Home Skills Base Digital security threats

Skills Base

Digital security threats

Why identity theft risk spikes after disasters, how to recognize phishing attempts that exploit emergency situations, what using public Wi-Fi at shelters actually risks, and what security concerns smart home devices create.

DomainHome security
Skill areaHome security
TypeInfo Page

01 — Why identity theft risk increases after disasters

Disasters create information chaos, and information chaos is an identity thief's operating environment

CISA and the Federal Trade Commission both document a consistent pattern: identity theft attempts and fraud schemes reliably spike in the days and weeks following a major disaster. The reasons are structural. Displaced people are applying for assistance through multiple channels, often providing personal information including Social Security numbers, bank account details, and insurance policy numbers to agencies and organizations they have had little time to vet. The chaos of the immediate post-disaster period means that normal verification habits are suspended, documents may be lost or unsecured, and people are receiving a higher-than-usual volume of communications claiming to be from government agencies, insurers, and relief organizations.

CISA's guidance on post-disaster scams identifies the specific information that most commonly becomes compromised: Social Security numbers used in FEMA and SBA applications, financial account information provided for direct deposit of benefits, and personal identifying information given to contractors and relief organizations whose legitimacy has not been verified. The FEMA application itself is a legitimate process, but fraudsters exploit the parallel flow of real FEMA communications to create convincing impostors. FEMA explicitly warns that its inspectors will never charge fees and that legitimate FEMA communications will always include a registration number the applicant can verify.

  • Apply for FEMA assistance only through official channels. The official FEMA application is at DisasterAssistance.gov or by calling 1-800-621-3362. FEMA inspectors do not charge fees, solicit financial information beyond what the official application requires, or contact applicants through unofficial channels. Any contact requesting payment or sensitive personal information outside the official application process should be reported to FEMA's fraud hotline.
  • Place a credit freeze after a major disruption. The FTC makes free credit freezes available at all three major bureaus (Equifax, Experian, TransUnion) as a right under federal law. A freeze prevents new accounts from being opened in the applicant's name even if a fraudster has obtained personal information. It can be lifted temporarily when the household needs to apply for credit and reinstated immediately afterward.
  • Monitor accounts actively during and after a disaster period. The FTC and CISA both recommend checking bank account and credit card statements more frequently during a disaster recovery period. Unauthorized charges in small amounts are common indicators that account information has been compromised; small charges are often used to test whether an account is live before larger transactions are attempted.
  • Protect physical documents during evacuation. Documents lost in a disaster often cannot be immediately replaced. If time allows before evacuation, secure the physical documents identified in FEMA's Emergency Financial First Aid Kit: Social Security cards, passports, birth certificates, insurance policies, and financial account records. Documents that cannot be taken should be photographed and stored in cloud backup before leaving.

02 — Recognizing phishing attempts in a disaster context

Phishing exploits urgency, authority, and topic relevance — disasters provide all three

CISA's guidance on social engineering and phishing attacks identifies the specific environmental conditions that make individuals most vulnerable to phishing: urgency, the appearance of authority, and topic relevance to the recipient's current situation. A disaster creates all three simultaneously. A displaced household waiting for a FEMA decision, trying to reach their insurance company, and monitoring communications for updates about their home is receiving communications about exactly the topics that a phishing attack would exploit, and is doing so under time pressure that reduces the careful verification that would otherwise flag suspicious messages.

CISA identifies four reliable indicators of phishing in email communications. Generic greetings rather than the recipient's name, a lack of contact information in the signature, hyperlinks that do not match the text displayed when hovering over them, and poor grammar, spelling errors, or inconsistent formatting are each signals that a communication may not be from the claimed source. Legitimate government agencies, insurance companies, and financial institutions use the recipient's name, include verifiable contact information, and do not send emails with mismatched links. In a disaster context, a fifth indicator is relevant: unsolicited contact that claims to be related to the disaster but comes through a channel the recipient did not initiate.

  • Verify by independent lookup, not by using contact information in the message. CISA's anti-phishing guidance is direct on this point: if a message appears to come from a known institution, verify it by looking up the institution's contact information independently through a search engine or a previously saved contact, not by calling a number or clicking a link from within the message. A phishing attempt that includes a fraudulent phone number or link cannot be verified through those channels.
  • Check the actual URL of any link before clicking. Hovering a cursor over a hyperlink in a desktop email client reveals the actual destination URL. A link displaying "disasterassistance.gov" that resolves to a different domain is a phishing link. On mobile devices, this behavior can be replicated by pressing and holding a link rather than tapping it to see the destination before clicking.
  • Urgency is a manipulation technique, not a feature of legitimate communications. CISA's guidance identifies communications that "implore you to act immediately" as a warning signal. Legitimate agencies have defined timelines and standard deadlines; they do not send messages claiming that failure to respond within hours will result in losing benefits. Urgency that compresses normal verification time is a technique, not a genuine constraint.
  • Report phishing attempts to both the agency being impersonated and to CISA. Phishing emails impersonating FEMA or other federal agencies should be forwarded to the FBI's Internet Crime Complaint Center at ic3.gov and to CISA at cisa.gov/report. Reporting allows the agencies to issue alerts and shut down fraudulent sites more quickly.

03 — Public Wi-Fi at shelters and community charging stations

An open network shared with strangers is not a secure network, regardless of who operates it

Emergency shelters, community centers, and disaster relief staging areas often provide public Wi-Fi to support displaced residents. CISA's guidance on cybersecurity hygiene notes that public Wi-Fi networks create two distinct categories of risk. The first is network interception: on an unencrypted public network, data transmitted without HTTPS encryption can be read by other devices on the same network. The second is shoulder surfing: in crowded public spaces, the physical visibility of screen content to people nearby is a real and simple attack vector that requires no technical sophistication.

The operational implications for a household using shelter or community Wi-Fi are straightforward. Activities that require entering sensitive credentials, including banking, accessing government benefits portals, or entering Social Security numbers, carry higher risk on public networks than on a private cellular data connection. A household's cellular data plan, even if limited, provides a private encrypted connection that a shared shelter Wi-Fi does not. For activities that must be performed on a shared network, ensuring that the website uses HTTPS (visible in the address bar and, on most browsers, indicated by a padlock icon) provides a baseline encryption layer that protects data from most forms of network interception.

  • Use cellular data for sensitive transactions, not public Wi-Fi. When a personal cellular data connection is available, use it for banking, FEMA applications, insurance communications, and any activity involving financial account numbers or government ID numbers. Reserve public Wi-Fi for lower-sensitivity activities: news reading, communication apps that encrypt their own traffic, and non-sensitive browsing.
  • Confirm HTTPS before entering any credentials. CISA's guidance specifies that the address bar should show "https" before entering personal information on any website. The "s" indicates that the connection between the browser and the web server is encrypted. On a public network, HTTPS does not prevent every attack, but it prevents the most common form of interception that an untrusted network enables.
  • Be conscious of screen visibility in crowded spaces. CISA's identity theft guidance notes that "strangers can easily shoulder surf and see the sensitive information on your computer or mobile device screen" on public Wi-Fi. Adjusting screen brightness, using a screen privacy filter if one is available, and positioning toward a wall rather than an open space are practical reductions in physical interception risk.
  • Log out of sensitive accounts after completing transactions. Remaining logged into financial or government accounts while on a shared network extends the exposure window beyond the specific transaction. Logging out explicitly, rather than simply closing the browser, terminates the active session on the server side.

04 — Smart home device security concerns

A device connected to the internet is an entry point into the home network

Smart home devices, including connected cameras, smart locks, smart speakers, video doorbells, and home automation hubs, provide convenience and some genuine security benefits. They also create an expanded network attack surface. CISA's guidance on IoT device security notes that each connected device is a potential entry point for unauthorized access to the home network, and that the security standards of consumer IoT devices vary considerably. Devices with weak default passwords, infrequently updated firmware, or unencrypted communication protocols can provide a path into the home network that bypasses the router's own security.

The specific concern during preparedness planning is the failure mode of these devices during and after a disruption. A smart lock that depends on a cloud service that becomes unavailable can fail to operate normally. A connected camera system that relies on cloud storage may be unable to record or alert during extended internet outages. An internet-connected security system that requires a subscription that lapses during financial disruption may become non-functional. Understanding the failure mode and offline behavior of each connected device is part of security planning, not an afterthought.

  • Change default usernames and passwords on all connected devices immediately after setup. CISA's IoT guidance consistently identifies default credentials as the most common attack vector on home network devices. Manufacturers ship products with known default passwords, many of which are published in publicly available documentation. Changing both the username and the password on every connected device, including the home router itself, closes the most exploited vulnerability.
  • Keep firmware updated. CISA's home network security guidance identifies firmware updates as essential because they address discovered security vulnerabilities. Many consumer IoT devices allow automatic firmware updates to be enabled; where this option exists, it should be. Devices that have stopped receiving manufacturer updates present ongoing unpatched vulnerabilities.
  • Know the offline failure mode of every security-relevant device. For any device that provides access control (smart locks, automated garage door openers, keypad entry systems), determine whether it defaults to locked or unlocked when power or internet connectivity is lost. This information is in the device documentation and determines whether a power outage or internet disruption leaves an entry point accessible or secured.
  • A connected camera is only as reliable as its network and power. A camera that depends on home Wi-Fi, cloud storage, and grid power provides no monitoring during a power outage unless it has battery backup, local storage, and cellular fallback. Understanding which conditions each device requires for normal function allows the household to plan for what fails first in a disruption.

Smart locks and power outages

Smart lock failure modes vary by manufacturer and model. Some default to locked on power failure (which may prevent entry without a physical key); others default to unlocked for fire-safety compliance. Every household with a smart lock on a primary entry door should know which behavior applies to their specific device and ensure a physical key is accessible for scenarios where the electronic function is unavailable.

Quick reference

  • Post-disaster identity theft: apply for FEMA only through DisasterAssistance.gov or 1-800-621-3362. Place a credit freeze at all three bureaus (free, federal right). Monitor accounts actively for small unauthorized transactions during the recovery period.
  • Phishing recognition: verify by independent lookup, not by contact information in the message. Check the actual URL before clicking. Urgency is a manipulation technique. Report impersonation attempts to ic3.gov and cisa.gov/report.
  • Public Wi-Fi: use cellular data for sensitive transactions. Confirm HTTPS before entering credentials on any public network. Log out of sensitive accounts when finished; do not remain logged in on a shared network.
  • Smart home devices: change default credentials on every connected device immediately. Enable automatic firmware updates. Know each security device's failure mode during power or internet outage. Keep a physical key for any door with a smart lock.

Primary sources

  1. CISA: Avoid Scams After Disaster Strikes (October 2024): the pattern of elevated identity theft and fraud following disaster declarations; referrals to FTC and CFPB resources for disaster fraud reporting.
  2. CISA: Identity Theft and Internet Scams Tip Card: phishing defined as email or malicious websites collecting personal information; imposter scams; the public Wi-Fi shoulder-surfing risk; the "https" website check; advice against sharing sensitive information on public networks.
  3. CISA: Avoiding Social Engineering and Phishing Attacks: the four phishing indicators (generic greeting, no contact information, mismatched hyperlinks, poor grammar and formatting); the definition of social engineering; how attackers exploit natural disasters as phishing themes; urgency as a manipulation technique.
  4. CISA: Securing Your Home Wi-Fi (Project Upskill, Module 5): home network security guidance including router credential changes and the security importance of keeping all network-connected devices updated.
  5. CISA / US-CERT: IC3 Alert on IoT Device Security Risks: the FBI Internet Crime Complaint Center alert on IoT vulnerabilities including smart home devices; the recommendation to review IoT security configurations.