Key Takeaways |
|
|
|
How Does Doxing Work?
Doxing becomes clearer when broken into three stages: collecting information, linking it together, and publishing it publicly. Each stage builds upon the last, turning scattered data points into a complete profile that can be used to harass or target someone.
Collecting personal and sensitive information
The first stage involves gathering raw data from social media profiles, public records, data breaches, and old forum posts. Attackers often start with something small, like a surname, and use it to search other platforms for matching accounts
Linking information from multiple sources
Attackers cross-reference data points to build a complete profile. A username on one social platform might connect to a real name on another, or even to a home address in a public records database. This correlation step separates doxing from simple data exposure, and it’s the core of doxing in practice.
Publishing or sharing exposed information
Once a profile is complete, threat actors publish the compiled information on forums, social media, or dedicated doxing sites. Some attackers share the information directly with a target to intimidate them. Others post it publicly to invite harassment from a wider group.
What Information Can Be Exposed Through Doxing?
Doxing can expose a wide range of personal and corporate data, from basic contact details to sensitive internal business information. What information gets exposed usually depends on the target and the attacker’s motive.
Personally identifiable information
Personally identifiable information (PII) includes, but is not limited to, full names, dates of birth, and financial account details. This type of information alone is often enough to enable identity theft.
Contact and location information
Home addresses, phone numbers, and real-time location data such as geotagged photos or check-ins fall into this category. Exposed location data creates immediate physical safety risks, especially for executives and public-facing employees.
Employee and executive information
Work email addresses, direct phone lines, and details about someone’s role or position are common targets. Executives are particularly exposed because their names and titles are often publicly listed on company websites.
Corporate and business information
Doxing can also expose internal documents, credentials, infrastructure details, and other proprietary data, especially when an employee’s personal accounts are compromised and used as an entry point. This can lead to a data leak, where confidential company data becomes publicly available.
What Are Common Doxing Examples?
Common doxing examples organizations should watch for include executive targeting, employee exposure, corporate data leaks, social media doxing, and dark web publication. Doxing can look different depending on the target and the attacker’s goal.
Executive and VIP doxing
Executives and other high-profile employees are frequent doxing targets because their visibility makes them easy to identify and locate. Attackers build a fake persona around a senior leader’s name, title, and public photos, then use that person to interact with customers, employees, or business partners as though they were the real person. These impersonations can be difficult to spot until the damage is already done because the underlying details are accurate.
Employee PII exposure
Employees below the executive level can also be targeted through data broker sites or breached databases that expose their personal information, such as home addresses, phone numbers, and personal email accounts. Attackers can then use this information to harass employees directly or impersonate them in social engineering attempts.
Corporate data exposure
Sometimes the target isn’t an individual, but the organization itself. Internal documents, source code, or credentials get published online to embarrass a company, pressure it during a dispute, or support a separate attack.
Social media doxing
Attackers often use social media as both a research tool and a publishing platform. Public posts, tagged photos, and friend lists can reveal a target’s location and personal relationships, which can then get compiled and shared publicly.
Doxing through dark web and leak sites
Dedicated leak sites and dark web forums commonly publish doxing dossiers, particularly for high-value targets. These sites are difficult for security teams to monitor without dedicated tools, since they sit on the dark web, a part of the internet that is not indexed by standard search engines and often requires specialized software like Tor to access.
Case in Point: Not every listing on these forums is what it claims to be. Group-IB found that data brokers in Chinese-speaking dark web forums and Telegram channels often sell large, “fresh” datasets recompiled from prior breaches, but padded with unrelated records to increase volume. Real personal details still appear even when the rest of the dataset is fabricated, so organizations can’t dismiss these listings on credibility alone. Read more in “Volume Obfuscation Game: The Lead Data Brokers Out To Waste Your Time.”
What Are the Risks of Doxing for Organizations?
Doxing puts employees at physical risk and exposes organizations to fraud, reputational damage, and follow-on attacks.
In the High-Tech Crime Trends Report 2026, Group-IB CEO Dmitry Volkov described the broader cybercrime landscape as being shaped by “cascading failures of trust,” rather than isolated incidents.
Doxing follows that same pattern on a smaller scale. The risks compound quickly once information is public, since one exposed detail often enables the next attack. The sections below break down the specific risks organizations should plan for.
Employee privacy and safety risks
Exposed personal details can lead to harassment, stalking, or physical confrontation. This risk is especially high for employees in customer-facing or public-facing roles.
Executive and VIP exposure
Executives and VIPs face a combination of privacy and reputational risk. A convincing fake account impersonating a senior leader can mislead customers, partners, or employees before anyone notices it lacks legitimacy. For organizations, unaddressed executive impersonation can expose the wider customer base to real financial harm.
The financial stakes of impersonation can be drastic. The Federal Trade Commission (FTC) reported that impersonation scams cost consumers $3.5 billion in 2025.
Identity theft and impersonation
Exposed PII gives attackers what they need to open fraudulent accounts, file false claims, or impersonate the victim in other schemes. The more complete the exposed profile, the easier this becomes. This is a different kind of impersonation from a fake executive account that misleads customers. Here, the attacker poses as the victim rather than as the company.
Social engineering and targeted attacks
Doxed information makes phishing and impersonation attempts far more convincing. An attacker who knows insider information, such as an employee’s manager, personal email address, and recent projects, can craft a message that’s difficult to distinguish from a legitimate one.
Reputational and business risks
When executives or corporate data are exposed, the fallout can erode customer trust and damage brand reputation. Organizations that respond slowly to a doxing incident risk compounding the damage.
Business impersonation is a serious concern in its own right. Combined with government impersonation reports, these two categories accounted for nearly half of all fraud reports the agency received directly that year. A doxing incident that hands attackers real employee or executive details only makes that kind of impersonation more convincing.
Why Do People Dox Others?
People dox others for reasons that range from personal grudges to financial gain. The motive usually shapes how the attack unfolds. The table below breaks down the most common reasons behind a doxing attack.
| Motive | What it looks like |
| Harassment or intimidation | An attacker targets an individual directly to scare or silence them |
| Retaliation | An attacker exposes information during a personal or professional dispute |
| Activism or public shaming | Groups publish information to hold an individual accountable or provoke public backlash |
| Extortion | An attacker threatens to publish information unless the target pays or complies |
| Corporate or competitive motives | A rival or disgruntled insider exposes confidential data to damage a company’s standing or gain leverage in a business dispute |
How Do Threat Actors Obtain Information for Doxing?
Threat actors combine open-source research with data from breaches and criminal marketplaces to build a target’s profile, often layering multiple methods to fill in gaps. The table below outlines the main sourcing methods and what they involve.
| Method | How it works |
| Open source intelligence (OSINT) | Attackers comb through social media, public records, and old forum posts for information a target may not realize is still accessible |
| Breaches and marketplace leaks | Credentials and personal data from past breaches continue to circulate on dark web forums and marketplaces long after the original incident, giving attackers a reliable source to draw from |
| Social engineering | Attackers trick a target, or someone close to them, into directly revealing information |
| Insider access | Individuals with legitimate access to confidential records misuse that access to expose sensitive information |
Case in Point: Infostealer malware is a common source of the credentials and personal data that gets compiled into a dox. It harvests browser passwords, cookies, and payment card details from an infected device, and that stolen data then gets traded in underground markets where other attackers can access it.
Between November 2025 and January 2026, Group-IB’s Business Email Protection detected a five-wave Phantom Stealer campaign targeting European logistics, manufacturing, and technology organizations before it reached end users. Read more in “Phantom Stealer: Credential Theft as a Service.”
How to Prevent Doxing
Preventing doxing starts with reducing publicly available personal information for employees and executives, monitoring for exposure, and having an incident response plan ready if that information surfaces. No single control eliminates risk entirely, but combining these steps significantly reduces exposure.
Reduce public exposure of personal information
Start by auditing what’s already public. From there, focus on the areas that create the most exposure:
- Remove unnecessary personal details from company websites and staff directories.
- Encourage employees to review and tighten their social media privacy settings.
- Limit how much personal information executives share publicly, including on personal social media accounts.
Monitor for exposed employee and executive data
Ongoing monitoring catches exposure that manual audits miss, including new entries on data broker sites or fresh posts on forums. Group-IB Digital Risk Protection platform continuously monitors these sources, flagging exposed executive and employee data before it’s weaponized against them.
Strengthen account and identity security
Multi-factor authentication and strong, unique passwords make it harder for attackers to compromise the accounts that often serve as a starting point for doxing. Identity security practices reduce the likelihood that a single compromised account will snowball into full profile exposure.
Monitor dark web and leak sites
Dedicated leak sites and dark web forums are where doxes often surface first, well before they reach mainstream platforms. This alerts security teams to exposed credentials and sensitive data before attackers compile them into a complete doxing profile.
Establish an incident response process
Having a clear process for responding to a doxing incident limits the damage once information is exposed. Group-IB Incident Response team helps organizations contain active threats and coordinate a fast, structured response when personal or corporate data is exposed publicly.
How Can Organizations Detect Doxing and Exposed Information?
Organizations detect doxing by combining automated monitoring with human analysis across the platforms where exposure typically occurs.
- Automated tools scan social media, forums, marketplaces, and dark web sources for mentions of company names, executive and employee details, or leaked data.
- Analysts then review flagged results to confirm genuine exposure and assess severity, since automated detection alone can produce false positives that require expert context to interpret correctly.
This layered approach reflects what doxing means for a security posture: an operational risk that needs the same combination of automation and human judgment used to catch other threats early.
How Group-IB Digital Risk Protection Helps Prevent Doxing Risks
Digital Risk Protection helps organizations catch doxing risks early by continuously monitoring for exposed employee and executive data. The platform’s VIP Protection module specifically defends executives’ personal brands by identifying impersonation attempts and fake accounts before they gain traction.
Once it finds a violation, the platform uses patented graph technology to trace connected infrastructure rather than treating each detection as an isolated incident. If a fake executive account or leaked data source is linked to a shared host or domain cluster, the platform checks every other resource on that same infrastructure for similar activity. A single flagged account can surface a wider network of related fake profiles or leak sources that would otherwise go undetected.
Group-IB solutions for Data Leak Detection uncover exposed code repositories, credentials, and other sensitive information on dark web forums, closing the gap between when data leaks and when a security team learns about it. When a violation is confirmed, Digital Risk Protection’s three-stage takedown process quickly removes exposed content, reducing the time compromising information remains accessible.
For organizations concerned about executive doxing or employee data exposure, this combination of monitoring and takedown gives security teams the visibility they need to act before an incident escalates.
Contact Group-IB experts to see how our solutions can flag exposed sensitive data before it’s used against your organization.
