// THREAT DETECTION AND DATA PRIVACY TERM

Doxing

Doxing is the act of researching and publicly broadcasting an individual's private or identifying information, like their home address or phone number, without their consent. It is typically done online with the intent to harass, shame, or intimidate the target.

Doxing — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Doxing is a malicious online attack where an adversary collects and publicly releases a target's personally identifiable information (PII), such as their real name, address, phone number, or financial details. This information is gathered from public records, social media, and data breaches to enable harassment, intimidation, extortion, or other forms of cyber-enabled abuse.

BACKGROUND

Doxing or doxxing is the act of publicly providing personally identifiable information about an individual or organization, usually via the Internet and without their consent, and or with the intention of harassing or causing distress to the victim. Historically, the term has been used to refer to both the aggregation of this information from public databases and social media websites, and the publication of previously private information obtained through criminal or otherwise fraudulent means.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • dropping dox
  • document dropping
  • PII release
  • online harassment
  • de-anonymization
  • info dump

USAGE NOTE

Doxing is a serious privacy violation and is often a tactic used in online disputes, by hacktivists, or for personal revenge.

DEVELOPERS

Organizations developing technology related to Doxing.

  • DeleteMe (a service of Abine)

    A privacy service that uses proprietary technology to find and remove personal information, such as names, addresses, and phone numbers, from data broker websites and people-search databases, directly reducing the data available for doxing.

  • ZeroFox

    Provides a Digital Risk Protection platform that uses AI to monitor the surface, deep, and dark web for threats. The technology identifies and facilitates the takedown of exposed PII, doxing posts, and threats on social media and other digital platforms.

  • Recorded Future

    A threat intelligence company whose platform collects and analyzes vast amounts of data from the open web, dark web, and technical sources to identify threats. This includes monitoring for compromised credentials and PII dumps that are often precursors or components of doxing.

  • Kanary

    Develops a privacy protection service that automatically scans thousands of websites for a user's personal information and submits removal requests to data brokers, helping to prevent doxing by reducing an individual's public data footprint.

  • Flashpoint

    A threat intelligence firm specializing in data from illicit online communities. Their platform allows security teams to monitor dark web forums and marketplaces for chatter and data dumps related to their organization, providing early warning of doxing threats.

  • Incogni

    Develops an automated system that formally requests data removal from data brokers on behalf of users. The technology continuously sends requests to ensure personal information stays off these databases, which are primary sources for doxers.

  • Optery

    Creates technology that scans and removes personal profiles from hundreds of data broker sites. It provides users with visibility into their exposed data and offers automated removal services to protect against identity theft and doxing.

RELATED TERMS IN THREATS & ATTACKS