Social Media Oversharing

Social Media Oversharing

See how attackers exploit your public profiles.

What Is Social Media Oversharing?

Attackers read public profiles before they write a phishing email. None of what you post is secret on its own; the value is in the combination. You leave a friendly comment under a colleague's conference talk and write a LinkedIn post about your current project, while an attacker pulls voice samples from the same talk. Then you watch him combine the comment, the post and the video into a targeted message that names your client, your teammate and your colleague.

What You'll Learn in Social Media Oversharing

Social Media Oversharing — Training Steps

  1. Introduction

    It's Monday morning, and Alice starts her day by checking her company email inbox.

  2. The Company Announcement

    Alice receives an internal company email celebrating Mike Stevens' successful presentation at a recent cybersecurity conference. The email encourages employees to watch the recorded presentation and leave congratulatory comments.

  3. Clicking the Link

    Alice clicks on the OurTube link from the email.

  4. Skipping the Presentation

    Alice decides to watch the video later after the workday is over. If she had watched it, she would have learned that during the talk, Mike mentioned that Nexlify Solutions was working on several exciting projects with major clients, though he didn't reveal specific details due to confidentiality agreements.

  5. Posting a Comment

    Alice scrolls down the page to find the comment section and leave an encouraging comment. While doing so, she accidentally shares internal company information.

  6. Bob's Video Analysis

    Meanwhile, Bob has also discovered the same OurTube conference video. However, his interest isn't in congratulating Mike - he's analyzing the audio to extract voice samples. Bob uses specialized software to isolate Mike's speech patterns, tone, accent, and vocal characteristics from the 45-minute presentation. Bob collects key phrases and words that Mike uses, noting his Boston accent and professional speaking style. This audio data will become the foundation for creating a convincing AI voice clone.

  7. The LinkedIn Inspiration

    In her comment on Mike's presentation, Alice mentioned the upcoming SecureTech project - information that should have remained private to the company and not been shared publicly. Feeling inspired to share her own professional achievements, Alice remembers her current project with Sarah for SecureTech Corp. She decides this would be perfect content for a LinkedIn post to showcase her work and celebrate teamwork.

  8. Creating a Post

    Alice creates a LinkedIn post about her work, inadvertently sharing even more sensitive company information publicly.

  9. Bob's OSINT Discovery

    Bob's automated monitoring tools alert him to Alice's new LinkedIn post within minutes. He now has valuable intelligence: Alice works on the SecureTech Corp implementation Sarah Johnson is her team member The project involves infrastructure security implementation Alice has a collegial relationship with Mike Stevens The company has ongoing high-profile projects Bob cross-references this information with Alice's previous comments, confirming the connections between these employees.

  10. Exploiting Social Media Intelligence

    Bob leverages all the information Alice unknowingly provided through her social media activity. He can now mention Sarah by name, reference the SecureTech project specifically, and impersonate Mike since Alice clearly knows and respects him. Bob creates a believable urgent scenario based on Alice's public posts and prepares to launch his attack.

Security Framework Coverage

MITRE ATT&CK

  • T1589 Gather Victim Identity Information
  • T1591 Gather Victim Org Information

CIS Controls

  • CIS 14.5 Train Workforce Members on Causes of Unintentional Data Exposure

NIST CSF

  • PR.AT-01 Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind