Skip to main content

National Cybersecurity Awareness Month

Image
Cybersecurity Awareness Month October 2026

We are Cybersecurity Champions!

The University of Arizona is celebrating the 22nd anniversary of National Cybersecurity Awareness Month (CAM). 

This year's theme is Don't Make it Easy for Them. We introduce four real-life cybercriminals (individuals or groups). While some of them have been arrested, more are following in their footsteps. 

Our goal? To do everything we can to make their business model unsuccessful. 

You don't have to be tech savvy to adopt the behaviors that make the scammers' jobs tough. Cybersecurity doesn’t have to be overwhelming. The habits that protect you most are simple, free, and faster than you’d expect.


 

DON'T MAKE IT EASY FOR THEM

MEET DPXAKER: LONG, UNIQUE PASSWORDS ARE TOO MUCH WORK

Dariy Pankov, known among hackers as “dpxaker,” paid for his lavish lifestyle by selling password-cracking software to criminals for just $250 – no subscription required. Powered by his program, hackers don’t have to sit in a dark room guessing passwords one at a time – dpxaker’s software and AI tests thousands of password combinations every second. These hackers love pet names and birthdays – they really love short passwords and reused passwords!

IN THE NEWS
DON’T MAKE LIFE EASY FOR DPXAKER
  • Every password should be at least 16 characters long
  • Every password needs to be unique to the account
  • Every password should be a random mix of letters, numbers, and symbols
RESOURCES

MEET ZESTIX: MFA IS SUCH A PAIN

Zestix invaded more than 50 multinational companies because a few people never turned on multifactor authentication. And if some of the biggest companies in the world can go down, it would be very easy for Zestix for zestily hijack any of our accounts if we only protect it with a password. After swooping up stolen passwords on the Dark Web, criminals can break into many accounts that don’t enable MFA. They can also get their hands on passwords lost in data breaches and spray them all over the internet with automated software. Unfortunately, it’s easy to nab a password these days... and criminals love it when it’s all they need.

IN THE NEWS
DON’T MAKE LIFE EASY FOR ZESTIX

  • Enable multifactor authentication (MFA) on every account that offers it
  • Use an authenticator app (Duo, Google Authenticator, and Microsoft Authenticator, for example) or biometrics (like FaceID) whenever possible
  • Don’t reuse passwords or iterations (like adding $ to another password)

Turn on MFA for every account!

RESOURCES

MEET COZY BEAR: UPDATED SOFTWARE FOILS HIS PLANS

Cozy Bear, a cybercriminal organization backed by Russia, stays in business by constantly hunting for outdated and unpatched software. Sometimes, the hunt is simple – the moment a company releases a software update, they study it to see what vulnerabilities it fixes. Then they peek around the web for companies and people who haven’t installed it yet. In a way, they get a how-to guide for infecting your machine. Every day you click “Remind Me Later” for an update is another day Cozy Bear hopes you’re vulnerable... and they want to make your life a lot less cozy.

IN THE NEWS
DON’T MAKE LIFE EASY FOR COZY BEAR
  • Turn on automatic updates whenever possible
  • Check regularly that operating systems, browsers, apps, and devices are updated
  • Restart devices when updates require it

Updates don’t just add features. They are full of Bear repellent. Most operating system updates take 5 minutes or less, even including restarting your device. Just do it when prompted, enjoy the little break, and don’t make it easy for them!

RESOURCES

MEET GIANT COMPANY: RESIST THE BAIT AND REPORT THE SCAM

Giant Company was one of many large-scale scam operations targeting Americans. While authorities arrested nearly 300 suspects and shut down nine scam centers, countless scams remain.

Scammers pose as trusted people and organizations to trick victims into clicking, responding, and sending money. AI is making these scams faster, more convincing, and more widespread. Their strategy is to create urgency, spark emotion, and rush you into action.

IN THE NEWS
DON’T MAKE LIFE EASY FOR GIANT COMPANY
  • Be extremely suspicious of every unexpected inbound message, especially if it seems urgent
  • Take a few seconds (4-9 seconds) when reviewing all communication
  • Look out for urgency, like fear (“you just got hacked!”) and pressure (“you won an expensive grill!”)

You don’t need to click. You don’t need to respond. You don’t need to answer the phone. You aren’t being rude. Their biggest enemy isn’t technology. It’s your skepticism.

RESOURCES

Online Security Tips

  • Remember to protect University information, as outlined in the University Information Resource Classification Standard and supporting documentation. 
  • When you are not on campus surrounded by coworkers who have taken security training, it is more important than ever to protect Internal and Restricted information.  

  • Practice good physical security around your device by locking it each time you leave your workspace. Developing the habit will serve you well, whether you are at home, traveling, or working in your office. 
  • Never leave mobile devices unattended in a public place.

  • Use up-to-date antivirus protection. Sophos Home is available at no charge if you need antivirus/anti-malware for Mac or Windows personal computers. 

  • Update your operating system, web browser, and other software when upgrades become available. New versions block vulnerabilities that a hacker could exploit. 

  • When you are not on the campus network, use the campus VPN (or your department’s VPN) to create a secure connection.  

  • Don’t write it on a sticky note, or share it with anyone.
  • Don’t approve unexpected 2FA push notifications.
  • Change your password if you suspect it has been compromised. 
  • Make passwords unique; don’t use the same password for different services.
  • Consider using a password manager to handle all your logins.
  • Consider using passphrases rather than passwords.
  • Check out the Password Security page for more tips. 

Whether working at home or on campus, phishing continues to be a major source of compromised accounts across the University community.