Your Executives Are More Exposed Than You Think. Here’s What We Found.
A home address on a real estate site, a fitness app that maps a daily running route, a family photo tagged at a school event… none of these feel like security incidents, but in the hands of a motivated threat actor, they could be.
This year, we analyzed 72 Executive Vulnerability Assessments (EVAs) conducted across a range of industries and locations. What we found should change how your organization thinks about executive protection.
Executive Digital Exposure Is Broader Than Most Organizations Realize
The numbers are stark:
- 94% of executives had home addresses publicly linked to their name in public records or people search sites. 86% had interior floor plans or blueprints viewable on popular real estate platforms.
- 100% had breach data linking their name to at least one current email address.
- 64% had their SSN exposed in breach data — and 54% had it listed for sale on a dark web marketplace.
These aren’t edge cases, they are the baseline.
And the exposure doesn’t stop with the executive. Immediate family members maintained an average of 8 public social media accounts. 97% of those accounts revealed personal details about the executive, often at a higher frequency than the executive’s own accounts.
The people closest to your executives are frequently their most significant digital vulnerability.
Physical Risk Starts Online
It’s easy to think of digital exposure as a cyber problem, but it is potentially much more. Threat actors use publicly available information to locate executives, map their properties, establish their routines, and identify when their homes are unoccupied. The murder of a sitting state lawmaker in June 2025, carried out using addresses sourced from data broker sites the suspect had documented by name, is a stark reminder that digital exposure has physical consequences.
32% of executives or their family members shared geolocation data through fitness tracking apps or public geotagged social media posts. Approximately 53% shared geolocation and pattern-of-life information through public reviews, most related to locations near their home.
This is the kind of exposure that doesn’t show up in a security dashboard. It requires looking where your internal tools don’t: across public records, open-source data, and the sites threat actors already know how to use.
That’s exactly what Executive Shield is designed to do: give your security team the outside-the-firewall visibility they need to identify and reduce executive exposure before it becomes an incident.
AI Is Changing What Threat Actors Can Do… and How Fast They Can Do It
Perhaps the most significant shift we documented this year isn’t in what threat actors want. It’s in what they can do, and how quickly.
AI tools are removing the last remaining barriers to targeting executives at scale. Tasks that previously required significant time, technical skill, and effort can now be automated or accelerated by almost anyone.
We identified multiple instances of potential threat actors using social media chatbots to request executives’ home addresses, social media handles, and biographical details about their spouses and children. While most responses were incomplete, they provided enough to enable follow-up research. We also observed chatbots helping users identify who to target in the first place, responding to prompts asking which companies to sue or which individuals to go after with specific names, alleged wrongdoings, and employee details.
The findings from our own testing were equally concerning. Many AI tools are likely trained on datasets that include PII from data brokers. Certain models provided residential addresses for executives linked to people search sites and tax documents. Even some models that initially declined to provide information responded accurately when we reworded the prompt or provided alternative context.
This isn’t a future risk. It’s happening now, and it will accelerate as AI becomes further embedded in the platforms and applications people use every day.
We also documented a related and potentially serious threat: 25% of executives or their spouses had at least one public social media profile photo featuring a minor child. Publicly accessible images of children can be used by threat actors to generate child sexual abuse material for blackmail, reputational harm, or private use. Between January and September 2025, NCMEC’s CyberTipline received over one million reports related to generative AI. The UK’s Internet Watch Foundation identified a more than 26,000% increase in AI-generated child sexual abuse videos in 2025 compared to 2024. The risk is real, it is growing, and it starts with a public profile photo.
How to Reduce Executive Digital Exposure
The good news is that exposure can be reduced, with deliberate action.
The steps are practical: tighten privacy settings across executive and family social media accounts, submit and regularly resubmit PII removal requests to data broker sites, stop using home addresses on business registrations and donation records, delete unused accounts, and treat every public post as if a threat actor is reading it — because one might be.
Ongoing monitoring matters as much as one-time cleanup. Data repopulates. New breach data surfaces. New PII sites launch. The threat landscape shifts. Effective executive protection requires continuous awareness, not periodic audits.
Get the Full Report
The 2026 Executive Digital Exposure Trends report covers all of this in detail: physical location risk, social media exposure, breach data, PII on data broker sites, and a full special feature on AI-associated targeting trends — all based on findings drawn from real executive vulnerability assessments.
If you’re responsible for protecting high-visibility individuals at your organization, this report is for you.
Frequently Asked Questions on Executive Digital Exposure
What is executive digital exposure?
Why is executive digital exposure a security risk?
How do threat actors find information about executives?
What is an Executive Vulnerability Assessment?
How can organizations reduce executive digital exposure?
About Nisos®
Nisos is a trusted digital investigations partner specializing in unmasking human risk. We operate as an extension of security, risk, legal, people strategy, and trust and safety teams to protect their people and their business. Our open source intelligence services help enterprise teams mitigate risk, make critical decisions, and impose real world consequences. For more information, visit: https://nisos.com.