AI tools can combine scattered personal information in minutes. 94% of executives studied had exposed home addresses and passwords.
Key Takeaways
- AI tools can quickly combine public records, breach data, and social media information into detailed profiles of executives and their families.
- All 72 executives studied had breach data connecting their names to a current email address.
- 94% had a home address publicly linked to their name, while the same share had at least one exposed password.
- 15% had been targeted by social media impersonators, most often for financial scams or deceptive messages.
AI is making it faster and easier for attackers to gather the personal information needed to target corporate executives with convincing phishing and impersonation attacks, according to a new report from Nisos.
Information that once required hours of searching across public records, data breaches and social media can now be collected and connected in minutes. Attackers can use the resulting profiles to create messages that appear to come from executives, colleagues or relatives.
Nisos also found that AI chatbots can reveal or help locate home addresses, family relationships and other personal details. That information can support cyberattacks as well as stalking, home intrusion, and other physical threats.
AI Speeds Up Executive Research
Nisos said it observed people using social media chatbots to request executives’ home addresses, social media accounts and information about their spouses and children.
Most chatbots did not provide complete answers, but they offered clues that could help users find the requested information through additional searches. The tools also responded to questions about which companies or individuals to target.
In its own testing, Nisos found that some AI models provided executives’ residential addresses using information linked to people-search websites and property records. Some models initially refused but disclosed accurate information after researchers reworded their questions or provided a different reason for asking.
The report did not measure how frequently attackers use AI in this way. It found that the technology can shorten the research needed to prepare personalized attacks and make that process accessible to people with fewer investigative or technical skills.
Nisos found that social media impersonation accounts targeted 15% of the executives. Most of those accounts impersonated executives to run financial scams or trick people into revealing information.
Personal Information Is Widely Exposed
The research found that all 72 executives had breach data connecting their names to at least one current email address. Another 94% had at least one password exposed as readable text.
Social Security numbers appeared in breach data for 64% of the executives. For 54%, those numbers were also listed for sale on dark web marketplaces.
Home information was similarly common. Nisos found public home addresses for 94% of the executives, while 86% had residences with interior images, floor plans or blueprints available online.
Family members often expanded that exposure. Executives’ immediate relatives maintained an average of eight public social media accounts, and 97% of those accounts disclosed personal details about the executive.
Roughly 32% of executives or their relatives shared location information through fitness apps or geotagged social media posts. Nisos said attackers can use those details to identify routines, map residences, or determine when someone is away from home.
The report also found that 25% of executives or their spouses used a public profile photo that included a minor child.
Nisos reviewed 72 executive vulnerability assessments conducted across a range of industries and locations between 2025 and the first quarter of 2026. The company examined public records, people-search sites, social media, property information, and data from previous security breaches.

