Originally published in Evan Kirstel’s “What’s up with Tech“

Targeted social engineering does not begin with a phish, a text, or a phone call.
It begins with reconnaissance.
Attackers need to know who works at a company, what they do, how they can be reached, who they work with, and what details will make an impersonation attempt feel believable. The more intelligence they have, the easier it becomes to choose and reach the right target, craft the right pretext, and make the interaction feel routine instead of suspicious.
Much of that intelligence is readily available through data broker sites, people-search sites, and business intelligence platforms. These sources expose phone numbers, email addresses, job titles, associate names, reporting relationships, and other personal and professional data that help attackers understand and reach their targets.
Federal guidance describes these sources in intelligence terms.
In the 2025 joint CISA/FBI/CNMF advisory on Scattered Spider, for instance, the authoring agencies noted that the group searches “business-to-business websites” to gather information and determine an individual’s role in a target organization. The same advisory also states that Scattered Spider’s social engineering attempts are enriched by personal information derived from sources including “commercial intelligence tools”.
The terms “business-to-business websites” and “commercial intelligence tools” both refer to data broker sites.
Attackers are using these commercially available data sources on the open web to support reconnaissance, targeting, and social engineering.
For legitimate users, many of these platforms serve sales, recruiting, marketing, or public-record lookup purposes. For attackers, they function as intelligence sources.
When employee and organizational information is easy to find across these sites, attackers gain an intelligence advantage. Organizations with significant data broker exposure provide numerous ways in for attackers. More exposed employees means more possible targets and avenues of compromise, more available contact channels, more impersonation options, and more ways to make a malicious interaction feel normal.
Security Leaders Are Treating Data Broker Exposure as a Social Engineering Risk
Optery’s 2026 Enterprise Social Engineering Survey Report shows that security leaders are recognizing and addressing data broker exposure to help prevent attacks.
In the survey of more than 400 cybersecurity leaders, respondents ranked data broker and people-search sites as the most significant source of attacker intelligence for social engineering, ahead of social platforms and breach data. Respondents also ranked reducing publicly exposed employee data as both the most widely used defense and the largest investment priority for social engineering defense.
If attackers are using data brokers as intelligence sources, the defensive move is to limit what they can learn.
This approach is a form of defensive counterintelligence.
Counterintelligence is about identifying and disrupting an adversary’s intelligence-gathering efforts. In the context of enterprise social engineering, that means reducing the employee and organizational data attackers can use to plan and launch attacks in the first place.
Removing employee personal information from data broker sites helps deny attackers easy access to the details they need for reconnaissance and targeting. It minimizes the exposed information required for phishing, smishing, vishing, credential compromise, account takeovers, doxxing, and other PII-driven threats.
For security teams, that means fewer attacks reaching employees and fewer incidents requiring investigation, containment, and response.
The survey data shows many organizations are already moving in this direction. More than three-quarters of respondents categorized reducing publicly exposed employee data as a core security initiative or supporting security measure. A strong majority also reported plans to expand personal data removal coverage in the next year.
This move toward broader coverage across the workforce has become a necessity, as attackers will target any employee who can provide them with the access they need.
Historically, many personal data removal programs have focused only on senior leaders, but targeting data from the survey shows executives have become only one important target set among several.
In the survey, IT and identity-focused roles were the most frequently reported targets, with 80.5% of organizations reporting targeting of IT/IAM personnel. HR followed at 44.7%, finance at 43.9%, executives at 42.3%, help desk at 33.0%, engineers at 22.8%, contractors at 17.8%, and sales at 9.3%.
That distribution shows why employee personal data removal has to scale beyond executive protection. If only the most visible leaders are protected, attackers will go around them.
Turning Counterintelligence Into Action
The need to reduce social engineering risk before attacks reach employees is urgent. Optery’s survey found that 96% of cybersecurity leaders report an increase in targeted social engineering attempts over the past year, 52.7% say the volume is creating increasing strain, becoming difficult to keep up with, or overwhelming existing defenses, and approximately three-quarters reported credential compromise from targeted social engineering in the last year.
Reducing that pressure requires minimizing the intelligence attackers rely on for social engineering.
Optery helps organizations put defensive counterintelligence into practice at a scale traditional data removal services cannot match. Its patented search technology and advanced opt-out automation help discover and remove dozens more exposed data broker profiles per person on average than competing services.
Optery is also the only service to provide screenshot-based Exposure and Removals Reports to prove its effectiveness. For security teams, leadership, insurers, and other stakeholders, Optery provides measurable visibility into organizational exposure reduction over time through its reporting and administrative dashboard.
Optery currently supports automated removals across 640+ data broker sites and more than 1,000 sites when Custom Removals requests are included, with coverage continuing to expand.
Organizations that want to see the results for themselves can start with a free 30-day trial of Optery for Business for a select group of high-risk employees.