No scanning. No tooling. No technical infrastructure.
Just a LinkedIn feed, a search, and everything an attacker would ever need to walk straight through the front door.

The post that said too much
During an OSINT engagement, our operator was mapping the organization’s community footprint through LinkedIn. Public information only. Reading what they’d chosen to share with the world.
That’s when it appeared: a post celebrating their partnership with a local charity. Warm, genuine, well-intentioned. A company proud of doing good in their community.
And an attacker’s roadmap.
The goodwill was real. The relationships were real. The warmth in the writing told us exactly who cared about this work and would never want to let the partnership down.
That’s not a human weakness. It’s a human strength. But in the wrong hands, it becomes the most believable hook imaginable.
The target hiding in plain sight
Cross-referencing that post against employee data, one person stood out immediately.
Senior HR lead. Long-tenured. Personally connected to the partnership.
She owned this relationship. A routine email arriving from the charity would land in her inbox as completely normal. Expected, even.
Then came the breach data. Her credentials had appeared in multiple known breaches.
The email that writes itself
No creativity required at this point.
A spring collection drive referencing the existing partnership. A request to review an updated agreement. Nothing suspicious. Just a cause she genuinely cares about, asking for a few minutes of her time.
A payload nobody would think twice about opening.
The most convincing phishing emails aren’t invented by attackers. They’re borrowed from the target’s own LinkedIn feed.
The uncomfortable question
Every piece of information that went into this pretext was posted voluntarily.
The partnership announcement. The employee’s name and role. The personal connection to the cause. None of it was stolen. None of it was leaked. It was shared, proudly, because it deserved to be.
That’s what makes this hard.
The answer isn’t to stop celebrating good work or hide your people from the world. It’s to understand that the same information your communications team shares as a feel-good story is being read by more than just your partners and supporters.
And to test whether your people, however experienced and well-intentioned, would hesitate before opening that attachment.
Because the most dangerous intelligence is the kind you gave away yourself.
Want to see what your public footprint is really saying?
Contact CovertSwarm and find out what an attacker sees before you do.