Cybersecurity and Mental Health: The Impact We Don't Always See
Cyberattacks can affect more than computers they can also create emotional stress and strain relationships across the campus community. Explores how attackers use tactics such as phishing emails and MFA fatigue to manipulate users, and explains how to recognize and report these threats quickly. Learn why victims should not blame themselves after an attack and where to find campus resources and support.
When people think about cybersecurity, they often think about technology: passwords, firewalls, malware, and data protection. But cybersecurity is also about people. Behind every account, device, and piece of personal information is someone who may experience fear, stress, embarrassment, or uncertainty when a cyber threat occurs.
Cybersecurity incidents are often discussed in terms of technical damage. Was an account accessed? Was malware installed? Was information exposed? While these questions are important, they do not tell the whole story. A cyberattack can also affect a person's sense of safety, privacy, control, and trust.
For our campus community, these effects can extend into academic responsibilities, professional relationships, and everyday life.
How Cybersecurity Threats Create Stress
A cybersecurity incident can disrupt the sense of security people associate with their digital accounts. Email, Canvas, Workday, research tools, and other services are part of everyday life. When access to those systems is threatened, people may feel that something familiar and dependable is no longer under their control.
Common emotional responses may include:
- Anxiety about what information may have been accessed.
- Embarrassment after interacting with a fraudulent message or website.
- Frustration with the time and effort required to recover an account.
- Loss of control over communications, files, or online identity.
- Uncertainty about whether the threat has been fully resolved.
- Fear that personal information may be misused.
- Concern about relationships if others receive suspicious messages from a compromised account.
These reactions do not mean someone is overreacting. Digital accounts often contain personal, academic, professional, and financial information. A threat to that information can feel like a threat to a person's privacy and identity.
A Montclair Example: Phishing and Account Compromise
This is not a hypothetical scenario. Our campus regularly sees phishing attempts that use this type of social engineering to target students and employees.
The attack often begins with an email that appears to come from IT. The message warns that the recipient's account will be deactivated unless they take immediate action. A link in the email leads to a fraudulent form designed to collect information such as email address, password, and phone number.
The attack switches over to text, with the attacker impersonating the IT Service Desk and continuing the conversation as though they are trying to help. The attacker will ask the user to verify their password or provide a Duo code or approve a Duo request. Repeated unexpected Duo requests, sometimes referred to as MFA bombing or MFA fatigue, can be used to pressure someone into approving access.
Once an attacker gains access to an account, they can use that account to send phishing messages to campus community members. Because the messages come from a legitimate university account, recipients may be more likely to trust them.
The technical university response may begin when Information Security receives a report of the compromised account. The account can then be contained and the password reset to remove the attacker's access. For a personal account, the individual would need to work directly with the service provider to secure and recover the account. But securing the account does not necessarily end the experience.
The person whose account was compromised may be left dealing with embarrassment, anxiety, frustration, and uncertainty about what happened. They may also discover that people responded negatively to phishing messages sent from their account. Those responses can be especially difficult to see because the account owner did not send the original message, yet the responses are directed back to their account.
This is one way a cybersecurity incident can move beyond technology and begin affecting a person's sense of trust, reputation, and well-being.
When Account Compromise Affects Relationships
A compromised account can create confusion and strain relationships because recipients may believe that messages sent from the account were intentionally written by the account owner.
For example, someone who receives a phishing message from a familiar Montclair email address may respond with frustration, anger, or inappropriate and hurtful language. Those responses may then arrive in the compromised account's inbox, even though the account owner did not write the original phishing message.
When the account owner later sees those responses, they may feel embarrassed, misunderstood, or worried about how others perceive them. They may also feel hurt by messages directed at them for something they did not knowingly do. Cybersecurity incidents can therefore affect more than passwords and devices. They can influence trust, communication, and relationships across campus.
Recipients should pause before assuming that a familiar sender intentionally sent a suspicious message. Reporting the message through the appropriate channels is more helpful than responding impulsively. A compromised account may not be under the control of the person whose name appears in the sender field.
Cybersecurity Risks Beyond Phishing
Phishing and account compromise are only some of the cybersecurity threats that can affect mental health. Other incidents may create different concerns.
Identity theft and financial concerns: Exposure of personal information can create worry about financial loss, fraudulent accounts, or misuse of personally identifiable information. Even when no financial harm occurs, the fear that it could happen may be stressful.
Privacy violations: A person may feel vulnerable if private emails, photographs, documents, or other information are accessed or exposed without permission. The uncertainty surrounding what someone viewed or copied can be especially difficult.
Cyberstalking and online harassment: Cyberstalking, harassment, threats, and targeted abuse can affect a person's sense of safety both online and offline. These experiences may lead to isolation, difficulty concentrating, or reluctance to participate in online spaces.
Faculty and staff may also experience stress when a university system or service is affected. Concerns may involve student information, employee records, departmental communications, or other responsibilities connected to their work.
Students may worry about academic records, financial-aid communications, personal information, or messages sent from their accounts. In both cases, the concern is not only what happened technically, but also what the incident may mean for their responsibilities, reputation, and relationships.
Why People May Blame Themselves
One of the most difficult emotional responses to a cyberattack can be self-blame.
Someone may think:
- “I should have noticed the warning signs.”
- “I should have known the message was fake.”
- “I caused problems for everyone else.”
- “I should have handled the situation differently.”
Cyberattacks are designed to manipulate people. Attackers use urgency, fear, authority, familiarity, and confusion to influence decisions. A person can be knowledgeable, careful, and still become a target.
A mistake or moment of uncertainty does not make someone responsible for the attack. Reporting the incident quickly is more important than hiding it out of embarrassment. Early reporting can help secure the account, limit further harm, and protect others from being targeted.
Responding to a Cybersecurity Incident
A supportive response should address both the technical and emotional aspects of an incident.
Pause and Verify
Do not click suspicious links, provide passwords, share Duo codes, or approve unexpected MFA requests. Use the Phish Alert Button (PAB) or email phishfiles@montclair.edu to report the message.
Report Quickly
If information has been submitted or an unexpected login request has been approved, contact phishfiles@montclair.edu. Do not delay because of embarrassment or fear of being blamed.
Avoid Blaming the Victim
People who experience account compromise need clear instructions and support, not ridicule or hostility. Blaming can discourage others from reporting future incidents.
Respond Carefully to Suspicious Messages
If a suspicious message appears to come from someone you know, avoid assuming that the person intentionally sent it. Report the message, preserve relevant information, and contact the apparent sender through another trusted method if necessary.
Seek Support
If a cybersecurity incident causes ongoing distress, anxiety, difficulty concentrating, or problems functioning, consider reaching out to the appropriate campus resource:
- Students: Visit CAPS Services & Support webpage for options available to you.
- Faculty & Staff: Visit the Employee Assistance Program webpage for option available to you.
Seeking support is a normal part of recovering from a stressful event, it does not diminish the seriousness of the cybersecurity incident itself.
Building a More Supportive Cybersecurity Culture
A strong cybersecurity culture is not based only on warnings or technical controls. It also depends on trust.
People should feel comfortable asking whether a message is legitimate, reporting suspicious activity, and admitting when they may have entered information or approved a request. They should know that the goal of reporting is to reduce harm, not to assign blame.
The campus community also has a responsibility to respond thoughtfully when suspicious messages are received. A familiar sender may be the victim of an account compromise rather than the person responsible for the message. By combining technical preparedness with empathy, universities can reduce both the impact of cyber threats and the emotional harm that may follow them.
Protecting Accounts and People
Cybersecurity is often measured by whether an attack was blocked, an account was secured, or information was protected. Those outcomes matter, but the well-being of the people involved matters too.
A phishing email can create fear. A privacy violation can damage a person's sense of safety. An account compromise can create uncertainty. A supportive response can help restore confidence and reduce the lasting effects.
Protecting accounts is important, but protecting people is equally important. Cybersecurity isn't just about keeping accounts and systems secure. It's also about helping others feel informed, supported, and safe in the digital spaces they depend on daily.
- Published
- Type
- Topic