How to protect your personal information online
Most advice here is about companies watching you. This is about the other half - what you hand over yourself, what each piece is worth to a criminal, and the small number of habits that cut off most of it.
The short answer
- Personal information is not equally sensitive. Identity numbers, date of birth and your phone number matter far more than an email address, because they cannot be changed.
- Most of what a scammer knows about you was published by you, sold by a data broker, or leaked in a breach - not stolen from your device.
- Answer security questions with invented answers stored in a password manager. Real answers are findable, and NIST now tells services not to use the questions at all.
- Set a PIN with your mobile provider. Your phone number is the recovery route for many accounts, and taking it over is a known attack.
- Public Wi-Fi is now usually safe because most sites are encrypted. Oversharing and reused passwords are the bigger risks.
Protecting your personal information comes down to four habits, and only four:
- Give out less than is asked for. Most forms request more than they need.
- Never answer security questions honestly. Invent the answers and store them in a password manager.
- Lock the two things that unlock everything else — your email account and your phone number.
- Treat unexpected requests as unverified, no matter how much the person already seems to know.
Everything below is the reasoning, and the detail of how to do each one.
This page is deliberately about what you disclose. For the parallel question of what companies collect without asking, start at online privacy.
Not all personal information is equal
The single most useful idea here is that these details differ enormously in value, and the difference is whether you can change them.
| Information | Why it matters | Can you change it? |
|---|---|---|
| Password | Opens the account directly | Yes, in a minute |
| Email address | The recovery route for most accounts, and a phishing target | Hard, but possible |
| Phone number | Receives security codes; a takeover target | Hard, and disruptive |
| Date of birth | Used to pass identity checks, forever | No |
| Home and previous addresses | Identity checks, and physical risk | Only by moving |
| Mother's maiden name, first pet, first school | Answers to account recovery questions | Not in reality |
| National ID or Social Security number | Enables credit and accounts in your name | Almost never |
The FTC's list of what identity thieves want covers the same ground: "your name and address, credit card or bank account numbers, Social Security number, or medical insurance account numbers."
The Identity Theft Resource Center's 2025 report reached the same conclusion from the attacker's side. It found that criminals "have prioritized static identifiers that facilitate long-term identity fraud over easily replaceable data, such as credit card numbers."
Where your information actually leaks
Almost none of it involves anyone breaking into your device.
You published it. Birthdays, employers, pets, schools, holiday dates, photographs of documents, the road you grew up on. The FTC found that scammers "exploit what a user posts to figure out how to target them". In 2025, nearly 30% of people who reported losing money to a scam said it started on social media. Reported losses reached $2.1 billion.
A company leaked it. The Identity Theft Resource Center recorded a record 3,322 US data compromises in 2025, and phishing remained the leading root cause. Its consumer survey found 80% of people had received at least one breach notice in the previous year.
A broker sold it. Address history, household composition, estimated income and inferred interests are assembled and sold by companies you have never contacted. See data brokers.
An app collected it. Location, contacts and identifiers flow out of apps through embedded third-party code. See app permissions.
It went in the bin intact. Paper still matters. The FTC's shredding guidance lists ATM receipts, credit and insurance offers, cleared cheques after 14 days, old credit reports and prescription details as things to shred.
Security questions are the weakest link, and the easiest fix
Consider what a security question actually is: a password that you cannot change, that you have told several hundred people, and that is often on your own social media profile.
Your mother's maiden name is on genealogy sites. Your first school is on your profile. Your first pet was in a photo caption.
NIST reached the obvious conclusion. Its current guidance says verifiers "SHALL NOT prompt subscribers to use knowledge-based authentication (KBA) (e.g., 'What was the name of your first pet?') or security questions". Many services still use them anyway.
So lie. The FTC's guidance is to avoid questions with answers someone could
find online or in public records. Its advice on quizzes goes further: treat the
questions like passwords and use a made-up answer, stored in your
password manager. Your mother's maiden name can be
Parmesan, which is the FTC's own example.
Lock the two accounts that unlock everything
Your email
Email is the reset mechanism for everything else. Someone with your inbox does not need your banking password — they can ask the bank for a new one.
The NCSC makes this its first Cyber Aware action: use a strong and separate password for your email, one you use nowhere else. Its reason is that "cyber criminals can use your email to access many of your personal accounts, leaving you vulnerable to identity theft."
Give it a unique password, turn on two-factor authentication, and check occasionally for forwarding rules you did not create.
Your phone number
Your number receives security codes, which makes taking it over valuable. In a SIM swap, someone persuades your mobile provider to move your number to their device. The FTC's description of the outcome is exact: "the scammer — not you — will get all your text messages, calls, and data."
They pass the provider's identity checks using details gathered from your public profiles and from breaches.
Two things help. Set a PIN or passcode on your mobile account — this is the FTC's first recommendation. And where a service supports it, use an authenticator app or a security key rather than SMS codes for anything valuable.
The sharing habits worth changing
You do not need to leave social media. You need to change a handful of specific things.
Do not post the answers to your own security questions. First pet, first school, first car, mother's maiden name, the street you grew up on.
Do not announce that you are away. CISA's tip sheet lists vacation plans alongside account numbers as things to keep private, and advises disabling geo-tagging, "which allows anyone to see where you are — and where you are not — at any given time."
Do not post images of documents. Boarding passes, driving licences, bank letters, exam certificates, a new bank card. Each carries numbers that are useful and often permanent.
Review who can see what, and do it again occasionally. CISA notes that defaults are often public and that settings change over time, so a review that happened once has already decayed.
Be careful with other people's information, especially children's. Schools, uniforms, routines and full names are the details that matter, and the child did not choose to publish them.
Use a separate email address for shopping and sign-ups. It keeps marketing lists and breach exposure away from the address that resets your bank.
Why this is a scam-prevention page, not just a privacy one
The reason to care is not abstract. Every detail about you is raw material for a more convincing approach.
A message naming your employer, your recent purchase and a colleague is not evidence of sophisticated hacking. It is evidence that someone read your profile or bought a list. The NCSC describes this directly: your digital footprint is "the information about you that is available online", and "criminals can use this to steal your identity, or make phishing messages more convincing."
That is the mechanism behind pretexting and impersonation scams. Reducing what is publicly knowable about you does not just protect your privacy. It directly lowers the quality of the story that can be built against you.
The baseline everyone should have
Both CISA and the NCSC reduced their public advice to a short list, and the two lists agree.
CISA's four steps are: recognise and report phishing, use strong passwords with a password manager, turn on multi-factor authentication, and update software. The NCSC adds two: back up your data, and build passwords from three random words.
Applied to personal information specifically:
- A unique password on every account, generated and stored by a password manager. The FTC suggests aiming for at least 15 characters.
- Two-factor authentication on email, banking and anything with stored card details.
- Software updates on, because updates "often contain critical patches and protections against security threats."
- Never act on an unexpected request using the contact details it supplied. The FTC's version: do not click a link in an unexpected email or text; contact the company using a phone number or website you know is real.
What matters less than people think
Public Wi-Fi. The FTC's current position is that "because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe." Look for https or a lock in the address bar. Note the limit, which the FTC also states: scammers can build encrypted fake sites, so the lock proves the connection is private, not that the site is honest.
Incognito mode. It stops browsing being saved on that device. It does not hide you from the sites you visit or from fingerprinting.
A VPN. It moves trust from your network provider to the VPN operator. It does nothing about what you type into a form or post on a profile.
Deleting one account while the same details remain on three others and several broker profiles.
A review you can do in twenty minutes
- Search your own name and see what a stranger finds
- Change any security question answer that is truthful and findable
- Set a PIN with your mobile provider
- Check the privacy settings on each social account
- Remove your birthday, address and phone number from public profiles
- Delete old posts that show documents, tickets or a home exterior
- Give email its own unique password and a second factor
- Turn off geo-tagging in your camera app
- Set a calendar reminder to do this again in six months
Where to go next
- Online privacy — what companies collect, and what you can change
- How online tracking works — the machinery behind it
- Data brokers — who sells your profile, and how to opt out
- App permissions — a ten-minute review
- Location privacy — the most revealing data you generate
- Password exposed in a breach — what to do when it has already leaked
- Removing your information from the internet — search results, people-search sites and old accounts
- Is public Wi-Fi safe? — what encryption fixed, and what it did not
See what you are giving away
Our privacy walkthrough shows what a stranger can assemble about a person from public posts alone, and how each piece would be used.
Try it freeFrequently asked questions
- What counts as personal information?
- Anything that identifies you or helps someone pretend to be you. The FTC lists what identity thieves are after as your name and address, credit card or bank account numbers, Social Security number, and medical insurance account numbers. In practice the list is wider, because a date of birth, a mother's maiden name, a phone number and your daily routine are all useful to someone building a convincing approach.
- What personal information should I not share online?
- CISA's guidance is to keep private your Social Security number, account numbers and passwords, along with your full name, address, birthday and vacation plans. Add anything that answers a security question, anything that identifies where a child goes to school, and photos of documents. Its wider point is that seemingly random details, even where you like to get coffee, are what a criminal needs to target you.
- How do scammers get my information?
- Mostly from three places. Things you posted publicly, data brokers who assemble and sell profiles, and company data breaches. The Identity Theft Resource Center recorded a record 3,322 US data compromises in 2025. The FTC notes that scammers exploit what a user posts to figure out how to target them. Very little of it involves breaking into anyone's device.
- Are online quizzes really dangerous?
- They can be, because their questions often match security questions. The FTC warns that scammers use quiz answers to try to reset your accounts, and the BBB lists typical quiz questions like your first car, your mother's maiden name and the street you grew up on. Either skip them or answer untruthfully.
- Is public Wi-Fi safe now?
- Usually, yes. The FTC's current position is that because most websites use encryption, connecting through public Wi-Fi is usually safe, and advises looking for a lock symbol or https in the address bar. It also warns that scammers can build fake sites that use https too, so the lock proves the connection is encrypted, not that the site is trustworthy.
- How do I stop someone taking over my phone number?
- Set a PIN or passcode on your mobile account, which is the FTC's first recommendation against SIM swap scams. If the swap succeeds, the scammer rather than you receives your calls, texts and data - including security codes. Where a service allows it, use an authenticator app or a security key rather than SMS codes for anything valuable.
- Does deleting old posts and accounts help?
- Partly. It reduces what someone finds when they search your name today, which is worth doing. But CISA's reminder holds - there is no delete button on the internet, and information copied or archived by someone else stays copied. Treat deletion as reducing future exposure rather than undoing past exposure.
Sources
- Protect Your Personal Information From Hackers and Scammers — Federal Trade Commission, 2024
- What To Know About Identity Theft — Federal Trade Commission, 2024
- Don't answer another online quiz question until you read this — Federal Trade Commission, 2023
- SIM Swap Scams: How to Protect Yourself — Federal Trade Commission, 2019
- Are Public Wi-Fi Networks Safe? What You Need To Know — Federal Trade Commission, 2023
- Protecting your personal information: which documents to keep and which to shred — Federal Trade Commission, 2025
- How To Protect Your Child From Identity Theft — Federal Trade Commission, 2024
- New FTC Data Show People Have Lost Billions to Social Media Scams — Federal Trade Commission, 2026
- Consumer Sentinel Network Data Book 2024 — Federal Trade Commission, 2025
- Secure Our World — Cybersecurity and Infrastructure Security Agency, 2026
- Cybersecurity Basics for Social Media — Cybersecurity and Infrastructure Security Agency, 2022
- Staying Safe on Social Networking Sites — Cybersecurity and Infrastructure Security Agency, 2021
- Social Media: how to use it safely — UK National Cyber Security Centre, 2022
- Top tips for staying secure online — UK National Cyber Security Centre, 2021
- NIST SP 800-63B: Digital Identity Guidelines — National Institute of Standards and Technology, 2025
- 2025 Annual Data Breach Report — Identity Theft Resource Center, 2026
- BBB Scam Alert: Bored? Think twice before taking that Facebook quiz — Better Business Bureau, 2023
About the author
Cybersecurity & Digital Literacy
Subash Poudel builds SafeSurf IQ, a digital literacy platform that teaches people to recognise scams by putting them in front of real ones. He writes the online-safety reference material here, working from primary reporting — FBI IC3, the FTC, Verizon's DBIR, NCSC and Ofcom — rather than secondhand summaries.
- Founder and engineer, SafeSurf IQ
- Writes and reviews the platform's phishing, scam and privacy curriculum
- Works from primary incident and fraud reporting, cited on every article
Last reviewed . Figures are checked against the primary sources listed above at each review.
Read next
- Privacy
Online privacy: what is actually collected, and what you can change
Online privacy is not about having something to hide. It is about who holds a record of your behaviour, how precisely you can be identified without cookies, and which of those things you can practically change.
- Privacy
How to remove your personal information from data brokers
Your name, address, relatives and estimated income are already for sale on people-search sites you have never heard of. Here is how to find what is exposed, remove it from the brokers that matter most, and reduce how quickly it comes back.
- Privacy
Which app permissions should you turn off?
A dozen apps on your phone are probably still holding location, contacts or microphone access from years ago. Here is which permissions are worth turning off, which are safe to keep, and the ten-minute review that finds them on iPhone and Android.