This article discusses what doxxing is, what examples of doxxing exist, and how we can protect ourselves and our businesses from being ‘doxxed’.
What Is Doxxing?
Doxing is a hacker term from the 1990s that refers to dropping (personal) dox, whereas dox is slang for documents. Doxxing is a malicious act in which personnel use various methods to discover private personal information about an individual or organization and then publicly reveal/expose that information to the general public, usually over the Internet. It could be anything from personal details to more sensitive, embarrassing, and destructive material released.
Why?
Doxxing is used as a method of attack, primarily for punishment or revenge and can lead to extortion.
What Details?
Personal details and information that doxxers may collect about a person, business, or organization may include name, telephone number, address, personal photographs, videos, comments and quotes, email content, account numbers, and more.
Where From?
Doxxers can gather various bits of information about their victim from multiple sources.
Hacks, social engineering, social media accounts, gaining access to a target’s email account, WHOIS lookups, using an I.P. logger to track online activities, reverse mobile phone lookup, tracking usernames, using GDPR subject access requests, collecting information that has been sold across the Web by data brokers, accessing details from hacks/sold hacked pieces, and more are all covered.
Is It Illegal?
Doxxing is often not prohibited, although it is malicious and can be highly detrimental. The majority of the data was taken from the public domain. Doxxing walks a tight line between what is legal and what isn’t, occasionally crossing into the unlawful realms of stalking, harassment, and other forms of harassment. The use of the threat of doxxing to obtain money is, of course, blackmail. Doxxing frequently violates the terms of service of numerous websites, at the very least.
Some Examples of Doxing
Just some of the many examples of doxing that have made the news include:
- December 2011 – the hacking group Anonymous exposed detailed information online about 7,000 law enforcement agents as revenge for investigations into hacking activities.
- In 2013, hackers posted Kim Kardashian’s Social Security number, credit report, address (+ six previous addresses) online.
- In 2016, while Donald Trump was campaigning for the U.S. presidency, Anonymous posted his Social Security number and phone number and the contact information for his agent and lawyer online.
- In 2017, the Russian (Moscow) hacker group Turla hacked the Instagram account of Britney Spears. It used it to post secret, cryptic comments.
How To Protect Yourself and Your Business From Being Doxxed
Some of the measures you can take to help protect yourself/your business from falling victim to doxxing include:
- By using a VPN to protect your I.P. address.
- Using strong passwords, avoiding password sharing, and using 2FA or multi-factor authentication where possible.
- Setting up different email addresses for various uses, e.g., professional, personal, and spam. MaximizingMaximizing your social media privacy settings and being careful what is shared. So bearing in mind GDPR, consent, personal details and privacy matters when sharing anything relating to staff.
- Hiding domain registration information from WHOIS.
- Avoiding logging into a website through Facebook or Google
- Remove any personal information that you are concerned about.
- Keeping up with good general online security practices and be careful what information you share via social media.
- Deleting old online accounts.
- Using the legislation available to tackle doxxers. Hong Kong introduced a new anti-doxing law in October 2021 (The Personal Data (Privacy) (Amendment) Ordinance 2021). This was mainly to prevent details of members of the authorities from being posted online and, perhaps, to crack down on criticism. However, the law could be used by citizens and businesses to combat malicious doxxing acts. The law amendment gives Hong Kong’s Privacy Commissioner for Personal Data the right to conduct criminal investigations and institute prosecution related to doxxing. Also, under UK GDPR, persons have the ‘right to be forgotten, i.e., requesting that a business/organization removes/deletes all data collected about them.
- For businesses – keeping an up-to-date record of processing activities. Showing what data is being collected, where it’s stored, how long, and who is being/has been shared with.
- Keeping levels of awareness and training about data protection, privacy, and threats like doxxing up to date among staff.
- Checking/monitoring compliance relating to contracts with third parties processing personal data on your/the company’s behalf.
- Using websites to help erase data about you stored around the Web / opting out of people searches. Examples (including the U.S.) include https://www.beenverified.com/app/optout/search, https://www.instantcheckmate.com/opt-out/, https://www.gov.uk/government/publications/register-to-vote-anonymously, opting out of the top 10 data brokers – https://databrokerswatch.org/top-ten, https://joindeleteme.com/.
What does this mean for your business?
The main motives for doxxing appears to be revenge, control, or even to blackmail someone. Good online security practices are the best way to avoid giving people the fuel and the openings they need to build their campaigns. Sadly, much of our data ends up being shared around the Web. Perhaps to places we wouldn’t expect to go, and determined doxxers may be able to find some things, despite our best efforts to maintain our privacy. That said, as highlighted in the list above, many proactive measures can be taken to reduce the risk of being doxed.