Learn the Tricks Hackers Use — And How to Avoid Them

Cybercriminals often rely on small, overlooked details rather than sophisticated hacking tools

Many attacks start with simple research and social engineering, and understanding these tactics can help you limit the information attackers can use against you and protect your digital life.

  • Search social media for personal clues
    Hackers look for details like pet names, birthdays, family members, or favourite hobbies to guess passwords or answer security questions.
    Mitigation: Keep profiles private, limit what you share publicly, and avoid posting information that could be used in security questions.
  • Analyse photos for sensitive information
    Images can reveal addresses, boarding passes, ID badges, or computer screens. Hackers scan photos for anything that can be exploited.
    Mitigation: Review images carefully before posting and remove or blur sensitive details.
  • Exploit personal information in passwords or security questions
    Many people use pet names, birthdays, or favourite sports teams in passwords or security questions, which hackers can research online.
    Mitigation: Use random, strong passwords and unrelated answers for security questions. A password manager such as LastPass can help.
  • Take advantage of password reuse
    Reusing the same password across multiple accounts allows hackers to access several services if one is compromised.
    Mitigation: Use unique passwords for each account and store them securely in a password manager.
  • Impersonate trusted contacts or organisations
    Hackers may send messages pretending to be colleagues, banks, or service providers to trick you into revealing information.
    Mitigation: Verify unexpected requests through official channels before responding or sharing sensitive data.
  • Exploit breaches or leaked credentials
    Attackers check if your email or accounts have appeared in data breaches and attempt to reuse passwords.
    Mitigation: Regularly monitor your accounts, update passwords after breaches, and enable multi-factor authentication (MFA).

By understanding what hackers do and actively applying these small mitigation strategies you can dramatically reduce your risk and protect your online accounts from the most common social-engineering attacks.