Cybersecurity Awareness Month 2026: Four major online threats and how to handle them

Scammers are not slowing down, but rather leveling up. As October is Cybersecurity Awareness Month, it’s a good time to focus on protecting your digital life. Artificial intelligence is making it easier for cybercriminals to scam you, but the Gen Fearless Planet Index (FPI), a Cyber Safety intelligence hub, can provide you with real-time insights into the global cyberthreat landscape.

Person focused on laptop work in warm-lit nighttime environment, representing cybersecurity awareness and digital protection in the online world.

The Fearless Planet Index is a Cyber Safety intelligence platform by Gen (the company behind Norton) that provides a real-time view of global cyberthreats, scams, and identity risks using threat intelligence collected by Gen Threat Labs. Think of the FPI as a weather map for digital risk: it shows which scams, malware threats, indicators of suspicious behavior, and other cyber risks are most active around the world. Insights are based on data from Avast, Norton, and LifeLock products, including threats blocked and alerts sent during the last 30 days.

As of late September 2026, the most common threats and risks to which our products alerted U.S. customers included phishing, suspicious bank account activity, fake shopping sites, and data breach exposure. Read on for a description of four major cyberthreats facing the U.S. this Cybersecurity Awareness Month, and learn what you can do to shore up your digital defenses.

Screenshot of the Fearless Planet Index
Screenshot of the Fearless Planet Index
Screenshot of the Fearless Planet Index

1. Phishing vs. pausing before you click

Phishing remains one of the most common ways cybercriminals attempt to trick you into revealing sensitive information. These deceptive messages can be sent via email, text message, social media, messaging apps like WhatsApp, or even QR codes. They are designed to fool you into clicking a malicious link, downloading an infected file, or revealing private information, like your login credentials. AI has the potential to make phishing messages more convincing and personalized than ever.

According to the FPI, phishing was the most common cyberthreat blocked by our products in the U.S. in the 30 days before this article was written. In that period, we blocked 17.6 million phishing attacks.

Phishing red flags

It’s easy to be distracted and tap on confirmation links without a second look, but a short pause before you click can save you a lot of financial headaches. The best defense is to be cautious, especially with unexpected or urgent messages. Red flags include:

  • Artificial urgency: “Act now” or “Your account will be closed” language is designed to pressure you into immediate action.
  • Unusual requests: Legitimate companies rarely ask you to confirm passwords, PINs, or payment information via email or text.
  • Suspicious sender addresses: Look carefully at the email address or phone number via which the message arrives. Subtle misspellings of a legit company name, strange email domains, and unexpected country codes are big red flags.
  • Generic greetings: “Dear customer” rather than your name can be a sign of a mass phishing campaign.
  • Grammar and spelling errors: Some phishing messages contain obvious mistakes. In fact, while AI can help phishers make their emails sound professional, some scammers leave spelling errors intentionally to filter out attentive victims.
  • Too-good-to-be-true offers: Unexpected prizes, refunds, or offers should be treated with extreme suspicion.

When in doubt, don’t click. Instead, contact the company directly using a phone number or website you know is legitimate, or mark the message as spam and delete it.

2. Suspicious bank account activity vs. turning on transaction alerts and MFA

Alerts about suspicious bank account activity don’t always mean your credit card details were stolen (maybe you bought 17 iPhones from Amazon on purpose), but they certainly warrant some extra investigation. After all, unauthorized financial transactions are a major sign that someone has stolen your identity. Identity theft can affect your credit, sap your bank account, and, in extreme cases, take years to unravel.

Gen products, including Norton 360 with LifeLock, can help draw your attention to suspicious financial transactions. The FPI reports that Gen products issued 2.1 million such notifications in the U.S. in the last 30 days alone.

Setting up suspicious transaction alerts and protecting your accounts with multifactor authentication (MFA) can help you protect your finances from identity thieves.

Set up suspicious transaction alerts

Regularly reviewing your bank statements is important, but transaction alerts can help notify you sooner when someone makes an unauthorized purchase or transfer. That way, without waiting for your next statement, you can quickly contact your bank, dispute charges, freeze your card, or change your account credentials to help limit potential damage.

Protect your accounts with MFA

The next step in protecting your sensitive accounts is to turn on MFA. This helps ensure that you are the only one with access to your online accounts — which is particularly crucial if these accounts have saved payment details.

MFA adds an extra layer of security to your online accounts. With it enabled, even if a cybercriminal steals your password, they’ll still need to complete an additional verification step to gain access. This can significantly reduce your risk of account compromise.

MFA works by requiring two or more verification factors:

  • Something you know: Your password.
  • Something you have: A one-time code from your phone, email, or an authenticator app.
  • Something you are: Biometric verification like your fingerprint or facial recognition.

Enabling MFA is particularly important for email, banking, social media, and any accounts linked to your financial information. While it takes a few extra seconds to log in, the protection it provides is invaluable.

Illustration of four major cyberthreats in the U.S., according to data from the Fearless Planet Index: Phishing, data breaches, unauthorized transactions, and fake shopping sites.
Illustration of four major cyberthreats in the U.S., according to data from the Fearless Planet Index: Phishing, data breaches, unauthorized transactions, and fake shopping sites.
Illustration of four major cyberthreats in the U.S., according to data from the Fearless Planet Index: Phishing, data breaches, unauthorized transactions, and fake shopping sites.

3. Fake shopping sites vs. real-time scam protection

That deal you saw in a social media ad could point to a scam e-store. Fake shopping sites can look like real online stores, often offering suspiciously low prices. But, many are AI-built fake websites designed to steal your money. Such scams, which our Threat Researchers have dubbed VibeScams, can make it look as if you’re buying a genuine product, when really, the site exists only to collect your payment information. You might receive a cheap, low-quality item — or nothing at all.

In the U.S., Gen products blocked 7.3 million attempts to visit fake shopping sites in the 30 days before this article was written.

Defend against fake websites with real-time scam protection

To help stay alert to scam websites, arm yourself with AI-Powered Scam Protection tools, like Norton 360. In addition to alerting you to scam text messages and deepfake videos, Norton 360 can help identify and block fake websites before you share personal information or payment details. It also gives you access to Norton Genie, an AI assistant you can consult about potential scams.

To further help reduce your risk when shopping online, pay with a credit card or another payment method that offers buyer protection.

If you think you’ve already purchased something on a fake shopping site, make sure you contact your bank or card provider right away to dispute the charge and ask whether they can block further payments. Save the order confirmation, product page, payment receipt, emails, and screenshots in case you need them for a claim or report, and then watch your bank statements for any other suspicious charges.

4. Data breach exposure vs. having a password manager

If you are notified that your personal information was exposed in a data breach, your identity could be at risk. Breached personal information like your name and address can expose you to targeted scams. Leaked login credentials can put you at risk of account takeover attacks.

Certain Gen products, including Norton 360 with LifeLock, help monitor the dark web, scanning illicit marketplaces where stolen personal information is traded and sold. They then notify customers if their personal information is found. We sent 1.8 million data breach notifications to potentially exposed customers in the last 30 days.

Password organization tips to help protect you from data breaches

Soon after a data breach notification, there are steps you can take to mitigate the potential fallout, depending on the severity of the breach and the specific data exposed. These could include securing your online accounts, freezing your credit, and setting up fraud alerts.One of the easiest things you can do is to start using a password manager.

A password manager is a secure way to maintain truly unique, strong passwords across all your accounts and apps. These tools store your passwords in an encrypted vault, generate strong passwords on demand, and automatically fill them in when you log in. That means you don’t have to remember unique passwords for dozens (or hundreds) of different websites by heart.

That way, if a data breach exposes your login credentials, those credentials can’t be used to access your other accounts. When selecting a password manager, look for one that:

  • Uses strong encryption to protect your password vault.
  • Generates strong passwords using a cryptographically secure method.
  • Works across all your devices and browsers for convenience.
  • Allows you to store secure notes and other sensitive information alongside passwords.

Other scams to remain vigilant about

The four threats above are among the most common risks highlighted by the FPI, but they’re not the only scams you may encounter. Cybercriminals are constantly adapting their tactics, using AI, impersonation, urgency, and emotional manipulation to target victims. Here are a few other scams to watch for, and what to do if you encounter one:

  • AI-powered imposter scams: Fraudsters pose as family members, government agencies, or known contacts, and use voice cloning technology, which now makes phone-based imposter scams quite difficult to detect by ear alone. If an unexpected call or voicemail requests money or personal information, hang up and call the person or business back on a verified number.
  • Reservation Hijacking: Scammers who gain access to accommodation booking systems (via Reservation Hijacking scams) can use your real hotel name, real dates, and real confirmation number to trick you into entering sensitive information into fake websites or payment portals. Always access booking platforms directly through official apps or URLs you’ve typed yourself, never through links in emails or texts.
  • Deepfake romance fraud: Thanks to AI, romance scams have become dramatically more convincing in 2026. These can include video chats that appear completely real. It’s best to be cautious, especially when personal information or money is involved. Cyber Safety tools with scam protection capabilities can help alert you to deepfakes, scam messages, and dangerous websites.
  • Financial or crypto scams: Whether it’s falsely claiming you owe money or convincing you to invest in fake cryptocurrency schemes, these attacks can cost you a pretty penny. Watch out for messages promising high financial rewards with little or no risk, and avoid sending money or sharing personal information until you’ve independently verified the offer.
  • Package delivery scams: The “failed delivery” text might not be real, so make sure to log directly into your carrier’s app to check actual delivery status. One way to spot these scams is to double-check for misspellings, extra words, or strange domain structures in the URLs.

Staying protected by taking control of your digital security

Cyberthreats will continue to evolve, and scammers are getting smarter, so your protection should too. This Cybersecurity Awareness Month, take the time to secure your digital life with the right tools. Your future self will thank you.

  • Implement strong password practices, enable MFA, be vigilant about suspicious messages, and keep your devices updated to help reduce your risk of falling victim to scams and cybercrimes.
  • Utilize powerful tools that help detect and block email or SMS scams before they reach you. The advanced security of Norton 360 Deluxe can help you avoid online scammers, as it uses AI technology to spot threats you might miss, giving you more peace of mind while you browse, shop, or bank online.
  • Familiarize yourself with Norton 360 Deluxe features, which include a VPN, Dark Web Monitoring, a Password Manager, and real-time threat protection to help keep your personal info safe, so you can focus on living your digital life worry-free.

iPhone is a trademark of Apple Inc., registered in the U.S. and other countries

Caitlyn Moorhead
Caitlyn Moorhead is a Staff Financial and Cybersecurity Writer for Norton with pieces focused on fraud prevention and how to avoid scams.

Editors’  note: Our articles offer educational information and are written to raise awareness about important topics in Cyber Safety. Norton products and services may not protect against every type of threat, fraud, or crime we write about. For more details about how we research, write, and review our articles, see our Editorial Policy.


Want more?

Follow us for all the latest news, tips, and updates.