Skip to content

October Is National Cybersecurity Awareness Month – Be Cyber Alert and Guard Against Phishing

October 14, 2021

This month is the 18th Annual National Cybersecurity Awareness Month in the United States, sponsored by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cyber Security Alliance. This year’s theme is again “Do Your Part. #BeCyberSmart.” Being Cyber Smart includes awareness of current threats like business email compromise (BEC), ransomware, supply chain compromise, and phishing. This Alert addresses phishing, which is CISA’s focus topic for this week, “Phight the Phish!”

Phishing uses fraudulent (spoofed) emails for criminal purposes, like installing malware, stealing money, and obtaining information such as login credentials, bank account information, personal information, and confidential business information.

The number of phishing attacks has increased during the COVID pandemic and remains high. The Anti-Phishing Working Group (APWG) has reported, “After doubling in 2020, the amount of phishing has remained at a steady but high level. APWG saw 222,127 attacks in June 2021, which was the third-worst month in APWG’s reporting history.”

Phishing is a frequent and dangerous threat. CISA has reported that over 90% of successful cyber attacks start with a phishing email. Given this high risk, prevention of phishing and response to phishing should be included in comprehensive cybersecurity programs for businesses and organizations of all sizes. Particularly important is training to promote constant security awareness by all users of technology. One important message from CISA is “Think before you click.”

The following are Email Security Tips from Clark Hill’s ASSET360 group to help to protect against phishing:

  • Be alert for telltale signs:
    • Poor wording, typos, fuzzy/incorrect logos, generic body message
    • Unexpected/strange timing/oddly constructed
    • Instills urgency, greed, curiosity
  • Look for suspicious From addresses or Subject lines
  • Hover over URL hyperlinks to view the real web address
  • Never click links or open attachments
  • Use multi-factor authentication (MFA)
  • Ask: “Would this person be sending this request?”
  • Verify requests (e.g. wire fraud and change of payment instructions) verbally from a known contact at a known number (not in the email)

CISA has published a Phishing & Spoofing Tip Sheet for this week’s topic.

If you have questions about the content of this alert, please contact David Ries (dries@clarkhill.com; 412.394.7787), Lara K. Forde (lforde@clarkhill.com; 713.374.5743), or another member of Clark Hill’s Cybersecurity, Data Protection, and Privacy Group.

Subscribe for the latest

Subscribe

Related

Event

2025 California Labor and Employment Law Symposium

Join Clark Hill for a full-day symposium exploring the most pressing legal issues facing California employers today. Our California Labor & Employment attorneys, along with colleagues from our Immigration and Cybersecurity/Data Privacy groups, will provide practical insights, legal updates, and strategic guidance across a range of workplace topics. Whether your role is in-house counsel, HR leadership, or company executive, this event is designed to equip you with the tools to help navigate California’s ever-evolving employment landscape.

Explore more
Event

Webinar: End of Year Privacy Check-In: What’s Changed, What Hasn’t and What’s Happening in 2026

Attendees will gain insights specific insight into the definition of ADMT under the new rules, common in-scope use cases and requirements, risk assessment and cybersecurity audit obligations and expectations for regulatory focus in 2026. You’ll walk away with a “check-list” of compliance priorities for 2026.

The session will provide practical guidance for legal, compliance, and business teams preparing for compliance deadlines and navigating emerging privacy risks.

Explore more
Legal Updates

Section 232 tariffs expand to medium and heavy-duty vehicles, parts, and buses

On Oct. 17, President Donald J. Trump issued a proclamation under Section 232 of the Trade Expansion Act of 1962 imposing sweeping new tariffs on medium- and heavy-duty trucks, truck parts, and buses, marking the first time that the United States has applied Section 232 measures to an entire vehicle class outside the passenger car segment. The new tariffs, 25 percent on trucks and key truck parts and 10 percent on buses, will take effect on Nov. 1, and will apply according to the rules on tariff stacking.

Explore more