AI Security Research: Threat Actors Now Build Executive Profiles in Minutes

A corporate executive in a suit works at a laptop in a private office

Ninety-four percent of corporate executives have home addresses publicly tied to their name in people-search databases. One hundred percent have breach data linking their name to at least one current email address. And now, according to new research from Nisos, the human risk management company, AI security teams face a changed calculus: threat actors are using AI tools to collapse aggregation tasks that once took trained investigators days into workflows that take minutes. The 2026 Executive Digital Exposure Trends report, released July 13, documents ten specific findings about executive exposure across public records, social media, breach datasets, and geolocation data. Taken together, they make a clear argument: executive protection is no longer just a physical security matter; it is now a human risk problem that sits squarely on the security team’s desk.

What the AI Security Threat to Executives Actually Looks Like

The Nisos research examined Executive Vulnerability Assessments conducted across a random distribution of industries and geographies between 2025 and Q1 2026. The findings show exposure that spans multiple channels simultaneously, which is exactly what makes AI-assisted targeting so concerning — an attacker does not need to find one vulnerability; they need to aggregate several pieces of individually public data into one coherent profile.

The numbers are specific and worth quoting directly from the report:

  • 94% of executives had home addresses publicly linked to their name via public records or people-search sites
  • 86% had residential addresses with viewable interior images, floor plans, or blueprints available online
  • 64% had Social Security numbers exposed in breach data; 54% had those SSNs listed for sale on dark web marketplaces
  • 69% had public social media accounts revealing personal or family information
  • 15% were targeted by social media imposter accounts, most running financial scams or social engineering against third parties
  • 25% of executives or their spouses had at least one public social media profile photo of their minor children — enough for a threat actor to identify and locate family members
  • Executives’ immediate family members maintained an average of 8 public social media accounts, with 97% of those accounts exposing personal details about the executive
  • 32% of executives or family members shared geolocation data via fitness apps or geotagged posts
  • 100% had breach data linking their name to at least one current email address
  • 94% had at least one plaintext password exposed in breach data

This is the attack surface before AI enters the picture. The Nisos researchers observed instances of threat actors using chatbot systems to gather biographical details, identify family relationships, and request sensitive personal information as part of broader targeting workflows. In some cases, AI systems surfaced or inferred personal data when fed publicly available records and breached datasets — reducing not just time but the technical skill required to build a detailed target profile.

That last point is what changes the risk calculus. It is not that executives are suddenly sharing more; it is that aggregation tasks which once required trained investigators can now be performed by almost anyone who knows how to prompt a chatbot. The barrier to entry for executive targeting has dropped substantially.

The Proximity Risk Problem Is Getting Harder to Contain

The report highlights what Nisos calls a “proximity risk” effect: executive exposure is amplified through family members and close contacts who unintentionally share sensitive personal and location data online. This is not a new observation in the executive protection field, but AI acceleration makes proximity risk much harder to manage. An executive can lock down their own social media presence and still be identifiable through a spouse’s fitness app routes, a child’s school sports photo, or a family member’s geotagged vacation post.

The physical dimension compounds the digital one. Publicly available property records and real estate imagery frequently expose interior layouts and exterior details of executive homes. That information can be used to facilitate stalking, impersonation, or physical intrusion. Geolocation sharing from fitness apps or geotagged posts lets a persistent attacker map routines and identify windows when a residence is unoccupied.

For security teams, this shifts the scope of executive protection programs in a direction many are not yet resourced for. The report recommends reducing data exposure in public records, restricting geolocation sharing, tightening social media privacy settings, and running ongoing personal data removal efforts across data broker sites. Those are all reasonable controls, but they require active participation from executives and their families — a management and communication challenge as much as a technical one. For teams tracking the broader AI security threat landscape, AI’s impact on phishing and social engineering has been documented to extend well beyond executive targeting, and the same aggregation dynamic applies across a range of attack scenarios.

What Security Leaders Should Do With This Data

The Nisos report is a follow-up to their June 2025 Executive Exposure Trends study, giving the team longitudinal visibility into whether the problem is improving. Based on the 2026 findings, it is not — not because the data landscape changed dramatically in one year, but because AI security tooling available to threat actors improved faster than the data hygiene practices of most organizations.

The practical implication: teams that have not run an Executive Vulnerability Assessment in the past twelve months are operating on stale intelligence. The exposure picture for any given executive can change significantly in that window — new property records, new breach datasets, new social media activity from family members. AI-assisted targeting updates faster than annual assessment cycles.

Reframe executive protection as a human risk program, not a physical security add-on. Nisos CEO Ryan LaSalle made this explicit in the report: “Organizations need to think beyond cybersecurity and recognize executive protection as a human risk issue.” If executive protection lives only under physical security, the cyber exposure component gets managed inconsistently. If it lives only under the CISO, the physical and family-proximity dimensions often go unaddressed. The teams that handle this well treat it as a shared problem — security, legal, HR, and executive staff functions working from a common threat model.

Run the data removal work continuously, not annually. One-time opt-out requests to data broker sites have a shelf life of a few months before data resurfaces. A continuous removal program is qualitatively different from an annual sweep, and the Nisos findings on plaintext passwords and SSN availability in breach data suggest that the passive exposure problem is not going away on its own.

The researcher who assembled that executive home address, family photo, and fitness app route into a targeting dossier in three minutes is not a sophisticated nation-state actor. That is precisely the point.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display