Security & Privacy
How to Protect Yourself on Social Media
A calm, jargon-free guide to staying safe on social media, covering privacy settings, oversharing, suspicious messages, and keeping control of your accounts.
Security & Privacy
A calm, jargon-free guide to staying safe on social media, covering privacy settings, oversharing, suspicious messages, and keeping control of your accounts.
The three changes that protect you most: set your account to private, turn on app-based two-factor authentication (not SMS), and use a unique password stored in a password manager. Everything else in this guide refines those three, but if you only do them once and walk away, you have already closed the doors attackers use most often.
Every major platform ships with defaults tuned for reach, not privacy. Your first job is to reverse that. Here is where the switch lives on each app as of 2026, though menus shift with redesigns:
A private account matters because it changes who can screenshot, forward, or scrape your content. Public profiles are routinely harvested by automated tools that build marketing and impersonation databases. Going private does not make you invisible to friends; it just means new followers need your approval.
While you are in those menus, find the setting that controls whether people can locate you by phone number or email. On Instagram and Facebook this sits under "How people find and contact you." Turning off discoverability by phone number severs a common link between a leaked number and your social identity.
Treat this as quarterly housekeeping. Platforms genuinely do reset preferences after major redesigns, and features you disabled a year ago sometimes reappear switched on.
The risk is rarely one dramatic overshare. It is the accumulation of small signals that together map your routine, your home, and the people around you.
Turn off automatic location tagging in each app's posting flow, and disable the camera app's own geotagging so it never gets embedded in the first place. On iPhone: Settings > Privacy & Security > Location Services > Camera > set to Never. On Android: open the Camera app > settings gear > turn off Location tags (sometimes "Save location").
Most large platforms strip EXIF metadata (the hidden data block that stores GPS coordinates, device model, and timestamp) when you upload a photo. But that protection disappears the moment you send the original file directly, over email, a messaging app, or a cloud share link. If a photo could reveal where you live, scrub it first: on iPhone, open Photos, tap the info button, and use Adjust to remove the location before sharing.
Sharing a holiday album the day you fly home avoids broadcasting an empty house to anyone watching. The memories are identical a few days later. Apply the same logic to a new car with a visible plate, a delivery box showing your full address, or a child's school logo on a uniform in the background.
Before posting, ask one concrete question: could a stranger use this to find where I am right now, or where I live? If yes, hold it or crop it.
Your login is the front door. A weak lock here undoes every privacy setting behind it.
Reused passwords are the single biggest cause of account takeovers, through a technique called credential stuffing: attackers take username-and-password pairs leaked from one breached site and try them everywhere else. A password manager (1Password, Bitwarden, or the one built into your browser or phone) generates a different long password for each account so a breach at one service cannot cascade. Check whether your address appears in known breaches at haveibeenpwned.com, and change any password it flags. Modern guidance from NIST favors length over forced monthly changes, so a long unique passphrase you keep is better than a complex one you rotate and forget.
Two-factor authentication requires a second proof beyond your password. Enable it on Instagram and Facebook under Accounts Center > Password and security > Two-factor authentication, and on X under Settings > Security and account access > Security.
Here is the detail most guides skip: not all second factors are equal. Choose an authenticator app that generates rotating TOTP codes (Google Authenticator, Authy, Aegis, or the code feature inside your password manager) over SMS text codes. SMS is vulnerable to SIM swapping, where a scammer convinces your carrier to move your number to their SIM and intercepts your codes. Better still, if the platform offers a passkey (a phishing-resistant credential tied to your device's fingerprint or face unlock, built on the FIDO/WebAuthn standard), turn it on. X, Facebook, and WhatsApp all support passkeys now.
When you enable 2FA, the app shows a set of backup recovery codes. Save them somewhere offline, a note in your password manager or a printout, because they are how you get back in if you lose your phone.
Two more menus are worth five minutes. First, "Where you're logged in" (Instagram and Facebook under Password and security; X under Apps and sessions) lists every active session; log out anything unfamiliar. Second, review third-party apps with access to your account, the quizzes and games you once connected. That access can persist for years and is a classic route for quiet data harvesting. Revoke anything you no longer use.
Scams work on social media precisely because the setting feels trustworthy. Watch for these patterns:
No legitimate service or real friend asks you to read out a login code. If a message from a friend feels off, contact them through a different channel, a phone call or a different app, before acting. Their account may be compromised. And before clicking any link, read the actual domain: instagram-support.co is not instagram.com.
The most frequent error is treating privacy as a one-time setup rather than an ongoing habit, then never checking again after a redesign quietly changes things. Close behind is relying on SMS 2FA and assuming it is enough. People also forget that going private does not retroactively hide old public posts, which is exactly what Facebook's "Limit past posts" tool fixes. Finally, many secure the account but keep oversharing location in real time, protecting the lock while leaving the windows open.
Yes, meaningfully. Any 2FA stops the majority of automated attacks that rely on a password alone. But move to an authenticator app or passkey when you can, because SMS can be defeated by SIM swapping, whereas an app-based code or passkey never leaves your device.
Setting your account private protects future and existing posts from non-followers, but old content you made public can linger in caches and search results. Use a bulk tool like Facebook's "Limit past posts," and manually delete anything sensitive rather than assuming the privacy toggle reaches back in time.
They can be. Many request broad access to your profile, friend list, and email in exchange for a result, and that data can be sold or used to build targeting profiles. Check your account's connected-apps list and remove any quiz or game you no longer use.
Change the password immediately from a device you trust, then log out all other sessions in the security settings. Confirm your recovery email and phone number have not been swapped, re-enable 2FA if it was turned off, and warn your contacts not to trust messages sent from your account in the meantime.
Keep reading
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.