Scammers increasingly exploit individuals' digital footprints—comprising both actively shared and passively collected data—to craft highly personalized social engineering attacks. Details such as job titles, locations, and even seemingly innocuous information like pet names can be pieced together from social networks, public databases, and data brokers, enabling attackers to convincingly impersonate or target victims. The aggregation of this data, especially when combined with information from data breaches, significantly raises the risk of identity theft and fraud.
At the same time, privacy practices among major social media and community platforms vary widely, with some services like Pinterest and Quora demonstrating stronger privacy protections, while others such as TikTok and Facebook are rated poorly for user privacy. Frequent changes in platform policies, ownership, and data processing approaches have prompted mass user migrations, highlighting growing concerns about how personal information is collected, processed, and potentially resold. Users are advised to consider these privacy risks when choosing where to share personal information online.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.