UIC Cybersecurity Awareness Month 2025 is Here!

2025 Cybersecurity Awareness Month Banner

Students: Learn to Protect Yourself Online & Take the Quiz for a Chance to Win One of Several $50 Gift Cards to the UIC Book Store!

October is Cybersecurity Awareness Month—the perfect opportunity for students to build safer digital habits. Cybercriminals don’t just target big companies; students are frequent targets because of their reliance on email, online accounts, and quick communication.

UIC Technology Solutions has developed a four-week campaign to give you tools and strategies for staying secure. Each week highlights a different threat—and how you can defend against it, so look out for our weekly emails and review the tips below to stay safe online!

3D cute robot

Contrary to what you see in movies, hackers don’t often “break into” computers using high-tech wizardry. Instead they often rely on tricking people into giving up sensitive information or access to their devices. This is tactic is called social engineering, and it’s one of the most common ways students are targeted.

Rather than attacking machines, cybercriminals “hack” human emotions – using manipulation, urgency, and misplaced trust to get what they want. Whether it’s a fake job offer, a suspicious email, or a message that feels just a little off, the goal is the same: to get you to click, share, or believe something you shouldn’t.

Some common forms of social engineering include:

  • Phishing emails that look like they’re from your professor, the university, or your bank.
  • Vishing calls (voice phishing) where scammers pretend to be tech support or government agencies, or even campus services.
  • Smishing texts (SMS phishing) with fake links to “support lines” or account recovery pages. These messages may claim you have an unpaid toll bill, were overcharged for an item, or need to verify your account urgently.
  • In-person impersonation by someone posing as staff, vendors, or delivery workers.
  • Malicious USB drops – like a flash drive labeled “Payroll” or “Private Photos” left in a public space, hoping someone will plug it in out of curiosity.

Even the smallest slip – like clicking a link or plugging in a USB – can give cybercriminals access to your personal data, accounts, or even your device.

🔒 How to protect yourself from social engineering:

  • Slow down—don’t respond to messages that feel rushed or “too urgent.”
  • Verify the source by contacting the organization directly through its official website or phone number.
  • Be skeptical of free offers, contests, or job opportunities that seem too good to be true.
  • Never share personal details like Social Security numbers, bank info, or login credentials over email or text.
  • Remember: UIC and most legitimate organizations will never ask for your password over email or text.
3D cute robot

Sometimes, it’s not about what the message says, but rather how it makes you feel. Hackers count on you being distracted, rushed, or stressed so you won’t notice the subtle warning signs. Recognizing those red flags – like urgency, pressure, or something that just feels “off” – can help you stop a scam before it gets you.

Be cautious if you notice:

  • Unknown senders or callers – especially if you weren’t expecting to hear from them.
  • Urgent language – messages pushing you to “act now” are classic hacker tactics.
  • Strange contact details – look closely, even a single extra character in an email address can be a trap.
  • Unusual attachments or links – if you didn’t ask for it, don’t click to open it.
  • Found USB drives – leave them where they are; plugging them in can launch malware immediately.

Cybercriminals are creative, but the red flags they use tend to repeat. If you stay alert, you can avoid becoming a victim.

🚩 Other red flags to watch for:

  • Spelling or grammar mistakes – professional organizations rarely send sloppy emails.
  • Requests for sensitive info – no legitimate company will ask for your password, Social Security number, or bank account details by email.
  • Unfamiliar greetings or closings – a professor wouldn’t sign off “Warmest regards, IT Help Desk.”
  • “Spoofed” URLs – links that look real but lead to fake sites (hover your mouse over the link to preview where it actually goes).

🔒 What to do if you notice a red flag:

  • Stop engaging—don’t reply, click, or forward.
  • Take a screenshot of the suspicious message.
  • Report it immediately to security@uic.edu.
3D cute robot

Your password isn’t enough anymore. Hackers can steal, guess, or even buy leaked passwords from the dark web. That’s why UIC uses Duo Two-Factor Authentication (2FA) to add an extra layer of protection to your accounts.

But attackers have started targeting Duo, too – the most common method we see is called MFA Fatigue or “Duo bombing.” This is when attackers send you repeated Duo push requests hoping you’ll approve one out of frustration or by accident.

Remember:

  • Never use the same password for multiple accounts, or reuse an old password.
  • Never approve a Duo request you didn’t initiate.
  • If it happens, immediately change your password.
  • Report suspicious activity to security@uic.edu right away.

Duo only works if you stay alert and make smart choices. With strong passwords and Duo, you’ve got a powerful tag team defense protecting your UIC accounts.

🛡️ Extra protection tips:

  • Set unique passwords for your school, banking, email, and social media accounts.
  • Use Duo’s “remember me” option on your trusted devices to avoid unnecessary prompts.
  • Enable notifications so you’ll know right away if someone else is trying to log in.
  • Never share your Duo device—treat it like your student ID or debit card.
  • Stay alert while traveling—public Wi-Fi networks are riskier, and attackers may try to trick you into accepting fake logins.
3D cute robot

If your password looks like “Summer2025!”, hackers can crack it in seconds. Short, predictable passwords are outdated and unsafe; even with common tricks like swapping letters for numbers (like using a 3 for an E or a 0 for an o). Hackers know those patterns too — and they’re built into their cracking tools.

Instead, create a long passphrase – 15 characters or more – that’s easy to remember but hard to guess. With longer passwords, it’s even safe to use real words, as long as the phrase is unique and personal and not a common phrase, quote, or song lyric.

Example:

  • Weak password: Summer2025!
  • Strong passphrase: Purple-Pizza-Party2!

Other key tips:

  • Never reuse passwords—if one account gets breached, all others with that same password are at risk (this is called “credential stuffing”).
  • Use a unique password for each online account and application – especially for your school, email, and financial accounts.
  • Turn on MFA wherever it’s offered, this extra step can save you from a very bad day.
  • Consider using a password manager to help you keep track of the login credentials you use for online accounts and applications, and features such as auto-login can help you login faster and protect you from logging into a fake website.

Your email account is especially valuable to hackers. With access to your email, hackers can reset your school, email, and financial accounts, or use your account to send phishing emails from your identity to trick others.

🔐 Password manager benefits:

  • Stores all your passwords in one secure place.
  • Creates long, random, unguessable passwords for every account.
  • Prevents you from accidentally logging into fake websites.
  • Syncs across devices, so you don’t have to memorize dozens of logins.

Take the 2025 UIC Cybersecurity Awareness Quiz for a chance to win one of several $50 UIC Bookstore gift cards.

All participants of the quiz automatically agree to the following CONTEST TERMS.

Take the 2025 UIC Cybersecurity Awareness Quiz