publicly shared information: what businesses should know
publicly shared information is an important part of keeping business technology practical, secure and reliable. This article explains the issue in plain language, with related context on account compromise and useful external guidance on password guidance.
Social engineering does not always start with a dodgy email.
Sometimes it starts with something much more boring.
A Facebook complaint. A LinkedIn update. A photo from the office. A public comment about being away. A joke post where people share personal details because everyone else is doing it.
Most of it looks harmless. Sometimes it is harmless.
But criminals do not need your full life story. They just need enough to make the next call, message, or email sound like it belongs in your day.
That is where people get caught.
Scammers do their homework
Not every scam looks like a badly written email from a fake prince with a suitcase full of money. Those still exist, somehow, because the internet remains deeply committed to disappointing us.
The nastier scams are quieter.
A scammer may already know your name, job title, company, bank, internet provider, courier company, or the software your business uses. They may know you complained about a service issue. They may know who handles accounts.
So when they contact you, it feels familiar.
That is the hook.
If they know your fibre provider, they can pretend to be from support. If they know your bank, they can pretend to be from fraud prevention. If they know your company uses Microsoft 365, they can pretend there is a security update.
No hacking montage required. Just public information, patience, and someone distracted on the other end.
The internet remembers more than you do
There is also the uncomfortable world of data brokers and contact intelligence platforms.
These are not secret criminal tools. Many are normal services used for sales, recruitment, marketing, and business research.
A free service such as RocketReach can already show how much may be available about a person or company. Job titles. Employers. LinkedIn profiles. Work history. Professional email addresses. Phone numbers. Locations. Related contacts.
That does not make RocketReach evil.
It does show how much information can be pulled together without breaking into anything.
And that is the bit people underestimate.
The same details that help a salesperson find the right person can help a scammer target the right person.
The harmless posts that are not always harmless
The risky posts are not always obvious. They usually do not ask for your password or banking details. If they did, we would hope most people would at least blink before walking into the trap.
Someone complains that their fibre is down and names the provider. Now a scammer knows they are frustrated and waiting for help.
Someone complains that their bank blocked a card again. Now a fake fraud-prevention call has a useful opening.
Someone asks whether anyone else is having issues with Sage, Xero, Microsoft 365, Teams, OneDrive, or a courier platform. Now attackers know what systems that person or business uses.
Someone shares a work photo, and a screen, access card, invoice, courier label, whiteboard, or internal system is visible in the background. Nobody meant to reveal anything. It still happened.
Then there are the funny joke groups.
The posts that casually ask for the name of your first pet as a nostalgic callback. Or the ones that get people talking about where they grew up, what school they went to, their first car, or old childhood memories.
Not every post like that is part of a criminal master plan. Some of it is just brainless engagement bait.
But the answers can still be useful.
The danger is not always the one post. It is the profile slowly being built around you.
The phone call is where it often lands
Phone calls are nasty because people still trust a confident voice.
A caller may sound professional. They may use the right company name. They may mention a service you use.
Then they ask for something small.
“I just need to confirm your ID number.”
“Can you confirm your email address?”
“We sent you a code. Please read it back to me.”
“Please approve the notification on your phone.”
“Can you install this remote support tool?”
That is where the wheels come off.
If someone calls you unexpectedly, they do not get to prove who they are by asking for your private information.
That is backwards.
They called you. You did not call them.
Slow it down. Ask for a reference number. End the call. Then contact the organisation using a trusted number from the official website, banking app, invoice, or known contact list.
Do not use the number the caller gives you. Do not click links they send while you are on the call. Do not install remote access software because a stranger told you to. Do not approve an MFA prompt unless you started the login.
If they become pushy, become more suspicious, not more cooperative.
This is a business problem too
Oversharing online is not only a personal privacy issue. It can expose the business.
A staff member may reveal which software the company uses. A manager may post travel plans. A team photo may show client information or internal tools. A public complaint may reveal a supplier, bank, courier, or service provider.
That is enough to help an attacker sound convincing.
It is how fake supplier changes happen. It is how payment fraud happens. It is how people get tricked into sharing passwords, approving sign-ins, opening links, or installing remote access tools.
The answer is not to panic and delete the internet.
Tempting, but no.
The answer is awareness and process.
Staff should know not to share MFA codes, approve sign-ins they did not start, confirm private information to unsolicited callers, process banking changes from email alone, or install remote access tools unless the request has been verified.
Real names and accurate company details do not make a request legitimate.
Verify unusual requests through a separate trusted channel.
Report suspicious calls, emails, and messages, even if nothing happened. That matters, because the next person may not be as lucky.
Healthy suspicion is not paranoia
Social engineering works because it targets normal behaviour.
Helpfulness. Trust. Frustration. Curiosity. Urgency. Routine.
A good scam does not always look like a scam. Sometimes it looks like a bank call, courier update, support request, supplier message, Facebook conversation, or quick favour from someone who seems to know your business.
Slow down.
Verify independently.
Share less than you need to.
Attackers do not need to know everything about you.
They only need to know enough to make you trust them for the next 30 seconds.
If your business needs help improving staff awareness, reviewing exposed information, or tightening everyday security habits, contact UIT and let’s help you reduce the risk before someone tries their luck.



0 Comments