Social Media as an Intelligence Source for Attackers
Before launching a targeted attack on an institution, attackers research it. LinkedIn shows them org charts, job titles, and staff names. Public Facebook or Instagram posts from staff reveal working patterns, travel schedules, and relationships. This research makes phishing and social engineering attacks significantly more effective. Staff social media is part of the institution's attack surface.
What Staff Should Never Post
Staff should not post: screenshots of internal systems or dashboards (metadata and visible data can be exploited), their work schedule or upcoming travel (enables timed attacks), complaints about internal processes (useful intelligence for attackers), or confirmation of personnel moves and org structure changes before they're public.
Securing Institutional Social Media Accounts
Institutional social media accounts should have MFA enabled, shared credentials stored in a team password manager (not personal accounts), and a clear policy for who can post and on what topics. When staff leave, access should be revoked immediately. Account takeover of an institutional social media presence is a reputational and operational incident.
Handling Social Engineering Attempts via Social Media
Attackers use LinkedIn and social platforms to impersonate staff, vendors, or regulators and initiate contact. Any unsolicited contact requesting sensitive information, access credentials, or urgent action — even through a professional platform — should be verified through official channels before any response.
