Online safety
Discover how to protect your data, devices, and personal information.
Popular pages on the Library website
Online privacy: what is and isn't private?
Most people expect a reasonable level of privacy when studying, working, or socialising online. However, you may have less privacy than you imagine. Many digital platforms aren't private, even when they feel personal.
Understanding where privacy is limited is the first step to protecting yourself.
Many online services are legally allowed to collect, store, and share information about you. This is usually explained, often in long terms and conditions that people rarely read.
Examples of non‑private platforms include:
- social media platforms such as Instagram, Facebook, X (formerly Twitter), Snapchat, and TikTok
- public discussion forums
- comment sections.
Conducting yourself online
Think before you post
What you share online can travel further than you think. Even if you have very few followers.
Any screenshot or share can potentially reach thousands, sometimes millions of people:
- beyond your intended audience.
- beyond your control.
- even after you delete the original post.
Social media
From Student to Professional: Online Conduct Matters
Sharing content about yourself or others online can have serious consequences. Online behaviour can affect:
- academic progress
- placements
- future employment, especially on professional courses.
There have been many real‑world cases where individuals lost job opportunities or employment because of inappropriate posts.
Many students, particularly those studying nursing, healthcare or social work, are already expected to follow professional codes of conduct set by their future employers.
Online behaviour may be considered part of professional conduct, even while you're still a student. So now is a good time to begin behaving professionally online.
Data Collection
Social media platforms also collect data about you, such as:
- your location
- your profile information
- who you interact with
- what content you view or engage with.
This data is commonly used for targeted advertising, analytics, and service optimisation.
If you want to check what data social media accounts hold on you, you can find information online about how to do this. You can also switch off location tracking in the apps you use on mobile devices.
Email, university systems and websites
Email communication is not always private, particularly when using institutional accounts.
Your email and network usage at the university may be monitored by Digital IT services, in line with the University’s Acceptable Use Policy. Employers may legally monitor work email accounts.
This monitoring is usually for security, legal compliance, and system maintenance, not personal surveillance. However it means you should treat institutional emails as a professional communication space.
Online behaviour and personal security
The main threat to online privacy is often our own behaviour. Listed below are some of the most common mistakes:
The most common mistakes
Leaving accounts signed in on shared computers
Have you ever walked away from a library computer without signing out of your account? If so, you've left yourself open to a breach of privacy. It's like leaving the door of your home wide open.
If you forget to sign out, the next person using the computer after you can access your email or university accounts. They may:
- read private messages
- change settings
- misuse your account without your knowledge.
What to do instead: Always sign out fully before leaving and close the browser.
Failing to lock mobile devices
An unlocked phone, tablet, or laptop makes it easy for others to:
- view personal data
- reset passwords
- access accounts.
Thieves target mobile devices, your phone, tablet or laptop. If you haven’t password protected them, a thief can easily steal your data and ultimately your identity.
What to do instead: Set a PIN, password, or biometric lock and use it every time.
Sharing passwords
Sharing passwords removes your control over how accounts are used. This makes it impossible to know who is responsible for actions taken in your name.
If one shared password is compromised, your other accounts may be put at risk as well.
What to do instead: Keep passwords to yourself and use different passwords for different accounts.
Lost or stolen devices can expose your data and even your identity
Thieves target mobile devices such as:
- phones
- tablets
- laptops.
If you haven’t password protected them, a thief could use them to access your accounts or pretend to be you online.
What to do instead: Lock your devices, enable location tracking or remote‑wipe features, and report lost or stolen devices as soon as possible.
Online scams and digital threats
Common online scams and digital threats are designed to invade your privacy by exploiting trust and urgency. They pressure you to act quickly, often before you realise something isn’t right or promise something for free.
Understanding these risks puts you in control of your online safety.
The good news is that there are simple, practical steps you can take to spot these threats and protect yourself online.
Common online scams and digital threats
Phishing emails and messages
Phishing is where criminals try to trick you into sharing personal information like passwords, bank details or to send them money.
They may pretend to be from trusted organisations or people, such as:
- your university
- a bank
- a delivery company
- family members.
It can be done by email, text message or by phone. It's still the most common way that hackers gain access to IT accounts.
How to spot this: Messages often create urgency such as “Your account closes today!” or prizes/deals that you must claim now.
Received a suspicious email?
- Look out for unexpected links and slightly misspelled sender addresses.
- Don’t click on any links or open attachments.
- Never log in, provide your password, or approve sign in requests from links in unexpected emails.
- Don’t reply or forward anything that seems suspicious, even to Digital IT.
- To keep you safe, and to help block similar threats in the future, use the Report Phishing option in Outlook. Right-click the email message, select Report and Report Phishing. This action will remove the email from your inbox and notify the University’s Information Security Team to review it.
- Verify the message by reaching out to the sender another way, for example by phone. Get the company's official contact information from their website and reach out to them directly.
Responded to a phishing attempt by mistake? Don’t worry, it can happen to anyone. Contact the Service Desk immediately – IT Service Desk Contact. They'll check your account, reset anything that’s needed, and make sure your data stays secure.
Fake login pages
Fake login pages look like real websites. They're designed to steal your username and password when you log in.
How to spot this: Check the website address carefully. Fake pages often have unusual URLs, spelling mistakes, or missing security indicators (such as “https”).
Malware links
Malware links install harmful software on your device when clicked. This can allow attackers to:
- steal information
- monitor your activity
- damage your files.
How to spot this: Be cautious of links or attachments you weren’t expecting, especially if the message urges you to click quickly or download something.
Social engineering
Social engineering is when attackers manipulate people rather than systems.
They use trust, fear, or urgency to persuade you to give away information or take risky actions. For example, using phrases such as “Your account will be locked” or “You must act now”.
How to spot this: If a message pressures you to act immediately or plays on emotion (“urgent”, “last chance”), pause and verify it independently.
Social media
Email scams are only the tip of the iceberg. Social media is very attractive to hackers. It's a quick way to spread:
- malware
- viruses
- identity fraud or scams.
This is partly because people are more likely to trust and click on links they see on social media.
Hackers can combine information about you from different social media sources to guess your identity. They look for your:
- full name
- address
- names of pets
- mother's maiden name and so on.
All of which may be used as passwords or could verify your identity.
Social media quizzes asking for personal details may also be used for identity theft.
How to spot this: When we feel rushed or reassured, we're more likely to:
- Click links without checking them.
- Share passwords or personal information.
- Download harmful files.
Remember: If an email message or social media post pressures you to act immediately or plays on your trust, it’s a signal to pause, check, and verify before responding.
New ways scammers target users
Common online scams and digital threats
QR‑code phishing (fake QR codes)
Fake QR codes are used to send you to harmful websites, such as:
- fake login pages
- sites that install malware.
Scammers may stick fake QR codes on parking machines or advertising posters. Designed to look legitimate, they can also be sent via email or text messages.
How to spot this: Always inspect physical QR codes for signs of tampering, such as a physical sticker placed over a printed image. Be cautious of QR codes in unexpected messages. If scanning takes you to a login page or asks for personal details, stop and check the web address carefully.
AI‑generated scam messages
AI can be used to create scam messages that sound:
- natural
- professional
- personalised.
These messages may closely imitate real emails or texts from trusted organisations or individuals.
How to spot this: Even if a message sounds convincing, check for urgency, unexpected requests, or pressure to act quickly. Always verify requests through official websites or trusted contact details.
Deepfake audio or video impersonation
Deepfake technology can be used to mimic someone’s voice or appearance, such as a:
- lecturer
- manager
- family member.
These impersonations may be used to persuade you to share information or take urgent action.
How to spot this: Be cautious if a message or video asks for sensitive information or immediate action. If in doubt, confirm the request using a different method, such as a known phone number or official email address.
Data leaks from third‑party apps
Apps and online services often store personal data on your behalf. If one of these services is hacked or suffers a data breach, your information may be exposed without your realising.
How to spot this: Look out for breach notifications, unusual account activity, or unexpected emails. Use strong, unique passwords and change them if a service you use reports a data breach.
Create strong passwords
Strong passwords are essential to protect your accounts.
Never re-use passwords. This increases security risk. A breach on one site can expose other accounts. Create a new password each time.
A good password should:
- Be at least 9 characters.
- Use upper and lower‑case letters.
- Include numbers and symbols.
Even better: use passphrases. A type of password made of multiple random words combined together; e.g. netball green floor. A passphrase is much easier for you to remember while remaining very difficult for a computer to crack (15–20+ characters).
Get more advice on how to Create a Strong Password.
Additional protection:
- Use two‑factor authentication (2FA) if available.
- Install antivirus software and keep it updated.
- Set up remote wipe on devices, to erase all data in the event of loss or theft.
If you suspect your account has been compromised, then you must change your password immediately to limit further unauthorised access.
Related information
Sadly, there are many ways that fraudsters and criminals may target you and their methods are constantly evolving.
AskUs has more information at Money Scams, Tricks and Frauds.