About UsMembershipMarketplaceResourcesGlobal Business Atlas
Top AI CompaniesTop Blockchain Influencers & AuthorsTop Global Digital AgenciesBusinessabc Country IndexesTop Accelerators and Chambers of CommerceTop Public Companies by MarketcapBusinessabc Education IndexesTop Malaysian Companies
DirectoryCompaniesLeadersInvestorsUniversitiesOrganisations
Loading article…

Businesses

Businesses Face Rising Fraud Risk as Employees Overshare on Social Media

Sara Srifi

23 Sept 2026

Businesses Face Rising Fraud Risk as Employees Overshare on Social Media

More than 80% of employees are reported to overshare online, potentially giving criminals the details they need to impersonate staff, build convincing phishing attacks and target company systems.

23 September 2026 — Businesses are being urged to treat employees’ social media activity as part of their wider cybersecurity strategy, as everyday posts can reveal enough information for criminals to impersonate staff, design targeted scams and expose sensitive details about company operations.

The warning comes from John Pepper, CEO and founder of Managed247, who says employees may unintentionally provide attackers with names, job titles, workplaces, colleagues, clients and professional responsibilities through personal social media accounts. When combined, those details can help fraudsters build a more convincing picture of how an organisation operates and who they should target.

The risk is increasing against a wider backdrop of rising identity fraud. Cifas recorded more than 220,000 fraud-risk cases on the UK National Fraud Database during the first half of 2026, with identity fraud accounting for 59% of the total. Cifas also reported that identity fraud rose 9% year on year to nearly 130,000 cases, while account takeover incidents increased by 5%. 

Social media can make impersonation easier

A social profile can reveal much more than an employee may realise. A job title can show where someone sits in the organisation, tagged colleagues can expose reporting lines, while photographs from offices or events can give attackers clues about internal systems, suppliers or customers.

Pepper warns that these small pieces of information become more dangerous when they are combined.

Employees can unintentionally give criminals a lot of useful information about themselves and the people they work with,” he said. “When those details are brought together, it can make it much easier for someone to convincingly impersonate a colleague or senior member of staff.

For businesses, that can translate into fraudulent requests for payments, access credentials or confidential information.

A criminal does not necessarily need to compromise a corporate system first. They may instead use publicly available information to convince an employee that a message is genuine.

Social engineering becomes more credible with context

The more attackers know about an organisation, the easier it becomes to make phishing or social-engineering messages look legitimate.

An employee posting about a new role, recently signed client, business trip or project can unintentionally provide the context needed for a highly targeted approach. A criminal might reference that information in an email appearing to come from a manager, supplier or colleague.

This makes verification processes increasingly important.

Pepper recommends that unusual requests involving money, system access or confidential information should be checked through a second trusted communication channel before employees take action.

For companies, this means training should extend beyond identifying obvious phishing emails. Employees increasingly need to understand how criminals use public information to remove the warning signs that traditionally made scams easier to spot.

AI is raising the stakes for employee impersonation

Generative AI has added another layer of risk.

Publicly available photographs, video and audio can be used to create synthetic content that imitates employees or executives. Voice-cloning tools can now reproduce a person’s voice from very short audio samples, while generative-image and video systems can make impersonation attempts more visually convincing.

The practical business risk is not the technology itself but how it can reinforce an already credible scam.

A criminal who knows the name of a finance director, their current project and who reports to them can potentially combine those details with synthetic voice or imagery to create a much more persuasive request.

That puts greater emphasis on internal processes rather than simply trusting a message because it appears to come from the right person.

Businesses can respond by requiring additional verification for high-value payments, password resets and access requests, especially when communications arrive unexpectedly or create artificial urgency.

Everyday workplace photos can expose more than intended

The risks extend beyond names and job titles.

Photos taken inside an office can inadvertently reveal security arrangements, access badges, documents, screens, equipment or physical entry points. Posts about new software systems, suppliers, locations or upcoming projects can also provide useful intelligence to attackers or competitors.

Even an otherwise harmless celebration of a new contract can reveal information before the business intended to make it public.

Pepper said the risk often comes from accumulated detail rather than a single major disclosure.

A photo from the office, a post about a new client or even an update about an upcoming project could give someone outside the organisation a better understanding of how that business operates.

This makes digital awareness particularly important for companies whose staff regularly post about their professional lives on LinkedIn, Instagram, TikTok and other public platforms.

Reputation is another business risk

Oversharing is not only a cybersecurity problem.

Employees who publicly list their workplace or discuss professional activity can be perceived as representatives of their employer, even when posting in a personal capacity.

Content that appears harmless in isolation can still affect how customers, colleagues, investors or prospective employees view the organisation.

That creates a reputational challenge for businesses trying to balance employee freedom with brand protection.

A practical social-media policy can help by defining which categories of information should never be posted publicly, while avoiding unnecessarily restrictive rules around ordinary personal use.

The objective is not to prevent employees from discussing work altogether, but to make them aware of how information can travel beyond its intended audience.

Cybersecurity increasingly starts with people

The findings reflect a broader change in cybersecurity risk.

Businesses have invested heavily in endpoint protection, identity security, email filtering and monitoring, but attackers continue to target people because human trust remains one of the easiest ways into an organisation.

Managed247 describes cyber security as a combination of endpoint, identity, email, awareness and compliance controls rather than a single technology product. Its security model combines 24/7 monitoring with investigation and response, mapped against frameworks including Cyber Essentials Plus and ISO 27001.

That layered model is increasingly relevant because social-media exposure sits outside the conventional corporate network.

An organisation may have strong technical defences but still be vulnerable if employees publish enough information for an attacker to construct a convincing identity or business pretext.

What businesses can do

Companies do not need to eliminate social media use to reduce risk. A more practical approach is to make employees aware of the types of information attackers value and build verification into business processes.

This can include reviewing what job and organisational details are publicly visible, encouraging staff to check photos before posting, limiting disclosure of confidential projects or client relationships and requiring independent verification for unusual financial or access requests.

Domain-security controls can also help reduce impersonation attacks that use a company’s name or email infrastructure. Managed247 notes that technologies such as DMARC, DKIM and SPF can help prevent attackers from spoofing legitimate domains, although these measures do not eliminate the risk of social engineering through personal accounts or lookalike domains. 

The broader principle is simple: technical controls and employee awareness need to work together.

As Pepper puts it, businesses should encourage staff to “take a second before posting” and consider whether anything in an image or caption provides outsiders with information they would rather keep internal.

About Managed247

Managed247 is a UK managed IT and cybersecurity provider offering services across managed IT, cloud, cyber security and consultancy. Its cybersecurity services include 24/7 monitoring, endpoint and identity protection, email security, awareness, compliance and incident response. 

Previous

How Canadian Handcrafted Jewelry Design Is Changing Modern Bridal Aesthetics

Next

Nearly One in Three UK Workers Lack Confidence Using Spreadsheets, Adobe Study Finds

Share

Sara Srifi

Sara Srifi

Sara is a Software Engineering and Business student with a passion for astronomy, cultural studies, and human-centered storytelling. She explores the quiet intersections between science, identity, and imagination, reflecting on how space, art, and society shape the way we understand ourselves and the world around us. Her writing draws on curiosity and lived experience to bridge disciplines and spark dialogue across cultures.

Read more

More Articles

article cover

1.9 Million UK Buildings Require Urgent Energy Efficiency Overhaul

article cover

#1 Cosmetic Dentist in New York City – Dr. Pia Lieb from Cosmetic Dentistry Center NYC (2026)

article cover

1 in 3 Big Business Audits Fail to Meet UK Standards - FRC Reveals as KPMG is Fined £13 Million

article cover

10 Benefits of Using Church Accounting Software

article cover

10 Benefits of Using Online Volunteer Scheduling Tools

article cover

10 Benefits of Using WordPress to Power Your Website

Logo

Businessabc provides digital business directory, digital blockchain AI certification, resources, and marketplace for businesses, organisations, and professionals.

Contacts

Email
Contact

Follow Us

Created Produced

Partner logo
Partner logo

Tech AI Media Platforms

Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo

Copyright 2026 © Businessabc powered by

Powered by ztudium group

DisclaimerPrivacy PolicyTerms of Service
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo
Partner logo