Tech

Securing Your Social Media Accounts

A practical guide to securing social media in Singapore: strong passwords, 2FA, login checks, privacy settings and spotting account takeover and impersonation.

Securing Your Social Media Accounts

For most of us in Singapore, social media is where family photos, work contacts, group chats and years of memories all live in one place. That makes securing social media in Singapore worth a little planning, because a hijacked account is not only a private headache. It can be used to message your friends, borrow money in your name or spread scams to everyone who trusts you.

The reassuring part is that you do not need to be a security expert. A handful of settings, checked once and reviewed now and then, will put you well ahead of the trouble. This guide walks through strong passwords, two factor authentication, reviewing your logins and app permissions, tightening privacy settings, and spotting the early signs of a takeover or an impersonator.

Start With Strong, Unique Passwords

The single most useful thing you can do is give every account its own long, unique password. The problem with reusing one password across sites is simple. If any one service is breached, attackers try that same password everywhere else, and your social accounts are often top of the list.

A good password today is less about odd symbols and more about length. A passphrase of several unrelated words is easy for you to remember and hard for a computer to guess. Better still, let a password manager create and store random passwords for you, so you only need to remember one strong master password.

Keep a few habits in mind:

  • Never reuse the password from your email on any social account, since your email can reset the rest.
  • Change a password straight away if a service tells you it was involved in a breach.
  • Do not save passwords in a note titled “passwords” or share them over chat.

Turn On Two Factor Authentication

Two factor authentication, often shortened to 2FA, asks for a second proof of identity after your password. Even if someone steals your password, they still cannot log in without that second step. Every major platform offers it, and turning it on is the highest value few minutes you will spend.

Where you can, choose an authenticator app that generates a rolling code, or a physical security key, rather than SMS. SMS codes are better than nothing, but they can be intercepted if your number is ported away in a SIM swap. When you set up 2FA, the platform usually shows a set of backup codes. Save these somewhere safe and offline, because they are your way back in if you lose your phone.

Review Your Logins and Connected Apps

Most platforms keep a list of the devices and locations currently signed in to your account, tucked inside the security or privacy menu. It is worth a look every few months. If you see a device you do not recognise or a login from a place you have never been, remove it and change your password.

The same menus usually list the third party apps and websites you have connected over the years, such as a game you tried once or a photo editor you granted access. Each connection is a small door into your account. Revoke anything you no longer use. Fewer connections means fewer ways in.

Tighten Your Privacy Settings

Privacy settings decide who can see your posts, your friend list, your photos and your contact details. Defaults tend to favour visibility, so it pays to review them deliberately rather than leave everything public.

Here is a simple way to think about the common controls:

Setting What it controls A safer choice
Post audience Who sees new posts Friends or a chosen list, not public
Profile details Phone, email, birthday visibility Hide or limit to friends
Friend or follow requests Who can reach you Friends of friends only
Tagging Who can tag you and where it shows Review tags before they appear
Search visibility Whether search engines link to you Turn off external indexing

You do not have to lock everything down. The aim is to share on purpose, so strangers cannot quietly harvest your birthday, workplace and daily routine to build a convincing scam or guess your security answers.

Spot Account Takeover Early

The faster you notice a takeover, the more you can save. Watch for messages you did not send, posts you did not write, a changed profile photo or name, or emails saying your password or recovery details were updated. Many platforms email you whenever a new device logs in, so do not ignore those alerts.

If you suspect your account is compromised and you can still get in, act quickly. Change the password, sign out of all other sessions, check that the recovery email and phone number are still yours, and confirm 2FA is on. If you are locked out, use the platform’s official account recovery flow. Tell your contacts too, so they know not to trust odd requests coming from your name.

Watch for Impersonation

Even a perfectly secure account can be copied. Impersonation is when someone creates a fresh profile using your name and photos, then messages your friends pretending to be you, often to ask for money, a favour or a one time code. Your real account is untouched, which is why security settings alone will not stop it.

The defence is awareness. Search your own name now and then to see if a clone exists. Keep your friends list private so a copycat cannot see who to target. If you find a fake, report it to the platform for impersonation and warn your genuine contacts. A short heads up to family, especially older relatives, goes a long way, since the whole trick relies on people not double checking.

One rule protects you from almost every version of these scams. Never share a one time password or verification code with anyone, even someone who sounds exactly like a friend or a platform’s support team. No legitimate service will ask you to read a code aloud or type it into a chat.

Make It a Routine

Securing social media in Singapore is not a one off task, but it is a light one once it is set up. Twice a year, take ten minutes to check your active logins, revoke unused app connections, glance over your privacy settings and confirm 2FA is still switched on. Between those check ins, stay a little sceptical of urgent messages and unexpected code requests.

If something does go wrong and money is involved, report it to the Police and to Singapore’s anti scam channels, and look up the official hotline rather than trusting a number sent to you in a message. A few steady habits keep your accounts, and the people who trust them, safely in your hands.

Explore more

Password Security Guide
Two-Factor Authentication Guide
Cybersecurity Basics
Using ScamShield and Singapore’s Anti-Scam Tools