Common Online Security Mistakes
The everyday habits that quietly undermine good security, and straightforward ways to fix each one.
Table of contents
Most successful account takeovers and data breaches don't rely on sophisticated hacking — they exploit a small set of everyday habits that quietly undermine otherwise reasonable security. None of these mistakes are unusual or embarrassing; they're extremely common, which is exactly why they're worth addressing directly. This guide covers the most frequent ones, and the straightforward fix for each.
Reusing the same password across accounts
This is the single most common mistake, and the most consequential. If one site you use is breached, attackers automatically try that same email-and-password pair on banking sites, email providers, and shopping accounts — a technique called credential stuffing.
Fix: use a password manager to generate and store a unique password for every account. See our guide on password managers explained for how to get started.
Skipping multi-factor authentication
Many people view MFA as an inconvenience and skip it, even though it's one of the most effective ways to stop an attacker who already has your password.
Fix: enable MFA on your email, banking, and password manager accounts first — see our full explanation in how multi-factor authentication works.
Ignoring software updates
Delaying updates on a device connected to the internet leaves known, often actively exploited, security vulnerabilities unpatched. This applies to operating systems, browsers, and even router firmware.
Fix: turn on automatic updates wherever possible, and don't dismiss update prompts indefinitely on your phone or computer.
Oversharing personal information on social media
Publicly visible details like your pet's name, your school, or your birth date are often exactly the answers used for account-recovery security questions, and can make phishing attempts far more convincing when an attacker references real personal details.
Fix: review your social media privacy settings periodically, and avoid posting real-time location information publicly.
Clicking links and attachments without checking
Clicking first and evaluating later is how the majority of phishing and malware infections happen. Our guide on signs of phishing emails covers the specific red flags to watch for.
Fix: pause before clicking any unexpected link or attachment, and navigate to important sites directly rather than through a message's link.
Not backing up important data
Ransomware, hardware failure, and simple accidental deletion all have the same result without a backup: permanent data loss.
Fix: follow the 3-2-1 rule where practical — three copies of important data, on two different types of storage, with one copy off-site or in the cloud — and automate the process.
Leaving home Wi-Fi on default settings
Default router admin passwords and outdated encryption settings are common and rarely revisited after initial setup, leaving every device on the network more exposed than necessary.
Fix: see our dedicated guide on how to secure your home Wi-Fi for the specific settings worth changing.
Trusting caller ID and sender names blindly
Caller ID and email display names can both be spoofed to show a trusted name or number, even when the actual source is entirely different. Assuming a call or message is legitimate purely because of how it's labeled is a common and exploitable mistake.
Fix: for any unexpected request involving money, credentials, or sensitive information, verify independently — call back using a number you look up yourself, rather than one provided in the suspicious message.
External references
Conclusion
Nearly every common online security mistake shares the same underlying pattern: a small shortcut taken for convenience that quietly increases risk over time. Password reuse, skipped MFA, delayed updates, oversharing, and unchecked clicking are all fixable with one-time setup changes rather than ongoing vigilance. Addressing even a few of these meaningfully reduces your overall exposure.
Frequently asked questions
Which mistake on this list matters most to fix first?
Password reuse, since it's the mistake most directly responsible for one breach cascading into many other compromised accounts.
Are these mistakes specific to less tech-savvy users?
No — these habits are extremely common across all levels of technical experience, largely because convenience naturally competes with security in everyday use.
Is it realistic to fix all of these at once?
Not necessarily in one sitting, but each fix is a one-time setup task rather than an ongoing chore, so tackling one or two per week is a practical approach.
Do these mistakes matter more for businesses than individuals?
They matter for both. Individual accounts are frequent targets precisely because these same habits are so common at scale.
Does having antivirus software cover these gaps?
Antivirus software helps with malware but doesn't address habits like password reuse, oversharing, or skipped MFA, which require separate, deliberate fixes.