Online Safety & Scam Awareness | Canandaigua Computer Service

Online Safety & Scam Awareness

Recognize common online scams and learn how to avoid them. This section covers phishing, fraudulent emails, social engineering, and practical steps to stay safe while browsing, shopping, or communicating online.

How to Spot Internet Scams

Most internet scams rely on a handful of familiar tactics designed to make people act before they have time to think. Scammers may create urgency, fear, excitement, or curiosity by claiming an account has been compromised, a payment is overdue, a prize has been won, or immediate action is required. These messages can arrive through email, text messages, social media, websites, online advertisements, or messaging apps.

Common warning signs include unexpected requests for passwords, verification codes, personal information, money, gift cards, cryptocurrency, or unusual payment methods. Be cautious of unfamiliar links, suspicious attachments, unexpected invoices, offers that seem unusually generous, and messages pressuring you to keep a transaction secret. Scammers may also impersonate legitimate businesses, government agencies, financial institutions, friends, or family members to make their requests appear trustworthy.

One of the strongest defenses against scams is simply to slow down and verify the situation independently. Don't use the phone number, website, or link provided in a suspicious message. Instead, contact the organization or person using information you already know is legitimate. Taking a few minutes to verify an unexpected request can prevent financial loss, stolen accounts, and exposure of personal information.

 

Common Email and Tech Support Scams

Email scams often impersonate trusted companies, financial institutions, delivery services, coworkers, or government agencies to convince recipients that a message is legitimate. They may claim that an account has been locked, a package cannot be delivered, an invoice is overdue, or suspicious activity has been detected. The goal is usually to make you click a malicious link, open an attachment, provide login credentials, or send money.

Tech support scams use similar tactics but often claim there is an urgent problem with your computer. Scammers may use fake security warnings, browser pop-ups, emails, or unsolicited phone calls claiming that your device contains viruses or has been compromised. They may then request payment, ask you to install remote-access software, or attempt to gain control of the computer. Unexpected warnings that include a phone number and demand immediate action are a major red flag.

If you receive a suspicious message or warning, do not click links, call numbers displayed in pop-ups, provide passwords, or allow unexpected remote access to your computer. Instead, close the message or browser window and independently contact the company using its official website or a known phone number. Taking a moment to verify the situation can prevent stolen credentials, unauthorized computer access, and financial loss.

 

Social Media and Marketplace Scams

Social media platforms and online marketplaces give scammers easy ways to create convincing profiles, listings, advertisements, and messages. Fake accounts may use stolen photographs and personal information, while fraudulent marketplace listings can copy images and descriptions from legitimate sellers. Scammers may also compromise real accounts, making suspicious messages or offers appear to come from someone you already know.

Common warning signs include prices that seem unusually low, requests to move conversations outside the platform, pressure to act quickly, unusual payment methods, and requests for verification codes or personal information. Marketplace scammers may request deposits for items that do not exist, send fake payment confirmations, or claim that additional fees must be paid before money can be released.

Whenever possible, keep communication and payments within the platform's official systems and review the protections offered to buyers and sellers. Be cautious when dealing with newly created accounts, verify unexpected messages from friends independently, and never provide security or verification codes to another person. A convincing profile or professional-looking listing is not proof that the person behind it is legitimate.

 

How Scammers Use Fear and Urgency

Scammers frequently use fear, urgency, and emotional pressure to convince people to act before they have time to question what is happening. A message might claim that your bank account has been compromised, your computer is infected, a payment is overdue, or legal action is imminent. Others create artificial urgency around prizes, purchases, investments, or limited-time opportunities.

These tactics work because strong emotions can interfere with careful decision-making. Scammers may demand immediate payment, passwords, verification codes, remote access, or personal information while warning that something terrible will happen if you hesitate. They may also discourage you from contacting family members, your bank, or another trusted person who could recognize the scam.

When an unexpected message creates pressure to act immediately, stop and independently verify the situation before doing anything. Legitimate organizations generally provide reasonable ways to confirm important issues and do not require payment through gift cards, cryptocurrency, or other unusual methods. Taking a few minutes to investigate can break the sense of urgency that scammers depend on and prevent an emotional reaction from becoming an expensive mistake.

 

What to Do If You’ve Been Scammed

If you believe you've been scammed, acting quickly can help limit the damage. Stop communicating with the scammer, save relevant emails, messages, receipts, phone numbers, and screenshots, and identify what information or access may have been compromised. If you provided a password, change it immediately and update any other accounts where the same password was used.

If money or financial information was involved, contact your bank, credit card company, or payment provider as soon as possible. They may be able to stop a transaction, replace compromised cards, or help protect affected accounts. If a scammer gained remote access to your computer, disconnect the device from the internet and have it checked for unwanted software or changes before using it for sensitive activities.

After addressing the immediate problem, secure affected accounts with new, unique passwords and multi-factor authentication, review recent account activity, and continue watching for suspicious behavior. Depending on the type of scam, it may also be appropriate to report what happened to the platform, company, financial institution, or relevant authorities involved. Keeping a record of the incident can make recovery and reporting considerably easier.

 

How to Secure Accounts After a Compromise

If you believe an online account has been compromised, changing the password is an important first step, but it may not be enough. Create a new, unique password and review recent login activity, connected devices, active sessions, and account settings for anything unfamiliar. If available, sign out of other devices or sessions to remove access that an unauthorized user may still have.

Next, enable multi-factor authentication (MFA) and carefully review recovery information such as backup email addresses and phone numbers. Attackers sometimes change these settings so they can regain access later. Also check for unfamiliar forwarding rules, connected applications, security keys, or other changes, particularly with email accounts that can be used to reset passwords for other services.

If the compromised password was reused anywhere else, change it on those accounts as well. Consider how the account was compromised in the first place, whether through phishing, malware, a data breach, or another method, so the same problem does not happen again. Continue monitoring the account for unusual activity and secure any other accounts that may have been affected.


A Basic Home Cybersecurity Checklist

Good home cybersecurity starts with a few simple habits that work together to reduce risk. Keep computers, phones, web browsers, and other connected devices updated so known security vulnerabilities are patched. Use reputable security software where appropriate, secure your home Wi-Fi with a strong password, and remove programs or accounts you no longer use.

Protect online accounts with strong, unique passwords and multi-factor authentication (MFA) whenever available. Avoid reusing passwords between important accounts, and consider using a password manager to keep track of them. Be cautious with unexpected emails, text messages, attachments, downloads, and links, especially when they request personal information, payment, passwords, or immediate action.

Finally, maintain regular backups of important files so hardware failure, malware, theft, or accidental deletion doesn't result in permanent data loss. Periodically review account security settings, connected devices, and backups to make sure everything is working as expected. No cybersecurity checklist can eliminate every threat, but these basic precautions create multiple layers of protection against many of the most common risks home users encounter.

 

New Computer Setup Checklist

Setting up a new computer properly can improve its security, performance, reliability, and usability from the start. Begin by installing all available Windows or macOS updates, updating important applications and drivers, and removing unnecessary trial software or preinstalled programs. Configure your preferred web browser, email, printer, and other devices you regularly use.

Next, focus on security and data protection. Enable automatic updates, device encryption when appropriate, strong account passwords, and multi-factor authentication for important online accounts. Install only software you recognize and actually need, and make sure built-in or third-party security protections are enabled and functioning correctly.

Finally, establish a backup system before important files begin accumulating. Configure cloud synchronization or backup services where appropriate and consider maintaining a separate local or external backup for important data. Taking time to configure a new computer correctly provides a clean foundation and can prevent security, performance, and data-loss problems later.

 

What to Do Before Selling or Donating a Computer

Before selling, donating, or giving away a computer, make sure any important files, photos, documents, passwords, and other personal data are safely backed up. Sign out of important accounts and services, remove the device from accounts where necessary, and confirm that anything you want to keep has been transferred before beginning the erasure process.

Simply dragging files to the Recycle Bin or Trash is not the same as securely removing your personal information. Use the appropriate Windows or macOS reset and data-erasure options to remove user accounts, applications, settings, and personal files. The correct method can vary depending on the computer and type of storage, so follow the manufacturer's recommended procedure when preparing a device for a new owner.

Once the computer has been erased, verify that it starts at the initial setup screen without displaying your accounts or personal information. If the computer contains particularly sensitive information or the storage drive is being removed rather than reused, additional data-destruction measures may be appropriate. Taking these precautions helps ensure your old computer gets a second life without your personal data going along for the ride.

 

Safe Browsing and Email Safety Best Practices

Many online threats begin with malicious websites, deceptive emails, suspicious links, or unsafe downloads. Be cautious with unexpected messages, especially those asking you to sign in, download a file, provide personal information, or make an urgent payment. Before clicking a link, check where it leads and consider accessing important accounts directly through their official website or app instead.

Email attachments should also be treated carefully, even when they appear to come from someone you recognize. Compromised accounts can be used to send convincing malicious messages, while scammers frequently impersonate legitimate businesses and organizations. Unexpected attachments, unusual requests, spelling variations in email addresses, and pressure to act quickly are all reasons to verify a message before responding.

Safe browsing also means keeping your web browser, operating system, and security software updated, using strong and unique passwords, and enabling multi-factor authentication where available. Avoid downloading software from unfamiliar sources, and never ignore browser security warnings without understanding why they appeared. A few seconds spent verifying something suspicious can prevent malware infections, stolen accounts, and exposure of personal information.

 

Protecting Family Members Online

Protecting family members online starts with recognizing that different people face different types of digital risks. Children may encounter inappropriate content, unsafe interactions, or misleading information, while seniors and less experienced users are frequently targeted by phishing, tech support scams, fraudulent messages, and other forms of social engineering. Understanding these differences makes it easier to put appropriate safeguards in place.

Technology can provide an additional layer of protection. Keep devices updated, use strong passwords and multi-factor authentication, enable appropriate privacy and security settings, and consider parental controls or content restrictions where appropriate. Family members should also know never to provide passwords, verification codes, financial information, or remote access to someone who unexpectedly contacts them.

Education is just as important as technical protection. Encourage family members to pause and ask questions when something online seems suspicious, urgent, or confusing rather than feeling pressured to handle it alone. Creating an environment where everyone feels comfortable asking for a second opinion can prevent many scams and security problems before they turn into something more serious.

 

An Everyday AI Safety Checklist

AI tools can be useful for writing, research, brainstorming, productivity, and problem-solving, but their output should not automatically be treated as accurate. AI can misunderstand questions, omit important context, or confidently generate incorrect information. Verify important facts with reliable sources, especially when using AI for financial, legal, medical, technical, or other consequential decisions.

Be careful about what information you provide to an AI service. Avoid entering passwords, financial details, confidential business information, customer data, private documents, or other sensitive information unless you understand how the service handles and protects that data. Privacy policies, account settings, and data-retention practices can vary significantly between AI providers.

Finally, treat AI as a tool that supports human judgment rather than replacing it. Review generated content before using or sharing it, question information that seems unusual, and recognize when a task requires professional expertise or independent verification. Used thoughtfully, AI can save considerable time while allowing you to remain in control of the final decisions.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.