Americans reported 16.6 billion US dollars in internet crime losses to the FBI’s Internet Crime Complaint Center in 2024, a 33 percent rise from the year before, across 859,531 complaints, according to HousingWire’s summary of the IC3 report. Phishing and spoofing was the most common complaint type, with 193,407 reports. The numbers explain why a month of awareness exists, and why October still matters.
Cybersecurity Awareness Month is observed every October and is organised in the United States by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cyber Security Alliance (NCSA). The 2026 national theme is “Securing the Next 250”, according to California State University, Long Beach’s campaign page. This guide explains what the month is, what the theme signals, and practical ways for individuals, families, schools, and businesses to take part.
What Cybersecurity Awareness Month Is
Cybersecurity Awareness Month is an annual public campaign that encourages people and organisations to take basic steps to protect themselves online. CISA and the NCSA lead the national effort in the United States, but the message applies worldwide, and many governments, universities, and companies run their own activities. The campaign usually focuses on a small set of behaviours: strong and unique passwords, multi-factor authentication, software updates, and recognising phishing.
The 2026 theme, “Securing the Next 250”, appears on California State University, Long Beach’s campaign page, which builds its own “We Can DoIT Together” initiative on top of it and offers more than 20 webinars and activities across October covering topics such as phishing awareness, AI and trust, and data protection. Check CISA’s site for the full list of national resources as they are released.
Why It Matters in 2026: The Threat Numbers
The IC3’s 2024 report shows the scale. Total losses reached 16.6 billion US dollars, up 33 percent, even though complaints fell slightly from 880,418 in 2023 to 859,531. Business email compromise caused 2.77 billion US dollars in losses across 21,442 complaints, and Americans over 60 reported 4.8 billion US dollars in losses, the highest of any age group, according to HousingWire’s summary. Average loss per incident rose to 19,372 US dollars from 14,197.
Verizon’s 2025 Data Breach Investigations Report adds the cause. The human element contributed to 60 percent of breaches, stolen credentials featured in nearly one-third, and third-party involvement doubled from 15 to 30 percent, according to Abnormal AI’s summary of the report. In other words, most attacks target people and their credentials, not firewalls. Our post on how hackers use AI now explains how attackers are scaling those methods.
How Individuals Can Take Part
Pick four actions and complete them before the end of October. First, turn on multi-factor authentication for email, banking, and social accounts. Second, use a password manager so every account has a unique password, and our comparison of the best password managers will help you choose. Third, install pending updates on your phone, laptop, and router. Fourth, learn to recognise phishing emails and texts, and report them instead of deleting them. Add a fifth if you have time: check which apps have access to your accounts and remove the ones you no longer use.
How Families and Schools Can Take Part
Families can hold a 20-minute household security session. Set up a shared password manager, enable screen-lock and automatic updates on every device, review privacy settings on children’s accounts, and agree on a family code word that confirms a real emergency call, which helps against voice-clone scams. Schools can run assemblies on phishing and online safety, include a short lesson on password habits, and invite local police or security professionals to talk. Teaching children to pause before clicking is one of the highest-value habits a family can build.
How Businesses Can Take Part
Businesses can use October as a natural deadline. Run a 30-minute staff training session, send a simulated phishing email with a friendly debrief, review who has access to what, and test your backups. Small businesses can start with a basic review of accounts, devices, and vendors using our guide to a small business cybersecurity audit, and remote teams can use the advice in our remote work cybersecurity guide. Because third-party involvement in breaches doubled, according to the Verizon report, ask your key vendors about their security controls too.
| Audience | Best October Action | Time | Cost |
|---|---|---|---|
| Individuals | Enable MFA and a password manager | 1 hour | Free to low |
| Families | Household security session and family code word | 20 minutes | Free |
| Schools | Phishing and password assembly | 1 week | Free |
| Small business | Staff training plus access review | Half a day | Low |
| Larger organisations | Phishing simulation and vendor review | 2 to 4 weeks | Medium |
Make It Stick After October
Awareness fades quickly. Turn the month into a routine by scheduling a quarterly 15-minute security check: review accounts, remove old devices, run updates, and test one backup. Set a calendar reminder now, and make one person responsible in your family or team. Organisations should repeat short training every few months rather than one long annual session, and track simple measures such as how many accounts use MFA and how many employees report suspicious messages.




