le of cyber threats The growing ubiquity of cyberattacks is a concern for even tech-savvy individuals, who tech experts said must upgrade their online defenses to keep their information private. For example, even an individual wary of phishing emails, which often contain spelling errors and suspicious links, could fall victim to a much more sophisticated, AI-enabled scam that uses deepfake technology. When most people encounter scams, they are messages from people they don't know, Higginbotham said. Armed with personal information obtained in a security breach, such as your physical address, a scammer could pose as a financial institution and offer you a tempting mortgage rate, for example. AI allows scammers to make better use of the personal data they have on consumers, and lowers the cost of reaching even more people with those personalized messages, Higginbotham said. She noted that one in every five scams includes some kind of customization, a share that's expected to grow quickly. More data breaches mean there's more personal information out there, and AI makes it easy to craft personalized messages, she said. The personalized nature of the scams is what makes bad actors more capable, experts said. Prior to AI, the level of effort required to personalize something was too great. You couldn't personalize 50 phishing messages; it was too much work, Colin Ferris, a cybersecurity expert at Silverfort, told CBS News. Two-factor authentication is a must Security measures, like some forms of multifactor authentication, that might once have seemed redundant or unnecessary are now essential, according to experts. While personal precautions are necessary, they're not sufficient, according to Brian Cute, president and CEO of the Global Cyber Alliance, who said in a statement that they alone can't stop the abuse coming from upstream via insecure routing and maliciously registered domain names. Closing those gaps takes industry, government and philanthropy working together, and that collaboration is as essential to a safer Internet as any password or security patch, he said. The 9-second rule One low-tech way to combat cyberattacks is to pause for a few seconds before clicking on, downloading or sharing a link. An initiative called Take9 encourages people to count for nine seconds before responding to suspicious texts or emails, prompting users to reset their bank passwords, for example.