Stop unwanted interruptions before they stop your workflow. Learn how.
Utility navigation bar redirect icon
Portal LoginSupportBlogContact
Search
Close search
Huntress Logo in Teal
  • Platform Overview
    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed EDR

    Get full endpoint visibility, detection, and response.

    Managed ITDR: Identity Threat Detection and Response

    Protect your Microsoft 365 and Google Workspace identities and email environments.

    Managed ITDR: Identity Threat Detection and Response

    Protect your Microsoft 365 and Google Workspace identities and email environments.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed SIEM

    Managed threat response and robust compliance support at a predictable price.

    Managed Security Awareness Training Software

    Empower your teams with science-backed security awareness training.

    Managed Security Awareness Training Software

    Empower your teams with science-backed security awareness training.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ISPM

    Continuous Microsoft 365 and identity hardening, managed and enforced by Huntress experts.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Managed ESPM

    Proactively secure endpoints against attacks.

    Integrations
    Integrations
    Support Documentation
    Support Documentation
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
    See Huntress in Action

    Quickly deploy and manage real-time protection for endpoints, email, and employees - all from a single dashboard.

    Huntress Cybersecurity
  • Threats We Stop
    Phishing
    Phishing
    Business Email Compromise
    Business Email Compromise
    Ransomware
    Ransomware
    Infostealers
    Infostealers
    Living off the Land
    Living off the Land
    View Allright arrowView Allright arrow
    Industries We Serve
    Education
    Education
    Financial Services
    Financial Services
    State and Local Government
    State and Local Government
    Healthcare
    Healthcare
    Law Firms
    Law Firms
    Manufacturing
    Manufacturing
    Utilities
    Utilities
    View Allright arrowView Allright arrow
    Tailored Solutions
    MSPs
    MSPs
    Resellers
    Resellers
    SMBs
    SMBs
    Compliance
    Compliance
    Disrupting your business is Big Cybercrime’s business model

    Stop unwanted interruptions before they stop your workflow.



    Huntress Cybersecurity
    Cybercriminals Have Evolved

    Get the intel on today’s cybercriminal groups and learn how to protect yourself.

    Huntress Cybersecurity
  • Pricing
  • Community Series
    The Product Lab

    Shape the next big thing in cybersecurity together.

    The Product Lab

    Shape the next big thing in cybersecurity together.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Fireside Chat

    Real people. Real perspectives. Better conversations.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    Tradecraft Tuesday

    No products, no pitches – just tradecraft.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    _declassified

    Exposing hidden truths in the world of cybersecurity.

    Resources
    Upcoming Events
    Upcoming Events
    Ebooks
    Ebooks
    On-Demand Webinars
    On-Demand Webinars
    Videos
    Videos
    Whitepapers
    Whitepapers
    Datasheets
    Datasheets
    Cybersecurity Education
    Cybersecurity 101
    Cybersecurity 101
    Cybersecurity Guides
    Cybersecurity Guides
    Threat Library
    Threat Library
    Real Tradecraft, Real Results
    Real Tradecraft, Real Results
    2026 Cyber Threat Report
    2026 Cyber Threat Report
    The Huntress Blog
    Your Profile Is a Dossier. Here's Who's Reading It.
    Huntress Cybersecurity
    Your Profile Is a Dossier. Here's Who's Reading It.
    Huntress Cybersecurity
    Before Your MSP Chases CMMC, Take an Honest Look at Your Operations
    Huntress Cybersecurity
    Before Your MSP Chases CMMC, Take an Honest Look at Your Operations
    Huntress Cybersecurity
    From Cookies to Keys: The Threat of Session Hijacking
    Huntress Cybersecurity
    From Cookies to Keys: The Threat of Session Hijacking
    Huntress Cybersecurity
  • Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    Why Huntress

    Go beyond AI in the fight against today’s hackers with Huntress Managed EDR purpose-built for your needs

    Huntress Cybersecurity
    The Huntress SOC

    24/7 Security Operations Center

    The Huntress SOC

    24/7 Security Operations Center

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Reviews

    Why businesses of all sizes trust Huntress to defend their assets

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Case Studies

    Learn directly from our partners how Huntress has helped them

    Community

    Get in touch with the Huntress Community team

    Community

    Get in touch with the Huntress Community team

    Compare Huntress
    Bitdefender
    Bitdefender
    Blackpoint
    Blackpoint
    Breach Secure Now!
    Breach Secure Now!
    Crowdstrike
    Crowdstrike
    Datto
    Datto
    SentinelOne
    SentinelOne
    Sophos
    Sophos
    Compare Allright arrowCompare Allright arrow
  • HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    HUNTRESS HUB

    Login to access top-notch marketing resources, tools, and training.

    Huntress Cybersecurity
    Partners
    MSPs

    Join our partner community to deliver expert-led managed security.

    MSPs

    Join our partner community to deliver expert-led managed security.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Resellers

    Partner program designed to grow your cybersecurity business.

    Tech Alliances

    Driving innovation through global technology Partnerships

    Tech Alliances

    Driving innovation through global technology Partnerships

    Microsoft Partnership

    A Level-Up for Your Business Security

    Microsoft Partnership

    A Level-Up for Your Business Security

  • Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Press Release
    Huntress Announces Collaboration with Microsoft to Strengthen Cybersecurity for Businesses of All Sizes
    Huntress Cybersecurity
    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Our Story

    We're on a mission to shatter the barriers to enterprise-level security.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Newsroom

    Explore press releases, news articles, media interviews and more.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Meet the Team

    Founded by former NSA Cyber Operators. Backed by security researchers.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Careers

    Ready to shake up the cybersecurity world? Join the hunt.

    Awards
    Awards
    Contact Us
    Contact Us
  • Portal Login
  • Support
  • Blog
  • Contact
  • Search
  • Get a Demo
  • Start for Free
Portal LoginSupportBlogContact
Search
Close search
Get a Demo
Start for Free
HomeBlog
Your Profile Is a Dossier. Here's Who's Reading It.
Published:
May 28, 2026

Your Profile Is a Dossier. Here's Who's Reading It.

By:
Beth Robinson
Share icon
Glitch effectGlitch effectGlitch effect

Key Takeaways

Attackers don't need the dark web to build a dossier on you. LinkedIn, corporate directories, and breach data sites on the open internet are enough.

Every post is a data point. A "first day at a new job" announcement tells an attacker your employer, your role, and your connections. Seemingly harmless updates add up fast.

The overlap between your work and personal life is where attacks start. Reused passwords and personal devices used for work sit in the gray zone where most successful attacks begin. Attackers don't care which door they get in through. They just want the initial foothold.

Your voice is public data, too. A convincing deepfake voice can be generated from just a few minutes of publicly available audio. Attackers are already using this to impersonate targets and manipulate the people closest to them.

Every LinkedIn update, every "first day at a new job!" announcement is data. And while you're sharing your exciting life milestones, cybercriminals are taking notes.

That's what we unpacked in the second episode of _declassified, where Truman Kain, Principal Product Researcher at Huntress, and cybersecurity educator Caitlin Sarian (aka Cybersecurity Girl) walked through exactly how attackers turn your public information into a playbook against you.



Attackers don't need the dark web to build a dossier

There's a common misconception that attackers need to venture into dark layers of the internet to find useful information about their targets. We’re putting that to rest, and here’s why. 

An attacker can pull together a detailed picture of someone using tools most people use (or can easily access) every day: LinkedIn, corporate directories, and breach data sites that live on the open internet. Search an email on a site like dehashed, click through a few records, and within minutes, you might be looking at usernames, old passwords, and even a social security number.



The information just needs to be convincing enough to get someone on the phone or to make a phishing email feel believable. A targeted phishing attempt against Jai Minton, Senior Manager of Detection Engineering and Threat Hunting at Huntress, landed in both his work and personal inboxes within two minutes of each other. The attacker had pieced together his corporate email format and found a personal email tied to a previous breach. Dark web searches weren't required.


The blurred line between work and home

Attackers use the overlap between your personal and professional digital details against you. 

Reused passwords and personal devices used for work sit right in the gray zone where most successful attacks begin. Attackers don’t care where they get in. They just want that initial access point to move on with their attack. 

A "first day at a new job" post on LinkedIn is a good example of how quickly this can go wrong. That single update gives an attacker your employer, your role, your connections, and the knowledge that you're brand new and probably not yet familiar with internal security processes. That makes you a high-value, low-friction target.

The same logic applies to other posts that feel like fun, harmless life updates. But in reality, a boarding pass photo reveals flight details, a vacation post tells the world your home is empty, and a picture of an office desk reveals a schedule and workspace. Every post is another data point in the attacker’s dossier.


Real attacks, real playbooks

In one real-world case shared during the episode, a Huntress job applicant named "Andrew" turned out to be a catfish using someone else's LinkedIn photo. The interviewer caught it, but the point landed hard: attackers are using public data to steal identities and apply for jobs, potentially gaining access to corporate systems in the process.


High-profile cases show how far this can go. A developer was targeted through a fake Slack workspace, a scheduled meeting, and a prompt to install software that turned out to be a backdoor. The dossier was fully built before the first message was ever sent.



Families aren't off the hook either. The ShinyHunters breach of Instructure, the company behind Canvas, exposed data from over 3,000 schools and millions of students. That breach immediately became fuel for hyper-targeted phishing, because attackers now knew which students were enrolled in which classes and could craft emails that seemed impossible to fake.



Your voice is public data, too 

Most people think about open-source intelligence (OSINT) in terms of the photos or words they post. But what they say out loud is fair game too. Using only a few minutes of publicly available audio, a convincing deepfake voice can be generated in minutes. Attackers are already using this tactic to impersonate targets over the phone and manipulate the people closest to them into handing over money or access.


Think like an attacker

The most actionable shift anyone can take is a simple one: ask yourself whether an attacker could use it. "Put your hacker hat on," as Caitlin puts it. Think through what types of information you’re sharing before you hit post. 

That's also the idea behind the Huntress OSINT Simulator. This interactive security awareness training simulation puts you in the attacker's seat, using open-source intelligence to build a target profile followed by an attempted social engineering attack over the phone. It's a safe, hands-on way for you and your team to kick the tires on how quickly public information becomes attack fuel. 


Tips that actually hold up

Treat security questions like passwords. A random app doesn't need to know your real information. Bend the truth when you get security questions like "what elementary school did you attend?" or "what city were you born in?"  Spin up fake answers and store them in a password manager.

Freeze your kids' credit. Kids’ identities can be stolen and used for years before anyone notices. It takes minutes to freeze and can prevent a much bigger headache down the road.

Create a family safe word. Voice cloning is accessible and fast. A convincing deepfake voice can be generated in about five minutes using only publicly available audio. A safe word is one of the few defenses that actually works against it.

Google yourself. Search your name and username in quotes to see what's publicly indexed, including comments on public posts you may have forgotten about.


Understanding what attackers see with the information you post is the first step to giving them less to work with.

Big cybercrime doesn’t stop here. Grab your spot for the next episode of _declassified to hear from John Hammond and Jesse McGraw, a former cybercriminal turned white-hat hacker, on how attackers use timing to disrupt your business.



Categories
Cybersecurity Education
ChatGPT logoChatGPTOpens in new tabClaude logoClaudeOpens in new tabPerplexity logoPerplexityOpens in new tabGoogle Gemini logoGoogle AIOpens in new tab
AI sparkle iconSummarize This Page
ChatGPT logoChatGPTOpens in new tabClaude logoClaudeOpens in new tabPerplexity logoPerplexityOpens in new tabGoogle Gemini logoGoogle AIOpens in new tab

Curious how cybercriminals think?

Join John Hammond and former cybercriminal Jesse McGraw for the latest edition of declassified and learn how attackers turn timing into business disruption.
Grab your spot
Share
Facebook iconTwitter X iconLinkedin iconDownload icon
Glitch effect

You Might Also Like

  • The Craftiest Trends, Scams, and Tradecraft of 2025 (So Far)

    John Hammond and Greg Linares with Huntress discuss the top tradecraft we’ve seen this year so far, from ClickFix attacks to deepfake social engineering
  • How EvilTokens Turbocharges Old School Phishing with AI

    Device code phishing doesn't need stolen passwords or malware—just a legitimate auth flow. Learn how EvilTokens weaponized AI to run this attack across 344 organizations.
  • Cobalt Strikes Again: An Analysis of Obfuscated Malware

    Join us for a threat hunting adventure as we analyze a suspicious run key that leads us to Cobalt Strike malware hidden across nearly 700 registry values.
  • How to Offend Your IT Team: A Guide for the Security Unaware

    Ready to drive your IT team crazy? See our top security blunders and learn practical tips to improve your cybersecurity habits.
  • Truman’s Take: A Product Researcher’s Insights on Managed Learning

    In this new blog series, we’ll explore the managed episodes from Huntress Managed SAT, dive into the topics, and gain insight into why these episodes are relevant right now.
  • Abusing Trusted Applications with Nested Execution

    Recently, my co-founders gave a talk at DerbyCon 7.0 on evading common persistence enumeration tools. Evasion using trusted applications has been a hot topic of discussion within the infosec community and is one of the techniques they covered in their presentation. However, very little discussion exists on why these matter or the steps researchers take to find “hosting” applications.
  • Nightmare-Eclipse Tooling Moves From Public PoC to Real-World Intrusion

    Huntress observed in-the-wild use of Nightmare-Eclipse tooling, including BlueHammer, RedSun, and UnDefend, in a live intrusion involving FortiGate VPN compromise as the initial access, reconnaissance commands, and likely tunneling activity.
  • Understanding Your SMB Clients' Cybersecurity Needs

    SMBs need more advanced cybersecurity. Learn about the tools you need to help guide your clients toward better threat detection and response.

Sign Up for Huntress Updates

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.
Privacy • Terms
By submitting this form, you accept our Terms of Service & Privacy Policy
Huntress Managed Security PlatformManaged EDRManaged EDR for macOSManaged EDR for LinuxManaged ITDRManaged SIEMManaged Security Awareness TrainingManaged ISPMManaged ESPMBook a Demo
PhishingComplianceBusiness Email CompromiseEducationFinanceHealthcareManufacturingState & Local Government
Managed Service ProvidersResellersIT & Security Teams24/7 SOCCase Studies
BlogResource CenterCybersecurity 101Upcoming EventsSupport Documentation
Our CompanyLeadershipNews & PressCareersContact Us
Huntress white logo

Protecting 250k+ customers like you with enterprise-grade protection.

Privacy PolicyCookie PolicyTerms of UseCookie Consent
Linkedin iconTwitter X iconYouTube iconInstagram icon
© 2025 Huntress All Rights Reserved.

Join the Hunt

Get insider access to Huntress tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy