Things You Should Never Do Online: The Guide to Staying Safe on the Internet
The internet makes shopping, banking, communication, entertainment, work and learning easier than ever. But many online problems begin with something surprisingly ordinary: clicking a link, sharing a piece of information, downloading a file or trusting a message that looks legitimate.
The biggest mistake is assuming that an online threat will always look suspicious.
Modern scams can imitate businesses, friends, employers, delivery companies, banks and even people you know. Some use urgency. Others use fear, curiosity, attractive offers or convincing technology.
The safest approach is not to become afraid of the internet. It is to develop a few habits that make it much harder for someone to manipulate you.
Here are the most important things you should never do online.
1. Never Use the Same Password Everywhere
If one website suffers a data breach and your password is exposed, attackers may try the same combination on your email, shopping, banking and social-media accounts.
Using a different password for every important account limits the damage from a single compromised password.
Your email account deserves particular attention because access to email can sometimes provide a route to reset passwords for other accounts.
Better habit
Use a unique password or passphrase for every important account and enable two-step verification wherever available.
2. Never Share Your Password With Someone Who Contacts You Unexpectedly
A message might claim to come from:
your bank
your employer
a delivery company
a government agency
technical support
a social-media platform
a friend
an online marketplace
The fact that the message appears official does not prove that it is genuine.
A legitimate-looking message can be designed to persuade you to reveal a password, verification code or other sensitive information.
The safest rule
Never disclose a password or security code because an unexpected message tells you to.
If you believe the request could be legitimate, contact the organization independently using information you already trust.
3. Never Click a Suspicious Link Just to See Where It Goes
Curiosity is one of the easiest emotions to exploit.
A message saying:
“Your account will be closed today.”
or
“You have received a payment.”
or
“Your delivery could not be completed.”
may encourage you to click immediately.
Phishing attacks commonly use stories involving account problems, payments, unusual activity or urgent verification. (Consumer Advice)
You do not need to click the link to investigate.
Open the relevant service yourself using a trusted method.
4. Never Trust a Message Simply Because It Contains a Familiar Logo
A logo proves almost nothing.
Scammers can copy:
logos
colors
email layouts
signatures
photographs
names
business addresses
website designs
A message can look almost identical to a genuine communication while sending you somewhere completely different.
Remember
Appearance is not authentication.
Verify the sender and destination independently.
5. Never Assume the Caller ID Is Genuine
A familiar name or number appearing on your phone does not automatically prove who is calling.
Scammers can manipulate caller identification information.
A particularly dangerous situation is when a caller creates urgency and asks you to transfer money, reveal security information or install software.
If something feels unusual, end the conversation and contact the organization through a number or website you independently know to be genuine. Consumer-protection guidance specifically warns that scammers can impersonate organizations and manipulate caller ID information. (Consumer Advice)
6. Never Give a Stranger Remote Access to Your Computer
One of the most dangerous online-support scams begins with a frightening message:
“Your computer has a serious virus.”
The person may then ask you to install remote-access software.
Once remote access is granted, the stranger may be able to view information, change settings, install software or access files.
Better rule
If you need technical support, initiate the support process yourself through a company or professional you already trust.
Do not give remote access merely because someone contacted you first.
7. Never Scan an Unknown QR Code Without Checking It
QR codes are convenient, but convenience can also be exploited.
A QR code can direct you to a website without you manually typing the address.
That means a fake QR code can send you somewhere you did not intend to go.
Current consumer warnings include scams involving QR codes placed over legitimate codes, including payment situations. (Consumer Advice)
Before scanning a QR code:
Ask yourself why it is there and where it is supposed to lead.
If you are paying for something, verify the destination before entering financial or login information.
8. Never Assume a Website Is Safe Because It Looks Professional
A polished website can still be fraudulent.
Look beyond the design.
Check:
the exact web address
whether the address is what you expected
contact information
return and refund policies
payment methods
unusual spelling in the domain
unexpected redirects
suspicious discounts
requests for unnecessary personal information
A secure connection is important, but HTTPS alone does not prove that the business itself is legitimate.
A scam website can also use an encrypted connection.
9. Never Buy Something Online Solely Because the Price Looks Incredible
An extremely cheap offer can be designed to bypass your normal judgment.
Before purchasing from an unfamiliar seller, consider:
Who is selling it?
How long has the seller existed?
Does the seller have a real return policy?
Is the price dramatically different from comparable offers?
What payment methods are being demanded?
Does the website provide meaningful contact information?
Online-shopping safety guidance recommends researching unfamiliar sellers and being cautious about deals that seem too good to be true. (FTC-I)
10. Never Send Money Because Someone Is Creating Panic
Pressure is one of the oldest scam techniques.
You may be told:
“Act now.”
“Do not tell anyone.”
“Your account will be closed.”
“You will be arrested.”
“Your computer is infected.”
“Your family member is in trouble.”
“You must pay immediately.”
The purpose is to prevent you from thinking.
Use the pause rule
Stop.
Do not pay.
Do not click.
Verify independently.
Legitimate organizations generally do not need you to make an irreversible financial decision within seconds.
11. Never Pay Using a Method a Stranger Specifically Demands
Be particularly cautious when someone insists that you must pay using a particular method because it makes the transaction difficult to reverse or dispute.
Common warning signs include demands for:
gift cards
cryptocurrency
unusual money-transfer arrangements
cash
wire transfers
payment to an unrelated person
The payment method can be part of the scam itself. (Consumer Advice)
If someone tells you that you must use a particular payment method immediately, stop and independently verify the situation.
12. Never Post Your Personal Information Publicly
Think carefully before posting information such as:
full date of birth
home address
personal phone number
travel plans
identification numbers
account details
photographs of official documents
boarding passes
tickets containing scannable information
information about your daily routine
Information that appears harmless individually can become much more useful when combined with information from other sources.
A useful question
Would I be comfortable with a stranger having this information?
If not, do not publish it publicly.
13. Never Photograph and Post Important Documents Without Checking What Is Visible
A photograph may contain more information than you realize.
Before posting a document, inspect it carefully for:
addresses
account numbers
QR codes
barcodes
signatures
identification numbers
booking references
phone numbers
email addresses
Cropping or covering sensitive information is safer than assuming nobody will notice it.
14. Never Post Your Exact Location Without Thinking About the Consequences
Location information can reveal more than where you are.
Repeated posts can reveal:
where you live
where you work
where your children go to school
when you are away from home
your regular routines
places you frequently visit
You do not necessarily need to stop sharing everything.
Instead, consider whether the information needs to be public and whether it needs to be posted immediately.
15. Never Announce That Your Home Is Empty
Public posts about holidays, long trips or extended absences can unintentionally reveal that nobody is currently at home.
Instead of broadcasting:
“Nobody is home for the next two weeks!”
consider sharing travel photographs after returning.
This is a simple example of how privacy is not only about passwords.
16. Never Accept Every App Permission Automatically
When an app requests access to:
contacts
location
microphone
camera
photographs
files
notifications
ask whether the permission is genuinely necessary.
A calculator does not normally need access to your contacts.
A simple flashlight app does not necessarily need your microphone.
The more access an application has, the more important it is to understand why that access exists.
17. Never Install Software Because a Pop-Up Says You Have a Virus
A frightening pop-up can itself be the trap.
It may claim:
“Your computer is infected!”
“Call support immediately!”
“Click here to remove the threat!”
Do not assume the warning is genuine simply because it looks technical.
Close the page or application safely and use your normal security tools or trusted support process.
Tech-support scams are specifically designed to persuade people that their computers have problems and then obtain money, information or remote access. (Consumer Advice)
18. Never Download an Attachment You Were Not Expecting
Unexpected attachments deserve caution even when the sender's name looks familiar.
A compromised account can send malicious messages to the person's contacts.
Before opening an unexpected attachment, verify with the sender through another communication method.
Do not rely solely on replying to the suspicious message.
19. Never Use Important Accounts on a Device You Do Not Trust
Be cautious when using:
shared computers
public computers
borrowed devices
unfamiliar devices
Avoid accessing particularly sensitive accounts when you cannot reasonably determine whether the device is secure.
If you must use another device, take extra care with passwords, saved sessions and logout procedures.
20. Never Assume Public Wi-Fi Is Private
A network name can look official without proving that the connection is trustworthy.
Be especially careful when performing sensitive activities on unfamiliar networks.
For important transactions, use a connection you trust or another secure method of connecting.
21. Never Save Your Passwords on Every Computer You Use
Saving passwords can be convenient on your own trusted devices.
It is a different situation on shared or public computers.
Before entering sensitive credentials on another person's device, consider whether the browser might save them.
Always check that you have fully signed out when using a device that is not yours.
22. Never Ignore Security Updates Forever
Updates are not merely about adding new features.
They can also fix security vulnerabilities.
Keeping your operating system, browser and important applications reasonably up to date reduces the risk created by known security weaknesses.
Automatic updates can make this easier.
23. Never Disable Security Features Just Because a Website Tells You To
A suspicious website might tell you to:
disable antivirus protection
allow notifications
install an extension
run a command
change browser settings
enable macros
install an unknown program
Do not follow instructions simply because a webpage says they are necessary.
Unexpected requests to weaken your security should be treated as a major warning sign.
24. Never Give an AI Tool More Personal Information Than It Needs
AI tools can be extremely useful, but you should think before entering sensitive information.
Avoid unnecessarily sharing:
passwords
financial account credentials
private identification numbers
confidential business information
private documents
information about other people that you have no reason to disclose
Before uploading a document, ask:
Does the tool actually need this information to answer my question?
If not, remove unnecessary sensitive details first.
25. Never Assume an AI-Generated Voice or Video Is Genuine
Seeing and hearing someone is no longer sufficient proof of identity.
AI can make fake voices, images and videos increasingly convincing.
If someone unexpectedly asks you for money or sensitive information, verify the request using another communication method.
For example, if someone claiming to be a family member urgently needs money, call them through a number you already have rather than relying on the incoming message.
26. Never Trust a Message Just Because It Knows Your Name
Personal information does not prove identity.
A scammer may know your:
name
approximate location
workplace
phone number
email address
family member's name
The important question is not:
“How did they know my name?”
It is:
“Can I independently verify who is contacting me?”
27. Never Share a Verification Code With Someone Who Calls You
One-time codes are often designed to confirm that the person attempting a login or transaction is really you.
If someone asks you to read them a code that has just arrived on your phone or email, stop.
The code may be exactly what the attacker needs.
28. Never Approve a Login You Did Not Start
If your phone suddenly asks:
“Do you want to approve this sign-in?”
and you were not trying to sign in, do not approve it.
Repeated unexpected authentication requests can indicate that someone is attempting to access your account.
29. Never Give an App More Access Than You Need
Review application permissions periodically.
If an application no longer needs access to your:
location
microphone
camera
contacts
photos
consider removing that permission.
Your privacy settings are not something you should configure once and forget forever.
30. Never Assume Social-Media Friends Are All People You Know
Someone can create a convincing profile using:
another person's photograph
copied posts
stolen information
fake employment details
fake relationships
fabricated interests
A familiar-looking profile is not proof of identity.
Be particularly cautious if an online contact quickly asks for money, private information or access to another account.
31. Never Send Private Images Because Someone Is Pressuring You
Pressure, threats and emotional manipulation are warning signs.
Once a private image leaves your control, you cannot guarantee where it will eventually appear.
Do not let someone else's urgency override your judgment.
If someone threatens you over an image or demands payment, preserve evidence and seek appropriate help rather than continuing to negotiate alone.
32. Never Believe That You Are “Too Smart” to Be Scammed
Scams do not only affect careless people.
A convincing message can fool someone who is busy, distracted, tired, worried or under pressure.
The best defense is not intelligence alone.
It is a process:
Pause → Verify → Decide
33. Never Let Urgency Make Your Decisions for You
This may be the most useful rule in the entire guide.
When someone wants you to act immediately:
Slow down.
When someone says you cannot check:
Check anyway.
When someone says not to tell anyone:
Tell someone you trust.
When someone says you must pay immediately:
Do not pay until you verify the claim.
Scammers frequently use urgency because careful verification makes their stories easier to expose. (Consumer Advice)
What To Do If You Already Clicked a Suspicious Link
Do not panic.
What you should do depends on what happened.
If you only opened the page
Close it.
Do not enter credentials or payment information.
If you entered a password
Change the password immediately from a trusted device and change it anywhere else you reused it.
Enable two-step verification.
If you entered financial information
Contact the relevant financial institution using a trusted contact method and monitor the account.
If you installed unknown software
Disconnect from the internet if appropriate, update security software and perform a security scan.
If you gave someone remote access
Treat the device and accounts as potentially compromised. Change important passwords and seek trusted technical assistance.
Official consumer guidance recommends changing compromised passwords, enabling two-factor authentication and scanning devices when someone has obtained account information or remote access. (Consumer Advice)
What To Do If You Sent Money to a Scammer
Act quickly.
Contact the bank, card provider, payment service or other company involved using its official contact information.
Explain that the transaction was fraudulent and ask what recovery or cancellation options are available.
Keep:
receipts
transaction numbers
emails
messages
screenshots
phone numbers
website addresses
usernames
dates and times
Do not delete evidence simply because you feel embarrassed.
Reporting scams can help identify patterns and may assist investigations. (Consumer Advice)
The 10-Second Online Safety Test
Before clicking, paying, downloading or sharing, ask:
1. Did I expect this?
2. Do I know exactly who sent it?
3. Am I being pressured to act now?
4. Can I verify it somewhere else?
5. Does this request involve money, passwords or private information?
If several answers make you uncomfortable, stop.
The Golden Rules of Internet Safety
You do not need to memorize hundreds of security rules.
Remember these:
Never rush.
Urgency is a warning sign.
Never reveal passwords or security codes.
Keep authentication information private.
Never trust appearance alone.
A convincing message can still be fake.
Never click simply because you are curious.
Verify first.
Never send money before independently verifying the request.
Especially when someone is pressuring you.
Never overshare publicly.
Information can accumulate into a detailed picture of your life.
Never give unnecessary permissions.
Apps should not automatically receive access to everything.
Never assume AI-generated content is authentic.
Verify important requests independently.
Never be embarrassed to ask someone else.
A second opinion can prevent a costly mistake.
A Simple Rule for Almost Everything Online
Whenever an online request involves money, identity, passwords, private information, downloads or urgent action, stop before responding.
Ask:
“How can I verify this without using the information provided in the message?”
That question is powerful because a scammer controls the information inside the scam.
If a message gives you a phone number, use a number you already trust.
If it gives you a link, open the service independently.
If it tells you where to send money, verify the destination separately.
If it tells you that something is urgent, give yourself time.
The goal is not to avoid the internet.
The goal is to make sure you remain in control of the decision.
Final Online Safety Checklist
Before doing something important online, remember:
☐ I know who I am dealing with.
☐ I did not rely solely on an unexpected message.
☐ I checked the destination before clicking.
☐ I am not being pressured.
☐ I am not revealing a password or security code.
☐ I am not sharing unnecessary personal information.
☐ I understand what an app or website is asking me to provide.
☐ I have independently verified unusual payment requests.
☐ I am not installing software because of a frightening pop-up.
☐ I know what to do if something goes wrong.
The safest internet user is not the person who never makes a mistake.
It is the person who has learned to pause before the mistake becomes irreversible.
