Skip to navigationSkip to loginSkip to content

What's best not to share on social media

Keytrade Bank logo

Keytrade Bank

keytradebank.be

August 18, 2026 

3 minutes to read

A post from your best friend sending birthday wishes. A holiday snap from the beach. A LinkedIn update about your new job. You may think all these messages are harmless – but anyone who pieces them together will know your date of birth, that your home is empty and can guess who approves payments at your company.

The days of fraudsters sending tens of thousands of identical emails at random are largely a thing of the past. Nowadays, the most dangerous type of fraud is personal in nature, with messages containing your name, your employer, your travel plans or your (grand)child's name. And criminals don't have to steal that information as you willingly give it out, post by post.

The numbers are clear. According to the Dutch Banking Association (NVB), more than 70% of all online fraud now starts on social media such as Facebook, Instagram and TikTok (source). Meanwhile, in Belgium the Centre for Cybersecurity (CCB) has issued a warning that criminals are using AI to create credible, personalised messages in no time (source). The raw material for such personalised messages comes from none other than your own social media profiles.

What a fraudster sees when they look at your profile

Security experts call it open source intelligence, or OSINT, where information is gathered from freely accessible sources. Hacking or data breaches are not required, as scammers just have to read what's already in the public domain. Take a look at your own profiles from the following angles:

Your birthday. Dozens of congratulatory messages on your feed reveal the day and the month. Your year is often visible on your profile or can be derived from a post about a '40th birthday'. Your date of birth is a classic authentication question for a whole host of services and a building block for identity fraud.

Your holiday photos, posted in real time. Anyone posting from the beach or the mountains says two things at the same time – their house is empty, and they're less contactable and vigilant than usual. And that's precisely when a message from your 'bank' about a suspicious transaction is highly effective, as you can't just pop in to the branch and take rapid action when you're in holiday mode. What's more. if you've included the name of your hotel, a fake payment request 'from your hotel' suddenly becomes a very plausible option.

Your family and pets. Your grandchild's name makes a 'friend-in-need' message (Grandad, this is my new number. Could you help me quickly?) personal and convincing. And let's be honest – how many people still use their pet's or child's name in their passwords or secret questions?

Your LinkedIn profile. Be it your role, your colleagues, your new job or your company's organisational chart, LinkedIn is a goldmine for CEO fraudsters. Criminals find out who the CFO is, who makes payments and which communication style is used at the company, and then send an urgent payment request 'from the boss'. Anyone who has recently started a new job and announced it with pride is a popular target, as new employees aren't yet familiar with the internal procedures and want to be helpful.

Your voice and face. Videos showing you talking, voice messages, podcasts or webinars are potential source material. Today, AI tools can generate a convincing clone of a voice with just a few seconds of audio. This technology is already in use. In early 2026, a Swiss entrepreneur was played for weeks – using the deepfaked voice of a business partner – and transferred millions before anyone was any the wiser (source).

The fun quizzes and questionnaires. 'What was your first car?', 'What was the name of your first pet?', 'What street did you grow up on?' If they sound familiar, it would be because they are the secret questions that banks and websites use to verify your identity. Sometimes, the viral questionnaires are even deliberately designed to collect such answers.

From individual pieces of a puzzle to a targeted attack

None of the elements are a disaster on their own. The danger comes to the fore when they can be pieced together. A fraudster who knows your name, employer, holiday plans and family situation no longer needs to send a generic phishing email. Instead, they can simply send a message that suits your life to perfection, when you are at your most vulnerable.

Examples of such attacks include spearphishing (a bespoke phishing email containing real details from your life), whaling (spearphishing targeted at managers and directors), CEO fraud (an employee receives an urgent payment request from a 'director') and friend-in-need fraud (a message from a 'child' or 'grandchild' in need of money). What they all have in common is that they work because they make sense. The details are correct, and it's precisely those details that help you let your guard down and trust the message.

Investors are also a target. Anyone who talks about investing on Facebook groups or shares their interest in cryptocurrency on LinkedIn makes themselves visible to recruiters for fake investment clubs and groups. You're never approached by chance, but rather because your profile makes you stand out as interesting prey.

What shouldn't you share (or is best to share afterwards)?

Social media is all about sharing, and you don't have to come off it entirely The important thing is being mindful of what you share. A few simple habits can make a huge difference:

1. Post holiday photos once you're back

Your holiday photos will look just as good a week later. Avoid posting photos showing your location, hotel name or travel dates in real time.

2. Don't take part in viral quizzes and questionnaires

This may well be the most important reflex of all. 'What was your first car?', 'What was the name of your first pet?' or 'What street did you grow up on?' may seem like harmless facts, but they are literally the secret questions that banks and websites use to verify your identity. Some of the viral questionnaires are even deliberately designed to obtain that precise information.

3. Keep your date of birth private

Remove your year of birth from your profiles, or change your settings so only you alone can see your birthday. Congratulatory messages may be fun, but identity fraud isn't.

4. Don't share photos of documents and tickets

Boarding passes, concert tickets, new bank cards, driving licences and address labels all feature barcodes and numbers that can be used by fraudsters. Also avoid sharing photos of your letterbox with a name plate or your front door with a house number.

5. Be sparing with family details

Whether it's the names of your (grand)children and pets, your children's school or your home address that can be recognised in a photo, the less information that is in the public domain, the better – as fraudsters have less material for personalised fraud.

Announcing a new position shouldn't hurt, but be wary when it comes to sharing details about internal processes, projects, absences ('two weeks of team-building!') or who approves what in your company.

Enhance your privacy settings

This is where you can make the biggest difference. While you don't need to delete everything from your feed, determining who can see your posts is far more important. Half an hour should be enough for a thorough clean-up:

1. Set your profiles to private or 'friends only'.

Facebook lets you decide who sees what for each section. Select 'friends' instead of 'public', even for older messages. Facebook also has a feature to restrict settings for all previous posts at once.

2. Don't accept requests from strangers.

This is crucial. If you receive a friend or connection request from someone you don't know, be careful. There is a real chance that they are just trying to access your profile to collect data. An impressive set of mutual friends isn't proof that they can be trusted either, as fraudsters build their fake profiles in the same way. If you're in any doubt, ignore it. You could also cut your existing friend list down at the same time, because hundreds of 'friends' you barely know means hundreds of pairs of eyes on your private life.

3. Disable location sharing.

Remove automatic location tags and check if old posts give away your home address or routines.

4. Check what an outsider can see.

Look at your profile using the 'View as' feature (Facebook) or through a browser that is logged out of your profile. What you see there is what fraudsters will see.

5. Restrict how easily others can find you.

Set up your profile so that it can't be found using your phone number or email address, and doesn't appear in search engines.

6. Don't forget LinkedIn.

Here, too, you can set who can see your connections, who can see your email address and whether your profile is visible outside of LinkedIn. For anyone holding a financial position, this should be common practice.

And the most important reflex may well be that if a message feels suspiciously personal, don't be lulled into a false sense of security. The fact that the sender knows your name, position or travel plans doesn't really mean anything nowadays. Verify the details through another channel, just as you would with any unexpected request.

Stay safe online with Keytrade Bank

At Keytrade Bank, security is a priority. If your bank details have been listed on a suspicious website, your personal details have been shared with an unknown person over the phone or you've spotted an unknown payment that you didn't make, you can call us 24/7 on +32 2 679 90 00.