Social media is a haven for scammers and hackers. Even if you haven’t been scammed yourself, you almost certainly know someone who has.
In this short lesson, we will look at some of the common traps people fall into and how you can avoid them.
Fake contests
Scammers may use fake contests to gather information they can use for spamming and phishing, or to sell to other criminals. But how can you tell the difference between a genuine contest and one set up by scammers?
If you found the contest on social media, check the page that created it.
- Has the page existed for a long time?
- Has it been verified?
- If the contest appears to be from a well-known company, check the company’s official website. Does it link back to that same social media page?
If all three of these indicators are missing, it is highly likely that scammers are at work. Immediately report any fake pages to the platform.
FREE, but not entirely without cost…
When someone tries to give something away for FREE, there may be an ulterior motive. To download a free e-book, you might be asked to provide your name, date of birth, phone number, email address, or other personal information. This information may be sold to people with dishonest intentions, such as spammers and scammers.
The e-book you downloaded could also contain malware, something you definitely do not want. The same applies to other types of downloaded files, such as PDFs, images, music, videos, and software. That is why you should not download material from websites you have never heard of before, and should steer clear of pirated copies.
If someone asks for personal information in exchange for a ‘free’ item, you might want to use a temporary email address, a fake name, and a fake phone number.
Account hijacking and cloning
If your Instagram password is weak, hackers are more likely to break into your account. Once inside, they can change your password and contact information, making it impossible for you to regain access. Next, they may use your account to scam others, spread rumours and fake news, verbally abuse people, and generally cause trouble; all in your name.
To avoid account takeover, using a strong password and enabling MFA (Multi-Factor Authentication) for your account are the most effective measures you can take.
In some cases, scammers may choose to clone your profile instead. They create a new profile using your name and copy your public photos to their account. They then message your friends, claiming you lost the password to your old account and created a new one. Unfortunately, many people fall for this and add the scammer as a friend.
So, if you receive a friend request from someone you already know, contact them via phone or their original profile to verify that the request is genuine. If the profile turns out to be fake, report it to the platform so it can be removed.
Curious?
A good, few years back, Facebook was flooded with posts like: “Find out who’s viewed your profile!”, which were, of course, complete nonsense. Yet, many people clicked on these posts and ended up on websites run by scammers.
Another well-known scam involves a “friend” messaging you to claim they’ve found a nude photo or video of you online. They ask you to click a link to verify if it’s really you. These messages are often sent via hacked or cloned accounts belonging to people you trust.
That is why you should think twice before clicking on anything. This also applies to links you receive from friends. If something looks suspicious, call the sender and check with them before doing something you might regret.
Phishing in the comments section
We all know we should be careful about what we share online, but sometimes we walk right into the trap without thinking. “It’s just a bit of harmless fun,” we tell ourselves. But is it really?
How many times have you seen similar posts on social media and given in to the temptation to comment?
Only legends drive BMWs!
If your first car was a “Beamer,” share a photo of it in the comments.
Do you have a furry friend in heaven?
Honour your friend by sharing their name and a photo below <3
Manchester United is the world’s best football team!
Comment below if you agree.
Your first car brand, your first pet’s name, your parents’ names, and where and when you were born are the answers to common security questions still used by some websites. If you lose access to your account, you need to know the answers to these questions to reset your password.
In some cases, the answers requested by the phishing post are directly related to your password. Football fans love using the team they support as their password, which doesn’t exactly make life difficult for hackers. As we mentioned in a previous nano lesson, “Liverpool1” is one of the most common passwords in the UK.
Fake fundraisers
Anyone can create a fundraiser on Facebook or GoFundMe and ask for donations. Professional platforms have security measures that catch most fraudulent actors, but private fundraisers are not vetted. This makes it easy to get scammed.
How to avoid fundraising scams:
- For Norwegian fundraisers: check if the organisation is registered with Innsamlingskontrollen.
- For US/Int. fundraisers: use Charity Navigator to verify the organisation’s legitimacy.
- For UK fundraisers: The Charity Commission for England and Wales has a searchable registry
- For crowdfunding: check if the story is credible and if there is supporting documentation.
- For private fundraisers on social media: be extra cautious, as these are the easiest to abuse and near impossible to verify.
Remember: If something seems urgent, emotionally charged, or unclear, there is all the more reason to pause and investigate.
Take our quick quiz to see if you remember the basics
Results
Well done!
Not quite there yet. You might want to read the lesson again.




