Originally published in Evan Kirstel’s “What’s up with Tech“

Historically, personal data removal has often been treated as a protection measure for executives only.
CEOs, board members, founders, and other highly visible leaders are obvious targets for both cyber and physical threats. When their personal information is exposed on data broker sites, attackers can use it to find where they live, reach them through personal and professional channels, impersonate them, launch spear-phishing attacks, take over their accounts, or target their families.
But today’s attackers do not primarily target executives.
They target any employees who can help them get the access they want. And they use social engineering tactics that rely on exposed personal and professional data to do it.
Optery’s 2026 Enterprise Social Engineering Survey Report shows how broad the target set has become. In the survey of more than 400 cybersecurity leaders, IT and identity-focused roles were the most frequently reported targets, with 80.5% of organizations reporting targeting of IT/IAM personnel. HR followed at 44.7%, finance at 43.9%, executives at 42.3%, help desk at 33.0%, engineers at 22.8%, contractors at 17.8%, and sales at 9.3%.
Executives remain a target set. But they ranked fourth.
This reality has changed how organizations think about employee exposure and is fueling the move to broaden personal data removal coverage across the workforce in order to reduce social engineering risk.
An IT or IAM employee can reset credentials, approve access, or support account recovery. A help desk worker can validate an identity or change an authentication workflow. A finance employee can process a payment request. An HR employee has access to sensitive employee data. An engineer may have access to systems or code. A contractor may have enough access to become a useful foothold. These roles need protection from targeted attacks and doing so requires personal data removal.
Attackers need exposed data about the employees they are targeting in order to identify and reach them, while the personal and professional data of another employee is often used in impersonation schemes against those targets. At the same time, employees who are frequently targeted for their access can also be impersonated in attacks against others, such as when an attacker poses as someone from IT to pressure an employee into approving access.
In any case, targeted social engineering starts with personal and professional data that is easy to find.
That data is not limited to public LinkedIn profiles or company staff pages. Data broker sites, people-search sites, and business intelligence platforms expose phone numbers, email addresses, job titles, associate names, reporting relationships, and other personal and professional data attackers can use to understand, reach, manipulate, and impersonate employees.
The result is a much broader social engineering attack surface than executive-only programs can address.
The Pressure Is Rising
The need to proactively reduce the exposed data attackers use for social engineering is urgent.
Optery’s survey found that 96% of cybersecurity leaders report an increase in targeted social engineering attempts over the past year. More than half, 52.7%, say the volume is creating increasing strain, becoming difficult to keep up with, or overwhelming existing defenses. Approximately three-quarters reported credential compromise resulting from targeted social engineering in the last year.
As more roles are targeted and attack volume increases, attackers are also reaching employees across multiple channels. Survey respondents reported confirmed incidents across social media, voice and phone, company website and domain impersonation, email, and SMS/text. No single channel dominated. Social media incidents were reported by 56.3% of respondents, voice and phone by 55.3%, company website or domain impersonation by 52.0%, email by 50.8%, and SMS/text by 41.1%.
Defensive confidence is also uneven. Email defenses were rated strong by 53.0% of respondents, compared with 50.4% for voice and phone impersonation, 49.6% for brand and domain impersonation, 44.2% for SMS/text, and 36.3% for social media impersonation.
The combination of multiple channels and broad employee data exposure gives attackers many options.
If one channel is well defended, attackers can try another. If one employee is difficult to reach, they can target someone else who offers another path into the organization.
Personal Data Removal Has to Follow the Risk
Personal data removal should be aligned with how attackers actually target organizations, and Optery’s survey data shows organizations are already moving beyond executive-only coverage.
Data broker and people-search sites ranked as the top source of attacker intelligence for targeted social engineering, and a strong majority, 85.3%, agree that reducing exposed employee data lowers social engineering risk. Reducing publicly exposed employee data also ranked ahead of every other social engineering defense as both the most widely used defense and the largest investment priority.
These findings are significant, especially since employee data removal is largely absent from major threat intelligence and breach-report recommendations, even as cybersecurity leaders on the frontlines are prioritizing it as a way to prevent attacks and reduce attack volume across channels.
64.6% say reducing publicly exposed employee data is already included in their 2026 budget, while another 34.0% say it is under consideration.
More than half of respondents, 53.9%, report having an org-wide program to reduce exposed employee data, with another 38.7% reporting programs focused on specific roles. Yet only 14.0% say personal data removal efforts currently cover the full workforce.
Together, the findings show that organizations have recognized the risk and started building programs, but many are still in the early stages of scaling coverage. They are prioritizing employees most likely to be targeted or exploited first, then expanding from there.
Expansion is already underway. 82.2% of survey respondents said they plan to expand personal data removal coverage in the next 12 months, with another 6.9% saying expansion is under consideration.
These organizations understand that if attackers are targeting the broader workforce, personal data removal has to follow the risk.
Putting Workforce Data Removal Into Practice
For organizations moving beyond executive-only protection, Optery for Business helps reduce data broker exposure across high-risk employees and the broader workforce at a scale traditional data removal services cannot match.
Its patented search technology and advanced opt-out automation help discover and remove dozens more exposed data broker profiles per person on average than competing services.
Optery is also the only service to provide screenshot-based Exposure and Removals Reports to prove its effectiveness. For security teams, leadership, insurers, and other stakeholders, Optery provides measurable visibility into organizational exposure reduction over time through its reporting and administrative dashboard.
Optery was recently named the best overall data removal service of 2026 by CNET because it had the highest removal success rate according to third-party testing and is “better than any other service” at showing users the work it does to remove personal data.
CNET’s recognition adds to a growing list of third-party validation for Optery’s product leadership. Optery has been named PCMag Editors’ Choice for personal data removal every year from 2022 through 2026, and has received major cybersecurity and technology honors from Cyber Defense Magazine, the Cybersecurity Excellence Awards, the Globee® Awards, SiliconANGLE, Fortress Cybersecurity Awards, Fast Company, and Evan Kirstel’s We Love Tech Awards.
Optery currently supports automated removals across 640+ data broker sites and more than 1,000 sites when Custom Removal requests are included, with coverage continuing to expand.
Organizations that want to see the results for themselves can start with a free 30-day trial of Optery for Business for a select group of high-risk employees.