How Can I Use Social Media Safely?

Overview

Social media makes it easy to communicate, build communities, share information, and maintain professional and personal connections. It also gives scammers and other malicious actors a place to collect information, impersonate people and organizations, distribute harmful links, and take over accounts.

Information posted on social media can be useful to an attacker even when it does not appear sensitive by itself. A birthday, family relationship, job title, class schedule, travel plan, photograph, or location can help someone create a convincing message, answer an account-recovery question, or impersonate you.

Privacy settings reduce who can see your content, but they do not guarantee confidentiality. Other people may copy, save, forward, or take screenshots of information you share. Treat every post, message, photograph, and video as something that could eventually reach a wider audience than you intended.

How It Works

Common social-media security risks include:

  • Account takeover. An attacker may use a stolen or reused password, a phishing page, a malicious application, or a stolen session to gain access to an account.
  • Impersonation. A scammer may copy a person's name, profile image, biography, or public posts to create a convincing fake account.
  • Direct-message scams. A message may appear to come from a friend, coworker, supervisor, organization, or business whose account has been compromised or impersonated.
  • Malicious links and attachments. A post, advertisement, message, or comment may direct you to a fake sign-in page, fraudulent store, harmful download, or scam.
  • Information gathering. Public posts can reveal relationships, routines, locations, interests, travel, employment details, or answers commonly used for account recovery.
  • Fraudulent advertisements and sellers. A sponsored post or marketplace listing may lead to counterfeit merchandise, non-delivery scams, investment fraud, or a request to pay outside the platform.
  • Abusive application permissions. A quiz, game, filter, or third-party application may request access to profile information, contacts, messages, photographs, or account functions that it does not need.

A familiar profile does not prove that the person behind it is genuine. An attacker who controls a real account can read prior conversations and use that context to make new requests sound credible.

Warning Signs

Be cautious when you notice:

  • A duplicate profile or a new connection request from someone you already follow.
  • An unexpected message asking for money, gift cards, cryptocurrency, account access, personal information, or an MFA code.
  • A message that creates urgency, asks for secrecy, or discourages you from contacting the person another way.
  • A link claiming that your account violated a rule, needs immediate verification, or will be suspended unless you sign in.
  • A request to move the conversation to another platform or payment method before you can verify the sender.
  • Posts, messages, follows, advertisements, or profile changes that you did not create.
  • Sign-in alerts, password-reset notices, or MFA prompts that you did not initiate.
  • A third-party application requesting broad access to your account, contacts, messages, camera, microphone, or files without a clear need.
  • A profile whose username, spelling, account age, follower history, or web address differs slightly from the person or organization it claims to represent.
  • A supposed platform-support representative who contacts you through a personal account or asks for your password, verification code, or payment.

A message may be fraudulent even when it comes from a real account. Verify unusual requests independently rather than relying only on the profile, writing style, voice, photograph, or conversation history.

How to Protect Yourself

  • Use a strong, unique password. Do not reuse the password for email, banking, UM, or other important accounts. A password manager can help create and store unique passwords.
  • Enable MFA. Use the strongest method the platform supports, and approve only requests you initiated.
  • Protect your email account. Email is often used to reset social-media passwords. Use a unique password and MFA on the email account connected to your profile.
  • Review privacy and security settings. Limit who can see posts, contact you, tag you, find you by phone number or email address, and view your location.
  • Limit personal details. Avoid publishing information that could support impersonation, account recovery, stalking, or fraud, including full birth dates, home addresses, class or work schedules, travel plans, identity documents, and financial information.
  • Consider the background of photographs and videos. Badges, mail, computer screens, whiteboards, vehicle plates, building access details, and other information may be visible unintentionally.
  • Verify unusual requests outside the platform. Call or message the person using contact information you already know. Do not use a number supplied in the suspicious message.
  • Review connected applications. Remove applications, browser extensions, games, and services you no longer use or do not recognize.
  • Keep applications and devices updated. Install security updates and use a screen lock on the phone, tablet, or computer that can access the account.
  • Do not share passwords or MFA codes. Platform support, a friend, an employer, and UM staff should not ask you to disclose them.
  • Be cautious with quizzes and public prompts. Questions about pets, schools, relatives, first cars, or childhood details can reveal information commonly used in passwords or account-recovery questions.
  • Review posts before publishing. Confirm the intended audience, remove unnecessary location data, and consider whether the information will still be appropriate if copied or viewed later.
  • Report and block fraudulent accounts. Use the platform's official reporting process for impersonation, scams, harassment, or compromised accounts.

What You Should Do at UM

If a social-media message, profile, advertisement, or post involves a UM account, UM identity, university organization, university data, or university financial process:

  1. Do not click unfamiliar links, send money, provide information, or approve an MFA request.
  2. Verify the person or office through a trusted UM channel. Use an official UM website, the UM directory, a known phone number, or a new message to a verified UM address.
  3. Report the account, post, advertisement, or message to the social-media platform. Preserve the profile name, web address, message, and screenshots when doing so is safe.
  4. Contact the UM IT Helpdesk or UM Information Security Office when the activity impersonates UM, uses a UM account, requests university information, or may affect a UM system or device.

If you entered your UM password on a page reached through social media, shared an MFA code, or approved a request you did not initiate, change your UM password through the normal UM account-management process and contact the UM IT Helpdesk or UM Information Security Office.

If a suspicious social-media notification arrives by email in your UM mailbox, use Outlook's Report Message tool and report the message as phishing. Delete the message after reporting it. The Report Message tool may remove it automatically.

For an official UM social-media account, do not share the account password among multiple people or use an individual's personal recovery information without an approved process. Limit administrative access to people who need it, use MFA, and remove access promptly when responsibilities change.

A problem involving only a personal social-media account should normally be handled through the platform's official account-recovery and reporting process. Contact UM when a UM account, device, message, identity, data set, or university process is also involved.

Additional Questions

For social-media activity involving a UM account, UM device, university identity, university information, or a UM business process, contact the UM IT Helpdesk and the UM Information Security Office. For an official UM social-media account, involve the appropriate UM communications office or account owner.

For a personal social-media concern:

  • Use the platform's official reporting, privacy, security, and account-recovery tools.
  • Contact the email provider if the email account connected to the profile may also be compromised.
  • Contact your bank, credit union, card issuer, or payment provider immediately if money or financial information was involved.
  • Report consumer fraud to the Federal Trade Commission. Internet-enabled fraud can also be reported to the FBI's Internet Crime Complaint Center.

Additional Resources

Was this helpful?
0 reviews