October marks Cybersecurity Awareness Month, and NCRA is proud to be champion of the National Cybersecurity Alliance, which provides guidance and educational resources designed to help everyone understand how they can protect themselves in our ever-changing digital world.
This year we focus on what you can do to make life difficult for cybercriminals –and you don’t have to be tech-savvy to do so. With just a few simple steps, you can make it harder for cybercriminals to violate your privacy and safety.
A quick look at the numbers reveals why protecting yourself from cybercrime is more important than ever. According to the 2025 Oh Behave! Annual Cybersecurity Attitudes and Behaviors Report:
- 44 percent of respondents reported experiencing cybercrime that led to data or monetary loss, a nine percent increase from 2024.
- Yet only 62 percent of respondents also reported regularly creating unique passwords, a decline from 2024.
- 41 percent reported never using a password manager.
We can certainly do better. Below are a few stories of real scammers, courtesy of the National Cybersecurity Alliance, followed by tips you can use to arm yourself. While some of these criminals have been arrested, you can be sure that more will step in to fill their shoes. Join us helping to make their lives difficult.
Meet dpxaker: Long, unique passwords are too much work for him!
Dariy Pankov, known among hackers as “dpxaker,” paid for his lavish lifestyle by selling password-cracking software to criminals for just $250 – no subscription required. Powered by his program, hackers don’t have to sit in a dark room guessing passwords one at a time – dpxaker’s software and AI tests thousands of password combinations every second. These hackers love pet names and birthdays – they really love short passwords and reused passwords!
Don’t make life easy for Dpxaker
- Every password needs to be unique to the account
- Every password should be a random mix of letters, numbers, and symbols
- Use a password manager to create and store awesome passwords – they are safe, easy to use, and many are even free!
An eight-character password can be cracked in seconds, no matter how many &s and !s you use. A complex 16-character password takes billions of years to crack – and hackers don’t have that kind of time!
Meet Zestix: MFA is such a pain
Zestix invaded more than 50 multinational companies because a few people never turned on multifactor authentication. And if some of the biggest companies in the world can go down, it would be very easy for Zestix to hijack any of our accounts if we protect it with only a password.
After swooping up stolen passwords on the Dark Web, criminals can break into many accounts that don’t enable MFA. They can also get their hands on passwords lost in data breaches and spray them all over the internet with automated software. Unfortunately, it’s easy to nab a password these days … and criminals love it when it’s all they need.
Don’t make life easy for Zestix
- Enable multifactor authentication (MFA) on every account that offers it
- Use an authenticator app (Duo, Google Authenticator, and Microsoft Authenticator, for example) or biometrics (like FaceID) whenever possible
- Don’t reuse passwords or iterations (like adding $ to another password)
Turn on MFA for every account!
Meet Cozy Bear: Roar back with software updates
Cozy Bear, a cybercriminal organization backed by Russia, stays in business by constantly hunting for outdated and unpatched software. Sometimes, the hunt is simple – the moment a company releases a software update, they study it to see what vulnerabilities it fixes. Then they peek around the web for companies and people who haven’t installed it yet. In a way, they get a how-to guide for infecting your machine. Every day you click “Remind Me Later” for an update is another day Cozy Bear hopes you’re vulnerable … and they want to make your life a lot less cozy.
Don’t make life easy for Cozy Bear
- Turn on automatic updates whenever possible
- Check regularly that operating systems, browsers, apps, and devices are updated
- Restart devices when updates require it
Updates don’t just add features. They are full of Bear repellent. Most operating system updates take five minutes or less, even including restarting your device. Just do it when prompted, enjoy the little break, and don’t make it easy for them!
Make life hard for them
You don’t need to know how all the scams work. You don’t need expensive tools. You don’t need to be an expert. Here’s what you should do to Stay Safe Online:
- Every password should be 16 characters long, unique to the account, and a random mix of letters, numbers, and symbols
- Use a password manager to create and store your passwords
- Enable multifactor authentication for every account
- Keep your software updated
- Scrutinize every unexpected inbound message, especially if it seems urgent or requests payment
Take time this Cybersecurity Awareness Month to stay curious, ask questions, and keep learning. Together, we can make technology work for us, not against us.













Comments are closed.