer defenses than large companies.
    • Automated attacks scan the whole internet and don’t care about company size.
    • They connect to larger clients, which makes them a way in.

    An attacker does not need to pick you. Your business only needs an open door.

    Mistake 1: Failing to update software and security systems

    Criminals look for flaws in outdated software. If your systems are behind, you are open to attacks that a free update would have blocked.

    How to fix it:

    • Turn on automatic updates on every computer and phone
    • Check for updates to servers, firewalls, routers, and business applications each month
    • Plan a time to install updates that need a restart
    • Replace software and devices the vendor no longer supports

    Mistake 2: Using weak passwords

    Weak passwords are easy to guess, and an attacker with access to one account can do a great deal of damage. Reused passwords are just as risky, because a breach at one site exposes every account that shares the password.

    How to fix it:

    • Use a long, unique password for every account and system
    • Give staff a password manager
    • Turn on multi-factor authentication for email, banking, and remote access
    • Change a password when there is a sign it was exposed. Current guidance from NIST no longer recommends forced changes on a fixed schedule.

    Mistake 3: Neglecting employee training

    Many small businesses give their staff no cybersecurity training. That leaves employees open to phishing and other scams, and most attacks start with a person.

    How to fix it:

    • Train every employee when they join and at least once a year after that
    • Add short refreshers through the year
    • Use real examples of phishing emails
    • Write clear policies for handling suspicious messages and sensitive data
    • Reward reporting. Never punish someone for admitting they clicked.

    Mistake 4: Not backing up data

    Without a recent backup, a ransomware attack or a failed drive can end the business. With one, you recover in hours or days.

    How to fix it:

    • Back up on a schedule, daily for important data
    • Keep a copy somewhere separate from your business systems, so an attacker who gets in can’t reach it
    • Follow the 3-2-1 rule: three copies, two types of storage, one offsite or offline
    • Test a restore every few months

    Mistake 5: Not having a cybersecurity plan

    Many small businesses have no plan. When something goes wrong, they improvise, and that costs time and money.

    How to fix it: Write a short plan that covers:

    • Who is responsible for security
    • How you handle updates and backups
    • How and when you train employees
    • What to do and who to call when an incident happens
    • How you will notify customers if their data is exposed

    One or two pages is enough to start. Review it once a year.

    What other mistakes should I watch for?

    • No multi-factor authentication. It blocks most attacks that use stolen passwords.
    • Too much access. Every employee can see every file, and former staff still have accounts.
    • Believing “we’re too small.” That belief is the reason the other mistakes go unfixed.
    • Leaving it all to the IT provider. Many IT contracts cover support and exclude security. Ask what yours includes.
    • No inventory. You can’t protect devices and accounts you don’t know about.

    How do I know if my business is at risk?

    Answer these questions:

    1. Do all our computers and phones update automatically?
    2. Does every account have a unique password and multi-factor authentication?
    3. Did every employee receive training in the past year?
    4. Did we restore a file from backup in the past three months?
    5. Do we have a written plan with phone numbers on it?

    Each “no” is a gap an attacker can use.

    How much does it cost to fix these mistakes?

    Less than most owners expect. Automatic updates and multi-factor authentication are free with the tools you already own. A password manager and cloud backup cost a few dollars per user each month. Training and a written plan cost time. Compare that with the cost of a week of downtime.

    Where should I start?

    Follow this order. Each step builds on the one before.

    1. Turn on multi-factor authentication for email.
    2. Turn on automatic updates.
    3. Set up backups and test a restore.
    4. Roll out a password manager.
    5. Schedule a training session.
    6. Write your plan.

    Most small businesses can finish the first three in a week.

    Who should be responsible for cybersecurity?

    Name one person. In a small company it is often the owner or the office manager. That person does not need to be technical. They need to make sure the tasks on this list happen and to know who to call for help.

    Do I need outside help?

    You can handle the basics yourself. Consider outside help when you store regulated data such as health or payment information, when a client or insurer asks for proof of your security, or after an incident. An assessment from a security professional shows you the gaps you can’t see from inside.

    How do I keep these fixes from slipping?

    Put them on the calendar. Schedule a monthly 15-minute check that updates and backups ran, a quarterly review of who has access, and a yearly review of the plan and the training. Security fails when it depends on someone remembering.

    Does antivirus fix these mistakes?

    No. Antivirus is useful, and it addresses none of the five. It can’t create a backup, train an employee, or write a plan. Keep it running, and treat it as one layer.

    Your next step

    Small businesses face growing risk, and these five mistakes account for most of it. Update your systems, use strong passwords, train your people, back up your data, and write a plan. Cerberus Cybersecurity can help with training, policy development, and assessments. Contact us to get started.