Why do social media platforms pose privacy risks?
Social media poses privacy risks for many reasons, but the main one is probably the lack of user control over their own data. With mainstream social media, the companies are the owners of the data and the communication channels. That means that theoretically the terms can shift at any time — a platform can quietly change default settings, remove a privacy feature people relied on, feed public content into AI training, or be exploited through its own support systems, often without meaningful notice.
Since most social media platforms are built on collecting, analyzing, and monetizing user data rather than just protecting it, privacy is rarely the default. For most people, that’s an inconvenience, but for journalists and activists, it can become a genuine risk that makes relying on a platform’s goodwill difficult.
How do social media platforms cause privacy and security risks?
Businesses that manage user data (including social media platforms) carry a legal and moral responsibility to store it safely and prevent it from falling into the wrong hands. However, while no one is fully protected from outside attacks, social media sites have tripped over their own feet at least a few times in the past, making questionable decisions regarding users’ private data. Below you’ll find at least a few of such instances.
Security feature removals
In May 2026, Meta discontinued Instagram's optional end-to-end encrypted messaging. That showed how protection someone built their workflow around can be taken away, with the company deciding for the user. According to Meta, very few users opted into the encrypted chat feature, making it hard to justify keeping it. Logical as it may sound, though, removing the right to choose weakened users’ digital privacy on the platform even more.
Situations like this show that users shouldn’t rely on a mainstream social platform’s messaging for anything sensitive. It might be better to move such conversations to a dedicated, end-to-end encrypted messenger like Signal, which is built around privacy and isn’t tied to an advertising business model. Direct messages on social platforms are best treated as if the company can read them — because, without end-to-end encryption, it often can.
Account takeovers through the platform’s own support systems
Sometimes the company’s own tools can prove to be a weak point. In 2026, attackers took over a set of high-profile Instagram accounts, including the Obama White House account, not by cracking passwords but by convincing Meta’s AI-powered support system to change the email address tied to the accounts, then using standard password-reset mechanisms to seize them.
The platform quickly patched the issue, but the underlying lesson is still relevant. While companies have (hopefully) learned from this incident, the risk of automated support systems falling to social engineering still exists, which is why users should be skeptical of sharing personal data with any AI-related tools, regardless of whether it’s an AI assistant on an online store or an AI image generator on a messaging app.
Silent default changes that expose content
Platforms regularly change defaults without asking, switching on new features before users notice. The clearest recent example was Meta’s infamous Muse Image tool, which briefly opted in public Instagram accounts by default, letting anyone generate AI images from public account photos.
Similar concerns have followed AI training on image uploads and generative tools rolling out across other platforms — for example, Twitch introduced a setting that let Amazon to use streamer content to train generative AI models. Privacy International told the BBC the Muse episode was “the latest sign AI companies see people’s images and data as raw material to be exploited.”
The warning signs of a compromised account
The warning signs of a compromised account are often easy to spot:
- An account email address or phone number was changed without the user’s knowledge.
- Password reset notifications that weren’t requested.
- Account recovery alerts that weren’t triggered.
- Login notifications from unknown devices or unfamiliar locations.
- The usual credentials suddenly stop working.
- Posts, messages, or profile details that the user didn’t create.
If any of these appear, the first things to do should be:
- 1.Change the password immediately.
- 2.Sign out of all online sessions.
- 3.Check that the recovery email address and phone number haven’t been changed.
- 4.Confirm 2FA is on.
- 5.Report the compromise to the platform.
If a user loses access entirely, they should start account recovery right away. Journalists and activists should also notify their sources and contacts about the incident as soon as possible.
Why does this matter more for journalists and activists?
For most people, a compromised social media account is a headache. For a journalist or an activist, it can expose an investigation or cause reputational damage. A hijacked account can be used to impersonate its owner, message their contacts, or quietly read conversations they assumed were private. Manipulated images of a reporter can be used to attack their credibility or blow their anonymity in the field.
While social media platforms are great tools for gathering reach and visibility, journalists and activists should be extremely careful when using them. Whether you’re a journalist, activist, or an everyday user, never leave your safety to a platform’s goodwill — especially where sensitive information is involved.
Extra protection while working and traveling
When it comes to cybersecurity, good habits are the foundation. However, online users can always invest in some extra protection. Journalists and activists, in particular, can strengthen their online presence simply by adding a couple of tools, such as:
- A password manager to lock down accounts. Reused or weak passwords are one of the most common ways journalists’ accounts get compromised. A password manager generates and stores unique, strong passwords for every account, so one breach doesn’t cascade.
- Encrypted messaging for source protection. Regular SMS and many chat apps leave conversations exposed. Apps like Signal provide end-to-end encrypted calls and messages with disappearing-message options, making them an alternative to social media apps.
- Metadata removal tools. Photos and documents carry hidden metadata such as GPS coordinates, device details, or timestamps. Those can reveal locations or identities and create privacy risks. Getting a metadata removal tool helps lower the risk of exposure when working with sensitive information.
- The Tor browser for sensitive research. When researching extremist groups or blocked content, a regular browser leaves a trail. The Tor browser routes traffic through multiple relays, masking the user’s IP address, isolates browsing state, resists fingerprinting, and provides anonymity through onion routing (three-hop encryption). You can download the Tor browser for free or use NordVPN’s Onion Over VPN feature to safeguard your browsing without relying on Tor.
- Account monitoring and breach alerts. Journalists are frequent targets of credential leaks and spear-phishing. Have I Been Pwned is a free service that alerts users when their email appears in a data breach, giving them a chance to change passwords before accounts are exploited. In addition, subscribing to identity theft protection services can help users respond to potential threats as soon as they occur.
- A VPN for safer connections. A VPN encrypts internet traffic and hides it from snoopers, which matters on public or untrusted networks. NordVPN — an all-in-one digital security app — runs a program supporting organizations that fight for digital freedom. Nonprofits can apply for free or discounted plans. Journalists and activists working in countries that crack down on free speech and the press can apply through NordVPN’s nonprofits page.
- An eSIM that comes with additional security features. When reporting on the ground or traveling, a secure data connection that doesn’t have to be borrowed from a local network is valuable. Saily runs a nonprofit program offering discounted eSIM data plans for journalists and activists, with applications at saily.com/nonprofit opens in a new tab.
Strengthen your online security so you can focus on what truly matters.