# How to use social media safely: a beginner's guide

> Use social media safely: protect the sign-in with a passkey or two-step verification, set privacy on each platform, spot scams and recover a hacked account.

- URL: https://computese.com/how-to-use-social-media-safely/
- Author: Duong Quan Nguyen, CEO, Computese
- Published: 2024-09-01
- Updated: 2026-09-25
- Topics: Security, IT support

## In short
- To use social media safely, protect the sign-in first: a unique password from a password manager, plus a passkey or two-step verification. Prefer an authenticator app, a security key or a passkey to text-message codes.
- Run each platform's security or privacy checkup, then limit who can see your posts, look you up and tag you. Keep travel plans and the details that answer security questions off your profile.
- Most social media scams follow one script: a hacked friend, a fake support account, a giveaway, an investment tip or a fast romance, then a request for money, a code or a login. Check another way before you act.
- In 2025, people reported $2.1 billion in losses to the US Federal Trade Commission from scams that started on social media, more than any other contact method and about eight times the 2020 figure.
- If an account is hacked, use the platform's own recovery page, change the password, sign out every other session, turn on two-step verification and warn your contacts.

To use social media safely, protect the sign-in first: a unique password kept in a password manager, plus a passkey or two-step verification. Then run each platform's checkup, limit who can see and contact you, share less about your life, and treat any message asking for money, a code or your login as a scam until you check it.

The stakes are real. In 2025, people reported $2.1 billion in losses from scams that started on social media, more than through any other way scammers make contact and about eight times the 2020 figure, according to the [US Federal Trade Commission](https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2026/04/reported-losses-scams-social-media-eight-times-higher-2020). This guide covers the settings and habits that stop most of it on Facebook, Instagram, TikTok, X, LinkedIn and YouTube, as each platform's help centre describes them in September 2026, plus what to do after a hack and the teen settings parents can check.

## Set up a new account safely

Whether you are joining a platform or tidying up an old account, the foundations are the same ones the UK National Cyber Security Centre (NCSC) starts from in its [social media guidance](https://www.ncsc.gov.uk/guidance/social-media-how-to-use-it-safely): control your settings, use two-step verification and be careful who you trust.

1. **Get the official app, or type the address yourself.** Meta's [security advice](https://www.facebook.com/help/213481848684090) is to check the URL before you enter a password and, when in doubt, to type www.facebook.com into the browser.
2. **Sign up with a well-protected email address.** Whoever controls your inbox can request password reset links for your other accounts, the [FTC points out](https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account), so turn on two-step verification there first.
3. **Add a phone number and email you will keep.** They are how the platform lets you back in. [LinkedIn lists](https://www.linkedin.com/help/linkedin/answer/a1340402) an outdated email or phone number, recycled to someone else, among the ways accounts are compromised.
4. **Use a password you use nowhere else.** Passwords stolen in one breach are tried on other sites. The NCSC suggests [three random words](https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words) or [a password manager](https://computese.com/cyber-it-security/), and warns against birthdays, pet names and favourite teams, because most of those details are on your social media profile.
5. **Do not mark a shared computer as trusted.** Facebook and Instagram offer to remember a device after two-step verification; decline on a library or other shared computer, and log out when you finish.

If you sign in on public Wi-Fi in cafés, hotels or airports, read how [snooping attacks](https://computese.com/understanding-snooping-attacks-how-they-work/) capture traffic on shared networks, and prefer your phone's mobile data for logins.

## Turn on a passkey or two-step verification

Two-step verification (2SV), also called two-factor authentication (2FA), adds a second check after the password: a code, a prompt on your phone or a security key. Even if someone steals or guesses your password, they cannot sign in without the second step. The [FTC](https://consumer.ftc.gov/articles/use-two-factor-authentication-protect-your-accounts) recommends turning it on first for your most sensitive accounts, and names email and social media among them.

### Which second step to choose

Not every second step is equally strong. From weakest to strongest:

- **Text message or email codes.** Better than nothing, but a criminal can take over your phone number. In a [SIM swap](https://antifraudcentre-centreantifraude.ca/scams-fraudes/sim-eng.htm), the Canadian Anti-Fraud Centre explains, the fraudster poses as you to your mobile carrier, gets your number moved to a SIM they control, then presses "Forgot password" on your apps and receives the codes.
- **An authenticator app or a sign-in prompt.** Apps such as Google Authenticator, Microsoft Authenticator or Duo generate codes on the phone itself, so a SIM swap does not expose them. The FTC rates them safer than text codes.
- **A security key or a passkey.** The FTC calls security keys the strongest two-factor method, because there is no code for anyone to steal.

In April 2026 the NCSC went further. It now [recommends passkeys](https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future) as the first choice wherever a service offers them, and a password manager plus two-step verification where it does not. Its [technical assessment](https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in) is blunt: every traditional method, including text codes, app codes and push approvals, can be phished, because a fake login page can collect the code or approval and relay it to the real site during the login. A passkey is cryptographically tied to the real service, so a lookalike page gets nothing it can use.

![A phone holding an orange key signs in to the real server, whose padlock matches the key, while a lookalike server with a dashed outline is blocked and receives nothing.](https://computese.com/images/blog/how-to-use-social-media-safely/passkey.664d7f67af-1536.webp)

*A passkey only works on the site it was made for, so a convincing fake login page has nothing to collect.*

### What each platform offers, as of September 2026

| Platform                 | Second-step options in its help centre                                                        | Passkeys                                                                              | Where to find it                                                       |
| ------------------------ | --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------- | ---------------------------------------------------------------------- |
| Facebook                 | Security key, authentication app, text message; 10 recovery codes                             | Yes, on mobile and on computers with Windows 10, macOS Ventura or ChromeOS 109 and up | Settings and privacy, Settings, Accounts Center, Password and security |
| Instagram                | Authentication app (recommended), text message, WhatsApp once text is on; backup codes        | Not in Instagram's help centre                                                        | Settings, Accounts Center, Password and security                       |
| TikTok                   | At least two of: phone, email, authenticator app, password                                    | Yes, in the app, on Android 9 or iOS 16 and later                                     | Settings and privacy, Security & permissions                           |
| X                        | Authentication app, security key; text message only for X Premium subscribers                 | Yes, in the iOS and Android apps                                                      | Settings and privacy, Security and account access, Security            |
| LinkedIn                 | Authenticator app (recommended) or text message                                               | Not in LinkedIn Help                                                                  | Settings & Privacy, Sign in & security                                 |
| YouTube (Google Account) | Google prompts, passkeys, security keys, authenticator app, text or voice codes, backup codes | Yes                                                                                   | Google Account, Security & sign-in                                     |

Sources: [Facebook two-factor](https://www.facebook.com/help/148233965247823) and [passkeys](https://www.facebook.com/help/1181045243159511), [Instagram](https://help.instagram.com/566810106808145), [TikTok account safety](https://www.tiktok.com/support/faq_detail?id=7543604780950624824) and [passkeys](https://www.tiktok.com/support/faq_detail?id=7581816994987776523), [X two-factor](https://help.x.com/en/managing-your-account/two-factor-authentication) and [passkeys](https://help.x.com/en/managing-your-account/how-to-use-passkey), [LinkedIn](https://www.linkedin.com/help/linkedin/answer/a1358878), [Google](https://support.google.com/accounts/answer/185839).

A few details matter in practice:

- **X** stopped offering text-message codes to non-Premium accounts on March 20, 2023. A security key can be your only method there, with no backup method required.
- **Instagram** only lets you turn on the authentication app method from the Android or iPhone app.
- **Google** notes that its sign-in prompts also help against SIM swaps, and that it never calls you to ask for a verification code.
- **LinkedIn** requires two-factor authentication for anyone using Recruiter, Campaign Manager or Sales Navigator.
- **Save the backup codes** each platform gives you (Facebook issues 10) in your password manager or on paper at home. They are your way back in if you lose the phone.

## Run each platform's security and privacy checkup

Most platforms bundle their protective settings into a guided review. Run it once now, and again after any scare or new phone.

- **Facebook:** Settings and privacy, then [Privacy Checkup](https://www.facebook.com/help/443357099140264). It walks through who can see your phone number, email and birthday, who can see past and future posts, login alerts, who can look you up by phone number or email, and which outside apps and websites you signed in to with Facebook. On a computer, [Security Checkup](https://www.facebook.com/help/213481848684090) reviews your security settings and sets up two-factor authentication.
- **Instagram:** the [scam guidance](https://help.instagram.com/514187739359208) points to its Security Checkup tool, and recommends login alerts and a review of previous sessions so you recognize every device with access.
- **TikTok:** Settings and privacy, Security & permissions, **Security checkup**. It checks your linked phone and email, two-step verification, trusted devices and the last 30 days of security activity, and offers to add a passkey.
- **X:** review the settings yourself. Under Settings and privacy, Security and account access, check two-factor authentication and passkeys, and open **Apps** to revoke any third-party app you do not recognize. X also [lets you require](https://help.x.com/en/safety-and-security/x-account-compromised) your email address or phone number before anyone can start a password reset.
- **LinkedIn:** Me, [Settings & Privacy](https://www.linkedin.com/help/linkedin/answer/a1337839). Sign in & security holds two-factor authentication; Visibility controls who sees your profile, network and activity; Data privacy covers who can reach you.
- **YouTube:** your channel is protected by your Google Account. Google's [Security Checkup](https://support.google.com/accounts/answer/46526) reviews your recovery phone and email, offers a passkey, turns on 2-Step Verification and removes risky access to your data.

## Set who can see your posts, find you and tag you

Default settings favour reach. Each platform lets you pull them back, and a personal account rarely needs everything public.

| Platform  | Make posts less public                                                                                                                                                 | Worth knowing                                                                                                                                                   |
| --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Facebook  | The [audience selector](https://www.facebook.com/help/120939471321735) on each post (Public, Friends, Only me), a default audience in settings, and "limit past posts" | Posts in a public group are always public; if you tag someone, their friends may see the post                                                                   |
| Instagram | Settings, Account privacy, [Private account](https://help.instagram.com/448523408565555)                                                                               | Business profiles cannot be private; accounts of people under 18 are private by default                                                                         |
| TikTok    | Private account in privacy settings, plus an audience for each post                                                                                                    | Your nickname, username and profile photo stay visible to anyone, even on a [private account](https://www.tiktok.com/support/faq_detail?id=7611839632052853259) |
| X         | [Protect your posts](https://help.x.com/en/safety-and-security/public-and-protected-posts): only your followers see them                                               | Posts are public by default; protected posts stay out of search engines, but followers can still screenshot them                                                |
| LinkedIn  | Settings & Privacy, Visibility                                                                                                                                         | Controls who sees your profile, your network and your activity                                                                                                  |
| YouTube   | [Video visibility](https://support.google.com/youtube/answer/157177): Public, Unlisted or Private                                                                      | Anyone with an unlisted video's link can watch and reshare it                                                                                                   |

Three more settings are worth a minute each:

- **Who can find you.** Facebook's Privacy Checkup controls who can send you friend requests and who can look you up by phone number or email address. Narrow lookup to friends, so a phone number leaked in a breach does not lead straight to your profile.
- **Tagging.** Facebook's Profile and tagging settings control who can see what others post on your profile and who can see posts you are tagged in. A tag can show where you were to a friend's whole audience.
- **Friend requests.** Meta advises against accepting friend requests from people you do not know: a scammer on your friends list can spam your timeline, tag you in posts and send you malicious messages.

## Decide what not to share

Privacy settings limit the audience; they do not make a post private forever. Followers can screenshot, accounts get hacked and settings change. The NCSC's advice on your **digital footprint** is to ask what your followers actually need to know, and which details are unnecessary but useful to a criminal, including what friends and colleagues post about you.

- **Where you are, in real time.** Post the holiday photos when you are home. A live location or "away for two weeks" tells strangers when the house is empty.
- **The answers to your security questions.** Your birthday, your pet's name and your first school are typical security-question answers, and the same details the NCSC warns against using in passwords.
- **Details that make a scam believable.** Your employer, your bank, a recent purchase, the friend you just visited: each one helps a scammer write a message that sounds like it comes from someone who knows you. The FTC notes that scammers use what people post to work out how to target them.
- **Anything with a number on it.** Boarding passes, tickets, ID cards and cheques carry names, numbers and barcodes meant for one reader, not for your followers.

![Icons from a public profile card, a birthday cake, a paw print, a house pin and an aeroplane, travel along dotted lines into one orange envelope on a laptop, beside a form with security questions.](https://computese.com/images/blog/how-to-use-social-media-safely/oversharing.63774cbc5b-1536.webp)

*Each detail is harmless alone; together they write a convincing message and answer the questions that reset your password.*

## Recognize the scams that start on social media

Scammers use social media because reaching people is cheap and faking an identity is easy. The FTC's 2025 figures show the pattern. More than 40% of people who lost money to a scam that started on social media had ordered something from an ad. Investment scams caused the largest losses, $1.1 billion, more than half the total. Nearly 60% of people who lost money to a romance scam said it began on a social platform, and so did one in three who lost money to a job scam.

| Scam                          | How it starts                                                   | The tell                                                                           | What to do                                                                                           |
| ----------------------------- | --------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| Hacked or cloned friend       | A friend's account asks for money, a favour or a code           | Urgency; payment by gift card, cryptocurrency or wire transfer                     | Call or text the friend on a number you already have                                                 |
| Fake support or security team | Your account will be "banned", "deleted" or "verified"          | A login link, or a request for your password or code                               | Instagram never messages you about your account by direct message; check official emails in settings |
| Giveaways, prizes and loans   | You have won, or qualify for a quick loan                       | A fee or tax to pay before you receive anything                                    | Walk away; the CAFC notes there are no prize fees or taxes in Canada                                 |
| Investment tips and coaches   | An ad, a post or a friendly stranger who got rich               | A platform that shows fast profits, lets you withdraw a little, then asks for more | Never let someone you met online direct your investments; check with a securities regulator          |
| Romance                       | A stranger who is quickly affectionate and wants to change apps | Cannot meet, then an emergency, a visa or a crypto opportunity                     | Never send money to someone you have not met in person                                               |
| Shopping ads                  | A big discount on a brand you know                              | An unfamiliar website, or a lookalike of the brand's site                          | Search the company name with "scam" or "complaint" before you pay                                    |
| Recovery offers               | A promise to get back lost money or a hacked account            | A fee up front, or a request for remote access to your device                      | Never pay in advance; the CAFC and police never ask you for a payment                                |
| QR codes and short links      | A code or link in a message you did not expect                  | A reason to act now: a missed delivery, a locked account                           | Do not scan or tap it; go to the company's site or app yourself                                      |

Sources for the table: [Instagram's scam guidance](https://help.instagram.com/514187739359208) and [phishing page](https://help.instagram.com/670309656726033), [CAFC fraud prevention](https://antifraudcentre-centreantifraude.ca/protect-protegez-eng.htm), the [FTC](https://consumer.ftc.gov/articles/investment-scams) and [CAFC](https://antifraudcentre-centreantifraude.ca/scams-fraudes/investment-investissement-eng.htm) on investment scams, the [FTC](https://consumer.ftc.gov/articles/what-know-about-romance-scams) and [CAFC](https://antifraudcentre-centreantifraude.ca/scams-fraudes/romance-rencontre-eng.htm) on romance scams, the [CAFC on recovery pitches](https://antifraudcentre-centreantifraude.ca/scams-fraudes/recovery-recuperation-eng.htm) and the [FTC on QR codes](https://consumer.ftc.gov/consumer-alerts/2023/12/scammers-hide-harmful-links-qr-codes-steal-your-information).

Two patterns deserve a closer look. Investment and romance scams increasingly merge: the Canadian Anti-Fraud Centre calls it **pig butchering**, where a relationship built over weeks turns into coaching on a fake cryptocurrency platform. And an account takeover does not need any hacking at all: a message, often from a friend's account that was already taken over, asks for the code the platform just sent you.

![A server sends a phone an orange code bubble, while a chat bubble from a friend's taken-over account asks for it. The path forwarding the code to a laptop is crossed out.](https://computese.com/images/blog/how-to-use-social-media-safely/code-request.26ceefc3bc-1536.webp)

*The code proves you are you. Whoever asks for it, even from a friend's account, is asking for the account.*

> [!IMPORTANT]
> Never share a sign-in or verification code, whatever the story. The FTC's rule: if you did not start the contact, do not give a code to the person on the other end. Google adds that it never calls you to verify a code.

Before you act on any message, slow down, because scammers rely on urgency; confirm through a channel you already trust, such as the friend's phone number or the company's own app; and refuse to pay by gift card, cryptocurrency or wire transfer. To size up an unfamiliar account or seller on Instagram, open **About This Account** from the three dots on the profile: it shows when the account was created, the country it is based in and any former usernames.

Report the account to the platform, then report any loss: in the US at ReportFraud.ftc.gov; in Canada to local police and the [CAFC](https://antifraudcentre-centreantifraude.ca/report-signalez-eng.htm), online at reportcyberandfraud.canada.ca or on 1-888-495-8501; in England, Wales and Northern Ireland to [Report Fraud](https://www.reportfraud.police.uk/), where the old Action Fraud address now leads; in Scotland, call 101.

## What to do if your social media account is hacked

The signs are usually obvious once you look: you cannot log in, you get an alert about a password, email or phone change you did not make, or friends ask about messages and posts you never sent. Act quickly, in this order, following the [NCSC](https://www.ncsc.gov.uk/guidance/recovering-a-hacked-account) and the [FTC](https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account):

1. **Start the platform's own recovery process** (links in the table below), from a device you have used before where possible.
2. **Secure your email first.** Check for forwarding rules you did not create; attackers add them to receive your password reset messages.
3. **Change the password**, on the hacked account and on every other account that used the same one.
4. **Sign out of every other session and device**, and remove third-party apps you do not recognize.
5. **Turn on two-step verification or a passkey**, and check that the recovery email and phone number are yours.
6. **Clean up.** Delete posts and messages sent in your name, and review new friends, follows and connections.
7. **Warn your contacts** not to click links or send money in response to recent messages from you.
8. **[Update your devices](https://computese.com/secure-your-personal-devices-from-cyber-attacks/) and scan for malware**, and if money was taken, call your bank and report it.

| Platform  | Where to start                                                                                                | Worth knowing                                                                                                                            |
| --------- | ------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Facebook  | facebook.com/hacked ([help](https://www.facebook.com/help/1216349518398524))                                  | Open it on a device you have used to log in before                                                                                       |
| Instagram | instagram.com/hacked ([help](https://help.instagram.com/149494825257596))                                     | An email from security@mail.instagram.com about an email change includes a link to reverse it; recovery may ask for a video selfie       |
| TikTok    | [My account has been hacked](https://www.tiktok.com/support/faq_detail?id=7581821084908067339)                | Security & permissions, Manage devices, to remove devices you do not recognize                                                           |
| X         | [Compromised account help](https://help.x.com/en/safety-and-security/x-account-compromised)                   | A password change does not sign out the mobile apps; revoke them under Apps. An email from verify@x.com lets you reverse an email change |
| LinkedIn  | The Report Unauthorized Account Access form ([help](https://www.linkedin.com/help/linkedin/answer/a1340402))  | Review your active sessions and sign out of everywhere                                                                                   |
| YouTube   | [Recover a hacked channel](https://support.google.com/youtube/answer/76187): recover the Google Account first | Every channel manager should secure their own Google Account too                                                                         |

> [!WARNING]
> Anyone who contacts you offering to recover your account or your money is not the platform. Instagram warns about people claiming to be from its security team, and the CAFC reports "recovery" fraudsters who charge a fee or ask for remote access. Recovery happens only through the platform's own pages.

## Social media safety for teens: the settings parents can check

Most platforms set the minimum age at 13, and the NCSC points out how easy it is to sign up with a false date of birth. The major platforms now apply teen defaults automatically, so the first job for a parent is to check that a teen's account really is registered as a teen account, then look at the settings together.

- **Instagram.** [Teen Accounts](https://about.fb.com/news/2024/09/instagram-teen-accounts/), introduced in September 2024 and available in every country since June 2025, are private by default; teens can only be messaged by people they follow or are connected to, and only tagged or mentioned by people they follow. Offensive words are filtered from comments and message requests, a reminder to leave comes after 60 minutes a day, and sleep mode mutes notifications from 10 PM to 7 AM. Teens under 16 need a parent's permission, through supervision, to loosen any of this. Since October 2025, teens are also placed in a [13+ content setting](https://about.fb.com/news/2025/10/instagram-teen-accounts-13-movie-ratings/) by default.
- **Facebook and Messenger.** Teen Accounts with similar protections [expanded worldwide](https://about.fb.com/news/2025/09/millions-teens-now-teen-accounts-plus-more-support-schools/) on September 25, 2025.
- **TikTok.** Accounts of [13 to 15 year olds](https://www.tiktok.com/support/faq_detail?id=7611839632052853259) are private by default, cannot use direct messages and cannot have their videos downloaded; 16 and 17 year olds also start private. A [daily screen time limit](https://www.tiktok.com/support/faq_detail?id=7543597459155687941) of one hour is on by default for 13 to 17 year olds, and their push notifications are muted at night. Family Pairing lets a parent manage these settings.
- **YouTube.** Take-a-break and bedtime reminders are [on by default for teens](https://support.google.com/youtube/answer/2802272), YouTube uses age estimation to apply teen protections to accounts it judges to be under 18, and a parent can link a supervised teen account to see channel activity.

Settings do not replace the conversation. Give teens the rules this guide gives adults: never share a code, check with a friend another way before sending anything, and come to you straight away if someone threatens to share their photos unless they pay. The FTC reports scammers who trick people into sending nude photos, then threaten to send them to their social media contacts.

## When social media is part of your job

The risks multiply when an account speaks for a business. Staff sign in to company pages, ad accounts and recruiting tools, and one phished employee can hand a stranger the brand. Meta warns that criminals have sent Business Manager partner requests containing phishing links, and that those notifications arrive from its real facebookmail.com domain, so the sender address alone proves nothing.

The rules above apply at company scale: every person with access signs in with their own identity protected by multi-factor authentication, nobody shares one password for the company page, and access ends when someone leaves. Our [IT support service](https://computese.com/services/it-support/) covers that ground: one identity per person, protected by MFA and conditional access, phishing-resistant sign-in where possible, and offboarding that revokes accounts, sessions and devices in one documented sequence. If scammers are borrowing your brand, our [security scanning](https://computese.com/services/security-testing/) service checks DMARC, SPF and DKIM on your domain and watches for lookalike domains. More guides like this one are in [Security](https://computese.com/category/security/).

## Key terms
- **Two-step verification (2SV)**: A second check at sign-in after the password, such as a code from an app or a text message, a prompt on a trusted phone or a security key. Also called two-factor authentication (2FA) or multi-factor authentication (MFA).
- **Passkey**: A sign-in credential built on a key pair from the WebAuthn standard. The private key stays on your device or in your password manager and is unlocked with your face, fingerprint or screen lock; the platform keeps only the public key.
- **Authenticator app**: An app such as Google Authenticator, Microsoft Authenticator or Duo that generates one-time sign-in codes on your phone, so the codes never travel over the phone network.
- **Security key**: A small physical device that proves it is you by cryptography, connected by USB, NFC or Bluetooth. The FTC calls it the strongest method of two-factor authentication.
- **SIM swap**: A fraud in which a criminal persuades your mobile carrier to move your phone number to a SIM they control, then receives your text-message codes and password resets.
- **Password manager**: An app that creates, stores and fills a different strong password for every account, so you only have to remember the one that opens it.
- **Phishing**: A message or web page that imitates someone you trust to get your password, sign-in codes, personal details or money. On social media it often arrives as a direct message.
- **Account takeover**: Someone else gaining control of your account, usually with a stolen password or code, and then using it to post, message or scam your contacts in your name.
- **Digital footprint**: The information about you that is available online, including what friends and colleagues post about you. Criminals use it to steal identities and to make phishing more convincing.
- **Pig butchering**: The name the Canadian Anti-Fraud Centre uses for scams that combine a slowly built online relationship with a fake cryptocurrency investment platform.

## Common questions

### What is the most important social media safety tip?

Protect the sign-in. A unique password plus a passkey or two-step verification means a stolen or reused password no longer opens the account on its own. Start with the email account behind your social media, because whoever controls it can reset your other passwords.

### Is two-factor authentication by text message safe enough?

It is much better than a password alone, but it is the weakest option. A SIM swap can move your number, and your codes, to a criminal's phone, and any code can be tricked out of you. Use a passkey, a security key or an authenticator app where the platform offers one.

### Should my social media account be private?

For a personal account, usually yes, or at least share posts with friends or followers only. A private account limits who sees your posts, but your name, username and profile photo usually stay public, and anything a follower can see can be screenshotted and shared.

### What should I do first if my social media account is hacked?

Open the platform's own recovery page, such as facebook.com/hacked or instagram.com/hacked, from a device you have used before. Reset the password, sign out every other session, turn on two-step verification, then warn your contacts not to trust recent messages from you.

### How can I tell if a social media account is fake?

Check when it was created, whether it is verified, whether the name looks random and whether its followers and activity look real. On Instagram, About This Account shows the creation date, country and former usernames. If a friend's account asks for money or a code, contact them another way.

### At what age can children use social media?

Most platforms set 13 as the minimum age, though the NCSC notes it is easy to sign up with a false birth date. Instagram and TikTok start teen accounts private with limited messaging, Facebook and Messenger have Teen Accounts too, and YouTube turns on break and bedtime reminders for teens.

## Sources
1. [Data Spotlight: Reported losses to scams on social media eight times higher than in 2020](https://www.ftc.gov/news-events/data-visualizations/data-spotlight/2026/04/reported-losses-scams-social-media-eight-times-higher-2020), U.S. Federal Trade Commission
2. [Social Media: how to use it safely](https://www.ncsc.gov.uk/guidance/social-media-how-to-use-it-safely), UK National Cyber Security Centre
3. [Keep your Facebook profile secure](https://www.facebook.com/help/213481848684090), Meta (Facebook Help Centre)
4. [How To Recover Your Hacked Email or Social Media Account](https://consumer.ftc.gov/articles/how-recover-your-hacked-email-or-social-media-account), U.S. Federal Trade Commission
5. [Report a compromised account](https://www.linkedin.com/help/linkedin/answer/a1340402), LinkedIn Help
6. [Top tips for staying secure online: Three random words](https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words), UK National Cyber Security Centre
7. [Use Two-Factor Authentication To Protect Your Accounts](https://consumer.ftc.gov/articles/use-two-factor-authentication-protect-your-accounts), U.S. Federal Trade Commission
8. [Sim card swap](https://antifraudcentre-centreantifraude.ca/scams-fraudes/sim-eng.htm), Canadian Anti-Fraud Centre
9. [NCSC: Leave passwords in the past, passkeys are the future](https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future), UK National Cyber Security Centre
10. [Passkeys are more secure than traditional ways to log in](https://www.ncsc.gov.uk/blogs/passkeys-are-more-secure-than-traditional-ways-to-log-in), UK National Cyber Security Centre
11. [How two-factor authentication works on Facebook](https://www.facebook.com/help/148233965247823), Meta (Facebook Help Centre)
12. [Create a passkey on Facebook](https://www.facebook.com/help/1181045243159511), Meta (Facebook Help Centre)
13. [Securing your Meta Account with two-factor authentication](https://help.instagram.com/566810106808145), Instagram Help Center
14. [Account safety](https://www.tiktok.com/support/faq_detail?id=7543604780950624824), TikTok Support
15. [Passkeys on TikTok](https://www.tiktok.com/support/faq_detail?id=7581816994987776523), TikTok Support
16. [How to use two-factor authentication](https://help.x.com/en/managing-your-account/two-factor-authentication), X Help Center
17. [How to use passkeys](https://help.x.com/en/managing-your-account/how-to-use-passkey), X Help Center
18. [Two-factor authentication overview](https://www.linkedin.com/help/linkedin/answer/a1358878), LinkedIn Help
19. [Turn on 2-Step Verification](https://support.google.com/accounts/answer/185839), Google Account Help
20. [Facebook Privacy Checkup](https://www.facebook.com/help/443357099140264), Meta (Facebook Help Centre)
21. [Avoid getting scammed on Instagram](https://help.instagram.com/514187739359208), Instagram Help Center
22. [What to do if your account has been compromised](https://help.x.com/en/safety-and-security/x-account-compromised), X Help Center
23. [Manage your account and privacy settings](https://www.linkedin.com/help/linkedin/answer/a1337839), LinkedIn Help
24. [Make your account more secure](https://support.google.com/accounts/answer/46526), Google Account Help
25. [Choose who can see your post on Facebook](https://www.facebook.com/help/120939471321735), Meta (Facebook Help Centre)
26. [Make your Instagram account private](https://help.instagram.com/448523408565555), Instagram Help Center
27. [Teen privacy and safety settings](https://www.tiktok.com/support/faq_detail?id=7611839632052853259), TikTok Support
28. [About public and protected posts](https://help.x.com/en/safety-and-security/public-and-protected-posts), X Help Center
29. [Change video privacy settings](https://support.google.com/youtube/answer/157177), YouTube Help
30. [Protect yourself from phishing on Instagram](https://help.instagram.com/670309656726033), Instagram Help Center
31. [Protect yourself from fraud](https://antifraudcentre-centreantifraude.ca/protect-protegez-eng.htm), Canadian Anti-Fraud Centre
32. [Investment Scams](https://consumer.ftc.gov/articles/investment-scams), U.S. Federal Trade Commission
33. [Investment](https://antifraudcentre-centreantifraude.ca/scams-fraudes/investment-investissement-eng.htm), Canadian Anti-Fraud Centre
34. [What To Know About Romance Scams](https://consumer.ftc.gov/articles/what-know-about-romance-scams), U.S. Federal Trade Commission
35. [Relationship and romance](https://antifraudcentre-centreantifraude.ca/scams-fraudes/romance-rencontre-eng.htm), Canadian Anti-Fraud Centre
36. [Recovery pitch](https://antifraudcentre-centreantifraude.ca/scams-fraudes/recovery-recuperation-eng.htm), Canadian Anti-Fraud Centre
37. [Scammers hide harmful links in QR codes to steal your information](https://consumer.ftc.gov/consumer-alerts/2023/12/scammers-hide-harmful-links-qr-codes-steal-your-information), U.S. Federal Trade Commission
38. [Report fraud and cybercrime](https://antifraudcentre-centreantifraude.ca/report-signalez-eng.htm), Canadian Anti-Fraud Centre
39. [Report Fraud: the place to report cyber crime and fraud](https://www.reportfraud.police.uk/), Report Fraud (UK police)
40. [Recovering a hacked account](https://www.ncsc.gov.uk/guidance/recovering-a-hacked-account), UK National Cyber Security Centre
41. [Recover a hacked account](https://www.facebook.com/help/1216349518398524), Meta (Facebook Help Centre)
42. [If you think your Instagram profile has been hacked](https://help.instagram.com/149494825257596), Instagram Help Center
43. [My account has been hacked](https://www.tiktok.com/support/faq_detail?id=7581821084908067339), TikTok Support
44. [Recover a hacked YouTube channel](https://support.google.com/youtube/answer/76187), YouTube Help
45. [Introducing Instagram Teen Accounts](https://about.fb.com/news/2024/09/instagram-teen-accounts/), Meta Newsroom
46. [Instagram Teen Accounts Will Be Inspired by 13+ Movie Ratings Criteria and Parent Feedback](https://about.fb.com/news/2025/10/instagram-teen-accounts-13-movie-ratings/), Meta Newsroom
47. [Hundreds of Millions of Teens Are Now in Teen Accounts](https://about.fb.com/news/2025/09/millions-teens-now-teen-accounts-plus-more-support-schools/), Meta Newsroom
48. [Screen time](https://www.tiktok.com/support/faq_detail?id=7543597459155687941), TikTok Support
49. [Tips & resources for parents of teens on YouTube](https://support.google.com/youtube/answer/2802272), YouTube Help
