Defending Your Turf: Your Defensive Playbook Against the New Cyber Playing Field

Defending Your Turf: Your Defensive Playbook Against the New Cyber Playing Field

Cybersecurity , OIT News   |  Oct 5, 2026  |  By Alejandra Castro-Ruiz
Padlock on top of computer keyboard.

Listen to this article

Scams are changing. Your instincts should, too.

Imagine walking across campus when a colorful flyer catches your eye. There’s a QR code attached for insight into an event, a club meeting, or to purchase tickets. Without thinking twice, you pull out your phone and scan the code.

Scanning QR codes to access digital content is part of our daily routine, but do you ever stop yourself to ask if the code is legit?

As QR codes and artificial intelligence (AI) become a bigger part of our daily lives, making many tasks faster and easier, cybercriminals are finding new ways to use these technologies to target everyday people.

This Cybersecurity Awareness Month, the focus is “cybersecurity is a team sport.” As the playing field changes, staying safe goes beyond creating a strong password and watching out for phishing emails. If something seems suspicious, slow down, verify through another channel, and report it or ask for help.

The QR Curveball
QR codes are everywhere. You see them on flyers, event signs, menus, and tickets. For many of us, scanning one has become a reflex.

According to Air Apps, 57 percent of 18-to-34-year-olds use them frequently, and half of Gen Z and Millennials report they scan QR codes at least once a week.

Cyberattacks targeting the use of QR codes are known as QR phishing, or quishing. Digital foul play is on the rise, as attackers often plant a malicious QR code on legitimate posters or send it through emails or text messages. When scanned, victims could be directed to fake websites designed to collect personal information or to a harmful malware download.

These types of scams are growing. Microsoft Threat Intelligence and the Microsoft Defender Security Research Team highlight the scale of this threat, stating that attack volumes in 2026 rose from 7.6 million in January to 18.7 million in March.

“QR-code phishing is scaling quickly because attackers can send one image to thousands of people, bypass some email-link protections, and move the interaction onto a personal phone,” says Jill Theroux, senior security analyst with UNLV IT’s Information Security Office. She also notes that the FBI has warned that academic institutions are being targeted with QR codes embedded in spear-phishing messages.

Play Defense: Think Before You Scan:

  • Consider what the code is asking you to do: Be cautious if a QR code unexpectedly asks you to log in, enter multifactor authentication (MFA) codes, provide information to recover your account, or make a payment.
  • Avoid QR codes sent in unexpected emails or text messages: Never scan a QR code sent in an unexpected message. Instead, contact the organization directly through a trusted website or phone number.
  • Inspect the web address before opening the link: Before opening a scanned link, check for misspellings or look-alike website addresses that don't match the organization you expect.
  • Protect your devices and accounts: Keep your phone’s operating system up to date, use strong passwords, and utilize MFA.
  • Report phishing: Every phishing event reported helps stop an attack while protecting you and your teammates.

Spotting the Deepfake Play


Can You Spot the Deepfake?

Now, you’re scrolling through social media and come across a video of your professor, a campus administrator, a coworker, or even a friend saying something they never actually said.

It looks like them, and sounds like them, too. But is it really them?

Deepfakes use AI and machine learning to create realistic videos, pictures, and audio. They can be used to pretend to be someone else, spread false information, or persuade someone to share information or take an action.

According to a report by Station X, eight million deepfakes are circulating online in 2026, with deepfake fraud accounting for roughly 6.5 percent of all fraud attempts globally, resulting in over $200 million in losses.

Deepfakes are also becoming harder to spot. AI can create convincing copies of familiar voices, faces, and movements, making it difficult to rely on what you see or hear alone.

Check the Play: Signs Something May Be Off:

  • Watch for visual distortions: Look for awkward, unnatural facial expressions, glitchy lip-syncing, and flaws in lighting or shadows.
  • Listen for unusual audio: Unnatural or robotic speech, strange pauses, unexpected questions, or intense pressure to do something can be warning signs.
  • Verify the person’s identity: Call or message the person directly using a phone number, account, or platform you already know and trust. Don’t reply directly to the suspicious message.
  • Report it: If you’re unsure whether something is real, preserve the original message with a screenshot or screen recording and report it to the UNLV Information Security Office or the IT Help Desk. If the deepfake involves an immediate safety concern such as harassment and threats, contact the Title IX office or campus police. Never download or reshare the content.

“Most cyberattacks rely on urgency, fear, curiosity, or pressure to make us act before we think,” Theroux says. “This is why slowing down matters more than ever. A few extra seconds can prevent a compromised account, financial loss, or a breach affecting the entire college community.”

Phishing and deepfake attacks represent a new phase of digital security in our everyday lives. Something seems off? Your best defense is to slow down, verify it another way, and know when to report or ask for help. The ball is in your court.

More information and resources can be found on the cybersecurity webpage on the UNLV Information Technology site.