How Attackers Research Their Targets
Targeted phishing starts with research. The public sources attackers use, from professional profiles to company websites and leaked data, and what individuals and organizations can reduce.

A good targeted phishing email looks effortless, but it is built on research. Before writing a word, attackers gather details about the person and organization they are targeting, mostly from public sources.
Where attackers look
| Source | What they learn |
|---|---|
| Professional profiles | Names, roles, managers, projects, new hires, tools used |
| Company website | Staff lists, email format, suppliers, press releases, office locations |
| Social media | Travel, events, family, interests, writing style |
| Job adverts | Software and systems in use, team structure |
| Public records and filings | Directors, addresses, finances |
| Leaked data | Old passwords, phone numbers, internal emails. See checking breaches |
| Conference and event pages | Who attended, who spoke, who met whom |
How the research is used
- To pick targets with access to money or systems.
- To choose a believable sender, such as a real supplier or manager.
- To time the message, for example while the CEO is travelling.
- To mimic tone and internal language. See spear phishing.
What individuals can reduce
- Share less about internal processes, systems and travel plans.
- Review privacy settings on personal social media.
- Be alert to messages that use publicly available details to seem genuine.
What organizations can reduce
- Avoid publishing full staff lists and direct emails for every role.
- Remove payment and approval process details from public pages.
- Use role-based addresses for public contact.
- Train staff with examples built from your own public footprint.
Got a message that knows too much? Paste it into CyberWatch AI Scan for a free check.
For all the types of phishing, read our complete guide.
Frequently asked questions
What is OSINT?
Open-source intelligence: information gathered from publicly available sources such as websites, social media, public records and news.
Should staff hide their job on social media?
Not necessarily, but they can limit detail about processes, systems, reporting lines and travel, and be alert to approaches that use this information.
What can organizations change?
Avoid publishing full staff directories and email formats where unnecessary, remove process details from public pages, and train staff with realistic examples.
Sources
- Social media: how to use it safely, UK National Cyber Security Centre
- Small business guide: cyber security, UK National Cyber Security Centre
- Have I Been Pwned, Troy Hunt


