Explore Elite Risk Management Services

Private Strategic Group

Article

Bypassing the Perimeter: How Personal Exposure Becomes Enterprise Risk

26 JUN 2026

/

11 min read



Executive working in airport lounge

The Rise of Executive Targeting

Historically, executive protection within the corporate context was primarily associated with armored vehicles, corporate aircraft, and close-protection teams. Today, executive protection is understood as a more comprehensive, proactive, and intelligence-led discipline that incorporates both physical and digital security considerations for business leaders. This shift has been driven by the rapid digitalization of business operations and the corresponding expansion of the cyber threat landscape. Despite these changes, however, corporate security teams have, in many cases, failed to prioritize the identification and mitigation of personal and professional digital vulnerabilities as a core component of their executive protection strategy, despite the material enterprise risk it can represent.

Exploitation of personal and professional digital exposure has become one of the most effective pathways into enterprise environments. Cyber threat actors routinely target executives and their personal and professional devices to bypass hardened corporate controls and gain access to enterprise systems, sensitive information and trusted business relationships. At Crisis24, our threat intelligence and cyber incident response teams have observed threat actors impersonating senior executives to authorize fraudulent payments or obtain confidential corporate information. We have also observed adversaries attempt to compromise executive accounts, as well as exploit real-time and predictive information relating to executive movements, routines, and travel schedules, often exposed through poor cyber hygiene practices or misconfigured consumer applications. While such information can facilitate harassment, extortion, kidnapping, and physical surveillance, its value extends far beyond personal security: the same intelligence enables threat actors to develop highly tailored social engineering campaigns that compromise trusted identities and penetrate the enterprise itself.

The primary issue, however, is that executive digital exposure can fall into a governance gap. Executives are often unaware of the volume, sensitivity, and adversarial utility of the information exposed about them online, while corporate security teams lack the resources, expertise, or authority to monitor and mitigate these risks. As a result, critical indicators of targeting, compromise and exposure frequently go undetected and untreated. The challenge is further exacerbated by executives' reliance on personal devices, accounts and consumer applications for business activities. As personal and professional digital lives become increasingly intertwined, the attack surface around senior leaders expands beyond the corporate perimeter and into environments that security teams often cannot monitor, control or defend, despite the enterprise risk they represent.

The Executive Attack Surface

Executives personify their respective organizations and associated brands. They often hold privileged access to critical systems, sensitive information, strategic decision-making, and trusted business relationships, which makes them a high-value, high-impact target. Executives’ personal data is of equal interest to threat actors – including contact information, habitual behaviors, personal interests, and political affiliations, as well as consumer Internet of Things (IoT) and home networking devices, financial assets, and business registries.

A joint cybersecurity advisory issued in July 2025 by several national agencies – including the US Federal Bureau of Investigation (FBI), the US Cybersecurity and Infrastructure Security Agency (CISA), and the UK National Cyber Security Centre (NCSC) – detailed the tactics, techniques, and procedures used by cyber threat actors linked to Scattered Spider, a financially motivated cybercriminal collective that specializes in identity-based social engineering and ransomware attacks. The advisory noted that the threat actor’s initial access to enterprise environments was often obtained through broad phishing campaigns targeting organization-specific domains. However, it also highlighted an increasing trend towards more targeted attacks, specifically the systematic collection of personally identifiable information relating to users with elevated privileges, including executives. According to the advisory, Scattered Spider gathers information from open-source intelligence, social media platforms, commercial intelligence tools, breached databases, and illicit marketplaces where stolen credentials are traded. The group also researches individuals through business networking platforms and other publicly accessible sources to understand their roles, responsibilities, and organizational relationships. Risk is not, therefore, confined to any specific source; in practice, threat actors aggregate information across the surface, deep and dark web sources.

In addition, in June 2026 the Wall Street Journal published an investigative report into the hidden security risks associated with consumer IoT devices, such as smart picture frames and streaming boxes. The investigation found that some devices were shipped with pre-installed malware that enrolls them into residential proxy networks, effectively providing cyber threat actors with infrastructure that could be exploited once connected to a home network. While residential proxy services have legitimate uses, threat actors frequently abuse them to obscure their identity while conducting criminal activities, including fraud, ticket scalping, credential attacks, and distributed denial-of-service (DDoS) operations.  

According to a cybersecurity advisory published by the FBI, the National Security Agency (NSA), and several international agencies in April 2026, cyber threat actors associated with Russian military intelligence have exploited similar vulnerabilities in home and small-office networking devices to facilitate cyber espionage operations. These attacks often target outdated networking equipment, which is subsequently used to intercept internet traffic, harvest credentials and authentication tokens, and obscure the origin of malicious activity. The compromised devices are often located in residential environments, allowing threat actors to blend malicious traffic with legitimate home internet usage and making attribution significantly more difficult.

From an executive protection perspective, the implications extend beyond the compromised device itself: as executives increasingly conduct business activities from home and rely on personal devices and residential networks, vulnerabilities within the home environment can create indirect pathways into corporate ecosystems. A compromised IoT device may not provide direct access to enterprise systems, but it can expose network traffic, facilitate reconnaissance, or provide threat actors with additional opportunities to target connected devices and users. As personal and professional technology environments continue to converge, residential networks and consumer devices are becoming part of the broader executive and enterprise attack surface, even as they remain outside the visibility, authority, and control of corporate security teams. 

Attack Paths in Practice

Executive attacks generally follow one of two pathways. The first is a direct attack against the executive, typically through phishing or other forms of social engineering, designed to facilitate fraud, extortion, harassment, reputational damage, or, in some cases, physical security threats. The second is an enterprise pivot, where threat actors seek to gain access to corporate systems and networks by exploiting the executive as an entry point. This may involve compromising accounts or personal devices used for work-related activities, or leveraging personal and professional information to build detailed target profiles, develop tailored social engineering pretexts, and establish trust before attempting to compromise corporate accounts, systems, or networks. In both pathways, executive digital exposure serves as the enabling layer that supports intelligence collection, target development, and attack execution.

In the majority of cases, threat actors leverage publicly available information, organizational context, communication patterns, and personal details to create highly credible impersonation attempts. These attacks are frequently enabled through phishing and social engineering techniques that exploit trust, identity, and personal information, rather than technical vulnerabilities alone. They frequently arrive through commonly used communication platforms such as WhatsApp, SMS, and email, as well as internal corporate communication tools, where actors exploit urgency, authority, and familiarity to influence employee behavior.

In October 2024, Assaf Rappaport, chief executive officer and co-founder of cloud security company Wiz, disclosed that several employees had been targeted in a social engineering campaign involving a deepfake impersonation of him. Deepfakes utilize generative artificial intelligence (AI) to analyze existing audio, video, or image content and generate synthetic media that mimics a target’s appearance, voice and mannerisms. In this case, the threat actor reportedly used publicly available audio recordings of Mr. Rappaport to create a convincing voice clone and then contacted multiple employees in an attempt to obtain credentials. The attack was ultimately unsuccessful, largely because employees recognized subtle inconsistencies in the synthetic voice. A similar attack was reported by DNB Bank in January 2025, when threat actors invited employees from the bank's Singapore and London offices to what appeared to be a legitimate meeting about a new product launch. During the call, the attackers used deepfake technology to impersonate Chief Executive Officer Kjerstin Braathen and Chief Financial Officer Ida Lerner, drawing on publicly available video footage of both, and attempted to persuade employees to transfer several million Singapore dollars as part of a purported investment opportunity. The deepfakes were convincing enough to make immediate identification difficult, but several anomalies – unusual communication channels, contextual inconsistencies and behavioral indicators – ultimately raised the suspicion of corporate security teams, who suspended communications with the threat actors.

Deepfakes, traditionally associated with online harassment, pornography, and political misinformation and disinformation campaigns, are now one of many tools that threat actors use to mimic legitimate corporate communications and imitate executives. Historically, threat actors seeking to exploit executive authority were required to compromise an executive's account, communications platform, or device. Today, publicly available audio and video content can provide sufficient material to fabricate highly convincing executive impersonations. As a result, executive digital exposure now extends beyond personal information, social media activity, and breached credentials to include voiceprints, video recordings, interviews, webinars, and other publicly accessible content. 

The Business Impact and Risk Mitigation

According to the FBI’s Internet Crime Complaint Center (IC3) 2025 Internet Crime Report, cyber-enabled crime continues to increase in both frequency and financial impact. Since 2015, the number of complaints submitted to the IC3 has increased from approximately 288,000 to more than one million annually, an increase of approximately 250 percent. Over the same period, reported losses increased from approximately USD 1 billion to more than USD 20.8 billion, a near-2,000 percent rise. More telling than the totals is a shift in how those losses are generated. Rather than relying solely on technical exploitation, many of the highest-loss crime categories now depend heavily on impersonation, social engineering, identity abuse, and the exploitation of trust relationships.

AI is increasingly used to produce convincing emails, voice clones and other synthetic content that mimics senior executives and trusted individuals. For corporate security teams, this reinforces a critical reality: the threat environment is being shaped by new technology. The business impact of executive digital exposure is no longer limited to the compromise of an executive’s personal accounts or devices. Publicly available information, voice recordings, images, videos, personal relationships and behavioral patterns can all be leveraged to impersonate senior leaders, manipulate employees and exploit trusted business processes. In many cases, the executive's identity itself has become the attack surface, allowing threat actors to bypass traditional technical controls and directly target the human trust mechanisms upon which organizations depend.

The goal is not to replace existing corporate cybersecurity programs, but to extend protection to the personal environments where traditional controls no longer operate. Every executive has a personal digital footprint, and understanding that exposure is the first step toward reducing it. Organizations that assess executive risk proactively will be better positioned to prevent personal compromises from becoming enterprise crises.


Crisis24’s Digital Executive Protection mitigates risk for global leaders by mapping their digital footprint, removing identified exposure, and assessing the attack surface to secure the executive, their family, and their company from threat actors. Learn more.   

Sharpen your 
view of risk

Subscribe to our newsletter to receive our analysts’ latest insights in your inbox every week.

Intelligence & Insights


Intelligence 
Worth Gathering

Employing a team of 200+ analysts around the world, Crisis24 is the only source you need for on-point, actionable insights on any risk-related topic.