Skip to content

How Exposed Personal Data Puts Civilian Government Personnel and Operations at Risk

Feature image

Personal information about civilian government personnel is widely available through data brokers and people-search sites. Available profiles can include home addresses, personal phone numbers and email addresses, relatives, and other details that make government employees and their families easier to identify, contact, impersonate, or target with cyber and physical threats.

For judges, prosecutors, elected officials, law enforcement officers, election personnel, investigators, regulators, and other public-facing employees, this exposure can support doxxing, harassment, swatting, intimidation, and physical targeting. For IT, identity, help-desk, and systems personnel, it can support phishing, impersonation, and fraudulent account-recovery attempts that lead to account compromise. 

The risk spans civilian federal agencies and state and local government. Recent incidents involving courts and public officials demonstrate the physical consequences of exposed personal information, while threat intelligence and government advisories show how commercially available data can also support cyberattacks and fraud.

Threats against judges and court personnel remain persistent

Judges and court staff face persistent harassment, intimidation, and threats against themselves and their families.

A 2022 report from the Administrative Office of the U.S. Courts states that threats and inappropriate communications involving federal judges and other court personnel increased from 926 incidents in 2015 to 4,511 in 2021. The U.S. Marshals Service reported 807 threats and inappropriate communications against protected persons during fiscal year 2025.

These incidents frequently extend beyond the official who made a decision. U.S. District Judge Reggie Walton described receiving threats from a caller who knew his daughter’s name and his home address. Colorado Supreme Court justices experienced doxxing, threatening communications, unwanted deliveries, and multiple swatting incidents after a politically charged decision. In one incident, nine armed SWAT officers entered a justice’s home in response to a false emergency report. Reuters documented the incidents and their effects on the justices and their families.

The FBI states that perpetrators of swatting attacks compile sensitive information from publicly available sources to build invasive profiles of their targets. Its guidance specifically recommends reviewing online exposure and considering services that reduce or remove sensitive publicly available information. FBI swatting guidance

Online information has enabled deadly targeting

The 2020 attack at the home of U.S. District Judge Esther Salas demonstrated how online personal information can enable physical violence.

According to the Administrative Office of the U.S. Courts, the assailant acquired Judge Salas’s home address, photographs of her residence, and information about her vehicle online. He went to the family’s home posing as a delivery driver, fatally shot Judge Salas’s son, Daniel Anderl, and seriously wounded her husband.

New Jersey subsequently enacted Daniel’s Law, which restricts disclosure of the home addresses and unpublished telephone numbers of active and retired judges, prosecutors, law enforcement officers, and their immediate family members. The state’s Office of Information Privacy administers the process through which covered individuals can request redaction from certain government records and internet postings. New Jersey Office of Information Privacy

Congress later enacted the Daniel Anderl Judicial Security and Privacy Act, which applies to active, senior, recalled, and retired federal judges and their immediate families. The law restricts certain publication and commercial use of covered personal information and enables federal judges to seek its removal from online data brokers. 

These laws recognize that protecting officials at work is insufficient when their home addresses, family relationships, and personal contact information remain easily accessible online.

People-search sites were reportedly used to locate public officials in Minnesota

The risk extends beyond the judiciary.

Following the June 2025 shootings of Minnesota Representative Melissa Hortman and her husband, Mark Hortman, and State Senator John Hoffman and his wife, Yvette Hoffman, investigators recovered notebooks containing information about public officials.

According to reporting on an FBI affidavit, the notebooks listed more than 45 Minnesota state and federal public officials. Representative Hortman’s home address was written next to her name, and another notebook listed 11 mainstream people-search platforms for finding home addresses, phone numbers, relatives, and other personal information.

The evidence provides a documented example of people-search platforms appearing in targeting research for attacks against civilian public officials.

The risk extends across the civilian-government workforce

Judges and elected officials are highly visible targets, but civilian-government exposure is much broader.

Law enforcement officers, prosecutors, election workers, investigators, inspectors, regulators, social-services personnel, public-health employees, code-enforcement officials, and other frontline workers may face hostility because of the duties they perform. Exposed addresses, family connections, and personal contact details can give threatening individuals a direct path from an employee’s public role to the employee’s private life.

Attackers pursuing agency systems or processes may seek different targets. IT and identity personnel can provide access to accounts and infrastructure. Help-desk employees may be targeted through fraudulent password-reset or account-recovery requests. Finance, payroll, and procurement employees can be impersonated or manipulated into changing payments. 

Personnel do not have to be senior officials to be valuable targets. Access, authority, institutional knowledge, trusted relationships, and public-facing responsibilities can all make an employee useful to a malicious actor.

Data brokers and people-search sites expose phone numbers, email addresses, home addresses, relatives, associates, and other information malicious actors need for cyber and physical targeting. Removing that information is necessary in order to help prevent targeted attacks.

Civilian government also faces cyberattacks and impersonation

Courts and other public institutions depend on digital systems to maintain records, communicate with the public, process payments, and deliver essential services.

In August 2025, the Federal Judiciary announced additional security measures in response to escalated cyberattacks of a sophisticated and persistent nature against its case-management system.

State and local courts have also experienced disruptive cyber incidents. The National Center for State Courts reports that the percentage of courts experiencing disruptive cyber incidents increased from 18% to 33% over four years. It identified recent incidents affecting courts in Colorado, Florida, Georgia, Mississippi, Missouri, Ohio, and Pennsylvania.

These incidents demonstrate the operational consequences of cyberattacks on public institutions. Separate threat intelligence establishes how data brokers and related commercial services can support the reconnaissance and social engineering that precede targeted cyberattacks.

Leaked communications, incident investigations, and government advisories have documented threat actors using commercial data sources to identify employees, map organizations, obtain personal contact information, and prepare targeted social engineering campaigns. The examples include Conti, Black Basta, 0ktapus, and Scattered Spider. Optery’s analysis brings these documented cases together.

The NATO Strategic Communications Centre of Excellence also cited a case involving compromised authorized customer accounts at U.S. data broker Interactive Data LLC. As Optery’s analysis of documented data broker misuse explains, fraudsters used information accessed through those accounts to impersonate people and businesses and file fraudulent Small Business Administration loan and state unemployment-insurance claims. A source monitoring the group estimated that it had stolen tens of millions of dollars from U.S. state and federal treasuries. The Interactive Data LLC case provides a documented example of personal information obtained through compromised data-broker accounts being used to facilitate impersonation fraud against federal and state government programs. 

Government identities are themselves valuable to attackers. In December 2025, the FBI reported that malicious actors had impersonated senior state-government, White House, Cabinet-level, and congressional officials through text messages and AI-generated voice messages. The actors targeted officials’ family members and personal acquaintances and sought authentication codes, personal documents, funds, and introductions to other contacts. The campaign demonstrates how attackers exploit the authority and relationships associated with a government identity, using an official’s personal network as additional routes to pursue access, information, and money. 

Federal and state governments have begun addressing the risks created by commercial personal data.

Judicial privacy laws provide important protections for certain judges, prosecutors, law enforcement officers, and their families. The scope and availability of these protections vary by jurisdiction and occupation, leaving many public employees without equivalent coverage.

The Department of Justice’s Data Security Program, effective April 8, 2025, prohibits or restricts defined transactions that could give countries of concern and covered persons access to U.S. Government-related data and Americans’ bulk sensitive personal data.

The program is an important national-security measure, but its scope is defined by particular transactions, data categories, countries, and covered persons. Publicly accessible people-search profiles remain available to domestic malicious actors, and commercially held information may also be obtained through account compromise or cyber intrusion.

The risk therefore extends beyond a purchase made directly by a known foreign entity. It includes domestic harassment, stalking, impersonation, fraud, and cybercrime, as well as illicit data resale and cyber intrusions targeting brokers that aggregate personal information at scale. 

Reducing the personal-data attack surface

Removing exposed profiles helps disrupt attacker reconnaissance by limiting the information malicious actors can gather about civilian-government personnel and their families.

This exposure-reduction work complements identity controls, security awareness, fraud prevention, threat monitoring, physical protection, and incident response. It addresses an earlier stage of the attack process by making personnel more difficult to locate, profile, contact, and target or impersonate.

Optery for Business provides:

  • Patented search technology that finds an average of 40–50 exposed profiles per person that other services miss
  • Automated removals across more than 640 data-broker sites
  • Coverage of more than 1,000 sites when Custom Removals are included
  • Before-and-after screenshots documenting completed removals
  • Recurring monthly scans and removals for new and repopulated profiles
  • Centralized reporting and administration
  • Bulk CSV enrollment and self-service deployment
  • SSO and SCIM integration
  • Flexible, role-based pricing
  • SOC 2 Type II attestation

Civilian-government organizations already using another removal provider can run a free Optery scan to identify profiles that remain exposed before deciding whether to switch. Book a demo or contact the Optery team at Carahsoft to begin a free 30-day trial for a select group of high-risk personnel. 

Ready to Remove Your Info from the Internet?

Free Tools + Paid Plans starting at $3.99/mo. 950+ Sites covered (Automated + Custom Removals). 30-Day Money Back Guarantee!

Get Free Scan

Ready to safeguard your employees’ data?

See why Optery is the leader in enterprise-grade personal data removal.
Request a Demo