Key Takeaways:
- Cyberattacks cost Americans $21 billion in 2025, and AI is making scams harder to detect.
- Every individual with financial accounts, email access, or a digital identity is a target.
- The five most impactful protections are: multifactor authorization, strong passphrases, software updates, phishing awareness, and knowing how to verify before you act.
- If you believe you’ve been compromised, act within 24 hours. Keep reading for steps to take if you believe you’re a victim of a cyberattack.
Cyberattacks are malicious attempts to gather private information about you and your accounts online. Some cyberattacks will target your accounts and sell your data; others will try to access your online financial accounts directly. Regardless of your net worth, if you have an email address or a financial account, you can be a target.
In 2025, the FBI reported $21 billion lost to scams. With AI tools now in criminals’ hands, the threat is accelerating, and high-net-worth individuals and executives are increasingly in the crosshairs.
It’s critical to understand the threat and take precautions to keep your accounts safe. This article will cover how to spot a cyberattack, how to protect yourself if you are targeted, and what to do if you’ve been compromised.
How to Recognize a Scam Before It Strikes
The Four Warning Signs of Any Scam:
- Pretend: A scammer will pretend to be someone you know or from an organization you recognize. This is a core trait of “imposter” scams, which have been increasingly popular since 2023. If you aren’t expecting to hear from that particular person, start questioning the conversation. You can always end the conversation and call the real organization to be sure.
- Problem/Prize: A scammer might tell you that you’re in trouble, or they might tell you that you have something to gain if you act. A common example is a call from the IRS telling you that you owe back taxes and threatening jail time if you don’t pay.
- Pressure: A scammer’s best friend is speed. They want you to act before you can do your research or think about what you’re doing.
- Payment: Scammers want you to pay in a specific, irreversible way. Immediate red flags are any discussion of cryptocurrencies or gift cards as payment.
The New Threat: AI-Generated Scams and Deepfakes
AI can now clone voices, generate fake video (deepfakes), and write flawless phishing emails. According to the FBI’s 2025 cybercrime report, AI scams led to almost $900,000,000 in losses last year. Popular AI scams include fake voice calls impersonating family members or executives, and AI-generated invoice fraud.
Common Cyber Scams to Know By Name
| Scam Type | How It Works | The Red Flag |
| Phishing | Fake email with malicious link | Urgency, wrong sender domain |
| Smishing | Fake text message | Unknown number, requests a click |
| Vishing | Fake phone call | Asks for account info or wire transfer |
| Romance Scam | Fake online relationship to gain trust | Never meets in person, asks for money |
| Business Email Compromise | Impersonates an executive or vendor | Slightly wrong email address |
| Fake Charities | Donation request for fake victims | Unusual payment method (gift cards, wire) |
| AI Voice Cloning | Clones a loved one’s voice to request emergency funds | Unusual urgency, can’t be reached independently |
8 Ways to Protect Yourself from Cyberattacks
1. Check If Your Data Has Already Been Exposed
Check on haveibeenpwned.com, a free, CISA-recommended website, for data breaches. A data breach means your email and password combination is on the dark web. If you’re flagged, change passwords immediately, enable multifactor authorization, and monitor accounts. Do this today and take your first step towards cyberattack protection.
2. Turn on Multifactor Authentication on Every Financial Account
Multifactor Authentication (MFA) opts you into an extra step when trusted websites and applications ask you to confirm your identity. It may also be called Two-Factor Authorization, Two-Step Factor Authentication, or 2FA.
Once MFA is turned on, you will be asked to provide your password or PIN, but also:
- Something you have, like an authentication application or a confirmation text on your phone OR
- Something you are, like a fingerprint scan or Face ID
This second factor of authorization is a lot harder for a scammer to fake than a password.
Authentication apps like Google Authenticator and Authy are more secure than SMS codes because they generate locally, so scammers can’t intercept the code. You should turn on MFA wherever it is available.
3. Use a Passphrase Instead of a Password
Instead of trying to remember 15 random characters, set your password as a passphrase: 3-4 random words (PurpleHammerCanoe72). Passphrases are harder to crack since they’re more likely to be random than passwords, and they’re easier to remember.
Using a password manager can store unique passphrases for each account securely. While you may be tempted to reuse passphrases, never reuse passphrases across financial accounts.
4. Keep Your Software and Apps Updated (Automatically)
Update your software and apps regularly. Scammers exploit flaws and weak points in the system.
Beyond updating the operating system on your devices, be sure to update applications (especially web browsers) too. The importance of updates applies to your router’s firmware, not just devices.
To make sure you are always updating as soon as possible, enable automatic updates.
5. Think Before You Click and Verify Before You Act
90% of successful attacks start with phishing emails. Smishing and vishing are modern variants where a scammer sends either a text or calls you looking for information.
The best way to avoid the scams is to verify their identity independently. If your bank, advisor, or family member contacts you urgently, hang up and call back on a number you look up yourself, never one provided in the message. Even if the person sounds like someone you know, it may be an AI scam.
6. Protect Your Devices (Not Just Your Accounts)
Beyond protecting your account, there are clear actions you can take to protect your devices:
- Set a PIN, fingerprint, or Face ID on every device.
- Enable remote lock and wipe on Apple Find My / Google Find My Device in case devices get stolen.
- Turn off Bluetooth and Wi-Fi when not in use.
- Never leave devices unattended in public.
- Install reputable antivirus/security software on laptops.
7. Avoid Public Wi-Fi for Any Financial Transactions
Public Wi-Fi creates a risk for a “man-in-the-middle” attack. Essentially, because public Wi-Fi networks are not secure, a hacker can be secretly placed between your device and the website you want to use. The hacker can then steal your data and intercept communication.
Never check bank accounts, brokerage accounts, or email on public Wi-Fi without a VPN. A VPN serves as a “private tunnel” for your connection and minimizes attack risk.
8. Secure Your Home Wi-Fi Network
Your home Wi-Fi network may be leaving you vulnerable to cyberattacks. Be sure to change your router’s default password and use WPA3 encryption if your router supports it. Keep your router firmware updated. If you have smart home devices or visitors frequently on your network, consider creating a separate “guest” network.
Cybersecurity Self-Audit Checklist
- I have checked my email on haveibeenpwned.com.
- I have MFA enabled on all financial accounts.
- I have unique passphrases.
- I have automatic software updates enabled on all devices.
- My phone has a PIN and remote wipe enabled.
- I never access financial accounts on public Wi-Fi.
- My home router password has been changed from the default.
- I know where to report scams (FTC, FBI, IC3).
Protecting Your Financial Accounts Specifically
Why Financial Accounts Are a Prime Target
Brokerage and retirement accounts can hold hundreds of thousands, if not millions, in assets. Unlike credit card fraud, unauthorized wire transfers can be permanent and uninsured. Certain accounts, such as your checking or basic savings accounts, are covered by the Federal Deposit Insurance Corporation (FDIC), an independent bank insurance agency. However, the FDIC does not cover investments, stocks, or brokerage accounts. SIPC is specific broker insurance that will cover up to a certain amount. For specifics on brokerage coverage, contact your financial institution.
How to Protect Your Investment and Retirement Accounts:
- Enable MFA on every investment platform, including brokerage portals, 401 (k) platforms, and tax software.
- Set up account activity alerts for any transfer or login attempt.
- Establish a verbal passphrase or “call-back” verification with your financial advisor’s firm before any wire transfer.
- Ask your advisor whether your firm offers “trusted contact” designations; this allows the firm to contact a trusted person if suspicious account activity is detected.
- Never wire money based on an email instruction alone. Always call to verify using a number on the firm’s official website.
What to Do If You’ve Already Been Targeted
Immediate Steps to Take:
- Stop all communication with the suspected scammer.
- Do not send additional money or information.
- Change passwords on all financial and email accounts immediately.
- Enable MFA if not already active.
- Contact your bank or financial institution’s fraud line directly using a number from their official website.
Where to Report Cybercrime and Fraud:
- FTC: https://reportfraud.ftc.gov
- FBI Internet Crime Complaint Center: https://www.ic3.gov
- Your state attorney general’s consumer protection office
- For identity theft specifically: https://www.identitytheft.gov
How to Recover Your Identity if Compromised:
- Place a credit freeze at all three bureaus (Equifax, Experian, TransUnion) for free.
- File a Federal Trade Commission (FTC) Identity Theft Report at IdentityTheft.gov.
- Alert your financial advisor and institutions immediately.
- Monitor all accounts weekly for 90 days minimum.
The Bottom Line
Cybercriminals are counting on inaction. The most impactful steps – enabling MFA, using unique passphrases, keeping software updated, and knowing how to verify before you act – cost nothing and take less than an hour. For those with significant financial assets, the stakes are even higher. The protections in this guide are your first line of defense.
Talk to a Financial Advisor About Protecting Your Wealth
Protecting your digital life is one piece of a comprehensive financial plan. Advisors at Wealth Enhancement work with clients to identify vulnerabilities, coordinate with financial institutions, and build safeguards around your account.
Frequently Asked Questions About Cyberattacks
What is the most common type of cyberattack on individuals?
Phishing via email remains the most common entry point, accounting for 90% of successful attacks. Smishing (text-based phishing) is the fastest-growing.
Am I at higher risk of cyberattacks because I have significant assets?
Yes. High-net-worth individuals and executives are explicitly targeted by business email compromise, wire fraud, and investment scams because the potential payoff is much larger.
What is multifactor authentication and do I really need it?
MFA requires a second form of verification beyond your password. Even if a hacker steals your password, they cannot access your account without the second factor. Yes, you do really need MFA. It is the single most effective account protection available today.
What should I do immediately after a cyberattack?
Stop communicating with the scammer; change passwords; enable MFA; contact your bank’s fraud line; report to the FTC at https://reportfraud.ftc.gov and the FBI at https://www.ic3.gov.
How can AI be used to scam me?
Criminals now use AI to clone voices, generate realistic phishing emails without spelling errors, and create fake videos (deepfakes). Always verify requests for money or sensitive information through an independent callback, even if the voice sounds familiar.
What’s the difference between phishing, smishing, and vishing?
Phishing is email-based, smishing is SMS/text-based, and vishing is voice call-based. All three use the same tactics: impersonation, urgency, and a request for sensitive information or payment.
Is public Wi-Fi really dangerous for checking my accounts?
Yes. Public Wi-Fi networks can allow attackers to intercept your data in real time. Avoid accessing financial accounts or sensitive email on public Wi-Fi. Use a VPN on your phone’s cellular data instead.
This article was originally published on 7/21/24 and has been updated.
#2026-14058
<a href=”/blog?keyword=&field_category%5B11%5D=11” class=”custom-taxonomy-link”>Financial Planning</a>