Home / Blog / External Identity Security: Reconnaissance on Your People Goes Undefended. That’s Changing.
Blog

External Identity Security: Reconnaissance on Your People Goes Undefended. That’s Changing.

Table of Contents

Building the dossier file on Sarah used to take an attacker an afternoon. Now it takes 15 minutes, and nobody builds it by hand.

She’s an executive assistant to the CFO of a company with a mature security program, and none of that program can see what’s about to happen, because none of it happens on company infrastructure. Her name went into a queue the moment an attacker found her LinkedIn. From there it runs on its own. A people-search site gives up her home address and her husband’s name for free. A breach dump from 2025 supplies a personal email, a mobile number, and a password she may still be reusing somewhere. Her social accounts fill in the rest, including the charity gala she’s organizing, the week the family spends at the lake every August, and her daughter’s soccer schedule. Out of it comes a working answer to which pretext will land, which number to call, and which story she’d have no reason to doubt.

But, Sarah isn’t the target: her whole company is. The same process runs against every employee at once, files assembling in parallel, each attack ranked and fired in order of how likely it is to work. Nothing touched the network, so nothing fired an alert, and the SOC that watches over Sarah never saw any of it.

Key Takeaways

  • MITRE's T1589 sits at the front of most targeted attacks, yet “cannot be easily mitigated with preventive controls”. Every other technique gets a vendor and a budget line.
  • Attackers target access, not titles. The EA who moves payments, the help desk lead who resets credentials, the finance manager who signs off wires. Internal tools score them low-risk. Attackers score them ideal.
  • Tailored pretexts once took hours, so attackers saved them for a short list. AI made the same targeting nearly free at scale. Starve the exposed data and you starve the attack.

The blind spot has a name

MITRE has a name for what the attacker did. Gather Victim Identity Information, technique T1589 in the ATT&CK framework. The mitigation guidance is unusually blunt for MITRE. The technique “cannot be easily mitigated with preventive controls,” and defenders should focus on minimizing the amount and sensitivity of data available to external parties. When you consider  the rest of the ATT&CK matrix, nearly every technique maps to a control category, a vendor shortlist, and a budget line. T1589 maps to nothing and is responsible for 65% of AI-fueled attacks.

Stages and controls shown are representative, condensed from MITRE ATT&CK’s 14 tactics. The pattern holds across the full matrix.

To be fair, half of reconnaissance does have an answer. Attack surface management watches the technical half: exposed domains, services, and cloud assets. The other half is the research attackers run on your people, and that’s the half MITRE flags as a problem with no solution. It lives at the front of nearly every targeted attack, and it’s the one place where the answer for most security teams to the “what do we have deployed against this” question gets a shrug.

The visibility paradox

Sarah didn’t do anything wrong, and neither did anyone else on the target list. People have to be visible to do their jobs. Executives give keynotes and earnings calls, salespeople live on LinkedIn, and assistants sit in every routing chain the company has. Data brokers, which have detailed personal information on nearly every American, package up their lives without asking for permission. That’s the visibility paradox. You have to be out there to do your job, but the moment you’re out there, you’re reachable. Traditional security stops at the corporate perimeter. The exposure attackers actually use lives past that perimeter, in personal data no firewall can reach.

It’s about privileged access, not titles

For many, their initial instinct is to assume this problem can’t be solved, as MITRE suggests, or to file it as an executive protection problem. But frontier AI models mean that the target list is long. Attackers go after access, and access pools in many places: the assistant who manages the CFO’s calendar and moves payment approvals, the help desk lead who resets credentials fifty times a week, and the finance manager whose sign-off releases a wire are all common examples of people with privileged access to systems, processes, people, or locations. Internal identity security tools score these people as low risk because every internal signal they can see looks healthy. Conversely, an attacker scores the same people as ideal targets, because they’re findable, easy to impersonate, and hold real privilege.

An analysis of 10,000 US executives found nearly all of them already exposed, with cleartext passwords sitting on the dark web, breach histories dozens deep, and a home address one search away. If that’s the state of the most protected people in the company, assume the assistant is worse off.

The playbook is already running

None of this is theoretical. Scattered Spider talked its way into MGM Resorts and Caesars in 2023 by impersonating employees to their own help desks, then spent the following years running the same pretexting play against retailers, insurers, and airlines..Their entry points are phone calls armed with personal details. In 2024, an employee at the engineering firm Arup wired roughly $25 million after a video call with what turned out to be a deepfake of the company’s CFO and several colleagues – all of which were assembled from publicly available material. And in April 2026, attackers socially engineered a single Carnival employee and walked away with personal data on nearly 6 million people.

The 2026 Verizon DBIR ties 35% of breaches to attacks that start with people, through phishing, credential abuse, and pretexting. Vulnerability exploits, where most of the security budget still concentrates, account for 31%. People-based attacks exceed infrastructure based attacks and the stack hasn’t caught up. One side gets patch cycles, scanners, and a market of controls. The other gets an awareness course. 

What AI changed

Generative AI can clone a voice and fake a face for pennies. But, without external identity data, even the best AI models can’t pick a target, dial the right number, or know which pretext story will land. Exposed data fuels these attacks, which is why the DBIR finds 65% of AI-assisted attacks are aimed at people.

AI turns this from an unsolved problem into an urgent one. The constraint that used to protect most employees was attacker effort. A convincing pretext took research, and research took a skilled human hours on each target, so attackers saved the treatment for a short list of high-value targets. Generative AI removed that constraint. The tailored attack that used to be saved for a short list now costs almost nothing to run against an entire workforce. The deepfakes get the headlines, but the targeting data is the fuel, and of the two, the fuel is the only part defenders can take away. You’ll never out-detect every fake, but you can starve the process that aims them.

Why the current solutions fail

The market has offered fragments. Manual removal services supplied by consumer data broker companies file opt-outs one site at a time and lose ground to brokers that repopulate within weeks. Dark web monitoring tells you a credential is stolen and leaves the fixing to someone else. Awareness training coaches people to spot the lure instead of removing what made the lure convincing in the first place. And none of it touches the exposure that can’t be deleted at all. Breach dumps and public records persist no matter who files the paperwork, and that residual risk goes unmeasured, invisible to the SOC and the security controls designed to protect the crown jewels of an organization. 

External Identity Security changes everything 

Minimizing the data available to attackers, the one mitigation MITRE points to, was not a control that was commercially available. Instead, it was a practice defenders  improvised around by processing a stack of opt-out forms, or setting up a hacked-together monitoring feed, or launching an urgent training module focused on a certain problem. None of these solutions are continuous or reliable compensating controls.

EXTERNAL IDENTITY SECURITY
The continuous discovery, reduction, and operational management of the identity exposure employees accumulate outside enterprise systems.

Treat it like any other attack surface and the requirements for a real control are obvious.

Discovery has to run continuously across data brokers, people-search sites, breach and credential dumps, stealer logs, credential markets, social platforms, and public records, because the surface regrows. Removal has to repeat and verify, not file once and hope. Whatever can’t be removed has to be quantified, so residual exposure becomes a number you can track instead of a fear you can’t. And all of it has to produce a signal the SOC can use, because a suspicious login from Sarah should read very differently once you know her credentials surfaced in a stealer log seven days ago. That warning is usually sitting there: the 2026 Verizon DBIR found 73% of ransomware victims had an infostealer infection or credential leak in the year before their attack, half within 95 days.

That control now exists. It’s called external identity security, and it treats reconnaissance the way the rest of the stack already treats later stages: something you defend and measure, not something you shrug at.

“Every other tool defends what a company owns. We defend the one thing a company can’t patch: the public personal data of its people. VanishID’s External Identity Protection takes the attacker’s raw material away continuously, and it protects the people attackers actually target. That list is far longer than the C-suite. It’s anyone whose access makes them worth attacking, or whose authority makes them worth impersonating.”

Matt Polak, CEO, VanishID

We’ve been building this category at VanishID since 2019. External Identity Protection, the first control built to those requirements, made its public debut at Black Hat USA 2026 and is available now. Customers typically see an 85% drop in the personally identifiable information an attacker can reach within the first 90 days.

The fastest way to understand this problem is to see your own people the way attackers do. Pick anyone and we’ll map their live exposure for free, entirely from the outside. Nothing to deploy, nothing to connect. Request a free risk analysis.


SOURCES

MITRE ATT&CK, Gather Victim Identity Information, T1589, Mitigations. attack.mitre.org/techniques/T1589

MITRE ATT&CK, Scattered Spider, G1015. attack.mitre.org/groups/G1015

Verizon, 2026 Data Breach Investigations Report. verizon.com/business/resources/reports/dbir

CISA and FBI, Joint Cybersecurity Advisory AA23-320A, Scattered Spider, updated July 2025. cisa.gov/news-events/cybersecurity-advisories/aa23-320a

CNN Business, “Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee,” May 16, 2024. cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk

Carnival Corporation, Substitute Notice, May 27, 2026. carnivalcorp.com

VanishID, Leadership at Risk in a Data-Exposed World. vanishid.com

Sean Goldstein
Written by

Sean Goldstein

Editor at VanishID

VanishID Protection

Ready to Strengthen Your Digital Security?

Whether you're protecting executives, your workforce, or sensitive family assets, VanishID provides tailored solutions for your unique security needs.

Comprehensive threat assessment
24/7 monitoring and response
Expert security consultation
Custom protection strategies

Copyright © 2019 – 2026 Picnic Corporation (dba VanishID)