← All terms

Doxxing

Doxxing is the deliberate gathering and publication of someone's private information — home address, phone, employer — to intimidate, harass, or enable attacks.

Doxxing (from "dropping docs") is the deliberate collection and public release of a person's private or identifying information — home address, personal phone numbers, family details, financial records, daily routines — without their consent, typically to intimidate, harass, extort, or enable further attacks. In a corporate security context, doxxing matters twice over: employees can be targeted as retaliation or pressure against their employer, and the same research techniques feed directly into social engineering campaigns against the organization itself.

How it works

Doxxers rarely need to hack anything. Most dossiers are assembled entirely from OSINT — open-source intelligence: social media profiles, data-broker listings, property and court records, breached-credential dumps, conference speaker bios, and photo metadata. Individually harmless fragments become dangerous in aggregate: a LinkedIn job title plus a tagged gym photo plus a people-search listing yields a name, employer, schedule, and home address. Attackers targeting a company use the same aggregation to select and profile victims — identifying who works in accounts payable, who reports to the CFO, and who just started and is eager to please — before launching a pretexting call or a spear-phishing email. Executives and finance staff are disproportionately targeted, which is why exposure data belongs in any serious human risk score.

How to defend against it

  • Shrink the public footprint. Encourage employees — starting with executives, finance, and admins — to lock down social media privacy settings, remove personal details from data-broker sites (or use a removal service), and keep home addresses and family information off professional profiles.
  • Separate work and personal identities: distinct email addresses, phone numbers where practical, and no corporate credentials on personal accounts, limiting how far one exposed fragment travels.
  • Teach targeting awareness. Employees who understand how attackers research them — covered in our guide to deepfake voice attacks, which typically begin with exactly this reconnaissance — treat unexpected, well-informed requests with appropriate suspicion instead of trust.
  • Have a response plan: a doxxed employee needs fast support — takedown requests, law enforcement contact, temporary security measures — and a no-blame channel to report it early.

Related terms

OSINT (Open-Source Intelligence)OSINT is intelligence gathered from publicly available sources. Attackers use it to research targets and build convincing social engineering pretexts.Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo