The Online Safety Mistakes I See People Make Again and Again

Sep 01, 2026By Jay Kells
Jay Kells

The Online Safety Mistakes I See People Make Again and Again

I've lost count of how many times I've heard some version of "I thought I was being careful" from someone who's just been caught out by a scam or a hack. Almost nobody who gets caught out is being reckless on purpose. It's usually one of a handful of small, forgivable habits repeating itself, the same few mistakes showing up again and again across completely different people. None of them are stupid mistakes. They're just the ones nobody ever sits you down and explains properly, so I want to walk through the five I see most often and what I'd actually do differently.


Reusing the Same Password Everywhere


This is the one I see most, and it's rarely one password for everything, it's more often one "good" password for the accounts someone thinks matter and a much weaker, reused one for everything else. The problem is that "everything else" usually includes some account you'd never think twice about, a forum you signed up to once, an old shopping site, a newsletter login, and any one of those getting breached hands over a password that might also unlock your email or your banking app. I don't try to remember dozens of unique passwords, because nobody can do that reliably and pretending otherwise is how the reused-password habit starts in the first place. A password manager generates and stores a different one for every single account, so the one that leaks in some random breach never opens a second door.


Ignoring Software Updates Until They're Forced


Everyone knows the "update available" notification, and almost everyone's instinct is to tap "remind me later" and get on with their day. I used to do exactly the same thing, right up until I actually understood what most updates are quietly fixing. A lot of them patch specific security holes that have already been found and are already being used against people who haven't updated yet, which means every day you put it off is a day that particular door stays open on your device. I've made peace with the ten minutes of mild inconvenience because the alternative is leaving a known gap unpatched for no real benefit. Turning on automatic updates where you can removes the decision entirely, which is honestly the easiest fix on this whole list.


Trusting Caller ID and Screen Names


I understand why people trust what's on their screen, it looks official, it says a real bank's name or a familiar area code, and there's no obvious reason to doubt it. The uncomfortable truth is that caller ID and sender names are trivially easy to fake, and scammers use exactly that trust deliberately, because a spoofed name does more of the persuading than anything they actually say. I've stopped treating a name on a screen as proof of anything at all. If a call or message claims to be my bank asking about my account, I hang up and call the number on the back of my card myself rather than continuing the conversation on their terms, and I'd genuinely encourage anyone to build that same habit before they need it.


Contemporary minimalist watch on young adult's wrist with natural light highlighting sleek metal band and dial design

Clicking Before Pausing When Something Feels Urgent


Urgency is the ingredient almost every successful scam has in common, a suspended account, a missed delivery, a security alert, something that makes clicking through feel more important than checking first. I've caught myself moving to click on pure instinct more than once, and the only thing that's ever stopped me is a habit rather than any particular cleverness, a deliberate pause of a few seconds whenever something feels urgent enough that I want to act immediately. That feeling itself is the signal to slow down, not speed up, because genuine emergencies from real organisations essentially never depend on you clicking one specific link in the next five minutes. Waiting an extra minute to check costs nothing. Not waiting has cost people everything.


Assuming a Locked Phone Means Nothing Else Matters


A lot of people treat a phone's lock screen as the finish line for their security, once that's set, everything else feels like it's already covered. A locked screen stops someone picking your phone up and scrolling through it, but it does nothing at all against a phishing link you tap on yourself, an app permission you granted without reading it, or a password reused from some other account. I think of the lock screen as one layer among several rather than the whole wall, alongside two-factor authentication on my important accounts and a password manager doing the parts my memory never could. Getting the lock screen set up is a good five minutes of effort. It's just not the whole job, however much it feels like it should be.


None of these five mistakes are about anyone being careless, they're just the habits that nobody ever properly walks you through, which is exactly why they keep repeating across so many different people. Unique passwords through a password manager, updates that actually get installed, healthy scepticism of anything a screen claims to be, a pause before clicking when something feels urgent, and treating your lock screen as one layer rather than the whole system, that's genuinely most of it. I use NordPass to handle the password side of this without relying on memory, and my free Safety Toolkit covers the rest of what I'd actually recommend in one place if you want to work through it properly, and the NCSC has its own guidance on the basics if you want a second source alongside mine.