Before the Phish: What Your Company Gives Away Online

Your company announces a new finance director. An employee shares a photo from the office. A job posting lists the tools your IT team uses.

These are ordinary parts of running a visible business. But someone preparing a social-engineering attack can read them too.

Before an attacker contacts an employee, they may already know whom that person reports to, which suppliers the company works with and what software they use. Those details can help turn a generic approach into something that sounds familiar.

The UK’s National Cyber Security Centre warns that criminals can use your digital footprint to make phishing messages more convincing. That footprint includes what you publish and what other people share about you. NCSC guidance

Small details can tell a bigger story

The risk is often in the combination of information.

Consider a hypothetical example. A public post identifies a new employee and their department. A recruitment advert names the company’s collaboration platform. A team page identifies their manager.

Someone could combine those details into a fake onboarding message: a request to finish setting up an account, apparently sent on the manager’s behalf. None of the individual posts contains a password. Together, they provide a believable introduction.

The same principle applies to workplace photos. The intended subject might be a team celebration, while the background contains a whiteboard, visitor badge or customer information on a screen.

A useful question before publishing is: what else does this reveal beyond the story we want to tell?

Review what an outsider can see

Start with a small review of your company website, public social profiles, recent recruitment adverts and downloadable documents. Involve marketing and HR alongside IT or security, because they understand why the information is there.

For each item, ask whether the detail serves a clear purpose:

  • Job adverts: Relevant technical skills help candidates assess a role. Internal system addresses, detailed configurations and access procedures usually serve a different purpose and deserve closer review.

  • Photos and screenshots: Check screens, whiteboards, badges and documents before publishing. Use demonstration data when showing a workflow.

  • Employee announcements: Celebrate appointments without unnecessarily describing sensitive approval responsibilities or access privileges.

  • Public documents: Check comments, tracked changes and document properties for internal information before release.

These are practical review points, not a reason to remove every employee name or technology reference. Decide what the audience needs and remove incidental detail that adds little value.

Give people something more useful than “don’t overshare”

Broad instructions leave employees guessing. Show them examples of what to check: a customer name visible in a screenshot, an internal URL in a tutorial, or a whiteboard behind a team photo.

Make it easy to ask for a quick review when someone is unsure. If an employee notices sensitive information after publishing, give them a clear contact who can help assess it and arrange removal. Deleting the original can reduce further exposure, although copies may already exist.

Apply the same care to company-owned channels. Employees should not carry the entire responsibility for information published by the organisation.

Familiar details are still not proof

Some information will remain public because customers, candidates and partners need it. That makes independent verification essential for sensitive requests.

Someone knowing your manager’s name or your supplier’s identity does not establish their authority to request a payment, account change or confidential file. The FBI recommends verifying payment requests using a previously known phone number rather than one supplied in the message. FBI guidance

Public-information reviews and verification serve different purposes. One reduces the material available to build a convincing story. The other helps employees handle that story when it reaches them.

Your company needs a public presence. Give people enough information to understand your business, while being deliberate about the details that reveal how it operates behind the scenes.

This article is part of the CTRL+ALT+DEFEND content series for Cybersecurity Awareness Month 2026, produced by ManageEngine Endpoint Central.

Sources

  1. NCSC: Social Media — How to Use It Safely

  2. FBI: Business E-Mail Compromise