• Explore
  • Blog
  • Podcast
  • Community
  • About
  • Services
  • Contact
Menu

Exploring Information Security

Securing the Future - A Journey into Cybersecurity Exploration
  • Explore
  • Blog
  • Podcast
  • Community
  • About
  • Services
  • Contact
No results found

How Cybercriminals Use Public Data to Target Our Employees

August 12, 2026

This was written for a security awareness program. Feel free to grab within your own program.

Before a hacker ever sends a phishing email, text, or picks up the phone to launch a vishing call, they do their homework. Modern cyberattacks are rarely random. Instead, attackers spend days (sometimes weeks) building a detailed profile of an organization and its employees using information readily available on the internet.

This process is known as Open Source Intelligence (OSINT) gathering. By piecing together small snippets of public data from social media, corporate websites, and job boards, threat actors can craft shockingly convincing scams that bypass human suspicion.

What Attackers Are Looking For

Cybercriminals look for specific pieces of information to make their impersonations look and sound authentic.

1. Organizational Structure and Reporting Lines

Using professional networking platforms like LinkedIn, attackers construct exact organizational charts. They map out who works in finance, who handles IT, and who reports to whom. Knowing that Jane is the direct manager of Alex allows an attacker to call Alex posing as Jane, leveraging natural workplace authority.

2. Internal Software and Tech Stacks

Attackers scrutinize public job postings and employee resumes to see what tools our organization uses. If a job listing mentions experience with specific VPNs, SSO platforms, or cloud infrastructure, attackers know exactly which login portals to spoof or which IT scenarios to invent when calling an employee.

3. Out-of-Office Indicators and Personal Schedules

Public posts on social media about vacation plans, attendance at industry conferences, or business travel give attackers the perfect window to strike. If an executive posts about being in a three-day, off-site meeting, an attacker can email their team claiming: “I'm in a conference with no cell service. Urgently process this request for me!”

4. Personal Identifiers and Contact Information

Phone numbers, work emails, personal email addresses, and even pet names or hometowns (often used to answer security questions) are gathered from public records, personal social channels, and historic data breaches.

How Online Data Turns Into a Cyberattack

Once an attacker builds a profile, they use that context to lower your defenses:

  • Hyper-Targeted Spear Phishing: Instead of a generic spam message, you receive an email referencing your actual department, your current project, or a real software vendor the company uses.

  • Precision Vishing (Voice Phishing): A caller claims to be from internal IT support and mentions your direct manager's name, your office location, and the exact tool you use to log in every morning. Because they know these details, the call feels legitimate.

  • Credential Stuffing: Attackers cross-reference work email addresses against leaked databases from breached personal websites, testing if employees reused personal passwords for work accounts.

 Have I Been Pwned is a great site to identify what breaches your personal email address is included in: https://haveibeenpwned.com/

3 Ways to Shrink Your Digital Footprint

You don't need to delete your online presence to stay safe, but adopting smart digital hygiene makes our organization a much harder target.

1. Audit Your Social Media Privacy Settings

Review privacy settings on personal platforms like Facebook, Instagram, and X. Restrict public viewing so that personal photos, family details, and real-time locations are only visible to trusted connections.

2. Be Mindful of Work-Related Details

Avoid posting photos that reveal security badges, office whiteboards, internal software dashboards, or specific project milestones. On professional platforms like LinkedIn, consider keeping job descriptions high-level rather than detailing specific internal software versions or architecture. 

3. Remember: Familiarity Does Not Equal Authenticity

Just because an inbound caller or email sender knows your manager's name, your job title, or what tools you use does not mean they are who they claim to be. All of that information can be found online in minutes. Always verify unexpected requests through trusted internal channels.

The Bottom Line

Cybersecurity isn’t just about firewalls and complex passwords—it’s about awareness. Attackers rely on us oversharing online to build their attacks, but you hold the power to starve them of that data.

Take 10 minutes today to audit your social media privacy settings, search yourself online, and practice healthy skepticism when unexpected requests hit your inbox. By tightening your digital footprint, you become the strongest line of defense for both your personal life and our organization.

In Advice Tags data breach, OSINT, security awareness
August 2026 - ExploreSec AI Cybersecurity Newsletter →

Latest PoDCASTS

Featured
May 5, 2026
[RERELEASE] What is the perception of information security - part 2
May 5, 2026
Read more →
May 5, 2026
April 28, 2026
[RERELEASE] What is the perception of information security - part 1
April 28, 2026
Read more →
April 28, 2026
April 21, 2026
Exploring the Quantum Horizon: Why We Need CBOMs Today
April 21, 2026
Read more →
April 21, 2026
April 14, 2026
Exploring the Risks of Model Context Protocol (MCP) with Casey Bleeker
April 14, 2026
Read more →
April 14, 2026
April 7, 2026
From Combat Zones to Corporate Lobbies: A Guide to Physical Security with Josh Winter
April 7, 2026
Read more →
April 7, 2026
March 31, 2026
[RERELEASE] What is a SIEM?
March 31, 2026
Read more →
March 31, 2026
March 24, 2026
[RERELEASE] What is threat modeling?
March 24, 2026
Read more →
March 24, 2026
March 17, 2026
[RERELEASE] What is cryptography?
March 17, 2026
Read more →
March 17, 2026
March 10, 2026
[RERELEASE] What is a Chief Information Security Officer (CISO)
March 10, 2026
Read more →
March 10, 2026
March 3, 2026
Exploring The Bad Advice Cybersecurity Professionals Provide to the Public
March 3, 2026
Read more →
March 3, 2026

Powered by Squarespace