Safety Resource Center/Digital Safety/Digital Footprint
Digital footprint: Doxxing, social engineering, phishing,
What is it
[edit]Your digital footprint is the trail of data and personal information that you leave behind as you use various apps and websites. This includes information you actively put on the internet (for example social media posts), but also the data that apps and websites passively track (IP addresses, cookies etc.). This information can be used to harm and trick you in different ways:
- Doxxing is the collecting and publishing of someone else’s personal information online with the intent to cause harm. This information can be a real name, phone number, email address, social media accounts, photos, date of birth, home or work addresses, etc.
- Social engineering refers to different forms of tricks to manipulate people into sharing sensitive information, sending money, compromising their security, etc. Social engineering makes use of human emotions such as trust, fear, panic or respect for authority.
- Phishing is the most common form of social engineering. It uses fraudulent messages that look like they come from a seemingly legitimate source, for example co-workers, governments, banks, postal service etc.). This tricks users into revealing information (like login credentials) or executing an action (like clicking on a malicious link). Phishing is commonly used to install malware, surveil and extort.
Why is it important
[edit]Sometimes our personal information is more accessible online than we think – and can be used by bad actors to surveil, construct convincing phishing messages, or reveal sensitive personal details to others. Moreover, generative AI tools are making it much easier to scrape the web for information and carry out large scale phishing and doxxing attacks with relatively little effort.
What can you do to protect yourself
[edit]Manage your digital footprint
[edit]Personal information isn’t limited to your home address, phone number, credit card number, or date of birth. It also includes less obvious indicators, such as the school you attend, your daily commute, your favourite coffee spot, or events you plan to attend – all of which a bad actor could use to find out who you are, where you study, work, live, and how to contact you. Additionally, your passive digital footprint – tracked by apps and websites – could contain information like IP addresses and browser histories.
| Recommendations | Tools and resources |
|---|---|
|
On Wikimedia and other online platforms, avoid using your real name as a username, or a username that might give clues to your real-life identity. |
|
|
As we interact with the online and offline world, we are inevitably sharing information about ourselves. Try to get an overview of how much and which information about yourself is online, who can access it and how fast. A better understanding of how attackers go about finding and sharing personal information will help you protect your data. |
|
|
Scout for information on yourself online that you don’t want others to see. Explore options of removing such data from the internet. |
|
|
Openness and transparency are fundamental to the Wikimedia Movement. However, this transparency can also make you more vulnerable to certain threats. Wikipedia is a permanent record – even if reverted, information on edits remains accessible via version histories. Be mindful of the information your contributions might reveal about you. |
|
|
Be mindful about the images you upload on Commons and the ‘invisible’ information in the form of EXIF-data you might be sharing. EXIF-data typically contains information on the time, date, and location of image creation, the device used, etc. Commons maintains all EXIF-data associated with an image when uploaded to the platform – altering or removing this data afterwards is very difficult. |
|
|
On social media platforms, privacy features are often deactivated by default. Check your settings and be mindful of what you post and comment on, who you tag, and who can see that information. Be mindful of the information your posts might reveal about you. |
|
|
Change your device names to not include your real name or any other identifiers.
|
|
|
Be aware of how third parties like apps and websites track your digital footprint. |
|
Compartmentalize
[edit]“Compartmentalizing” means separating the different parts of your digital life, for example by using different computers and accounts for work and personal use. This way, in case one “compartment” is compromised (for example by a data breach), the other compartments remain safe since they are not connected to each other. It also reduces the risk of data from one part of your life being visible in another part (for example work and private).
| Recommendations | Tools and resources |
|---|---|
|
Use different email accounts and usernames for different digital identities, such as work, friends, Wikimedia activity, online shopping, mailing lists, etc. Use distinct profile pictures or avatars for easier distinction. Use a password manager to keep track of the different accounts. |
|
|
Avoid using single-sign-on (“SSO”)/social login services (for example “Sign in with Google/Facebook/Apple” prompts). While very convenient, it ties all your accounts together, with your access credentials stored across the various services you used it for. If one service gets compromised, all others are at risk as well. Use unique usernames and passwords for your accounts. Use a password manager to keep track. |
|
|
Most browsers allow you to create browser profiles to keep your information separate, including browsing history, preferences or social media profile logins. Consider setting up different browser profiles for different use cases (like work, personal use, or Wikimedia activity) |
|
|
If you have separate on- and off-wiki identities, be mindful not to accidentally link them, for example by commenting on a wiki-related social media post with your personal account. Make sure you are logged in to the right account before interacting with content online (for example by using different browsers or browser profiles for different accounts). |
Be wary of phishing messages
[edit]Phishing is one of the most common tactics used by cybercriminals and other bad actors, with messages getting more and more sophisticated with the use of AI tools. Even for a trained eye, a well constructed phishing message can seem almost indistinguishable from a real one. As phishing exploits human vulnerability and is specifically designed to trick you, sharpening your awareness can go a long way in recognizing and preventing attacks. Phishing can take the form of emails, SMS, phone calls and other communication channels.
| Recommendations | Tools and resources |
|---|---|
|
Learn how to spot phishing messages. Typical indicators include:
|
|
|
If you have any doubts, verify if the message is really coming from the source it claims to be. To do this, use a different, previously known or official channel of communication – don’t use the channels or numbers provided in the potential phishing message. Consider establishing a “safe word” with important trusted contacts to verify their identity. |
|
|
Don't open, respond to, click links in or open attachments from emails that appear suspicious. Always hover your mouse over links to see if the actual link is different from the displayed link. You can also right-click on the link and copy the address to inspect it before clicking.
|
|
|
When images load in an email you receive, a request is made to wherever on the internet that image is hosted. Bad actors can use this to covertly track you. Prevent images to be loaded automatically in your email provider. |
|
|
Sometimes phishing attacks are based on information the attacker already has about you. This targeted approach is called “spearphishing”. Being mindful of your digital footprint is important to make it harder for a bad actor to construct a convincing phishing message. |
|