The Online Safety Myths I Wish Would Finally Disappear
Why These Myths Refuse to Die
I hear the same handful of myths again and again, from people who are switched on about most things and still repeat advice that stopped being true years ago, if it ever was. I've written before about the classic myths around antivirus and passwords, but this time I want to tackle a different batch, the ones that catch out otherwise careful people. None of these myths came from nowhere. They usually started as something reasonable, then got stretched past the point of being useful. The trouble is they make people feel safer than they actually are, and that gap is exactly where scammers do their best work.
Myth: Scammers Are Easy to Spot by Their Bad English
This one used to hold up. A lot of it doesn't any more. AI tools have sorted out the spelling mistakes and dodgy grammar that used to give a scam email away in the first line, so a badly written message is only one clue among many now, not proof either way on its own. I've seen phishing emails that read better than some of my own drafts, if I'm honest. What still gives them away is more subtle, an odd sense of urgency, a request that doesn't quite match how the organisation normally contacts you, a link that goes somewhere slightly off when you hover over it. I've written before about the exact red flags I check on every message that lands in my inbox.
Myth: My Bank Will Always Refund Me If I'm Scammed
Banks do refund a lot of fraud cases now under the newer reimbursement rules, and that's genuinely good news for anyone who gets caught out. But "always" is doing a lot of heavy lifting in that sentence. If you authorised the payment yourself, even because you were tricked into it, the bank can still investigate whether you took reasonable care before deciding to refund you, and that's a judgement call that doesn't always go your way. The Financial Ombudsman Service publishes decisions on exactly this kind of dispute, and reading a few of them was enough to convince me I'd rather not find out the hard way where that line sits. I still treat every payment like it's final the second I send it.

Myth: iPhones and Macs Don't Get Hit by Scams
Apple devices are genuinely good at blocking traditional viruses, and that's where this myth comes from. But most of what catches people out now isn't a virus at all, it's a scam text, a fake login page, a phishing email asking you to verify your Apple ID. None of that cares what phone you're holding. I know several people on iPhones who've had their Apple ID phished in the last year alone, which is its own kind of expensive problem given how much banking and photo history usually lives behind it. Two factor authentication and a proper password manager close most of that gap regardless of which phone is in your pocket.
What Actually Keeps You Safer Than Any Myth
None of these myths are stupid, they're just out of date, and the fix isn't panic, it's a handful of boring habits done consistently. A password manager so you're not reusing the same password everywhere, I use NordPass myself and recommend it to almost everyone I talk to. Two factor authentication switched on for anything that matters. And a healthy pause before you click, type, or pay anything you weren't expecting five minutes ago. If you want the fuller list I actually use myself, I've put it together on my Safety Toolkit page, and if something doesn't sit right, get in touch and I'll have a look with you.
