
Mistakes companies make with their digital exposure
Anonymized real cases of companies that discovered too late what information was circulating about them. Practical lessons for executives.
The executive who appeared on the dark web
A medium-sized tech company hired our services after their CEO received extortion emails citing detailed personal information: previous residence addresses, family members' names, private phone numbers.
The audit revealed that a former HR service provider had suffered a data breach two years earlier. The executive team's personal data had been circulating in cybercriminal forums ever since. The company was never notified, and they never thought to check.
Internal documents on Google
A law firm discovered during an audit that several internal documents—including contract drafts and client emails—appeared indexed in search engines.
The cause: an employee had shared documents through 'public' Google Drive links, thinking 'if you don't share the link, no one finds it.' Search engines think differently. Some documents had been publicly accessible for over a year.
The org chart that shouldn't have existed
A family business was preparing a confidential sale. During the buyer's due diligence process, a detailed company org chart appeared with names, positions, and even estimated salaries.
The source: a LinkedIn profile of a former employee who had uploaded the org chart as a 'work sample' in their portfolio. They never thought anyone would use it for anything else. The buyers used that information to negotiate down, citing 'excessive personnel costs.'
The photo that revealed the location
The founder of a fintech startup regularly posted on social media to build a personal brand. One of their photos included EXIF metadata with exact GPS coordinates of their home.
This information was used in a social engineering attempt against the company, with attackers calling the company pretending to be neighbors of the founder who needed to 'verify urgent information.'
Credentials that never expired
A routine audit revealed that corporate email credentials for three employees appeared in public breach databases. All three had reused passwords between personal and professional services.
When we verified, two of the three accounts were still active with the same passwords. Any attacker with access to those public databases could have accessed corporate email.
Common lessons
These cases share repetitive patterns: excessive trust in 'obscurity' as protection, lack of monitoring of the corporate digital footprint, unawareness of what information about the company circulates publicly.
OSINT audit is not paranoia. It's knowing your real exposure before someone uses it against you. Attackers already have access to these tools. The difference is whether you also know what they see.
Frequently asked questions
Related articles
Are you making corporate decisions without all the information?
Request a confidential strategic evaluation. We analyze your specific situation and indicate whether we can help — and how.
Response within 24-48 hours. Confidentiality guaranteed.