Doxing is a social engineering technique where an attacker publicly discloses personal information about a target to intimidate, coerce, or manipulate them.
Why It Matters
In the context of phishing and social engineering, doxing serves as a compelling psychological tactic that attackers leverage to apply pressure on their targets. By exposing or threatening to expose private data such as phone numbers, home addresses, financial details, or embarrassing personal communications, attackers aim to sow fear and disrupt the target’s sense of security. This type of information disclosure can leave individuals and organizations vulnerable to further attacks, negative publicity, and reputational damage.
Doxing often precedes or accompanies targeted phishing campaigns, using the disclosed information to increase the authenticity of the phishing attempt. Attackers may impersonate trusted contacts who appear knowledgeable about the target’s personal life, making phishing emails or social engineering calls more convincing. The effectiveness of these engagements often hinges on the shock value and perceived legitimacy that doxing can provide.
In Practice
Consider an example where an attacker collects and publishes personal data from an executive’s leaked emails, then uses that information to craft a spear-phishing email. The email might appear to come from a colleague and reference specific internal projects or personal family details, thus amplifying its believability:
Subject: Internal Project Update
Hi [Executive's Name],
I hope you had a restful weekend at [specific family event detailed in leaked emails]. I've attached the latest draft of the 'Innovate Future' project document for your review. Let me know your thoughts.
Cheers,
[Colleague’s Name]
[Malicious Attachment: Innovate_Future_Update.docx]
In another scenario, attackers might create a sense of urgent threat by publicly posting snippets of a target’s financial information on pastebin-like services, with links circulated in various forums. The public exposure serves both as a taunting gesture to the victim and a lure for unscrupulous actors who might want to carry out secondary attacks:
Hey [Victim's Name],
We know about your secret investments. See what was shared on public forums:
[Link to pastebin with leaked financial details]
Pay us $500 in Bitcoin to take it down.
Regards,
A Friend
Lastly, consider the use of doxing in conjunction with phone-based tactics. An attacker might call an employee, armed with their personal info gleaned through doxing, to socially engineer them into revealing confidential company data:
Caller: Hi [Employee's Name], I'm with IT. I see you're dealing with some high-priority personal issues right now, like that incorrect $500 charge on your Visa last week. We received a similar alert on your corporate account, and I need your login credentials to investigate further.
Related Terms
Exploring doxing can broaden understanding of adjacent concepts like spear-phishing, which is a targeted form of phishing that often uses data obtained via doxing. Similarly, understanding social engineering tactics such as pretexting or baiting can provide deeper insights into how doxing fits into broader attack strategies. Together, these terms emphasize the multifaceted nature of social engineering attacks.
References
For a deeper dive into the mechanics and implications of doxing, refer to these sources:
Related Reading
Educational Purpose: This content is provided for awareness and defensive purposes only. Understanding attacker methodologies helps individuals and organizations protect themselves.

