Skip to main content
IT Service Status
IT Service Status

2026 Cybersecurity Awareness Month: Don't Make It Easy for Them

Cybersecurity Guidance in a Changing Environment

University leadership shared tips on spotting scams, protecting your accounts, and reporting suspicious activity, including a new warning about fake "verify you are human" prompts. Read the message from Luke Figora and Sean Reynolds.

Every October, Northwestern IT joins the National Cybersecurity Alliance and the Cybersecurity and Infrastructure Security Agency in marking Cybersecurity Awareness Month. This year's national theme, "Don't Make It Easy for Them," is a good description of the philosophy behind staying safe online: most successful scams don't rely on sophisticated hacking—they rely on someone being in a hurry, distracted, or simply unaware of what to watch for. A few consistent habits go a long way toward closing that gap.

Here's a look at the fundamentals worth reinforcing, a new scam to watch for, two areas—AI tools and file sharing—where good habits are more important than ever, and information on the Big Ten Academic Alliance’s upcoming events.

Use a Password Manager and Passkeys Where You Can

Weak or reused passwords remain one of the easiest ways into an account. 1Password, Northwestern's supported password manager, creates and stores your credentials in an encrypted vault protected by a single password, auto-filling your logins so you don't have to remember or retype them. Where a site or service offers a passkey instead of a password, use it—passkeys are tied to your device and can't be phished or guessed the way a typed password can.

Keep Multi-Factor Authentication On and Approve Only What You Requested

Nearly every Northwestern system requires Duo Multi-factor Authentication (MFA), and many banks, medical providers, and shopping sites now offer it too. MFA is one of the single most effective protections available, but it only works if you treat unexpected prompts with suspicion. If you get an MFA request you didn't request, deny it and report it. Don't approve it just to make the notification go away. As a reminder, Northwestern IT (and other service providers) will never ask you for your password or an MFA code.

Recognize and Report Phishing

Phishing remains the most common way attackers try to get into Northwestern accounts, and the attempts are getting more convincing. Visit the Avoiding Phishing page for tips on spotting suspicious messages and see real examples of phishing attempts targeting Northwestern. When in doubt, don't click. Report it to security@northwestern.edu instead.

Spotlight

Watch for Fake "Verify You're Human" Prompts

You know the drill: click a checkbox, select some images, prove you're not a robot. That familiar routine is exactly what a new scam is exploiting. Fraudulent websites are showing fake CAPTCHA screens that, instead of asking you to click images, instruct you to press a combination of keys and paste something—a sequence that actually runs hidden malware on your device rather than verifying anything at all.

The giveaway: a real CAPTCHA never asks you to leave your browser, open a Run box or Terminal, or paste a command. If a "verification" step asks you to do any of that, stop. Read the “Beware of Fake "Verify You're Human" Prompts” story.

Keep Devices and Software Updated

Outdated software is one of the easiest doors for attackers to walk through. Turn on automatic updates wherever possible for your operating system, browser, and apps, and don't put off installing security patches. Find more tips for securing your devices.

Using AI Tools Responsibly with University Data

As generative AI tools become part of daily work and study across campus, it's worth a reminder that not all data should go into every AI tool. Northwestern's data classification levels—from Level 1 (public data) to Level 4 (legally restricted data)—determine which AI tools are appropriate to use with which kinds of information. A few habits to carry into any AI tool:

  • Share only what's needed. If a file or dataset contains sensitive columns or details that aren't necessary for your task, remove or de-identify them first.
  • Limit access. Give an AI tool the narrowest access required—a single file rather than an entire folder, for example.
  • Know your tool. Free or individual AI accounts (including free Claude or ChatGPT accounts) are appropriate for public, Level 1 data only, and they can train the models on any data provided. Sensitive University data, including student records, research data, HR information, etc., requires a Northwestern-supported tool and the right data classification level.

Review Data Security with AI Tools for full guidance, or visit the AI at Northwestern IT pages to explore what's available to you.

Sharing and Storing Files Securely

Where you store and how you share University data matters as much as how you protect your passwords. A few reminders as you work with files day to day:

  • Know where your data lives. Synced email, auto-backup to personal cloud storage, and shared drives can all mean a sensitive file exists in more places than you realize.
  • Share deliberately. Use Northwestern's supported file-sharing tools rather than personal cloud accounts or email attachments for sensitive material, and share with only the people who need access.
  • Avoid public networks for sensitive work. Use Northwestern’s GlobalProtect VPN when connecting from airports, cafes, or hotels.

Visit the Northwestern IT website for more data security tips.

Security Is Everyone's Responsibility

None of these habits require special technical expertise, just a little consistency and a healthy pause before clicking, approving, or pasting something unexpected. If you spot anything suspicious, like a strange email, an MFA prompt you didn't request, or a verification screen that doesn't look quite right, contact the Information Security Office at security@northwestern.edu. Reporting it, even once, helps protect the whole Northwestern community.

Join the Big Ten Academic Alliance for a Month of Cybersecurity Events

Northwestern's own efforts this October are part of a larger push across the region: the Big Ten Academic Alliance (BTAA) is hosting a full slate of free virtual events this month. Open to faculty, staff, and students at BTAA institutions, the sessions bring in industry experts, campus security leaders, and researchers to share insights, best practices, and practical strategies for navigating today's cybersecurity landscape—no matter your role. You can register for any or all sessions on the BTAA events page. Questions can be directed to ciosupport@btaa.org.