This article is brought to you by Aura.
Watch the video to see how we protect you online.
This article is brought to you by Aura. Watch the video to see how we protect you online.
Start Free Trial
White arrow pointing right, used for navigation
4.7-star rating on Trustpilot
4.7 stars on Trustpilot
White close button to close the window or modal
Play button to start video/audio
What is Aura? (1:10)
Play button to start video/audio

How To Protect Your Personal Information on Social Media

Using social media is often a trade-off between connection and protection. But with a few small changes you can keep your personal information secure.

An illustration of a tilting phone displaying an abstract social media app icon

Aura’s app keeps you safe from scams, fraud, and identity theft. Try Aura for free.

Trustpilot logo4.5-star rating on Trustpilot
4.6 stars as of Sept. 2024

In this article:

    In this article:

      See more
      Illustration of a hand holding a phone that resembles a lock

      Aura’s digital security app keeps your family safe from scams, fraud, and identity theft.

      See pricing
      White arrow pointing right, used for navigation
      Share this:

      What Can Hackers Find Out About You on Social Media? 

      Your personal information is safest when you don’t share it on social media. Social media will always be a trade-off between connection and protection. 

      The more you share on social media, the more information about your life can be stolen.

      It’s hard to strike a balance. But there are three areas where you can make small changes to protect your personal information on social media: sharing, security, and surroundings.

      {{show-toc}}

      12 Tips to Safeguard Your Privacy on Social Media

      We all publish some amount of private information on social media. Knowing what kind of personal data cybercriminals can use will help you understand what you shouldn’t post.

      1. Don’t share your live location or daily routines

      Sharing photos while you’re on vacation can be fun, but those photos immediately alert everyone that you’re away from home. Instead, collect photos on the trip and only share once you’re back.

      Also, avoid posting about routines in your daily life. A story about your “daily 6 a.m. workout” tells stalkers where they can find you every morning and lets thieves know when you’re away.

      ⛑️ Protect your online accounts, identity, and privacy — with a single app. Aura combines identity and fraud protection with advanced digital security, 24/7 support, and up to $1 million in insurance coverage. Plans start at $3/month.

      2. Don’t share identification numbers

      You might not think so, but your identity can be stolen with just your ID.

      Identification and financial information like your Social security number (SSN), driver’s license number, bank account numbers, and passport number should never make it to a social media site.

      These can be used immediately for identity theft and more. (As an added warning, it's not always possible to change your Social Security number — even after identity theft.)

      But when we’re first-time drivers, proud world travelers, and excited entrepreneurs, it’s easy to think of our license, passport, or first paycheck as something to show off on social media.

      But resist the urge to flaunt your success. If you absolutely need to post it on social media, make sure none of your personally identifying numbers or information is legible.

      📚 Related: 10 Airbnb Scams That Will Ruin Your Next Vacation

      3. Share less in the “About” section

      Social media platforms let you share all kinds of personal information online. But all this information just adds to your online footprint. Just because a field is offered doesn’t mean you need to fill it in.

      Consider leaving information blank on your social media profile or only giving a broad answer. For example, enter the industry you’re in instead of a specific employer. Even seemingly harmless information like your maiden name or hometown can help hackers crack your security questions.

      {{hacker-view-widget}}

      4. Only accept connection requests from people you know

      You’ve heard it plenty of times, but it’s still true: only accept followers and friend requests from people you know. If you’re building a public persona, consider creating a separate account.

      Even if you’re careful about what you post, friends can see what others post about you. With a little deduction, any of your friends can quickly find your date of birth and mine your friends list for information about you.

      Plus, the people behind the fake accounts may use them to organize scams, defraud your friends, and even run blackmail campaigns.

      📚 Related: The Latest Social Media Scams (and How To Avoid Them)

      5. Create strong, unique passwords

      Passwords are our first, and sometimes only, line of defense against hackers. It pays to make them as secure as possible.

      First, follow the basics. Don’t use “password,” your username, or easy-to-find data like your anniversary. Not only are these insecure, but in some instances, they expose personal details — like your birthday or phone number — along with the password [*].

      Generally speaking, a long password is a strong password. Every password should have a minimum of 12 characters — ideally, closer to 16. Every extra character makes it an order of magnitude harder to crack your password.

      Your password should also be unique to every site. If one login is ever leaked, every account with that password is at risk. For the same reason, never recycle passwords (like using your old Twitter password as your new Snapchat password). 

      This method was used on some of the highest-profile hacked celebrities, including Facebook founder Mark Zuckerberg, so it can happen to you.

      It’s hard to keep track of dozens of secure, different passwords. Consider using a password manager to track them securely.

      📚 Related: How To Recover a Hacked Instagram Account

      6. Use two-factor authentication (Avoid SMS)

      Two-factor authentication is a security measure that requires a one-time code, either from an app on your phone or a text message, in addition to your password. Today, most major social media accounts include this feature.

      Since these codes are only valid for a few minutes, they’re more secure. But they’re even stronger, since they require whoever’s trying to log in to have a password and the right device — unlikely in most hacking scenarios.

      Pro tip: use an authenticator app like Google or Microsoft, instead of SMS for an extra layer of security.

      ⚠️ Is your information on the Dark Web? Aura scans billions of data points across the internet, Dark Web, public records, and more to alert you if your identity, accounts, and finances are at risk. Try Aura’s privacy protection plans for as low as $3/month.

      7. Tighten your profile's privacy settings

      It’s easy to leave the default privacy settings on your account. They might be fine if you never share sensitive information, but you should at least review the choices rather than hope for the best.

      In just fifteen minutes, you can quickly review the account information for the social media sites you use regularly like Facebook, Twitter, LinkedIn, and Instagram. Choose what different social media user groups — like your friends, friends of friends, or unregistered users — can see.

      And remember, the settings go beyond just posts. On most sites, basic profile data, comments to public posts, and online activity at third-party sites (like comments or quizzes) are shared publicly.

      Decide what you want and don’t want to share.

      📚 Related: The 10 Biggest Instagram Scams Happening Right Now

      8. Force logout of unrecognized devices and sessions

      Many social networking sites, including Facebook, Instagram, Pinterest, and LinkedIn, let you see active account logins worldwide.

      If you’ve never done this, make sure you recognize all of the logins — for example, on your own laptop and phone. If you don’t recognize them, you can sign out of all open sessions. You’ll need to sign back in later, but it’s worth the extra effort.

      Even if you know how to use social media responsibly, it’s not just the network itself where you should pay attention. Your accounts are only as secure as your devices and the precautions you take when you’re not logged in.

      📚 Related: How To Recover a Hacked Facebook Account

      9. Watch your back when out in public

      You’re at the local coffee shop and want to browse Instagram. What’s the safest way to do it?

      First off, there's a type of identity theft attack called shoulder surfing, where wandering eyes lurk over your shoulder as you're typing in your password to any social media account. Beware of prying eyes anytime you're using your mobile device to sign-in to any online accounts in public.

      Secondly, avoid public Wi-Fi, as it’s surprisingly easy for hackers to intercept your connection and collect all the data. A better option is to use a private hotspot from your phone.

      If you must use Wi-Fi, consider a VPN, which scrambles the data you send and makes your location untraceable. For any site — but especially when logging in or entering credit card data — always check for an HTTPS connection (often represented by a green padlock symbol).

      📚 Related: How To Properly Set Up Your iPhone's Privacy Settings

      10. Pay close attention to security alert emails

      Email can be one of the best safeguards for your social media accounts.

      Notifications of failed login attempts or changes to your password could be a warning sign of a hacking attempt. Add two-factor authentication if you haven’t already, and consider changing your password.

      But you should pay attention to the emails themselves, as they’re also common phishing scams.

      Phishing uses pretend authority to trick you into sharing personal data. Let’s say you get a warning email with a button or QR code to log in to Instagram. The button takes you to a site that looks exactly like the Instagram login page — but when you type in your password, it goes straight to a hacker.

      To protect yourself from phishing, always verify that emails are from who they claim to be from. Misspelled sender names (like “Instagram”) are easy to fake, so look at the email address. It should come from the official website, like “security@mail.instagram.com.”

      If you’re still unsure, the safest option would be to visit Instagram.com directly to resolve any issues.

      📚 Related: How To Protect Your Identity Online in 2023

      11. Delete expired social media accounts

      We all have online accounts we never use — will you or anyone you know even notice if you delete your old MySpace site?

      Every social networking site you keep open is an extra window of vulnerability. Delete unused accounts and think carefully before signing up for new accounts.

      If you’re a member of social sites you don’t use often but don’t want to delete, make sure you have a secure password and two-factor authentication for them. You can also improve security by logging out of the site on your devices and deleting the app from your phone. It’s one less vulnerability if someone accesses your device.

      📚 Related: How To Remove Your Personal Information From the Internet

      12. Don't ignore software updates

      Some social media risks work because they exploit bugs in your computer, phone, or tablet. You can protect yourself from these types of cyber attacks by updating to the most recent software, which has stronger code and fewer bugs.

      Update your operating system, like macOS or Windows, as well as your browser, like Chrome or Safari.

      For additional protection, you can also use antivirus and anti-malware software.

      ⚡️ Get warned fast if scammers have your personal information. Aura’s award-winning solution constantly monitors the Dark Web, public records, and more for your most sensitive information and warns you if its been compromised. Try Aura's privacy-first plans today.

      Recent Social Media Data Breaches: Were You Affected?

      Even if you do your best to keep your social media accounts secure and private, hackers and scammers find ways to access your personal information. In recent years, social media sites have become targets for hackers who want to leak your information in data breaches and even sell if on the Dark Web.

      Here are some of the most recent social media data breaches:

      • WhatsApp (November 2022): 487 million WhatsApp user phone numbers was allegedly available for sale according to Cybernews correspondents [*].
      • Facebook (November 2022): Meta was hit with a $276 million fine after the April 2021 data leak that exposed data belonging to 533 million users [*].
      • LinkedIn (October 2022): A previously-scraped archive containing 500 million LinkedIn profiles was allegedly being auction on the Dark Web alongside 327 million new profiles [*].
      • Twitter (July 2022): A threat actor claimed to have stolen data from 5.4 million Twitter accounts that was up for sale on a popular Dark Web marketplace [*].
      • Twitch (October 2021): Almost the entire Twitch source code was leaked online including information on their 7 million users [*].

      📚 Related: Is Norton Privacy Monitor Assistant Worth It?

      The Bottom Line: Protecting Yourself on Social Media

      With social media, security is in your hands. Luckily, you don’t have to choose whether you’d rather have an account with plenty of connections—lots of friends, sharing, and information—or one with more protection.

      Your online safety is a serious matter. Take action and improve the security of your social media accounts today.

      Don’t let scammers outsmart you. Try Aura risk free today.

      Editorial note: Our articles provide educational information for you to increase awareness about digital safety. Aura’s services may not provide the exact features we write about, nor may cover or protect against every type of crime, fraud, or threat discussed in our articles. Please review our Terms during enrollment or setup for more information. Remember that no one can prevent all identity theft or cybercrime.

      Is this article helpful so far?
      Yes
      No
      Skip
      Need an action plan?
      No items found.
      Is your child ready for a cell phone? Take this quiz to find out.
      Start Quiz
      White arrow pointing right, used for navigation
      Illustration of a tilted question mark
      What do hackers
      know about you?
      Run a scan and find out now.
      By entering your email and clicking "Scan", you agree to our Terms and acknowledge our Privacy Policy.

      Award-winning identity theft protection with AI-powered digital security tools, 24/7 White Glove support, and more. Try Aura for free.

      Related Articles

      Illustration of a man sitting on a couch and staring at his phone with a concerned look on his face
      Identity Theft

      25 Warning Signs of Identity Theft: How To Tell If You're a Victim

      Are you worried that someone may have stolen your identity? Learn the 25 most common warning signs of identity theft and how to protect yourself today.

      Read More
      June 6, 2023
      Illustration of a man wearing a mask
      Fraud

      The 12 Latest Types of Social Engineering Attacks (2024)

      Hackers use social engineering attacks to manipulate you into giving them what they want — passwords, data, and money. Here’s how to protect yourself.

      Read More
      December 8, 2023

      Try Aura—14 Days Free

      Start your free trial today**