To use social media safely, protect the sign-in first: a unique password kept in a password manager, plus a passkey or two-step verification. Then run each platform's checkup, limit who can see and contact you, share less about your life, and treat any message asking for money, a code or your login as a scam until you check it.

The stakes are real. In 2025, people reported $2.1 billion in losses from scams that started on social media, more than through any other way scammers make contact and about eight times the 2020 figure, according to the US Federal Trade Commission. This guide covers the settings and habits that stop most of it on Facebook, Instagram, TikTok, X, LinkedIn and YouTube, as each platform's help centre describes them in September 2026, plus what to do after a hack and the teen settings parents can check.

Set up a new account safely

Whether you are joining a platform or tidying up an old account, the foundations are the same ones the UK National Cyber Security Centre (NCSC) starts from in its social media guidance: control your settings, use two-step verification and be careful who you trust.

  1. Get the official app, or type the address yourself. Meta's security advice is to check the URL before you enter a password and, when in doubt, to type www.facebook.com into the browser.
  2. Sign up with a well-protected email address. Whoever controls your inbox can request password reset links for your other accounts, the FTC points out, so turn on two-step verification there first.
  3. Add a phone number and email you will keep. They are how the platform lets you back in. LinkedIn lists an outdated email or phone number, recycled to someone else, among the ways accounts are compromised.
  4. Use a password you use nowhere else. Passwords stolen in one breach are tried on other sites. The NCSC suggests three random words or a password manager, and warns against birthdays, pet names and favourite teams, because most of those details are on your social media profile.
  5. Do not mark a shared computer as trusted. Facebook and Instagram offer to remember a device after two-step verification; decline on a library or other shared computer, and log out when you finish.

If you sign in on public Wi-Fi in cafés, hotels or airports, read how snooping attacks capture traffic on shared networks, and prefer your phone's mobile data for logins.

Turn on a passkey or two-step verification

Two-step verification (2SV), also called two-factor authentication (2FA), adds a second check after the password: a code, a prompt on your phone or a security key. Even if someone steals or guesses your password, they cannot sign in without the second step. The FTC recommends turning it on first for your most sensitive accounts, and names email and social media among them.

Which second step to choose

Not every second step is equally strong. From weakest to strongest:

  • Text message or email codes. Better than nothing, but a criminal can take over your phone number. In a SIM swap, the Canadian Anti-Fraud Centre explains, the fraudster poses as you to your mobile carrier, gets your number moved to a SIM they control, then presses "Forgot password" on your apps and receives the codes.
  • An authenticator app or a sign-in prompt. Apps such as Google Authenticator, Microsoft Authenticator or Duo generate codes on the phone itself, so a SIM swap does not expose them. The FTC rates them safer than text codes.
  • A security key or a passkey. The FTC calls security keys the strongest two-factor method, because there is no code for anyone to steal.

In April 2026 the NCSC went further. It now recommends passkeys as the first choice wherever a service offers them, and a password manager plus two-step verification where it does not. Its technical assessment is blunt: every traditional method, including text codes, app codes and push approvals, can be phished, because a fake login page can collect the code or approval and relay it to the real site during the login. A passkey is cryptographically tied to the real service, so a lookalike page gets nothing it can use.

A phone holding an orange key signs in to the real server, whose padlock matches the key, while a lookalike server with a dashed outline is blocked and receives nothing.
Fig. 1 A passkey only works on the site it was made for, so a convincing fake login page has nothing to collect.

What each platform offers, as of September 2026

PlatformSecond-step options in its help centrePasskeysWhere to find it
FacebookSecurity key, authentication app, text message; 10 recovery codesYes, on mobile and on computers with Windows 10, macOS Ventura or ChromeOS 109 and upSettings and privacy, Settings, Accounts Center, Password and security
InstagramAuthentication app (recommended), text message, WhatsApp once text is on; backup codesNot in Instagram's help centreSettings, Accounts Center, Password and security
TikTokAt least two of: phone, email, authenticator app, passwordYes, in the app, on Android 9 or iOS 16 and laterSettings and privacy, Security & permissions
XAuthentication app, security key; text message only for X Premium subscribersYes, in the iOS and Android appsSettings and privacy, Security and account access, Security
LinkedInAuthenticator app (recommended) or text messageNot in LinkedIn HelpSettings & Privacy, Sign in & security
YouTube (Google Account)Google prompts, passkeys, security keys, authenticator app, text or voice codes, backup codesYesGoogle Account, Security & sign-in

Sources: Facebook two-factor and passkeys, Instagram, TikTok account safety and passkeys, X two-factor and passkeys, LinkedIn, Google.

A few details matter in practice:

  • X stopped offering text-message codes to non-Premium accounts on March 20, 2023. A security key can be your only method there, with no backup method required.
  • Instagram only lets you turn on the authentication app method from the Android or iPhone app.
  • Google notes that its sign-in prompts also help against SIM swaps, and that it never calls you to ask for a verification code.
  • LinkedIn requires two-factor authentication for anyone using Recruiter, Campaign Manager or Sales Navigator.
  • Save the backup codes each platform gives you (Facebook issues 10) in your password manager or on paper at home. They are your way back in if you lose the phone.

Run each platform's security and privacy checkup

Most platforms bundle their protective settings into a guided review. Run it once now, and again after any scare or new phone.

  • Facebook: Settings and privacy, then Privacy Checkup. It walks through who can see your phone number, email and birthday, who can see past and future posts, login alerts, who can look you up by phone number or email, and which outside apps and websites you signed in to with Facebook. On a computer, Security Checkup reviews your security settings and sets up two-factor authentication.
  • Instagram: the scam guidance points to its Security Checkup tool, and recommends login alerts and a review of previous sessions so you recognize every device with access.
  • TikTok: Settings and privacy, Security & permissions, Security checkup. It checks your linked phone and email, two-step verification, trusted devices and the last 30 days of security activity, and offers to add a passkey.
  • X: review the settings yourself. Under Settings and privacy, Security and account access, check two-factor authentication and passkeys, and open Apps to revoke any third-party app you do not recognize. X also lets you require your email address or phone number before anyone can start a password reset.
  • LinkedIn: Me, Settings & Privacy. Sign in & security holds two-factor authentication; Visibility controls who sees your profile, network and activity; Data privacy covers who can reach you.
  • YouTube: your channel is protected by your Google Account. Google's Security Checkup reviews your recovery phone and email, offers a passkey, turns on 2-Step Verification and removes risky access to your data.

Set who can see your posts, find you and tag you

Default settings favour reach. Each platform lets you pull them back, and a personal account rarely needs everything public.

PlatformMake posts less publicWorth knowing
FacebookThe audience selector on each post (Public, Friends, Only me), a default audience in settings, and "limit past posts"Posts in a public group are always public; if you tag someone, their friends may see the post
InstagramSettings, Account privacy, Private accountBusiness profiles cannot be private; accounts of people under 18 are private by default
TikTokPrivate account in privacy settings, plus an audience for each postYour nickname, username and profile photo stay visible to anyone, even on a private account
XProtect your posts: only your followers see themPosts are public by default; protected posts stay out of search engines, but followers can still screenshot them
LinkedInSettings & Privacy, VisibilityControls who sees your profile, your network and your activity
YouTubeVideo visibility: Public, Unlisted or PrivateAnyone with an unlisted video's link can watch and reshare it

Three more settings are worth a minute each:

  • Who can find you. Facebook's Privacy Checkup controls who can send you friend requests and who can look you up by phone number or email address. Narrow lookup to friends, so a phone number leaked in a breach does not lead straight to your profile.
  • Tagging. Facebook's Profile and tagging settings control who can see what others post on your profile and who can see posts you are tagged in. A tag can show where you were to a friend's whole audience.
  • Friend requests. Meta advises against accepting friend requests from people you do not know: a scammer on your friends list can spam your timeline, tag you in posts and send you malicious messages.

Decide what not to share

Privacy settings limit the audience; they do not make a post private forever. Followers can screenshot, accounts get hacked and settings change. The NCSC's advice on your digital footprint is to ask what your followers actually need to know, and which details are unnecessary but useful to a criminal, including what friends and colleagues post about you.

  • Where you are, in real time. Post the holiday photos when you are home. A live location or "away for two weeks" tells strangers when the house is empty.
  • The answers to your security questions. Your birthday, your pet's name and your first school are typical security-question answers, and the same details the NCSC warns against using in passwords.
  • Details that make a scam believable. Your employer, your bank, a recent purchase, the friend you just visited: each one helps a scammer write a message that sounds like it comes from someone who knows you. The FTC notes that scammers use what people post to work out how to target them.
  • Anything with a number on it. Boarding passes, tickets, ID cards and cheques carry names, numbers and barcodes meant for one reader, not for your followers.
Icons from a public profile card, a birthday cake, a paw print, a house pin and an aeroplane, travel along dotted lines into one orange envelope on a laptop, beside a form with security questions.
Fig. 2 Each detail is harmless alone; together they write a convincing message and answer the questions that reset your password.

Recognize the scams that start on social media

Scammers use social media because reaching people is cheap and faking an identity is easy. The FTC's 2025 figures show the pattern. More than 40% of people who lost money to a scam that started on social media had ordered something from an ad. Investment scams caused the largest losses, $1.1 billion, more than half the total. Nearly 60% of people who lost money to a romance scam said it began on a social platform, and so did one in three who lost money to a job scam.

ScamHow it startsThe tellWhat to do
Hacked or cloned friendA friend's account asks for money, a favour or a codeUrgency; payment by gift card, cryptocurrency or wire transferCall or text the friend on a number you already have
Fake support or security teamYour account will be "banned", "deleted" or "verified"A login link, or a request for your password or codeInstagram never messages you about your account by direct message; check official emails in settings
Giveaways, prizes and loansYou have won, or qualify for a quick loanA fee or tax to pay before you receive anythingWalk away; the CAFC notes there are no prize fees or taxes in Canada
Investment tips and coachesAn ad, a post or a friendly stranger who got richA platform that shows fast profits, lets you withdraw a little, then asks for moreNever let someone you met online direct your investments; check with a securities regulator
RomanceA stranger who is quickly affectionate and wants to change appsCannot meet, then an emergency, a visa or a crypto opportunityNever send money to someone you have not met in person
Shopping adsA big discount on a brand you knowAn unfamiliar website, or a lookalike of the brand's siteSearch the company name with "scam" or "complaint" before you pay
Recovery offersA promise to get back lost money or a hacked accountA fee up front, or a request for remote access to your deviceNever pay in advance; the CAFC and police never ask you for a payment
QR codes and short linksA code or link in a message you did not expectA reason to act now: a missed delivery, a locked accountDo not scan or tap it; go to the company's site or app yourself

Sources for the table: Instagram's scam guidance and phishing page, CAFC fraud prevention, the FTC and CAFC on investment scams, the FTC and CAFC on romance scams, the CAFC on recovery pitches and the FTC on QR codes.

Two patterns deserve a closer look. Investment and romance scams increasingly merge: the Canadian Anti-Fraud Centre calls it pig butchering, where a relationship built over weeks turns into coaching on a fake cryptocurrency platform. And an account takeover does not need any hacking at all: a message, often from a friend's account that was already taken over, asks for the code the platform just sent you.

A server sends a phone an orange code bubble, while a chat bubble from a friend's taken-over account asks for it. The path forwarding the code to a laptop is crossed out.
Fig. 3 The code proves you are you. Whoever asks for it, even from a friend's account, is asking for the account.

Important

Never share a sign-in or verification code, whatever the story. The FTC's rule: if you did not start the contact, do not give a code to the person on the other end. Google adds that it never calls you to verify a code.

Before you act on any message, slow down, because scammers rely on urgency; confirm through a channel you already trust, such as the friend's phone number or the company's own app; and refuse to pay by gift card, cryptocurrency or wire transfer. To size up an unfamiliar account or seller on Instagram, open About This Account from the three dots on the profile: it shows when the account was created, the country it is based in and any former usernames.

Report the account to the platform, then report any loss: in the US at ReportFraud.ftc.gov; in Canada to local police and the CAFC, online at reportcyberandfraud.canada.ca or on 1-888-495-8501; in England, Wales and Northern Ireland to Report Fraud, where the old Action Fraud address now leads; in Scotland, call 101.

What to do if your social media account is hacked

The signs are usually obvious once you look: you cannot log in, you get an alert about a password, email or phone change you did not make, or friends ask about messages and posts you never sent. Act quickly, in this order, following the NCSC and the FTC:

  1. Start the platform's own recovery process (links in the table below), from a device you have used before where possible.
  2. Secure your email first. Check for forwarding rules you did not create; attackers add them to receive your password reset messages.
  3. Change the password, on the hacked account and on every other account that used the same one.
  4. Sign out of every other session and device, and remove third-party apps you do not recognize.
  5. Turn on two-step verification or a passkey, and check that the recovery email and phone number are yours.
  6. Clean up. Delete posts and messages sent in your name, and review new friends, follows and connections.
  7. Warn your contacts not to click links or send money in response to recent messages from you.
  8. Update your devices and scan for malware, and if money was taken, call your bank and report it.
PlatformWhere to startWorth knowing
Facebookfacebook.com/hacked (help)Open it on a device you have used to log in before
Instagraminstagram.com/hacked (help)An email from security@mail.instagram.com about an email change includes a link to reverse it; recovery may ask for a video selfie
TikTokMy account has been hackedSecurity & permissions, Manage devices, to remove devices you do not recognize
XCompromised account helpA password change does not sign out the mobile apps; revoke them under Apps. An email from verify@x.com lets you reverse an email change
LinkedInThe Report Unauthorized Account Access form (help)Review your active sessions and sign out of everywhere
YouTubeRecover a hacked channel: recover the Google Account firstEvery channel manager should secure their own Google Account too

Warning

Anyone who contacts you offering to recover your account or your money is not the platform. Instagram warns about people claiming to be from its security team, and the CAFC reports "recovery" fraudsters who charge a fee or ask for remote access. Recovery happens only through the platform's own pages.

Social media safety for teens: the settings parents can check

Most platforms set the minimum age at 13, and the NCSC points out how easy it is to sign up with a false date of birth. The major platforms now apply teen defaults automatically, so the first job for a parent is to check that a teen's account really is registered as a teen account, then look at the settings together.

  • Instagram. Teen Accounts, introduced in September 2024 and available in every country since June 2025, are private by default; teens can only be messaged by people they follow or are connected to, and only tagged or mentioned by people they follow. Offensive words are filtered from comments and message requests, a reminder to leave comes after 60 minutes a day, and sleep mode mutes notifications from 10 PM to 7 AM. Teens under 16 need a parent's permission, through supervision, to loosen any of this. Since October 2025, teens are also placed in a 13+ content setting by default.
  • Facebook and Messenger. Teen Accounts with similar protections expanded worldwide on September 25, 2025.
  • TikTok. Accounts of 13 to 15 year olds are private by default, cannot use direct messages and cannot have their videos downloaded; 16 and 17 year olds also start private. A daily screen time limit of one hour is on by default for 13 to 17 year olds, and their push notifications are muted at night. Family Pairing lets a parent manage these settings.
  • YouTube. Take-a-break and bedtime reminders are on by default for teens, YouTube uses age estimation to apply teen protections to accounts it judges to be under 18, and a parent can link a supervised teen account to see channel activity.

Settings do not replace the conversation. Give teens the rules this guide gives adults: never share a code, check with a friend another way before sending anything, and come to you straight away if someone threatens to share their photos unless they pay. The FTC reports scammers who trick people into sending nude photos, then threaten to send them to their social media contacts.

When social media is part of your job

The risks multiply when an account speaks for a business. Staff sign in to company pages, ad accounts and recruiting tools, and one phished employee can hand a stranger the brand. Meta warns that criminals have sent Business Manager partner requests containing phishing links, and that those notifications arrive from its real facebookmail.com domain, so the sender address alone proves nothing.

The rules above apply at company scale: every person with access signs in with their own identity protected by multi-factor authentication, nobody shares one password for the company page, and access ends when someone leaves. Our IT support service covers that ground: one identity per person, protected by MFA and conditional access, phishing-resistant sign-in where possible, and offboarding that revokes accounts, sessions and devices in one documented sequence. If scammers are borrowing your brand, our security scanning service checks DMARC, SPF and DKIM on your domain and watches for lookalike domains. More guides like this one are in Security.