Risk analyses

Anatomy of a threat

Cybersecurity does not stop at the office's front door or the network firewall. The international case studies below show how seemingly harmless online information became the blueprint for targeted digital infiltration, extortion, or physical threats.

17
International case studies
4
Risk categories
100%
Public sources

From online footprint to physical threat

For executives, key personnel, and their immediate circle, publicly findable information can be the run-up to a physical incident. Not only a home address is sensitive, a public agenda is too.

US · HEALTHCARE2024

Brian Thompson, CEO of UnitedHealthcare

Findable online

UnitedHealth Group had publicly announced, including in a notice and an SEC filing, that its annual investor conference would take place on December 4, 2024, in New York. Thompson was identifiable as CEO of UnitedHealthcare through corporate profiles and news coverage.

How it was used

On the morning of December 4, Thompson was shot dead outside the conference hotel, on his way to that meeting. Police described the attack as targeted and premeditated.

CI-IT's key lesson

Home addresses are not the only sensitive data. Public agendas, investor days, and conference locations make the physical presence of a key person predictable. For a perpetrator it is sometimes unnecessary to know where someone lives; it can be enough to find out online where and when that person will be present without much security.

Sources: UnitedHealth Group, AP

FR · CRYPTO2025

David Balland, co-founder of Ledger

Findable online

In the crypto sector, founders, roles, wealth signals, and conference appearances are often visible online through media, social media, and events.

How it was used

Balland was kidnapped and a ransom was demanded. He was later freed by French police.

CI-IT's key lesson

Visibility of role, wealth, and agenda can pose a direct physical risk in sectors such as crypto, finance, energy, and defense.

Source: Le Monde

AU · ENERGY

Meg O'Neill, CEO of Woodside Energy

Findable online

Her position as CEO was publicly known. Activists were able to identify her home address.

How it was used

According to Australian reporting, activists went to her home for protest actions. The executive's home address thus became a stage for pressure on the organization.

CI-IT's key lesson

An executive's home address can become a means for activists or perpetrators to create reputational pressure or personal threat.

Source: ABC News

UK · PHARMA

SHAC / Huntingdon Life Sciences (incl. director Brian Cass)

Findable online

Activists published names, addresses, and personal data of employees, executives, suppliers, and business relations. U.S. court documents refer to websites on which that personal information was posted.

How it was used

The data was used for intimidation, threats, and pressure campaigns against people around the organization. Director Brian Cass was physically attacked.

CI-IT's key lesson

Not only the leadership, but also banks, suppliers, clients, and individual employees can become pressure points. An attack on an organization runs through the private data of key people and their relations.

Source: U.S. Department of Justice

NL · GOVERNMENT

Mayor Hubert Bruls, Nijmegen (COVID-19 period)

Findable online

According to reporting, during the COVID-19 period there was a concrete threat that activists would visit the mayor and his family at home. His role, his position in pandemic policy and the safety region, and his residential area were publicly traceable enough to make him a private target.

How it was used

The threat was not aimed at the city hall as an abstract organization, but at the mayor's private home. As a precaution, he and his family were temporarily housed elsewhere.

CI-IT's key lesson

The public visibility of an official, combined with online mobilization or threat, can move the risk from the organization to the private sphere.

Source: RTL Nieuws

NL · GOVERNMENT2022

Minister Christianne van der Wal, farmers' protests

Findable online

As Minister for Nature and Nitrogen, she was publicly linked to the nitrogen policy. Protesters were able to find her home.

How it was used

Protests took place at her home. According to reporting, one action escalated: a police barrier was broken through and a police car was damaged; the minister stated that her children were inside.

CI-IT's key lesson

A policy file tied to a person, plus a findable home address, brings the conflict literally to the front door. The chain runs from policy to person, to home address, to a means of pressure.

Source: NL Times

NL · POLITICS2022

Sigrid Kaag, torch at her home

Findable online

As a political leader and Minister of Finance, she was publicly visible.

How it was used

A man appeared with a lit torch at her home and shared footage on social media. He was later convicted.

CI-IT's key lesson

The private home was used as a stage for intimidation. Social media amplified the effect: not only physical presence at the door, but also online distribution of the act toward a wider audience.

Source: NOS

NL · POLICE2026

Utrecht police officer, doxing after viral footage

Findable online

After an arrest at Utrecht Central Station, footage of the officer went viral on social media. According to reporting, serious threats were then made and the officer's personal information was shared online.

How it was used

The officer subsequently stayed with his family in a safe location for a time. The chain runs from footage to identification, to private data, to threat, to a security measure.

CI-IT's key lesson

The trigger was a public act performed on duty, but through social media the risk shifted to the officer as a private individual and to his family.

Source: NOS

These cases show that online risks are not limited to classic data breaches or cyberattacks. A role, a policy file, a visible public act, a public agenda, or a shared video clip can be enough to identify and locate an employee or executive and then pressure them personally. The organization is then approached not through the company's front door, but through the person's front door.

Defense, military, and special forces

In defense and special forces, the risk goes beyond reputational damage or privacy. Online information can lead to the identification of military personnel, linkage to a unit or operation, and reconstruction of routines.

US · DEFENSE2015

ISIS "kill list" of U.S. military personnel

Findable online

A group calling itself the "Islamic State Hacking Division" published online the names, photos, and alleged addresses of U.S. service members. According to reporting, the group stated that the information came partly from social media and partly from hacked sources.

How it was used

The data was published to incite sympathizers to attack the service members. The chain runs from military role to online identification, to address data, to physical threats against service members and their families.

CI-IT's key lesson

A military role combined with a visible online presence can make a person and their family a target.

Source: Military.com

UK · DEFENSE2025

British special forces, names online for years

Findable online

According to reporting, names, ranks, and ties to British special forces had for years appeared in documents accessible online through military-affiliated publications. It concerned at least twenty service members; the documents were removed after being reported.

How it was used

For this group, anonymity is part of their security. The publication made it possible to link real name, rank, and unit.

CI-IT's key lesson

Even elite units are vulnerable through seemingly administrative publications. Innocuous-looking documents can undermine anonymity and create risks for operations, blackmail, targeting, and family members.

Source: The Times

FR · DEFENSE2026

StravaLeaks, French military via fitness data

Findable online

According to reporting, public Strava activity showed that thousands of French service members could be identified and tracked. Profiles around military bases could be linked to locations and patterns.

How it was used

The data was not necessarily used by malicious actors, but the case clearly shows what an adversary could do: identify service members, uncover routines, infer bases and missions, and reconstruct private patterns.

CI-IT's key lesson

Not only addresses, but also routine and location data from everyday apps pose a risk to military personnel.

Source: Le Monde

US · DEFENSE2026

Lockheed Martin / Handala, defense engineers doxed

Findable online

An Iran-linked hacktivist group, Handala, claimed to have obtained Lockheed Martin data and threatened to publish information on engineers said to work on sensitive military projects. According to reporting, it concerned several dozen senior engineers, with an ultimatum.

How it was used

Not the executive, but technical key employees were targeted. The information was used for intimidation, political pressure, and possible physical threat against people with knowledge of sensitive projects.

CI-IT's key lesson

At defense companies the risk shifts to engineers, key employees, suppliers, and insurers. Anyone visibly part of the defense chain can be used as a pressure point.

Source: Cybernews

In defense and special forces, online information can lead to the identification of military personnel, linkage to a unit or operation, reconstruction of routines, exposure of family members, and ultimately physical threats. At defense companies, the risk also shifts to technical key employees, engineers, suppliers, and insurers: anyone visibly part of the defense chain can be used as a pressure point.

From online footprint to digital infiltration

Public information about who holds which role helps attackers approach exactly the right employee. The person thus becomes the way into the organization.

US · CASINO2023

MGM Resorts / Scattered Spider

Findable online

Attackers used LinkedIn, among other sources, to identify MGM employees: name, role, employer, and likely position within the organization.

How it was used

With that information they posed as an employee contacting the IT help desk. Through social engineering they gained access to accounts and systems.

CI-IT's key lesson

Public information about roles and teams helps attackers approach exactly the right employee. The employee is the way into the organization.

Source: Specops

US · TECH2020

Twitter hack

Findable online

Employees and their roles were identifiable online.

How it was used

Through social engineering targeting employees with access to internal tools, attackers gained access to internal systems, after which well-known accounts were misused.

CI-IT's key lesson

Public information about roles, teams, and access levels helps attackers approach the right employee.

Source: NY Dept. of Financial Services

Facial recognition as an accelerator

Facial recognition reverses the direction of search: from name to photo, it becomes from photo to name. A face from imagery can be linked to a name, role, social media, employer, family, or address.

US · GOVERNMENT2025

ICE agents identified via facial recognition tools

Findable online

Photos and videos of ICE agents during enforcement actions and protests appeared online. Activists used commercial facial recognition tools to link faces to names and other online profiles. According to reporting, U.S. senators referred in 2025 to cases in which at least twenty agents were said to have been identified through facial recognition.

How it was used

Imagery was linked to a name, to private data, to threat and doxing. Someone does not need to display their name; a face in footage can be enough to search further for an address, family, social media, and employer.

CI-IT's key lesson

Being visible in imagery has become a risk in itself, even without a name or role on screen.

Source: Politico Pro

UA · DEFENSE

Military personnel identified via facial recognition in a conflict zone

Findable online

In the conflict in Ukraine, imagery of military personnel was combined with facial recognition. According to reporting, Ukraine gained access to commercial facial recognition to identify people; journalists and researchers also used commercial facial recognition tools to recognize soldiers from short videos.

How it was used

Facial recognition makes it possible to identify people who do not voluntarily share their name. A photo from an operation, training, ceremony, or social media post can later be linked to a name, family, or unit.

CI-IT's key lesson

Facial recognition is used not only by states, but also by journalists, activists, researchers, and malicious actors with commercial tools. That makes imagery of military personnel, security staff, engineers, and executives far more sensitive.

Sources: TIME, WIRED

US · JUSTICE

Misidentification as a risk

Findable online

Studies and court cases show that facial recognition can also lead to false identifications. Reporting described cases in which people were wrongly arrested after too much reliance on a facial recognition match.

How it was used

In doxing or online outrage, a false match can lead to an innocent person being threatened.

CI-IT's key lesson

Facial recognition is a powerful tool, but also dangerous through misidentification. A wrong match can make an innocent person a target.

Source: Reader Supported News

A photo of an employee at an event, a police action, a defense trade fair, a company opening, or a public meeting can be linked through commercial facial recognition tools to social media profiles, old news articles, employer pages, sports clubs, or family members. Imagery thus becomes a starting point for doxing, intimidation, social engineering, or physical approach.

Overview

Which digital traces pose a risk?

For executives, security officers, plant managers, compliance officers, and spokespersons, these online traces are especially risky.

From online trace to concrete use

The same traces, translated into how they were used in the cases above.

After the investigation

From insight to measures

A target analysis is not an end in itself. After mapping the publicly visible footprint, CI-IT advises on concrete steps to reduce the risk.

Take information offline

We advise on having personal information removed or shielded: removal requests, opt-outs with data brokers, and shielding public registers and profiles.

Create noise

Where removal is not possible, reducing traceability helps. By deliberately adding noise, it becomes harder to unambiguously identify, locate, or track a person.

Build resilience

Targeted, practical guidance for the key personnel involved and their immediate circle, so they keep their footprint small over time.

Frequently asked questions

Questions about these insights

A target analysis reveals which information can be misused. On that basis, CI-IT advises on concrete measures: taking information offline, creating noise, and building the resilience of those involved.

Yes. After the analysis we advise on removal requests, opt-outs with data brokers, and shielding public registers and profiles, so that the publicly visible footprint shrinks.

Where information cannot be removed, reducing traceability helps. By deliberately adding noise, it becomes harder to unambiguously identify, locate, or track a person.

Precisely. For executives and key personnel, the analysis can, on request, also extend to the publicly visible information surrounding their immediate circle.

Yes. CI-IT works exclusively with publicly available information (OSINT) and within the boundaries of the GDPR. Results are shared confidentially and exclusively with the client.

Yes. This page analyzes seventeen international cases in which publicly findable information was the first step toward digital infiltration, extortion, or physical threats, from CEOs and ministers to soldiers and police officers. Each case is backed by a public news source.

Almost always with digital reconnaissance: an attacker first collects publicly available information about the target, such as role, routines, locations, and network. Only then does the approach follow. A target analysis reveals which information makes that reconnaissance possible.

Know what an attacker can find about your people online

A target analysis maps the publicly visible footprint of your key personnel, so you can shield it before it can be misused.

Schedule a consultation