Most Americans finally got the message about passwords. After years of data breaches, identity theft, and nonstop warnings from banks and technology companies, people have slowly become familiar with two-factor or multi-factor authentication. Enter your password, grab your phone, approve the login, and move on. It isn’t perfect, but it became the closest thing to a universal security habit that everyday people actually adopted.

Read more Nicole Collier had the right to protest

Unfortunately, cybercriminals have already moved on. One of the biggest cybersecurity stories this month exposed an unsettling trend. Rather than trying to bypass multi-factor authentication altogether, attackers are patiently waiting for victims to complete it themselves. The victim enters their password, approves the authentication request, and unknowingly hands criminals the keys to the kingdom.

The attack doesn’t defeat multi-factor authentication (MFA). It defeats the person using it. That distinction matters because millions of Americans barely understand why they’re approving those authentication requests in the first place. They were simply told, “Use MFA because it’s safer.” Now scammers are exploiting that limited understanding, creating fake login pages and convincing users they’re protecting their accounts when they’re actually surrendering them.

For older Americans, this is becoming an especially dangerous trap. Many seniors have embraced online banking, telehealth, social media, and digital communication later in life. They learned enough technology to participate, but they didn’t grow up recognizing sophisticated phishing attempts or fake authentication prompts. Criminal organizations know this. They understand who is most likely to hesitate, become confused, or assume that if a phone asks for approval, it must be legitimate.

Cybercrime has become less about breaking computers and more about manipulating people. That should concern everyone because even the federal government is acknowledging that the digital battlefield is changing faster than traditional defenses can keep up. The Trump administration recently announced new efforts to identify cybersecurity weaknesses created by artificial intelligence and emerging technologies. If Washington believes it needs to aggressively hunt for vulnerabilities before adversaries exploit them, imagine how exposed the average household really is.

Government agencies cannot protect every home computer, smartphone, or small business. They never could. Too many people still assume that buying a new laptop or switching from Windows to a Mac somehow places them outside the reach of hackers. That misconception has survived for years despite overwhelming evidence to the contrary.

Mac malware has expanded dramatically. Information-stealing malware, adware, remote-access trojans, credential harvesters, and spyware now routinely target Apple’s ecosystem. Criminals follow the money and the users. As Apple’s market share has grown, so has its appeal to cybercriminals. Operating systems are no longer security strategies.

The same false confidence extends into business environments. Small business owners often believe antivirus software checks a compliance box and the problem is solved. Today’s attacks don’t politely announce themselves with flashing warning messages. They quietly establish persistence, steal credentials, spread laterally across networks, and wait.

That is where Endpoint Protection Platforms, or EPP, have become essential. Modern endpoint protection goes well beyond signature-based antivirus by identifying suspicious behavior, isolating compromised systems, and giving organizations centralized visibility into what is happening across every connected device. Businesses also need centralized monitoring so they aren’t discovering breaches weeks after customer information has already left the building.

Read more Channelling the inner child for gun control

Visibility has become as important as prevention. Another overlooked threat is the return of computer worms. Many people remember hearing about worms years ago and assume they disappeared with dial-up internet. They didn’t.

A worm is malicious software capable of spreading from one system to another without requiring users to manually install it. Once inside a network, worms can rapidly infect additional computers, steal information, install ransomware, or create backdoors for future attacks. Recent threats have shown that this decades-old technique remains remarkably effective because organizations continue to underestimate how quickly malware can propagate across poorly monitored networks.

Even cybersecurity professionals are questioning whether long-standing defensive philosophies remain sufficient. Zero Trust architecture, which assumes no user or device should automatically be trusted, remains one of the strongest frameworks organizations can adopt. But frameworks alone don’t stop criminals who successfully convince legitimate users to hand over their credentials or approve malicious login requests.

Technology cannot compensate for human deception forever. The cybersecurity conversation has reached a point where awareness needs to catch up with reality. Passwords were never enough. Multi-factor authentication remains important, but it is no longer the finish line. Buying a Mac instead of a PC is not a security plan. Installing antivirus and forgetting about it is not a strategy. Assuming someone else is watching your network is wishful thinking.

Cybercriminals have become remarkably patient. They study behavior, exploit routine, and manipulate trust better than ever before.

That means ordinary Americans have to stop thinking about cybersecurity as something reserved for IT departments or Fortune 500 companies. Every smartphone, every family computer, every small business, and every online account now represents a potential target.

The criminals already understand that. The question is whether the rest of us can catch up before they get there first.

Julio Rivera is a business and political strategist, cybersecurity researcher, founder of ItFunk.org and ReactionaryTimes.com, and a political commentator and columnist. His writing, focused on cybersecurity and politics, has appeared in major publications around the world.

Read more Cynicism toward the intellectual class

ChatGPT

Image generated by ChatGPT.

By admin

Leave a Reply

Your email address will not be published. Required fields are marked *