What Attackers Can Learn About Your Small Business Before They Ever Contact You
A phishing email, impersonation scam, or fraudulent payment request does not need to begin with a sophisticated technical breach. In many cases, an attacker can learn a surprising amount about a small business using information that is already publicly available. That information can help an attacker determine who to target, how to approach them, and what kind of message is most likely to appear legitimate. For small businesses, understanding that public exposure is an important part of reducing risk.
Attackers Start With Information
A typical small business publishes a lot of information online. A company website may identify the owner, leadership team, employees, office location, phone number, email addresses, clients, vendors, and services. LinkedIn may reveal job responsibilities and reporting relationships. Social media may reveal travel, conferences, employee schedules, family members, or frequently visited locations. Public records and people-search services may connect a business owner to a home address, personal phone number, relatives, previous addresses, and other identifying information. This information is all publicly available and easily accessible.
Why Public Information Matters
When combined, public information can reveal much more than a small business owner may realize. An attacker could learn important things such as:
Who approves payments
Who manages payroll
Which vendors the company uses
When the owner is traveling
How employee email addresses are formatted
Who reports to whom
Which financial or technology platforms the company uses
The owner’s personal contact information
Personal interests and habits
That context can dramatically improve an attacker’s ability to create a believable pretext. Instead of sending a generic phishing message, the attacker can send something that appears specifically relevant to the business.
Real-World Example: Vendor and Payment Impersonation
The FBI documented a case in 2020 in which criminals spent significant time researching victim companies, including identifying key employees and gathering contact information. They also utilized phishing to gain access to company email systems, which gave them additional insight into the organizations and their business relationships. Armed with that information, the fraudsters contacted the companies while pretending to be a legitimate vendor and instructed them to change the bank account information for upcoming payments. The companies ultimately sent more than $120 million to fraudulent accounts.
This type of fraud shows why seemingly ordinary business information can matter. Publicly identifying employees, vendors, roles, business relationships, and contact information can provide part of the context an attacker needs to build a believable pretext. The FBI specifically advises businesses to be cautious about posting financial and personnel information publicly and to independently verify changes to vendor payment instructions.
Real-World Example: Executive Impersonation
In a documented 2019 case, the managing director of a UK energy company received what appeared to be a phone call from the CEO of the company’s German parent organization. The caller’s voice reportedly matched the executive’s accent and speech patterns closely enough that the request seemed legitimate. The managing director was told to urgently transfer €220,000 — roughly $243,000 — to a supplier account in Hungary, and he authorized the payment. Investigators and the company’s insurer later concluded that AI-based voice-mimicking technology had likely been used to impersonate the executive.
The case is a useful reminder that impersonation is no longer limited to suspicious emails. An attacker who knows who reports to whom, who has payment authority, how executives communicate, and what kinds of urgent requests would seem plausible can build a much more convincing social-engineering attack. Publicly available information about leadership roles, travel, business relationships, and employee responsibilities can provide part of that context.
Personal and Business Exposure Often Overlap
For many small businesses, the owner and the company are closely connected, which makes personal information relevant to business security. Public records, data brokers, social media, and business directories may make it possible to connect:
The owner’s personal and business email addresses
A home address
Personal phone numbers
Family members
Business ownership
Professional affiliations
Travel or location patterns
This does not mean every piece of personal information must disappear from the internet. It does mean business owners should understand what is visible and whether that information creates unnecessary risk.
What Small Businesses Can Do
The goal is not to become invisible but to reduce unnecessary exposure and make attacks harder to execute. A few practical steps regarding online exposure include:
Review what is public and what someone could learn about how your business operates, your business life, and your personal life.
Reduce unnecessary exposure: Remove personal phone number, home addresses, personal and specific business email addresses, family information, and further details about your day to day. Additionally, review who is included on public business websites and listings.
Review Social Media and do not post travel information, real-time location information, employee schedules, internal processes, and business relationships.
Have an internal, not public, process for verifying high-risk requests, specifically involving money, credentials, account access, and sensitive information.
Becoming a Harder Target
While it is impractical to eliminate all public information about your business and your self, the goal is visible, reduce unnecessary exposure, strengthen verification procedures, and make it harder for an attacker to turn public information into a successful attack.
That is the purpose of Du-Zel Consulting’s Small Business Digital Exposure Protection Program. We review your digital snapshot for you, help you understand your main risks and recommended actions. We then provide continued support throughout the year with quarterly exposure reviews, threat intelligence, and practical security resources designed specifically for small businesses.
You can learn more about the program here: https://www.du-zel.com/small-business-digital-exposure-protection-program