The dangers of seemingly harmless online quizzes.

“”
What kind of cheese are you? What is your travel personality? Which Harry Potter character are you?

Do these questions sound familiar? In the age of social media, we are bombarded with online quizzes promising to reveal our true personality, the love of our life, or where we’ll be in the future. While these quizzes may seem fun and harmless, the information you provide when you’re answering these questions can put your online security at risk.

Three ways online quizzes can compromise your security.

Malicious actors are creating online quizzes designed to collect user data for personal identifying information that may be used as answers to your account security questions, known as data mining. The personal data gathered from your answers to these questions can then be used to reset your passwords for various accounts, including your bank accounts, email accounts, and social media accounts.

Here are some red flags to look out for that will help you avoid falling victim to these deceptive online quizzes:

1. Don’t enter any personal information.

Harmless quizzes won’t ask you for personal identifying information, such as when you were born, or what street you grew up on. If you see a question like these, close the webpage immediately, as these types of quizzes are usually scams.

2. Beware of unknown senders.

If you receive an email or message from someone you don't know, don’t click on any links in the message without properly vetting the legitimacy of the sender. Emails or messages that appear to be from a legitimate source but are designed to trick you into revealing personal information are called phishing scams and can be used to take over your device and accounts if you click on a malicious link.

3. Understand account security best practices.

Following best practices for strong passwords and account protection will make it more difficult for hackers to access your accounts, even if they have your personal information. Use a password that contains 8-15 characters, is difficult to guess, and includes uppercase, lowercase, numerical, and special characters. You should also enable two-factor authentication (2FA) for your accounts when available for an added layer of protection.

Know the common security questions targeted by online quizzes.

It’s important to be familiar with common security questions used to protect your online accounts so you can spot attempts to mine the answers in online quizzes. Even on multiple choice quizzes, your selections could reveal the answers to your account security questions, so be cautious.

Some common security questions that could be targeted include:
  • What was the make and model of your first car?
  • What year did you graduate from high school?
  • What is the name of the street you grew up on?
  • What was the first concert you attended?
  • What is your mother's maiden name?
  • What is the name of your first pet?
  • What is your favorite color?
  • What is your favorite food?


Additional tips for protecting your personal data online.

In addition to being wary of online quizzes, you should follow these online security best practices to protect your personal data:

Install the latest software updates.

Keeping your software and devices updated to the latest version will help protect you from new security threats. It’s also important to use reputable antivirus and VPN software to protect your devices from malware.

Exercise caution with the information you share online.

Be careful about what you share online. Avoid sharing any personal information on your social media accounts or other public online forums. Some examples of personal information that can be dangerous to post include:
  • Unknowingly providing answers to security questions in stories or reels
  • Posting that you’re not at home, or are on vacation
  • Sharing your current location
  • Posting photos that can be used to identify your current location
  • Sharing a location that you visit often

Enjoy yourself but stay safe.

Online quizzes can be a fun and entertaining way to pass time, but knowing the potential security risks is essential to help protect your personal information from being data mined. If you recently completed an online quiz, consider changing your passwords and security questions. It’s also recommended to update your passwords every 60-90 days to ensure none of the account passwords you’re currently using are compromised. You should also review your bank account transaction history and contact information regularly to ensure no one has made any unauthorized changes. If you notice any suspicious activity on your account(s), please change your password and contact the Customer Care Center immediately. If you need to submit sensitive personal information to us, we recommend that you sign in to Popular Direct Online Banking and use secure messaging to send anything personally identifying or sensitive. We’re here to help.