HACKS VITAE

TOOLS & TECH · SOURCES SHOWN

Cybersecurity Crash Course
Everything You Need to Know, in Plain Words

PRICES, VERSIONS AND FACTS AS OF SEPTEMBER 2026

A plain-words cheat sheet for ordinary people and small businesses: the scams and attacks that matter now, the protections that work best, the myths, what to do in the first hour after being hacked or scammed, and where to report it in five countries. Sourced to NIST, the UK NCSC, CISA, the FBI and other official bodies.

9 SECTIONS · HOVER A POINT TO JUMP
Published
September 22, 2026
Updated
September 28, 2026
Facts as of
September 2026
Read
20 min
Sections
9

BACKGROUND · REMBRANDT, HERMAN DOOMER, 1640 · THE MET, OPEN ACCESS

THE SHORT VERSION

  1. Most attacks are not personal. They try every address, every leaked password and every unpatched device, so you only have to be reachable, not interesting.
  2. Four habits matter most, in our reading of the official advice: two-step verification (passkeys are strongest), a different password for every account kept in a password manager, automatic updates, and a backup that is not plugged in.
  3. The best scam defence is a rule, not a gadget: if a message or call asks for money, a code or a change of bank details, contact the person or company yourself, using details you already have.
  4. If it happens: call your bank first, then secure your email, change reused passwords, log out every other device, and report it. Figures here are as of September 2026.

THE ARTICLE · 20 MIN

This is a crash course for ordinary people and small businesses, not security professionals. It explains how the common attacks work and how to protect yourself, in plain words, drawing on official sources: NIST (the US standards body), the UK’s National Cyber Security Centre (NCSC), the US Cybersecurity and Infrastructure Security Agency (CISA), the FBI, Australia’s Signals Directorate and others. Figures are as of September 2026. This page gives no legal or financial advice.

Do these first

Our ranking, from what the sources below say matters most for one person’s accounts:

  1. Turn on two-step verification on your email first, then everywhere else. Passkeys or a security key are the strongest kind; codes by text message are the weakest, but still better than nothing.
  2. Use a different password for every account, kept in a password manager. The one built into your browser or phone counts.
  3. Switch on automatic updates for your phone, computer, browser and router.
  4. Keep a backup that is not plugged in, and check once that you can restore from it.
  5. Never act on a message’s own contact details. If anyone asks for money, a code or new bank details, contact them yourself using details you already had.

The basics in four ideas

Security has three parts, not one. The standard definitions are about keeping information secret (confidentiality: “preserving authorized restrictions on information access and disclosure”), unaltered (integrity: “guarding against improper information modification or destruction”) and reachable (availability: “ensuring timely and reliable access to and use of information”). Ransomware attacks the third.

Threat, vulnerability and risk are different words. A threat is who or what could hurt you. A vulnerability is the weak spot, a “weakness in an information system … that could be exploited or triggered by a threat source”. Risk depends on how bad it would be and how likely it is. You cannot remove criminals; you can remove weak spots.

Your attack surface is every way in: each account, app, device and person, anywhere “an attacker can try to enter, cause an effect on, or extract data from”. Fewer old accounts and apps means fewer doors.

A lot of “hacking” is persuading a person. Social engineering is “an attempt to trick someone into revealing information (e.g., a password) that can be used to attack systems or networks”. Verizon’s 2026 breach report found a “human element was present in 62% of breaches”, and social engineering on its own was “16% of all breaches”.

What the numbers measure

Two big annual reports are widely quoted, and they measure different things.

  • The FBI’s IC3 report counts crimes that victims report, mostly in the US. For 2025 it recorded “1,008,597 complaints; $20.877 billion in losses; 26% increase in losses from 2024”. It “received complaints from more than 200 countries”.
  • Verizon’s 2026 Data Breach Investigations Report (DBIR) studies breaches of organisations: “more than 22,000 were confirmed data breaches involving organizations in 145 countries”, with a dataset that “covers Oct 2024 through Nov 2025”. Its headline finding: “Exploitation of vulnerabilities is now the most common initial access vector for breaches”, at 31%, ahead of stolen or misused logins (“credential abuse”) at 13%. In plain words, unpatched software is now the most common way into the organisations Verizon studied.

The threats that matter now

Phishing: fake messages by email, text, call or QR code

A phishing message pretends to be someone you trust. It comes by email, by text (smishing), by phone (vishing) or by QR code (quishing). The UK NCSC says: “It used to be easier to spot scams.” The FBI warns that AI tools “can correct for human errors that might otherwise serve as warning signs of fraud”, so bad spelling is no longer a reliable tell.

What still gives scams away is the pressure. The NCSC lists five signs: authority, urgency, emotion, scarcity and current events. Its advice: “If you have any doubts about a message, contact the organisation directly”, and “use the details from their official website.” Phishing and spoofing was the most-reported crime type to the FBI in 2025.

QR codes. The NCSC says “the QR codes used in pubs or restaurants are probably safe for you to scan”, but “scanning QR codes in open spaces (like stations and car parks) might be riskier”. The FBI adds: check that the code “has not been tampered with, such as with a sticker placed on top of the original code”, and “Do not download a QR code scanner app”; use the camera your phone already has.

Business email compromise

A criminal gets into, or imitates, a real email account (a supplier, a boss, a lawyer) and asks for a payment to “new bank details”. It was the second-largest loss category in the FBI’s 2025 report, at over $3 billion. The FBI’s advice is to use “secondary channels and/or two-factor authentication to verify requests for changes in account information”. In practice: any change of bank details is confirmed by phone, on a number you already had.

Ransomware

Ransomware is “a form of malware designed to encrypt files on a device, rendering them and the systems that rely on them unusable”. Criminals now often steal a copy first and threaten to publish it; CISA calls this “double extortion”, which is why a backup alone no longer ends the story. Ransomware was in 48% of the breaches in Verizon’s 2026 report, and “small organizations are disproportionally impacted”.

Should you pay? The UK’s NCSC says it and UK police “do not encourage, endorse nor condone the payment of ransom demands”: “there is no guarantee that you will get access to your data”, and “you’re more likely to be targeted in future”. Its protection is simple: “always have a recent offline backup of your most important files and data.”

Stolen and reused passwords

When one website leaks passwords, criminals feed them automatically into other sites’ login forms. This is called credential stuffing, and it works “since many users will re-use the same password”. A different password for every site defeats it, and the OWASP security project calls multi-factor authentication “by far the best defense against the majority of password-related attacks”.

Infostealers

An infostealer is malware that quietly copies saved passwords, cards and crypto wallets, and also “application tokens and session cookies”, the small files that keep you logged in. With those, a criminal can sometimes get in without your password or your code. Europol says “phishing techniques are the main vector for the distribution of infostealers”. In one 2025 operation, Microsoft found “over 394,000 Windows computers globally infected” by a single infostealer in two months.

SIM swapping

A criminal persuades your mobile provider to move your number to their SIM card. “Once the SIM is swapped, the victim’s calls, texts, and other data are diverted to the criminal’s device”, including text-message login codes. This is one reason text-message codes rank below other kinds of two-step verification. Our advice: ask your mobile provider what extra protection it offers for your number.

Tech-support and “government agent” scams

“Tech support scams often start with a bogus warning about a problem with your computer.” The fake technician wants remote access and payment, and “they often insist that you pay with gift cards, a wire transfer, a bank transfer, cryptocurrency, or a payment app”. A variant hands you to a fake official who tells you to move your money somewhere “safe”. The US FTC: “Someone who works for the government will never tell you to put your money in a federal safety locker.” Tech and customer-support scams were the third-largest loss category in the FBI’s 2025 report.

Relationship investment scams

A stranger met through a text, social media or a dating app builds a friendship, then introduces an “investment” platform showing fake profits. “Cryptocurrency investment fraud was the highest source of financial losses to Americans in 2025 with $7.2 billion reported in losses.” When victims try to withdraw, “they are told they need to pay a fee or taxes.” Afterwards, fake “recovery” services often target the same people; the FBI says: “Do not pay for services that claim to be able to recover lost funds.”

Deepfake voices and video

“Criminals generate short audio clips containing a loved one’s voice to impersonate a close relative in a crisis situation”, and fake live video calls with “alleged company executives, law enforcement, or other authority figures”. In early 2024, Hong Kong police said an employee of a multinational firm was tricked into a video call with fakes of the finance chief and colleagues and paid out 200 million Hong Kong dollars. The FBI says such content “is often difficult to identify”, so do not rely on spotting glitches. The defences are procedural: “Create a secret word or phrase with your family to verify their identity”, and hang up and call back on a number you already have.

Data breaches

When a company you use is breached, your email, phone number or password may circulate. You cannot prevent it, but you can make it harmless: unique passwords and two-step verification. The free site Have I Been Pwned lets you check whether your email address appears in known breaches; in September 2026 it listed more than 17.8 billion breached account records.

The protections that work

Passwords: length beats complexity

NIST SP 800-63B, the US government’s rules for logins to its own services (revised in July 2025), now says:

  • a password used on its own must be “a minimum of 15 characters in length”; one used with a second step may be shorter, but must be “a minimum of eight characters in length”;
  • services “SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types)”;
  • they “SHALL NOT require subscribers to change passwords periodically”, but “SHALL force a change if there is evidence that the authenticator has been compromised”;
  • they must check new passwords “against a blocklist that contains known commonly used, expected, or compromised passwords”, and “SHALL allow the use of password managers and autofill functionality”.

These rules bind US government services, not you or other websites, but they tell you what works. The UK NCSC’s advice is to “combine three random words to create a password”. It says “longstanding advice around making your passwords very complex … is not helpful”, because complex passwords are hard to remember, and swapping letters for symbols is a trick “cyber criminals know … as well”. NCSC’s own three-word example is 13 characters, under NIST’s 15 for a password used on its own, so use three or four random words, and add two-step verification. Writing a password down is “also OK, provided you keep it somewhere safe.”

Password managers

“A password manager stores passwords safely for you, meaning that you can have unique passwords for each service.” It also “helps protect you from phishing attacks as the password will only autofill on the correct website.” The one built into your browser or phone is fine on your own devices, but on shared computers “you should never save your password in the browser.” Protect the manager itself with two-step verification.

Two-step verification (MFA), and why some kinds are stronger

Multi-factor authentication means proving it is you with a second thing beyond the password. CISA says “any form of MFA is better than no MFA”, but “not all forms of MFA are equally secure”, and “phishing-resistant MFA is the gold standard”. From strongest to weakest:

  1. Passkeys and security keys (the FIDO standard), which a fake website cannot capture.
  2. Authenticator apps, or login approvals where you type a matching number.
  3. Plain “approve this login?” pop-ups, which criminals abuse by flooding you with requests until you tap yes (“push bombing”).
  4. Codes by text or voice call, which a SIM swap can redirect.

A 2023 preprint by Microsoft researchers, on business accounts that showed suspicious activity, found MFA “reduces the risk of compromise by 99.22%”. Microsoft’s widely quoted “99.9 percent” comes from a 2019 company blog post.

Passkeys

“A passkey is an authentication credential based on FIDO standards, that can be stored on your phone or computer, or in a hardware security key”, and you unlock it with “the same process that they use to unlock their device”. It resists phishing because it only works on the website that created it; NIST says this “prevents a falsified web page from being able to capture and reuse an authenticator output.” Use passkeys wherever a site offers them.

Updates

The NCSC calls updating “one of the most important (and quickest) things you can do to keep yourself safe online”, and says to “turn on ‘automatic updates’ in your device’s settings”. CISA warns that “attackers may target vulnerabilities for months or even years after updates are available”. A device that no longer gets updates “won’t receive the security updates from the manufacturer”, so plan to replace it.

Backups: the 3-2-1 rule

“Keep 3 copies of any important file: 1 primary and 2 backups”, “keep the files on 2 different media types”, and “store 1 copy offsite”. CISA’s own paper credits the rule to a photographers’ book, Peter Krogh’s The DAM Book. The ransomware lesson on top: “When the removable media isn’t in use, it’s important that you disconnect it”, because malware “can move to attached media automatically”.

Device encryption

Encryption protects your data if a device is lost or stolen. Windows turns on “BitLocker encryption automatically” on many machines, though “if you’re using a local account, Device Encryption isn’t turned on automatically”. On Macs with Apple silicon, “your data is encrypted automatically”, but Apple says turning on FileVault is what keeps “someone from decrypting or getting access to your data without entering your login password”, so turn it on. Keep the recovery key safe: Apple warns that if you forget both your password and the key, “your files and settings will be lost forever.”

Antivirus

You do not need to buy it for most devices. The NCSC’s device guidance says “you should not need to use AV products on platforms like Chrome OS, Android and iOS in their default configuration.” Windows includes “Microsoft Defender Antivirus, Windows Firewall, and Smart App Control”. Keep the built-in protection on, and install software only from official stores and websites.

VPNs

A VPN moves who can see your traffic from your Wi-Fi network and internet provider to the VPN company. The digital- rights group EFF says “a VPN is not a tool for anonymity”, and “while a VPN hides your browsing data from the ISP, it’s all visible to the VPN provider.” It can help on an untrusted network, “and you have a VPN you trust”. A VPN from your employer, for reaching work systems, is a different thing.

Your browser and home network

Leave your browser’s built-in dangerous-site protection on; in Chrome, “Standard protection offers security from known dangers.” For your router, CISA’s advice: “Change your router’s administrator password”, “use the strongest encryption protocol available”, and “disable Wi-Fi Protected Setup (WPS)”.

What you share

Public details feed scams: birthdays and pet names answer security questions, and voice clips feed voice clones. The NCSC says “you can reduce the likelihood of being phished by thinking about what personal information you (and others) post about you”, and the FBI suggests you “limit online content of your image or voice”.

Myths, checked

Myth “I’m not a target.” CISA lists “their home network is too small to be at risk of a cyberattack” as a misconception, because “most attacks are not personal in nature”. The NCSC compares most attacks to “a thief trying your front door to see if it’s unlocked.”

Myth “Macs don’t get viruses.” Apple itself says “macOS includes built-in antivirus technology called XProtect”. Microsoft’s researchers report that “since late 2025”, they have seen “macOS targeted infostealer campaigns using social engineering techniques”. Apple’s built-in protection helps; it does not make Macs immune.

Myth “Incognito makes you anonymous.” Google’s own help page: “While Incognito can help keep your browsing private on your device, it doesn’t make you invisible.” Your school, employer or internet provider “may be able to observe your activity in Incognito”.

Myth “A padlock means the site is safe.” The padlock means the connection is encrypted, not that the site is honest. Google’s Chrome team wrote that “the lock icon does not indicate website trustworthiness”, that “only 11% of study participants correctly understood the precise meaning of the lock icon”, and that “nearly all phishing sites use HTTPS, and therefore also display the lock icon.”

Partly true “Public Wi-Fi will get you hacked.” The agencies differ in emphasis. The US FTC says “because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe.” Australia’s ACSC still calls hotspots “an attractive target for cybercriminals”, and advises turning off “auto-join” and: “If your browser displays a warning message when you try to visit a website, do not continue.” The ACSC also says: “Reconsider your need to access sensitive information, such as your online banking.” The risk is small, not zero.

Myth “Change your password every 90 days.” The NCSC advised against forced changes in 2015, because “the new password will be similar to the old one”, and NIST now forbids US government services from requiring it. Change a password when there is a reason: a breach, a phishing slip, a shared login. Not every official source agrees: the FBI’s 2024 advice on business email compromise still says to change passwords “periodically”. We follow NIST and the NCSC, because forced changes push people toward predictable passwords.

Myth “A VPN makes you anonymous and secure.” See above: the VPN company sees what your internet provider used to see. It does not stop phishing, malware or you logging in to your own accounts.

Myth “Caller ID proves who is calling.” CISA: “VoIP easily allows caller identity (ID) to be spoofed”.

If you have been hacked or scammed

Order matters. Money first, then your email (it resets everything else), then everything else.

  1. Lost money? Call your bank or card provider now, on the number on your card, and ask them to stop or recall the payment. The FBI: “If you discover a fraudulent transfer, time is of the essence.”
  2. Recover the account through the provider’s own help pages, not a search ad or a “recovery service”.
  3. Check your email for forwarding rules. “A common tactic used by cyber criminals is to set up a forwarding rule” that copies your mail to them.
  4. Change the password on the hacked account and “for any accounts that are using the same password”.
  5. “Log all devices and apps out of your account”. This also shuts out stolen login cookies.
  6. Turn on two-step verification, and update the device.
  7. If a device is infected, disconnect it from the network and restore it from a clean backup. Our advice: change passwords from a different, clean device.
  8. US readers whose identity details leaked can freeze their credit: “When a credit freeze is in place, nobody can open a new credit account in your name”, and “there’s no cost to place or lift a credit freeze”. Other countries have different systems.
  9. Keep evidence (screenshots, numbers, transaction references) and report it, even if you lost nothing.

Where to report it

Where you areReport toPhone
AnywhereYour local police; the FBI’s IC3 also accepts complaints from outside the US—
United Statesic3.gov (FBI); ReportFraud.ftc.gov (FTC) for scams—
UK (England, Wales, Northern Ireland)Report Fraud, reportfraud.police.uk0300 123 2040
UK (Scotland)Police Scotland101
UK, scam emails and textsForward emails to report@phishing.gov.uk; forward texts to 77267726
AustraliaReportCyber at cyber.gov.au; Scamwatch for scams1300 292 371 (emergencies: 000)
CanadaCanadian Anti-Fraud Centre, reportcyberandfraud.canada.ca1-888-495-8501
IndiaNational Cyber Crime Reporting Portal, cybercrime.gov.in1930

Elsewhere, contact your national police or cybercrime unit. Criminals impersonate these agencies too: the FBI warns about anyone “impersonating or claiming to work with IC3”.

For small businesses

In our reading, government baselines agree more than they differ. The UK’s Cyber Essentials is “the minimum standard of cyber security recommended by the Government for organisations of all sizes”, with five controls: firewalls, secure configuration, security update management, user access control and malware protection. Australia’s Essential Eight is: “patch applications patch operating systems multi-factor authentication restrict administrative privileges application control restrict Microsoft Office macros user application hardening regular backups.” The US NIST Cybersecurity Framework 2.0 organises everything under six headings: “GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER”. (The US CISA also has a guide called Cyber Essentials, for small-business leaders; it is a different thing from the UK scheme.)

The short version for a small team:

  • “Too small to be a target” does not hold up. The NCSC: “if you think your business is too small to be a target, think again.”
  • Least privilege: give each person only the access their job needs, “the minimum necessary to accomplish assigned tasks”, and, our advice, remove access the day someone leaves.
  • MFA for everyone. Where phishing-resistant MFA is not yet possible, CISA says app-based codes or “mobile push with number matching are the best options for small- and medium-size business”.
  • A payment rule: no change of supplier bank details without a phone call to a known number.
  • Backups: offline, encrypted and tested.
  • Staff training is recommended by several government baselines, but its effect is disputed. Earlier studies found people scored better on security quizzes straight after training, but within four to five months they were back where they started. The strongest test we found, a randomised study of “over 19,500 employees at a large healthcare organization” (2025), found that common training formats “offer limited value”, and an earlier study of about 14,000 employees found no benefit either. The 2025 study’s authors suggest technical controls “may offer a better return on investment”. That does not make training useless; it means controls that do not depend on people noticing, like MFA and payment call-backs, should come first.

Glossary

TermIn plain words
Attack surfaceEvery way in: accounts, apps, devices, people.
Authenticator appAn app that shows login codes or approves sign-ins.
BackupA spare copy you can restore from.
BreachAn incident where data is confirmed to have reached someone it should not have.
Business email compromiseA real or faked business email account used to redirect a payment.
Credential stuffingTrying leaked username-and-password pairs on other sites, automatically.
DeepfakeFake audio, image or video of a real person, made with AI.
Double extortionRansomware that also steals the data and threatens to publish it.
EncryptionScrambling data so only someone with the key can read it.
FirewallA gatekeeper that blocks unwanted network traffic.
HTTPS / padlockAn encrypted connection to a website; not proof the site is honest.
InfostealerMalware that copies saved passwords, cards, wallets and login cookies.
Least privilegeEach person gets only the access their job needs.
MalwareAny software made to do harm.
MFA / 2FA / 2SVProving it is you with two different kinds of thing: something you know, have or are.
PasskeyA login that replaces the password with a key on your device, unlocked by face, fingerprint or PIN.
Password managerAn app or browser feature that creates and remembers a different password for every site.
Patch / updateA fix for a flaw in software.
PhishingA fake message pretending to be someone you trust, to get your details or money.
Phishing-resistant MFATwo-step verification a fake website cannot capture: passkeys and security keys.
Push bombingFlooding someone with login approvals until they tap “accept”.
QuishingPhishing through a QR code.
RansomwareMalware that locks your files and demands payment.
Session cookieA small file that keeps you logged in; stealing it can skip the login.
SIM swapGetting your phone number moved to a criminal’s SIM card.
Smishing / vishingPhishing by text message / by phone call.
Social engineeringTricking a person rather than breaking a machine.
VPNAn encrypted tunnel to a provider, who then sees your traffic instead of your internet provider.
Zero-dayAn attack on a flaw the maker did not yet know about, so no fix exists.

Sources

Checked September 2026.

Related: Website security crash course · How cybersecurity is built · How to check something online before you share it · How audio AI is changing what we hear · Web design resources

  • cybersecurity
  • security
  • scams
  • cheat sheet
  • fact check

SHARE & CITE

Hacks Vitae. "Cybersecurity Crash Course: Everything You Need to Know, in Plain Words." September 22, 2026. https://www.hacksvitae.com/life-hack/cybersecurity-crash-course-everything-you-need-to-know-in-plain-words

That's what we found. The rest is your call.

118 articles, each with its sources listed. Spotted something off? hacksvitae@gmail.com

Open the library