Many individuals take steps to protect themselves from cybercrime by securing their laptops, smartphones and other devices. However, the greatest risk may be the theft of personal data through alternative methods.
A survey commissioned by cybersecurity company NordVPN, released on Friday, reveals that cybercriminals are changing their tactics, and many people are overlooking the warning signs. While attackers once focused on devices—such as inserting malicious files into computers—they now target individuals directly through scam calls, phishing messages that mimic reputable companies and fake login pages designed to steal passwords.
Based on a survey of 1,200 Americans, NordVPN found that 91% are concerned about cybersecurity scams. About 56% worry more about broader threats like identity theft or fraud than about scam calls, which they encounter more frequently. On a daily basis, 46% report experiencing scam calls, while only 17% say they personally deal with identity theft or fraud.
"People picture cybercrime as stolen accounts or drained bank balances, but criminals succeed much earlier in the process," NordVPN Chief Technology Officer Marijus Briedis said in a statement. "The real moment of attack is when someone feels rushed, scared or pressured into trusting too quickly. From that point, it takes just a few clicks to go from a phone call to a stolen identity."
In other words, many are unaware of the significant risks associated with scam calls or phishing emails. "They're the starting point for exactly the kinds of identity theft and financial fraud people are most afraid of," Briedis added.
Scam calls have risen dramatically over the past year, but there are ways to counter them. For instance, using the iOS call screening feature on an iPhone and ignoring calls from unknown numbers can help.
NordVPN recommends several steps to protect against cybercrime. If you receive a suspicious text, email or call, pause before taking any action. According to NordVPN, scammers aim to rush you, and any message that seems urgent should be treated with suspicion.
"Modern attacks depend on people reacting faster than they can think," Briedis stated.
Additional protective measures include: verifying information before responding; ensuring links and addresses are legitimate before clicking; enabling multifactor notifications whenever possible and using strong passwords; accepting downloads only from trusted sources; and installing security software capable of handling multiple cyber threats at once.
