
Introduction
Welcome to Part 3 of our series. In Part 1 we covered reconnaissance outside your firewall, and in Part 2 we looked at how leaked credentials expose your identities. This time we turn to people. Many security programs are built around systems: the servers, networks, and applications you can patch and monitor. But as most security professionals know, some of the most damaging attacks never touch a system at all. They target people.
An attacker who impersonates your CEO to a finance clerk does not need to breach anything. They just need the clerk to believe the request is real. An attacker who studies a public executive can build a doxing campaign or a targeted scam that no firewall will ever see. And an attacker who cannot get into your company directly will often go after a vendor who already has a way in.
These are the threats that live at the edges of the traditional security map. They aim at your leaders and public-facing staff, at your brand and the customers who trust it, and at the partners you depend on every day. What they share is a target: not a system, but trust in a familiar identity.
This third article looks at the same data through the attacker's eyes: the executive details, brand assets, and vendor relationships they quietly research to build a convincing attack. The good news is that most of it sits in the open, where you can find it first, and see the impersonation or scam taking shape before it reaches your people.
Why Executives Are a Favorite Target
Executives make attractive targets for a simple reason. They have authority, visibility, and access, all at once.
Authority means a request from them carries weight. When an email that looks like it came from the CFO tells someone to move money quickly and quietly, people tend to act first and question later. This is the engine behind business email compromise, one of the most expensive forms of fraud year after year. It rarely involves any hacking. It involves convincingly pretending to be someone in charge.
Visibility means there is a lot of raw material to work with. Executives appear in press releases, conference programs, interviews, and social media. An attacker can learn a leader's travel schedule, writing style, key relationships, and current priorities without any special access. Every one of those details makes an impersonation more convincing.
Access means the payoff is high. Executive accounts often reach sensitive financial systems, strategic plans, and the authority to approve large actions. Compromising one is worth far more than compromising an average account, so attackers invest more effort in it.
Put those three together and you get a target that is both valuable and easy to research. The defense cannot be to make your leaders invisible. It has to be to watch for the moment someone starts building an attack around them.
Impersonation, Doxing, and the Threats Aimed at Individuals
Threats against individuals take a few recognizable shapes, and each leaves signs you can watch for.
Impersonation is the most common. An attacker registers a domain that looks almost like yours, or sets up a social media profile using an executive's name and photo. From there they can send fraudulent requests to staff, deceive customers, or damage relationships. The fake asset usually appears before it is used, which means spotting the registration early can stop the campaign before it starts.
Doxing is the deliberate collection and publishing of someone's private information, often to harass or intimidate. Home addresses, family details, personal phone numbers. For a public executive, a doxing campaign is both a personal safety issue and a business one. Warning signs often surface on forums and paste sites before the full campaign goes public.
Targeted scams use the details gathered during research to craft something highly personal. Not a generic phishing blast, but a message that references a real project, a real colleague, or a real trip. These are harder to catch with standard filters precisely because they are tailored and low volume.
The common thread is that all three begin with activity outside your network. A domain gets registered. A profile gets created. Personal data gets posted. If you are watching the right places, you see the preparation and act on it. If you are only watching your network, the first sign you get is the fraudulent transfer or the frightened employee.
When the Target Is Your Brand
Impersonation does not stop at individuals. The same tactic scales up to the organization itself, and here the people being deceived are usually your customers, partners, and prospects rather than your staff. An attacker who cannot easily impersonate your CFO can still stand up something that looks like your company and trade on the trust your name carries.
The most common form is the lookalike domain. An attacker registers a web address that is a near-copy of yours, swapping a letter, adding a word, or changing the ending. From there they can host a convincing fake login page, send invoices that appear to come from you, or run a phishing campaign against your own customers using your brand as cover. Related tactics include spoofed social media profiles, fake mobile apps, and cloned websites that borrow your logos and language.
This is where the brand angle and the people angle meet. A lookalike domain is often the delivery mechanism for the very threats described above: the fraudulent executive request, the vendor-invoice scam, the phishing lure that harvests a credential. The fake asset is registered first and used later, which means catching the registration early can disrupt the campaign before a single customer or employee is fooled. Watching for new domains, spoofed profiles, and unauthorized use of your brand turns a reactive cleanup into an early warning.
Your Vendors Are Part of Your Attack Surface
Even a business with excellent internal security carries a risk it does not fully control: the security of everyone it does business with.
Your vendors, suppliers, and software providers often hold your data, connect to your systems, or both. If one of them is breached, your information can be exposed even though nothing on your side failed. If a software provider you rely on is hit by ransomware, your operations can stall through no fault of your own. Attackers understand this advantage, which is why supply chain attacks have grown into a favorite strategy. Break one vendor, reach many customers.
The hard part is that you usually have no window into a vendor's security day to day. You find out about their breach when they tell you, and that notice often arrives late, after the data is already exposed or the disruption has already begun.
Supply chain threat intelligence narrows that blind spot. By monitoring ransomware leak sites, criminal forums, and data leak sources for mentions of your key vendors, you can learn that a partner is in trouble early, sometimes before their official notice reaches you. That early knowledge buys time. Time to rotate shared credentials, to check what data that vendor holds, to line up an alternative, or simply to brace for a disruption instead of being blindsided by it.
For any business whose operations depend on a handful of critical partners, this visibility is a core part of business continuity, not a security nicety.
People-Focused Threats Need Both: Proactive Intelligence and Layered Controls
The common thread across all of these threats — impersonation, doxing, brand spoofing, vendor compromise — is that they take shape in the open, and they take shape early. A lookalike domain is registered before it hosts a fake login page. A spoofed profile appears before it messages your staff. A vendor's data shows up on a leak site before their breach notice reaches you. That timing is the whole opportunity: these attacks announce themselves, if someone is watching the right places.
But watching is only half of a sound defense. The most resilient programs pair proactive intelligence with preventative controls that blunt these attacks even when one slips past. The two reinforce each other — monitoring catches what prevention misses, and prevention limits the damage of anything monitoring flags late.
On the prevention side, a few controls can do the heaviest lifting to reduce risk:
Phishing-resistant MFA raises the bar on account takeover, and pairing it with controls that resist session-token theft — shorter session lifetimes, re-authentication for sensitive actions, and device-compliance checks — closes the MFA-bypass gap attackers increasingly exploit.
DMARC, DKIM, and SPF make it far harder for an attacker to spoof your own domain in a business email compromise attempt, and a DMARC policy set to reject stops most lookalike-of-you email before it reaches a customer or employee.
Strong email filtering and impersonation protection catch the display-name spoofing and newly registered lookalike domains that carry executive-fraud and vendor-invoice scams.
Regular, practical user awareness gives your employees and executives the instinct to pause on an urgent, out-of-band money request — the human check that no filter fully replaces.
On the intelligence side, three kinds of monitoring for human sourced threats help reduce the most common risks:
- Executive and VIP monitoring watches for impersonation, doxing, and targeted threats against your named high-profile people — tracking the domains, profiles, and forum activity tied to them.
- Brand and domain monitoring extends that watch to your organization's identity, catching lookalike domains, spoofed profiles, and unauthorized use of your brand, ideally while the fake asset is still dormant.
- Supply chain monitoring does the same for your critical vendors, flagging ransomware activity and data leakage involving the partners you depend on — early enough to respond on your schedule, not theirs.
Together, these two sides form a layered defense around the human target. Preventive controls narrow the ways in; intelligence tells you when someone is trying anyway. And a capability is only as valuable as the judgment applied to it — someone still has to separate a real impersonation attempt from a harmless coincidence, and a serious vendor breach from routine noise. Whether that judgment comes from your own team or a managed partner, the objective is the same: fewer openings for the attacker, and a short list of findings that genuinely deserve attention, each with a clear next step.
Where to Go From Here
Some of the most damaging attacks are the most human ones. They exploit trust, authority, and the relationships that let your business function, and no firewall defends against those directly, because they do not begin inside your network.
Watching for threats aimed at your people, your brand, and your partners closes that gap. It is how you protect the individuals who carry the most risk, the brand your customers trust, and the vendor relationships your operations quietly depend on.
If you want to understand what an attacker could learn about your executives and your supply chain today, we would be glad to show you.
Next time, in Part 4 and the final article of the series, we step back to a practical question: why external threat intelligence delivers the most value when it is actively managed, and how to weigh a platform-only approach against a managed one.
Talk to a Netrix Global team member about a free threat exposure assessment.

.jpg)

