An executive's home address, the school run schedule, the make and model of the car in the driveway. Two years ago, assembling that package took a determined attacker days of manual digging across property records, social media, and data broker sites. AI-assisted scraping tools now read a data broker's page layout well enough to keep working even after the site changes its design, and reports from teams building these tools describe cutting the setup time for a new target from weeks to hours. The same pipeline that lets a fraud crew clone an executive's voice from a single earnings call also builds the profile a harasser needs to show up at a front door. Security vendors tracking deepfake-enabled vishing report a sharp surge in these attacks through 2025, and that growth runs through the identical reconnaissance step that feeds physical targeting.
That's the reframe worth sitting with. Digital footprint reduction was pitched for years as privacy hygiene, worth doing but not urgent. It now sits next to residential alarm coverage and travel security on the list of controls that prevent physical harm, and it needs to be resourced that way.
Why This Got Harder, Not Just Bigger
The underlying threat isn't new. Data brokers have compiled address histories, phone numbers, and family connections for two decades, and opt-out requests have existed almost as long. What changed is speed and correlation. A human OSINT analyst needed real skill and real time to link a shell LLC to a home purchase or match a gym check-in to a commute pattern. AI-assisted scraping and entity resolution collapse that work, reading a data broker's page the way a person would and recognizing that a title next to a headshot means an executive, regardless of the underlying page structure.
Security chiefs are watching this show up as violence risk, not just brand embarrassment. A 2025 industry survey of corporate security leaders across dozens of countries, commissioned by Allied Universal and G4S, found that a large share had seen the threat of violence toward company executives rise over the prior two years, and most reported their organization had dealt with a disinformation or misinformation campaign in the year before. The FBI's Internet Crime Complaint Center has continued warning that swatting remains an active threat, one that draws an armed law enforcement response to a residence and carries real risk of injury or death. Reconnaissance for a deepfake fraud attempt and reconnaissance for a doxxing campaign draw on the same source material, earnings call audio, conference keynote video, a social post with a recognizable driveway in the background. One team builds a synthetic voice for a wire transfer request. Another builds a home address for a false emergency call. Most organizations still assign that intelligence-gathering surface to two teams, corporate security and IT security, that rarely compare notes.
What Changed in the Threat Model
Three things separate today's exposure from the doxxing threat model of five years ago.
Cost is the first. Building a target profile used to require paid investigator time or genuine analyst skill. AI-assisted OSINT tools push the marginal cost of a profile close to zero, which puts the capability in reach of low-skill harassers and swatting-for-hire operators, not just sophisticated adversaries.
Correlation across silos is the second. Data brokers each hold a fragment, one has the address, another has the phone number, a third has vehicle registration. AI entity resolution stitches these fragments into a single profile faster and more reliably than a human cross-referencing manually, which means an opt-out at one broker buys less protection than it used to when the same facts can be reassembled from three others.
Test this against your own principal before assuming the exposure is small. Take three public facts you would call harmless in isolation, a county property record, a vehicle registration, and a club or gym membership listing, then see how quickly they resolve to a home address and a daily pattern. That is the exercise an entity resolution tool runs in seconds, and it is worth doing before you decide the footprint is acceptable.
Synthetic content is the third. A dossier used to stop at facts, name, address, routine. It now extends to fabricated audio and video convincing enough to support impersonation, targeted harassment, or a false report designed to trigger an armed response at a real address. Reconnaissance and weaponization increasingly run through the same automated pipeline rather than two separate efforts.
The 2026 Regulatory Lever
For most of the last decade, defense against this meant filing opt-out requests one broker at a time and hoping the same information didn't reappear from a re-aggregated feed a few months later. That changed in 2026.
California's Delete Act created the Delete Request and Opt-Out Platform, DROP, run by the California Privacy Protection Agency. It opened to consumers on January 1, 2026, and registered data brokers doing business in California are required to check the platform on a recurring basis and process deletion requests submitted through it, rather than handling opt-outs broker by broker. California has also moved to raise the cost of noncompliance for brokers that fail to register or ignore deletion requests.
California is no longer the only state with teeth in this space.
| State | What brokers must do | Centralized deletion |
|---|---|---|
| California | Register with the CPPA, honor deletion requests through DROP | Live since January 2026 |
| Vermont | Register with the state | None, the statute has no deletion right |
| Texas | Register with the Secretary of State, honor individual deletion requests | None, deletion handled broker by broker |
| Oregon | Register with the state DOJ, honor individual deletion requests | None, deletion handled broker by broker |
| Connecticut | Expanding registration and deletion requirements under recent amendments | Centralized mechanism required in the coming years |
None of this is a single button that erases an executive from the internet. Registries are self-reported, some brokers under-comply, and a new address or a name change restarts the exposure clock. But a centralized, state-enforced deletion channel did not exist eighteen months ago, and it changes both what a footprint reduction program can promise and how the removal work gets scheduled.
What This Looks Like in Practice
A program built for this threat model starts with an exposure assessment that treats OSINT reconnaissance and physical risk as one exercise rather than two. That means mapping what an attacker could assemble today, home and family addresses across public records and broker sites, routine indicators like recurring event check-ins or geotagged posts, and any audio or video an attacker could pull for voice cloning or impersonation, before deciding what to remove first.
Removal then runs on two coordinated tracks. State opt-out platforms, DROP foremost among them, should be the default first move wherever a broker is registered and covered. The manual track still matters for brokers outside a state's reach, aggregators that resurface data under a new domain after removal, and public records no opt-out platform touches, court filings, property records, professional licensing sites.
Monitoring has to run continuously rather than as a one-time sweep, because deletion isn't permanent. A broker that honors a request today can rebuild the same profile from a new data source within months, so the removal cycle has to assume reappearance rather than treat removal as finished work. Family members belong in the same cycle from the start. A spouse's real estate listing or a teenager's public sports roster can hand over the exact address the executive already had removed.
Where Programs Get It Wrong
The most common mistake is treating this as a project with an end date. A footprint reduction engagement that runs once and stops loses value every month afterward, because new data sources launch constantly and old ones re-aggregate what was removed.
The second mistake is scoping the program to the executive alone rather than the household, for the reasons above. Attackers building a harassment or swatting package go after whoever is easiest to find.
Scope the program to the household, not the principal. A spouse's unprotected property record or a teenager's public roster listing gives up the same address, so a footprint reduction that covers one adult and stops has not reduced the address exposure at all. Anyone sharing the residence has to be in scope from the start.
The third is organizational. Threat intelligence teams commonly point to poor integration between tools, information overload, and a lack of contextual relevance as the top reasons exposure data doesn't turn into action. The whole value of a state opt-out platform is that it turns a slow manual process into something a security team can run on a predictable cycle. If nobody on the physical security side owns that cycle, and it stays parked with legal or privacy as a compliance checkbox, the regulatory opening gets wasted.
Where This Leaves Protection Programs
None of this replaces a protective detail or a hardened residence for the executives who need one. It replaces the assumption that digital exposure is a separate, lower-priority problem from physical safety. The two are worked by the same attacker with the same tools now, and the response has to be run by one team on one calendar. The regulatory mechanisms that arrived in 2026 make the removal side of that work faster and more durable than it has ever been. They don't make it optional.
Related Service
Learn more about how we can help with Executive Protection.
Explore Executive Protection Services →


