$5M Identity Theft Insurance ·Now included with Hush. Learn more

Vulnerability Types

What is a Vulnerability?

A vulnerability is information that can be used to target you, your family or your organization.

At Hush, we look for:

  • Banking challenge answers

  • Personally Identifiable Information

  • Home addresses and photos

  • Children

  • Controversy

  • Sex and nudity

  • Social media accounts

  • Luxury assets

  • Tone-deaf luxury travel

  • "Not home" posts

  • Profanity

  • Alcohol and drugs

  • Negative news

  • AI search engine results

Some are direct vulnerabilities. A publicly available home address, personal phone number or banking challenge answer should not be public.

Others depend on context. A photograph, social post or old news story may be harmless on its own but useful as part of an attack.

Hush looks at both.

More importantly, we look at how vulnerabilities connect.

From vulnerability to attack chain

Security teams use the term attack chain to describe the steps an attacker takes to reach an objective.

MITRE ATT&CK, one of the frameworks commonly used by security teams to understand adversary behavior, includes activities such as reconnaissance, resource development, initial access and credential access.

Personal targeting follows the same basic pattern.

Consider an executive whose information is spread across public records, data brokers and social media:

  • A home address identifies the residence.

  • Property records identify a spouse.

  • Social media identifies children and other relationships.

  • Posts reveal travel and routines.

  • A personal phone number provides a direct channel.

  • Public interviews provide voice and video.

  • Professional information identifies bankers, attorneys, colleagues and other trusted relationships.

An attacker can use those pieces together for impersonation, social engineering, account takeover, financial fraud, extortion, reputational attacks or physical targeting.

Hush does not only ask whether a piece of information is exposed. We ask what attack chains it enables.

AI changes the economics of targeting

This is becoming substantially more important because attacker reconnaissance, target selection and engagement can now be AI-led.

Historically, targeting an executive well required time.

An attacker had to search multiple sources, identify the correct person, reconcile conflicting records, map family and professional relationships, understand context, and then construct a credible approach.

AI can automate much of that work.

An AI-enabled attacker can increasingly:

  • Search and summarize large amounts of public information.

  • Correlate information across many sources.

  • Identify attractive targets based on wealth, position or exposure.

  • Map family and professional relationships.

  • Identify likely vulnerabilities.

  • Generate personalized phishing and social-engineering approaches.

  • Adapt messages using information about the target.

  • Produce convincing voice, image and video impersonations.

  • Conduct many of these activities simultaneously across large target populations.

The result is not necessarily a new type of attack.

It is a major reduction in the cost of conducting a good one.

Reconnaissance that previously justified significant effort only for a very valuable target can increasingly be performed automatically.

Target selection can increasingly be automated.

Engagement can increasingly be personalized at scale.

That changes the risk calculation for executives and other high-value individuals.

Public information is now easier to operationalize

There has always been information about people on the internet.

The difference is how easily it can be turned into intelligence.

A human researcher might see hundreds of disconnected search results.

An AI system can be asked:

Who is this person? Where do they live? Who is in their family? What assets are associated with them? Where do they travel? Who do they work with? What organizations do they trust? What personal information could be useful for identity verification? What recent event would make a particular request believable? What is the best way to contact them?

Not every answer will be correct. For an attacker, it does not need to be.

AI can generate hypotheses, rank targets and identify promising paths. The attacker can validate the most useful information before acting.

This is why obscure information matters more than it used to.

The cost of finding and connecting it is falling.

The threat actor determines how the information is used

Different attackers want different things.

A fraudster may need enough personal information to pass identity verification.

A social engineer may want family, colleagues, communication patterns and current events to make an impersonation credible.

An organized criminal group may map an executive's financial relationships before attempting payment fraud.

A physically motivated actor may care about residences, vehicles, children and travel.

A reputational adversary may look for old posts, photographs, disputes or controversies.

Hush considers these different threat models when assessing exposure.

What the vulnerability categories mean

  • Banking challenge answers. Former addresses, family names, schools, pets, dates and other facts can support identity verification, account recovery and impersonation.

  • Personally Identifiable Information. Personal emails, phone numbers, dates of birth, government identifiers and related information can support phishing, identity fraud and account takeover.

  • Home addresses and photos. A publicly available home address is always a vulnerability. It connects a person's identity to a physical location and can lead to property information, family members, vehicles, wealth indicators and routines. Photos can provide additional physical and contextual intelligence.

  • Children. Children's names, schools, activities, accounts and locations expose relationships and routines. Family members can also create lateral paths to an executive. Hush therefore treats household exposure as part of the protection problem.

  • Controversy. Litigation, disputes, public statements and other controversial material can create reputational risk or provide useful context for social engineering.

  • Sex and nudity. Exposure can create risks involving extortion, non-consensual distribution, impersonation and synthetic media.

  • Social media accounts. Social media provides relationship, location, behavioral and photographic intelligence.

  • Luxury assets. Homes, aircraft, boats, vehicles and other assets can signal wealth, aid target selection and reveal locations or service providers.

  • Tone-deaf luxury travel. Travel content can create reputational exposure when viewed in the context of layoffs, restructuring, litigation or other sensitive events.

  • "Not home" posts. Travel posts establish absence from a residence and can create both physical-security and fraud opportunities.

  • Profanity. Historic public content can become relevant during transactions, appointments, litigation or periods of increased scrutiny.

  • Alcohol and drugs. Public material may create professional, reputational or coercive risk depending on context.

  • Negative news. Negative coverage affects reputation and can provide an attacker with information about disputes, counterparties and current pressure points.

  • AI search engine results. We care about what AI systems say about a client because attackers can use the same tools. What matters is not only what information exists online, but what an AI system can assemble from it quickly.

How Hush assesses vulnerability

We use a straightforward set of questions:

  • What is exposed?

  • Is it accurate?

  • Who could use it?

  • What could they use it for?

  • What other information can it be combined with?

  • What attack chain does that create?

  • How does AI make that attack easier, cheaper or more scalable?

  • What can we remove or reduce?

This requires looking beyond the executive.

Spouses, children and household members often expose the same addresses, travel patterns and personal networks relevant to targeting the principal.

It also requires looking beyond traditional search. Public records, data brokers, social networks, images, video, audio, news and AI-generated search results can all contribute to the same attack chain.

Why Hush goes this deep

The enterprise may be well protected while the people who control it remain highly visible.

Attackers do not have to attack the strongest part of the security stack.

They can attack the person.

They can attack the family.

They can impersonate a trusted relationship.

They can use public information to make an otherwise suspicious interaction credible.

Hush's job is to identify those vulnerabilities, understand how they could be used and remove or reduce them before they become part of an attack.

As AI reduces the cost of reconnaissance and personalized targeting, the amount of exploitable information available about a person matters more.

Our objective is straightforward: give the attacker less to work with.

Was this article helpful?

Still have questions?

Our Member Services team is available to assist you. hello@gohush.com or +1 (866) 806-0932