Key Takeaways

  • Doxing involves collecting and publishing private information, often with the intent to harass, threaten, or embarrass the victim.
  • Understanding what doxing is and how it typically unfolds is the first step toward reducing exposure for employees, executives, and the business as a whole.
  • Group-IB Digital Risk Protection provides continuous, cross-platform monitoring paired with analyst review to detect doxing incidents early and contain incidents that get through.

How Does Doxing Work?

Doxing becomes clearer when broken into three stages: collecting information, linking it together, and publishing it publicly. Each stage builds upon the last, turning scattered data points into a complete profile that can be used to harass or target someone.

Collecting personal and sensitive information

The first stage involves gathering raw data from social media profiles, public records, data breaches, and old forum posts. Attackers often start with something small, like a surname, and use it to search other platforms for matching accounts

Linking information from multiple sources

Attackers cross-reference data points to build a complete profile. A username on one social platform might connect to a real name on another, or even to a home address in a public records database. This correlation step separates doxing from simple data exposure, and it’s the core of doxing in practice.

Publishing or sharing exposed information

Once a profile is complete, threat actors publish the compiled information on forums, social media, or dedicated doxing sites. Some attackers share the information directly with a target to intimidate them. Others post it publicly to invite harassment from a wider group.

What Information Can Be Exposed Through Doxing?

Doxing can expose a wide range of personal and corporate data, from basic contact details to sensitive internal business information. What information gets exposed usually depends on the target and the attacker’s motive.

Personally identifiable information

Personally identifiable information (PII) includes, but is not limited to, full names, dates of birth, and financial account details. This type of information alone is often enough to enable identity theft. 

Contact and location information

Home addresses, phone numbers, and real-time location data such as geotagged photos or check-ins fall into this category. Exposed location data creates immediate physical safety risks, especially for executives and public-facing employees. 

Employee and executive information

Work email addresses, direct phone lines, and details about someone’s role or position are common targets. Executives are particularly exposed because their names and titles are often publicly listed on company websites.

Corporate and business information

Doxing can also expose internal documents, credentials, infrastructure details, and other proprietary data, especially when an employee’s personal accounts are compromised and used as an entry point. This can lead to a data leak, where confidential company data becomes publicly available. 

What Are Common Doxing Examples?

Common doxing examples organizations should watch for include executive targeting, employee exposure, corporate data leaks, social media doxing, and dark web publication. Doxing can look different depending on the target and the attacker’s goal.

Executive and VIP doxing

Executives and other high-profile employees are frequent doxing targets because their visibility makes them easy to identify and locate. Attackers build a fake persona around a senior leader’s name, title, and public photos, then use that person to interact with customers, employees, or business partners as though they were the real person. These impersonations can be difficult to spot until the damage is already done because the underlying details are accurate.

Employee PII exposure

Employees below the executive level can also be targeted through data broker sites or breached databases that expose their personal information, such as home addresses, phone numbers, and personal email accounts. Attackers can then use this information to harass employees directly or impersonate them in social engineering attempts.

Corporate data exposure

Sometimes the target isn’t an individual, but the organization itself. Internal documents, source code, or credentials get published online to embarrass a company, pressure it during a dispute, or support a separate attack.

Social media doxing

Attackers often use social media as both a research tool and a publishing platform. Public posts, tagged photos, and friend lists can reveal a target’s location and personal relationships, which can then get compiled and shared publicly.

Doxing through dark web and leak sites

Dedicated leak sites and dark web forums commonly publish doxing dossiers, particularly for high-value targets. These sites are difficult for security teams to monitor without dedicated tools, since they sit on the dark web, a part of the internet that is not indexed by standard search engines and often requires specialized software like Tor to access. 

Case in Point: Not every listing on these forums is what it claims to be. Group-IB found that data brokers in Chinese-speaking dark web forums and Telegram channels often sell large, “fresh” datasets recompiled from prior breaches, but padded with unrelated records to increase volume. Real personal details still appear even when the rest of the dataset is fabricated, so organizations can’t dismiss these listings on credibility alone. Read more in “Volume Obfuscation Game: The Lead Data Brokers Out To Waste Your Time.”    

What Are the Risks of Doxing for Organizations?

Doxing puts employees at physical risk and exposes organizations to fraud, reputational damage, and follow-on attacks. 

In the High-Tech Crime Trends Report 2026, Group-IB CEO Dmitry Volkov described the broader cybercrime landscape as being shaped by “cascading failures of trust,” rather than isolated incidents. 

Doxing follows that same pattern on a smaller scale. The risks compound quickly once information is public, since one exposed detail often enables the next attack. The sections below break down the specific risks organizations should plan for.

Employee privacy and safety risks

Exposed personal details can lead to harassment, stalking, or physical confrontation. This risk is especially high for employees in customer-facing or public-facing roles. 

Executive and VIP exposure

Executives and VIPs face a combination of privacy and reputational risk. A convincing fake account impersonating a senior leader can mislead customers, partners, or employees before anyone notices it lacks legitimacy. For organizations, unaddressed executive impersonation can expose the wider customer base to real financial harm. 

The financial stakes of impersonation can be drastic. The Federal Trade Commission (FTC) reported that impersonation scams cost consumers $3.5 billion in 2025.

Identity theft and impersonation

Exposed PII gives attackers what they need to open fraudulent accounts, file false claims, or impersonate the victim in other schemes. The more complete the exposed profile, the easier this becomes. This is a different kind of impersonation from a fake executive account that misleads customers. Here, the attacker poses as the victim rather than as the company.

Social engineering and targeted attacks

Doxed information makes phishing and impersonation attempts far more convincing. An attacker who knows insider information, such as an employee’s manager, personal email address, and recent projects, can craft a message that’s difficult to distinguish from a legitimate one.

Reputational and business risks

When executives or corporate data are exposed, the fallout can erode customer trust and damage brand reputation. Organizations that respond slowly to a doxing incident risk compounding the damage. 

Business impersonation is a serious concern in its own right. Combined with government impersonation reports, these two categories accounted for nearly half of all fraud reports the agency received directly that year. A doxing incident that hands attackers real employee or executive details only makes that kind of impersonation more convincing.

Why Do People Dox Others?

People dox others for reasons that range from personal grudges to financial gain. The motive usually shapes how the attack unfolds. The table below breaks down the most common reasons behind a doxing attack.

Motive What it looks like
Harassment or intimidation An attacker targets an individual directly to scare or silence them
Retaliation An attacker exposes information during a personal or professional dispute
Activism or public shaming Groups publish information to hold an individual accountable or provoke public backlash
Extortion An attacker threatens to publish information unless the target pays or complies
Corporate or competitive motives A rival or disgruntled insider exposes confidential data to damage a company’s standing or gain leverage in a business dispute

How Do Threat Actors Obtain Information for Doxing?

Threat actors combine open-source research with data from breaches and criminal marketplaces to build a target’s profile, often layering multiple methods to fill in gaps. The table below outlines the main sourcing methods and what they involve.
 

Method How it works
Open source intelligence (OSINT) Attackers comb through social media, public records, and old forum posts for information a target may not realize is still accessible
Breaches and marketplace leaks Credentials and personal data from past breaches continue to circulate on dark web forums and marketplaces long after the original incident, giving attackers a reliable source to draw from
Social engineering Attackers trick a target, or someone close to them, into directly revealing information
Insider access Individuals with legitimate access to confidential records misuse that access to expose sensitive information

Case in Point: Infostealer malware is a common source of the credentials and personal data that gets compiled into a dox. It harvests browser passwords, cookies, and payment card details from an infected device, and that stolen data then gets traded in underground markets where other attackers can access it. 

Between November 2025 and January 2026, Group-IB’s Business Email Protection detected a five-wave Phantom Stealer campaign targeting European logistics, manufacturing, and technology organizations before it reached end users. Read more in “Phantom Stealer: Credential Theft as a Service.” 

How to Prevent Doxing

Preventing doxing starts with reducing publicly available personal information for employees and executives, monitoring for exposure, and having an incident response plan ready if that information surfaces. No single control eliminates risk entirely, but combining these steps significantly reduces exposure. 

Reduce public exposure of personal information

Start by auditing what’s already public. From there, focus on the areas that create the most exposure:

  • Remove unnecessary personal details from company websites and staff directories.
  • Encourage employees to review and tighten their social media privacy settings. 
  • Limit how much personal information executives share publicly, including on personal social media accounts.

Monitor for exposed employee and executive data

Ongoing monitoring catches exposure that manual audits miss, including new entries on data broker sites or fresh posts on forums. Group-IB Digital Risk Protection platform continuously monitors these sources, flagging exposed executive and employee data before it’s weaponized against them.

Strengthen account and identity security

Multi-factor authentication and strong, unique passwords make it harder for attackers to compromise the accounts that often serve as a starting point for doxing. Identity security practices reduce the likelihood that a single compromised account will snowball into full profile exposure.

Monitor dark web and leak sites

Dedicated leak sites and dark web forums are where doxes often surface first, well before they reach mainstream platforms. This alerts security teams to exposed credentials and sensitive data before attackers compile them into a complete doxing profile. 

Establish an incident response process

Having a clear process for responding to a doxing incident limits the damage once information is exposed. Group-IB Incident Response team helps organizations contain active threats and coordinate a fast, structured response when personal or corporate data is exposed publicly.

How Can Organizations Detect Doxing and Exposed Information?

Organizations detect doxing by combining automated monitoring with human analysis across the platforms where exposure typically occurs. 

  • Automated tools scan social media, forums, marketplaces, and dark web sources for mentions of company names, executive and employee details, or leaked data. 
  • Analysts then review flagged results to confirm genuine exposure and assess severity, since automated detection alone can produce false positives that require expert context to interpret correctly. 

This layered approach reflects what doxing means for a security posture: an operational risk that needs the same combination of automation and human judgment used to catch other threats early. 

How Group-IB Digital Risk Protection Helps Prevent Doxing Risks

Digital Risk Protection helps organizations catch doxing risks early by continuously monitoring for exposed employee and executive data. The platform’s VIP Protection module specifically defends executives’ personal brands by identifying impersonation attempts and fake accounts before they gain traction. 

Once it finds a violation, the platform uses patented graph technology to trace connected infrastructure rather than treating each detection as an isolated incident. If a fake executive account or leaked data source is linked to a shared host or domain cluster, the platform checks every other resource on that same infrastructure for similar activity. A single flagged account can surface a wider network of related fake profiles or leak sources that would otherwise go undetected. 

Group-IB solutions for Data Leak Detection uncover exposed code repositories, credentials, and other sensitive information on dark web forums, closing the gap between when data leaks and when a security team learns about it. When a violation is confirmed, Digital Risk Protection’s three-stage takedown process quickly removes exposed content, reducing the time compromising information remains accessible. 

For organizations concerned about executive doxing or employee data exposure, this combination of monitoring and takedown gives security teams the visibility they need to act before an incident escalates. 

Contact Group-IB experts to see how our solutions can flag exposed sensitive data before it’s used against your organization. 

 

Frequently Asked Questions

Is doxing illegal?

arrow_drop_down

Doxing is illegal in some cases, but it depends on the jurisdiction and intent. While it isn’t always categorized as its own distinct crime, the actions involved often violate harassment, stalking, or privacy laws, particularly when exposure leads to threats or physical harm.

 

What is the difference between doxing and identity theft?

arrow_drop_down

Doxing involves publicly exposing an individual’s private information with the intention of harassing or intimidating them. Identity theft goes a step further by using that exposed information to impersonate the victim for financial or other fraudulent gain.

 

Can businesses be victims of doxing?

arrow_drop_down

Yes, businesses can be victims of doxing when internal documents, credentials, or executive information are exposed publicly during a dispute, extortion attempt, or competitive attack. This can damage the business’s reputation and expose it to further security risks.

 

Can doxing lead to ransomware or other cyberattacks?

arrow_drop_down

Yes, doxing can lead to ransomware or cyberattacks because exposed credentials or internal information give attackers the details they need to launch follow-on attacks. Doxing often serves as reconnaissance for a larger attack. 

 

How can you tell if your personal information has been exposed?

arrow_drop_down

Signs that your personal information has been exposed include unexpected contact from strangers who reference private details, unfamiliar accounts using your information, or direct notification that your data was exposed in a breach. Regularly monitoring data broker sites and breach notification services can help catch exposure early.

 

What should you do if your employee has been doxed?

arrow_drop_down

If your employee has been doxed, act quickly to assess what information was exposed and how it’s being used. Support the employee directly, involve law enforcement if there’s a safety threat, and work together to get the exposed content taken down from wherever it was published.

 

Can doxed information be removed from the internet?

arrow_drop_down

Doxed information can be removed from the internet, but it depends on where it was published. Typically, data broker sites and some social platforms will remove personal information on request. Content on dark web forums or leak sites is far harder to remove and often requires specialized takedown expertise.

 

How can companies monitor for doxing threats?

arrow_drop_down

Companies can monitor for doxing threats by tracking mentions of executives’ and employees’ names across social media, forums, and the dark web, combined with dedicated data leak monitoring. Digital Risk Protection provides continuous, cross-platform monitoring paired with analyst review to confirm genuine exposure.

Group-IB: Fight
against cybercrime