Every time you post a photo, fill in a profile field, or accept a friend request online, you leave a small piece of yourself behind. Individually, these details seem harmless. But put together, your name, birthday, school, workplace, and location create a detailed picture that cybercriminals can exploit – for identity theft, phishing, stalking, or fraud. According to the FBI’s 2024 Internet Crime Report, cybercrime losses reached $16.6 billion in 2024 alone – up from $12.5 billion the previous year. The good news? A few smart habits can go a long way in keeping you safer online.
Table of Contents
- Why you should think twice before sharing personal information online
- What counts as sensitive personal information?
- Using social media privacy settings to control your digital footprint
- Facebook privacy settings you should review
- Instagram and other platforms
- Keep revisiting your settings
- Being smart about online friends and connections
- The problem with fake profiles
- How to spot a suspicious friend request
- Sharing with online friends – even known ones – needs caution
- Additional security habits worth building
Why you should think twice before sharing personal information online
Social media is built around sharing – but that doesn’t mean everything is worth sharing. The challenge is that oversharing often happens without people even realizing it. A birthday post here, a vacation check-in there, a photo of a job offer – and before long, a stranger online knows more about you than you’d be comfortable with.
Social media users have a 30% higher chance of becoming fraud victims than those who aren’t active on these platforms. The risk is even higher on Facebook, Instagram, and Snapchat, where users face a 46% greater risk of account takeovers and financial fraud.
What counts as sensitive personal information?
Most people know not to post their Social Security number or bank details online. But identity thieves also target your phone number, home address, date of birth, email address, and even the names of your children or pets. Why? Because these details are frequently used as answers to security questions or as building blocks for password guessing. In fact, 59% of adults in the U.S. use their birthday and name to create passwords – and sharing that information publicly makes cracking accounts far easier for attackers.
Here are key categories of personal information to keep off social media:
- Location details – your home address, daily commute route, or the places you visit regularly.
- Vacation plans – posting about travel in real time tells the world your home is empty. Security experts recommend waiting until you return home before sharing vacation photos.
- Financial or document information – never photograph anything that reveals account numbers, passport details, or salary information.
- Your children’s details – names, schools, ages, or photos of children can be used in child identity theft or, more seriously, by predators.
A simple rule to follow: if you wouldn’t display it on a public notice board, don’t post it online.
Using social media privacy settings to control your digital footprint
One of the most effective steps you can take is reviewing and tightening your privacy settings – yet most users never bother. On most social media platforms, the default settings are not enough to adequately protect your personal information. Platforms like Facebook encourage you to fill in extensive profile details – school, workplace, hometown, relatives – and by default, much of this is visible to people you don’t know.
Facebook privacy settings you should review
Facebook offers one of the most detailed sets of privacy controls among major platforms. The Facebook Privacy Checkup tool walks you through your settings step by step. Key things to configure include: who can see your posts (Friends vs. Public), who can look you up using your phone number or email, whether your profile appears in search engine results, and who can send you friend requests. Also review your “About” section – remove any information that doesn’t need to be public, such as your phone number, precise location, or relationship details.
Instagram and other platforms
On Instagram, the most important step is switching your account to private, which restricts your profile and posts to only approved followers. This is especially important for younger users, since Instagram does not let you hide your follower list – meaning a bad actor who gets into your followers can see everyone else following you too.
On X (formerly Twitter), you can protect your posts by going to Settings and Privacy โ Privacy and Safety โ Audience and Tagging and enabling “Protect your posts.” This makes your content visible only to followers you approve.
Across all platforms, the Future of Privacy Forum recommends reviewing your location data settings carefully. Most apps ask for access to your location – often to personalize ads or share it with third parties – but in the majority of cases, there’s no reason to grant that permission.
Keep revisiting your settings
Privacy settings aren’t a one-time task. Platforms update their policies regularly, sometimes changing what is visible by default without alerting users. Revisit your account settings every few months to make sure nothing has changed without your knowledge. According to cybersecurity researchers, Meta’s frequent updates have caused older posts to resurface or become visible to wider audiences than users originally intended.
Also remember: what you share on social media might become public someday, even if it was only meant for a limited audience – through data breaches, platform policy changes, or companies sharing your information with third parties. The safest approach is to assume that anything you post could eventually be seen by anyone.
Being smart about online friends and connections
Social media makes it easy to accumulate hundreds – even thousands – of “friends” and followers. But not everyone who sends you a request has genuine intentions, and accepting unknown connections can open you up to serious risks.
The problem with fake profiles
On Facebook alone, an estimated 120 million accounts are fake. These profiles are created to scam users, gather personal information, spread propaganda, or launch phishing attacks. A 2024 analysis estimated that 64% of X (formerly Twitter) accounts could be bots – suggesting hundreds of millions of automated accounts on that platform alone.
Fake profiles are often convincingly set up with stolen photos and fabricated backstories. Cybercriminals use fake profiles to gather your personal information or launch phishing scams, sometimes impersonating someone you know to make you more likely to accept a request and lower your guard. Once they’re connected with you, they gain access to your posts, your friends list, and any personal information that’s only visible to connections.
How to spot a suspicious friend request
Before accepting any friend request from someone you don’t know personally, take a moment to investigate. Red flags to watch out for include: a very recently created profile, few or no personal posts, a profile picture that looks like a stock photo (you can check using a reverse image search on Google), an unusually low or high number of friends, and a list of connections that’s overwhelmingly of one gender. If something feels off, trust that instinct and reject the request.
Accepting a friend request from a stranger increases the risk of scammers spoofing your own profile – creating a duplicate of your account to then target your real friends and family. Your connections, who trust you, are far more likely to fall for messages appearing to come from your account.
Sharing with online friends – even known ones – needs caution
Even with people you do know online, be cautious about what you share in private messages. The UK’s National Cyber Security Centre advises using 2-step verification (2SV) on all accounts, since even if someone gets hold of your password, they won’t be able to log in without the second verification step. This also protects you if a friend’s account is hacked – so that a message appearing to come from them is not automatically trusted.
For younger users, the risks go beyond financial fraud. Online groomers often target children by sending out friend requests to see who responds, then build trust gradually through friendly conversation before steering discussions toward harmful territory. Research from Ofcom found that 30% of 12-15-year-olds had been contacted by a stranger online who wanted to be their friend. Children and parents should talk openly about this risk, and young users should always tell a trusted adult if an online contact makes them feel uncomfortable.
Additional security habits worth building
Beyond privacy settings and careful connections, a few more habits make a significant difference. The U.S. Department of Veterans Affairs recommends using passwords of at least 12 characters – mixing uppercase, lowercase, numbers, and special characters – and updating them every four to six months. Never reuse the same password across multiple accounts; a single breach can then cascade into multiple compromised accounts.
Enable multi-factor authentication (MFA) wherever possible. This adds a second layer of verification beyond your password. According to the NCSC, even if a criminal knows your password, they won’t be able to access any account protected with 2-step verification. Most major platforms – Facebook, Instagram, X, Snapchat – offer this option in their security settings.
Finally, avoid logging into your social media accounts on public computers or shared devices. If you don’t fully sign out on a public device, your account can remain accessible to the next person who uses it. Similarly, use caution when accessing personal accounts on public Wi-Fi networks – these connections are vulnerable to interception, particularly if the sites you’re visiting don’t use HTTPS encryption.
What do you think? Now that you know how much personal information can be pieced together from your social media activity, would you make changes to what you currently share online? And if you were advising a younger sibling or student about accepting friend requests, what would be the one rule you’d insist they follow?
References
- https://www.iii.org/fact-statistic/facts-statistics-identity-theft-and-cybercrime
- https://www.identityguard.com/news/social-media-identity-theft
- https://www.adirondackbank.com/blog/from-likes-to-identity-theft-the-unseen-risks-of-social-media-on-your-finances-and-personal-information
- https://its.uky.edu/news/how-oversharing-on-social-media-could-put-your-personal-information-risk
- https://www.thecyberhelpline.com/helpline-blog/2024/7/24/your-data-and-privacy-on-social-media
- https://www.facebook.com/privacy/checkup/
- https://fpf.org/blog/7-essential-tips-to-protect-your-privacy-in-2024/
- https://rainn.org/safe-media
- https://department.va.gov/privacy/fact-sheet/safeguarding-your-online-presence-privacy-best-practices-for-social-media/
- https://www.cleartechgroup.com/is-that-social-media-friend-request-real/
- https://www.totaldefense.com/security-blog/friend-request-stranger-danger-on-social-media/
- https://cmitsolutions.com/blog/fake-social-media-friend-requests-represent-latest-ploy-scammers/
- https://verveacu.com/2018/12/06/think-twice-about-accepting-that-friend-request/
- https://www.ncsc.gov.uk/guidance/social-media-how-to-use-it-safely
- https://www.internetmatters.org/issues/online-grooming/learn-about-it/
- https://dataprivacymanager.net/how-to-protect-your-privacy-on-social-media/
Leave a Reply