What I Actually Tell People About Social Media Safety

Jul 27, 2026

Social media is where most of the scams and impersonation attempts I hear about actually start now, more than email most weeks. It's not because the platforms are badly built, it's because that's where everyone already is, friends, family, strangers, and the people trying to take advantage of all three. Here's what I actually tell people when they ask me how to use it without becoming an easy target.

None of this means deleting your accounts or treating every message as a threat. It means knowing which few things are actually worth locking down, and not wasting energy on the rest.

The Friend Request That Isn't Your Friend

Cloned profiles are the one I get asked about most. Someone copies a real person's profile picture, name, and public photos, builds a near-identical account, and sends friend requests to that person's actual friends list. Once you've accepted, the message usually follows within a day or two, an emergency, a gift card, a "can you lend me this until Monday". The photos and mutual friends make it convincing at a glance, especially now that AI makes it trivial to generate a full set of fake images rather than just steal real ones, something I've covered in more detail in the AI scams I keep hearing about. Before accepting any request from someone you're apparently already friends with, check whether the original account still exists. If it does, that request is fake. It costs ten seconds and it's the single most useful habit I can give you here.

The Privacy Settings Most People Skip

Most people set their privacy settings once when they first sign up and never touch them again. It's worth a five minute check every so often. Turn off public visibility on your full friends list, since that's exactly what a cloned profile needs to look convincing. Limit who can find you by phone number or email, and switch off location tagging on photos unless you genuinely need it there. I also keep the password on each account unique and stored in NordPass, since a reused password is often the quickest way in if a friend's account gets compromised first. None of this makes your account bulletproof, but it makes you a noticeably less appealing target than the account next to yours with everything left wide open.

What Not to Post, Even If It Feels Harmless

Some of what gets shared without a second thought is exactly what scammers and identity thieves are looking for. Your full date of birth, your child's school, a photo of a boarding pass, or a "which decade do you belong in" quiz that quietly asks for your mother's maiden name along the way. None of it looks dangerous in isolation. Pieced together, it's often enough to answer a bank's security questions or guess a password. I'm not saying don't post, I'm saying think about what a stranger could actually do with it before you do.

Quizzes and Apps Are Data Harvesting in Disguise

Every personality quiz and every app asking to connect to your account is collecting something, usually your friends list, your email, and whatever personal questions the quiz itself asked you to answer publicly. Most of it is genuinely used for nothing worse than ad targeting. Some of it ends up being sold on, or used to build exactly the kind of profile a scammer needs to impersonate you convincingly. I treat any app requesting more access than it obviously needs to function as a reason to say no, not a reason to read the fine print.

Marketplace and Buy-Sell Groups Have Their Own Rules

Buying and selling through social media has its own specific scams: fake listings for items that don't exist, buyers who "accidentally" overpay and ask for a refund of the difference, sellers who ask you to pay outside the platform's protection where there's no way to get your money back if it goes wrong. Meet in a public place for anything local and worth more than pocket change, and treat any request to move the conversation off the platform as the red flag it usually is.

Protecting Kids Without Spying on Them

If you've got children on social media, the aim isn't to read every message they send, it's to make sure they know what to do when something feels wrong. Talk to them about what a cloned or fake profile looks like, and agree that any online friend requesting money or private photos gets reported and told to you, not handled alone. Age-appropriate privacy settings and a genuinely open conversation do more than any parental control app I've come across.

What I Do the Moment Something Feels Off

If a message asks for money, the urgency feels manufactured, or a "friend" is suddenly writing completely differently to how they normally do, I stop and verify through a separate channel, a phone call, a text, anything that isn't the account that just messaged me. A lot of these messages are really just phishing wearing a different platform, so the same red flags I check when I try to spot a phishing email apply here too. If it turns out to be a scam, I report it through the platform and, if money or personal details were involved, through Action Fraud as well, since that feeds the intelligence that gets the next version of that scam caught earlier. My Safety Toolkit has the settings and tools I actually use to keep my own accounts locked down, and it's worth five minutes of anyone's time.