What Attackers Can Learn About Your Small Business Before They Ever Contact You

A phishing email, impersonation scam, or fraudulent payment request does not need to begin with a sophisticated technical breach. In many cases, an attacker can learn a surprising amount about a small business using information that is already publicly available. That information can help an attacker determine who to target, how to approach them, and what kind of message is most likely to appear legitimate. For small businesses, understanding that public exposure is an important part of reducing risk.

Attackers Start With Information

A typical small business publishes a lot of information online. A company website may identify the owner, leadership team, employees, office location, phone number, email addresses, clients, vendors, and services. LinkedIn may reveal job responsibilities and reporting relationships. Social media may reveal travel, conferences, employee schedules, family members, or frequently visited locations. Public records and people-search services may connect a business owner to a home address, personal phone number, relatives, previous addresses, and other identifying information. This information is all publicly available and easily accessible.

Why Public Information Matters

When combined, public information can reveal much more than a small business owner may realize. An attacker could learn important things such as:

  • Who approves payments

  • Who manages payroll

  • Which vendors the company uses

  • When the owner is traveling

  • How employee email addresses are formatted

  • Who reports to whom

  • Which financial or technology platforms the company uses

  • The owner’s personal contact information

  • Personal interests and habits

That context can dramatically improve an attacker’s ability to create a believable pretext. Instead of sending a generic phishing message, the attacker can send something that appears specifically relevant to the business.

Real-World Example: Vendor and Payment Impersonation

The FBI documented a case in 2020 in which criminals spent significant time researching victim companies, including identifying key employees and gathering contact information. They also utilized phishing to gain access to company email systems, which gave them additional insight into the organizations and their business relationships. Armed with that information, the fraudsters contacted the companies while pretending to be a legitimate vendor and instructed them to change the bank account information for upcoming payments. The companies ultimately sent more than $120 million to fraudulent accounts.

This type of fraud shows why seemingly ordinary business information can matter. Publicly identifying employees, vendors, roles, business relationships, and contact information can provide part of the context an attacker needs to build a believable pretext. The FBI specifically advises businesses to be cautious about posting financial and personnel information publicly and to independently verify changes to vendor payment instructions.

Real-World Example: Executive Impersonation

In a documented 2019 case, the managing director of a UK energy company received what appeared to be a phone call from the CEO of the company’s German parent organization. The caller’s voice reportedly matched the executive’s accent and speech patterns closely enough that the request seemed legitimate. The managing director was told to urgently transfer €220,000 — roughly $243,000 — to a supplier account in Hungary, and he authorized the payment. Investigators and the company’s insurer later concluded that AI-based voice-mimicking technology had likely been used to impersonate the executive.

The case is a useful reminder that impersonation is no longer limited to suspicious emails. An attacker who knows who reports to whom, who has payment authority, how executives communicate, and what kinds of urgent requests would seem plausible can build a much more convincing social-engineering attack. Publicly available information about leadership roles, travel, business relationships, and employee responsibilities can provide part of that context.

Personal and Business Exposure Often Overlap

For many small businesses, the owner and the company are closely connected, which makes personal information relevant to business security. Public records, data brokers, social media, and business directories may make it possible to connect:

  • The owner’s personal and business email addresses

  • A home address

  • Personal phone numbers

  • Family members

  • Business ownership

  • Professional affiliations

  • Travel or location patterns

This does not mean every piece of personal information must disappear from the internet. It does mean business owners should understand what is visible and whether that information creates unnecessary risk.

What Small Businesses Can Do

The goal is not to become invisible but to reduce unnecessary exposure and make attacks harder to execute. A few practical steps regarding online exposure include:

  1. Review what is public and what someone could learn about how your business operates, your business life, and your personal life.

  2. Reduce unnecessary exposure: Remove personal phone number, home addresses, personal and specific business email addresses, family information, and further details about your day to day. Additionally, review who is included on public business websites and listings.

  3. Review Social Media and do not post travel information, real-time location information, employee schedules, internal processes, and business relationships.

  4. Have an internal, not public, process for verifying high-risk requests, specifically involving money, credentials, account access, and sensitive information.

Becoming a Harder Target

While it is impractical to eliminate all public information about your business and your self, the goal is visible, reduce unnecessary exposure, strengthen verification procedures, and make it harder for an attacker to turn public information into a successful attack.

That is the purpose of Du-Zel Consulting’s Small Business Digital Exposure Protection Program. We review your digital snapshot for you, help you understand your main risks and recommended actions. We then provide continued support throughout the year with quarterly exposure reviews, threat intelligence, and practical security resources designed specifically for small businesses.

You can learn more about the program here: https://www.du-zel.com/small-business-digital-exposure-protection-program

Next
Next

Why SMS and Push MFA Alone Are No Longer Enough