Cybersecurity Awareness Month Theme Aims to Prevent Scams Like This
Originally Published: Oct. 1, 2026
By Tracey Birkenhauer, journalist and Chief Impact Officer, STACK Cybersecurity
A member of the STACK Cybersecurity team saw a Facebook post from a childhood friend helping an uncle transition into assisted living. She was selling off vehicles, heavy equipment, and a hot tub at relatively low prices.
That history is why the post didn't get the scrutiny a message from a stranger would have. Cybersecurity Awareness Month, observed every October, exists to close that gap. The National Cybersecurity Alliance built its 2026 theme, "Don't Make It Easy for Them," around five behaviors that would have changed how this played out: strong, long and unique passwords, a password manager to store them, multifactor authentication, scrutiny of inbound messages, especially unexpected or urgent ones, and current software and devices.
The friend's account never got that scrutiny until money entered the conversation.
Executive Summary
A familiar Facebook account isn't proof that the familiar person is behind it. During Cybersecurity Awareness Month 2026, a STACK Cybersecurity team member encountered a believable Facebook post from a childhood friend's account that led to a request for a $5,000 deposit. The transaction stopped only after the team member verified the friend's identity through a separate channel that existed before the scam started and found the "proof" sent back through the original conversation wasn't genuine. The Federal Trade Commission reports that impersonation is the most commonly reported form of fraud. The National Cybersecurity Alliance's 2026 campaign gives businesses a working checklist for the same risk: strong, unique passwords stored in a password manager, multifactor authentication, scrutiny of unexpected or urgent messages, and current software.
A Believable Post, Until the Details Stopped Adding Up
Nothing about the post read as an obvious scam. The family story was plausible, the pictured items looked real and the prices were reasonable rather than suspiciously low. At first glance, there was little reason to treat it differently than any other post from a longtime friend.
Then a few details stopped lining up. Comments on the post had been turned off. The phone number provided carried an area code the friend wouldn't be expected to have. Her husband wasn't tagged. A phone call wasn't possible because the friend was reportedly out of town helping with the move.
No single detail proved the post was fraudulent. Together, they were enough to slow down before sending money.
A $5,000 Request Changed the Question
After the STACK team member expressed interest by text, the conversation moved quickly to a $5,000 refundable deposit, payable through Apple Cash or a wire transfer.
The staffer asked for proof of identity. The reply came back through the same conversation: an image of a woman standing beside a man in a hospital bed.
Why the Verification Happened Somewhere Else
A photo sent through a conversation that's already in question doesn't prove anything about who sent it. So the team member didn't rely on it. She contacted the friend through a communication channel nship that predated the scam entirely, a channel the person behind the Facebook account had no way to touch.
That call is what confirmed the account had been compromised, and it's also how the photo was exposed. The woman in the image resembled the friend but wasn't her. The man presented as the uncle in the hospital bed couldn't be identified at all, and the image carries the hallmarks of an AI-generated photo rather than a real snapshot of a real moment. A resemblance isn't identity, and in this case the photo wasn't even a real picture of the people it claimed to show.
The Federal Trade Commission's guidance on impersonator scams makes the same point. Stop and check the story using a phone number or contact method already known to be real, not one supplied by whoever is asking for payment. Continuing to ask a suspect conversation for more proof keeps the entire verification process under the scammer's control. Stepping outside it is what breaks that control.
A Trusted Account Is a Working Tool for an Attacker
The Federal Trade Commission warns that hackers target email and social media accounts because a stolen account can be used against the account holder's own contacts, not just the account holder. The commission recommends a unique password for every account, two-factor authentication where available, current account-recovery information and a routine check for unauthorized activity.
Friends, relatives, customers, vendors, and coworkers trust the account already. They've seen its photos and its history, and they've talked to it for years. A scammer who takes it over doesn't need to earn that trust. It's already there, which is why a compromised business account works against customers and partners the same way.
The Five Habits Behind Cybersecurity Awareness Month 2026
The National Cybersecurity Alliance and the Cybersecurity and Infrastructure Security Agency (CISA) have co-led Cybersecurity Awareness Month since 2004. The alliance's 2026 theme, "Don't Make It Easy for Them," asks people to build five habits into daily use of email, social media and messaging apps.
- Use strong, long, unique passwords for every account.
- Create and store those passwords with a password manager.
- Turn on multifactor authentication wherever it's offered.
- Scrutinize inbound messages, especially ones that are unexpected or urgent.
- Keep software and devices updated.
The fourth habit is the one this story tests. A message from a known contact asking for an unusual, time-pressured payment is precisely the scenario the habit describes, and it's the hardest one to apply consistently because the message looks like it came from someone familiar. CISA is running a companion 2026 theme, "Securing the Next 250," tied to the country's 250th anniversary and focused on the infrastructure operators who keep power, water and transportation running. Both campaigns point in the same direction for everyday users: build the habit before the request arrives, not during it.
What Businesses Can Take From This
- A recognizable name, photo or shared history with an account says nothing about who controls it right now.
- Treat an unexpected request for money, credentials or sensitive information as a verification event, not a transaction to complete quickly.
- Look at the pattern rather than one detail. A single inconsistency might mean nothing. Several of them around a financial request are worth checking.
- Verify through a channel that existed before the suspicious message arrived, never one the other party supplies.
- An employee's compromised account can be used against customers, vendors and coworkers the same way a personal account was used here. Protecting the account protects everyone who trusts it.
Impersonation remains the most frequently reported form of fraud to the FTC. Building an out-of-channel verification step into incident response planning turns that habit into policy rather than a judgment call an employee has to make alone, under pressure, in the moment.
Frequently Asked Questions
What are the five behaviors in the 2026 Cybersecurity Awareness Month campaign?
The National Cybersecurity Alliance's "Don't Make It Easy for Them" campaign asks people to use strong, long, unique passwords, store them with a password manager, turn on multifactor authentication, scrutinize inbound messages that are unexpected or urgent, and keep software and devices updated.
Can a compromised social media account be used to scam someone's contacts?
Yes. The FTC warns that attackers can use a hacked email or social media account to scam the people in that account's network, not just the account holder.
Is a photograph enough to verify someone's identity online?
No. A photograph sent through the same conversation being questioned doesn't establish who took it or sent it. In the STACK team member's case, the photo wasn't exposed as fake until she contacted the friend through a separate, previously known channel.
What should someone do if a friend unexpectedly asks for money online?
Stop before sending money and verify the request through a contact method known to be real, not one supplied inside the conversation. The FTC recommends checking the story with the person or another trusted source before wiring money or sending a digital payment.
What should someone do if they suspect a social media account has been compromised?
The FTC recommends changing the password, signing the account out of other devices, turning on two-factor authentication where available, confirming recovery information is current and reviewing the account for unauthorized activity.
Build Verification Into How Your Team Handles Requests
STACK Cybersecurity helps businesses turn awareness into policy through security awareness training, tabletop exercises and incident response planning. Check out our cybersecurity training programs, email info@stackcyber.com or call (734) 744-5300.