The Cybersecurity Myths That Still Catch People Out

Sep 02, 2026By Jay Kells
Jay Kells

The Cybersecurity Myths That Still Catch People Out

I hear the same handful of cybersecurity myths over and over, usually from people who think of themselves as careful. They're not reckless, they just picked up a rule of thumb somewhere along the way that stopped being true, or was never quite true to begin with. This isn't a general list of security tips. It's the specific misunderstandings that keep coming up when I actually talk to people about what's put them at risk, and why each one is more dangerous than the truth it's covering up.


The Padlock Icon Doesn't Mean What Most People Think


For years the advice was simple: look for the little padlock in the address bar before you trust a site. That padlock only tells you the connection between your browser and the site is encrypted, nothing about who actually runs the site or whether they're being honest with you. Free encryption certificates are trivial to get, and most phishing sites now use them as a matter of course precisely because people still associate the padlock with safety. A fake banking page with a padlock is no safer than one without it, it just looks more convincing to someone who was taught the wrong lesson. I still check for it, but it's the last thing I check, not the first. What actually matters is the domain itself, spelled out carefully, checked for the extra letter or the swapped word that a genuine site would never have, not the icon sitting next to it.


A Pop-Up Warning About a Virus Almost Never Comes From Real Antivirus Software


If a browser tab suddenly fills your screen with a flashing warning that your device is infected, complete with a countdown timer and a phone number to call immediately, that's not how any legitimate antivirus product behaves. Real antivirus software runs quietly in the background and alerts you through its own interface, not through a website you happened to land on. The whole point of that fake warning is to panic you into calling a number that connects you to someone who'll either charge you for a fake fix or get remote access to your device. I've written separately about the specific antivirus myths I keep having to correct, and this one sits right alongside them: real protection doesn't shout at you through your browser, and Bitdefender is the actual antivirus software I run precisely because it works without ever needing to.


My Phone Doesn't Get the Same Protection as My Laptop, and That's the Problem


A lot of people who are genuinely careful on their laptop treat their phone as something inherently safer, mostly because app stores feel more curated than the open web. That confidence doesn't hold up. Phones carry banking apps, authentication codes, and years of message history, and text-based phishing, usually called smishing, works precisely because people who'd hesitate over a suspicious email will tap a link in a text without a second thought. I check app permissions on my phone the same way I'd check anything installed on a computer, and I treat a suspicious text exactly the way I'd treat a suspicious email, not as a lesser risk just because it arrived on a smaller screen. I also keep my phone's operating system updated the moment a new version is available rather than putting it off for a few weeks, since a lot of those updates are quietly patching the exact vulnerabilities that make a phone worth targeting in the first place.

My Bank Won't Always Call to "Verify" Something, and Neither Will Most Companies


The myth that does the most damage is the belief that a call claiming to be your bank must be genuine because it sounds official and the number on your screen matches. Caller ID can be spoofed convincingly enough that the number itself proves nothing, and any bank that actually needs to reach you will never ask you to read out a one-time passcode over the phone, because that code exists specifically to stop someone doing exactly that. My rule is simple: if a call asks me to verify anything sensitive, I end it and call my bank back on the number printed on my card, not the number that just rang me. Action Fraud has documented this exact pattern across thousands of reported cases, and it's worth reading if you want to see how convincing these calls have become.

Customer hand selecting from colorful array of newspapers and magazines displayed on newsstand counter in natural light


Scams Don't Only Target People Who Aren't Careful


The most persistent myth of all is the quiet belief that scams happen to other people, usually people who aren't paying attention. I've corrected plenty of overconfident assumptions like that before, and this is the one that trips up genuinely careful people the most, because it makes them slower to question something aimed specifically at them. Sophisticated scams are built around timing and pressure, not carelessness, and a convincing message that lands at the exact moment you're expecting a delivery or waiting on a payment can catch out someone who'd never fall for an obvious one. I've spoken to people who work in finance, in tech, people whose entire job is spotting exactly this kind of thing, who've still been caught out once by a message that arrived at precisely the wrong moment. Assuming you're not the type doesn't make you a smaller target. It just means you're less likely to notice when you already are one.

None of these myths are stupid to have believed. They were reasonable shortcuts that made sense at some point, and most people never got a clear reason to update them. My free Safety Toolkit covers the account-level habits that hold up regardless of which of these myths you grew up believing, and correcting even one of them tends to change how you read the next message that lands in your inbox.