Security Threats Don’t Stop at the Office: Why Executives’ Families Need Training Too
Those closest to executives must match their security postures because the weakest link in a family becomes the entry point for attacks.
Those closest to executives must match their security postures because the weakest link in a family becomes the entry point for attacks.
An attacker attempts to breach an executive’s personal laptop, but effective multifactor authentication (MFA) blocks them. Actually, it was only a deterrent, because the attacker discovers the executive’s son did not enable MFA on his gaming console, and uses that access to move laterally, eventually breaking into the corporate network.
Cybercriminals’ increasingly brazen techniques have expanded beyond the office walls to target top executives’ family members and friends who may not know how to protect themselves— worse yet, they don’t even see it coming. While leadership receives ongoing security awareness training on password hygiene, and how to look out for signs of phishing and vishing, that still leaves those closest to them vulnerable, creating a dangerous blind spot for organizations, and artificial intelligence (AI) now offers bad actors new tools to exploit it.
In March, Google Cloud’s Office of the CISO warned that personal attacks against executives are on the rise. Authors urged boards to consider how they are supporting executives and their families in implementing effective social media settings, knowing attackers routinely use that avenue for reconnaissance.
Attacks abusing those relationships always start with reconnaissance, due to everyone’s enormous digital footprint. Eerily, an attacker can map out a household’s relationships, routines, and locations without ever touching a network, warns Brian Hill, field chief information security officer (CISO) of client advisory at BlackCloak.
From there, attacks branch out into three categories: impersonation, compromising the household’s devices, and phishing or smishing—a tactic aimed at less technical family members.
However, the consequences aren’t just digital, Hill warns. A leaked itinerary or home address can turn into physical surveillance, a break-in, or extortion.
“Even something as harmless as a child’s school play on a shared calendar can give an attacker exactly the timing they need for a fraudulent wire request,” Hill tells Dark Reading.
It May Not Be New, But It Works
The tactic of using executives’ confidants to conduct social engineering campaigns, assist with account takeovers, or to provide clues that help an attacker guess passwords is not a new phenomenon.
In 2023, BlackCloak and Ponemon Institute released a study titled, “Understanding the Serious Risks to Executives’ Personal Cybersecurity & Digital Lives” where 42% of respondents said, “their key executives and family members already experienced at least one attack by a cybercriminal.”
That same year, Dragos disclosed that it blocked a ransomware attack where a threat actor contacted family members after one of its executives ignored ransom demands. The problem was further highlighted by Mandiant’s CTO, Charles Carmakal, at RSA Conference 2024 where he warned that cybercriminals engaged in SIM swapping attacks against executive’s children. Attackers used that access to contact executives, adding pressure on ransomware victims to give into payment demands, according to a KnowBe4 blog post.
The latest research from Ponemon and BlackCloak showed that 51% of organizations reported attacks on their business leaders in 2025, up from 43% in 2023, reveals Hill. In the cybersecurity and digital privacy company’s own onboarding of new clients, 39% of executives had devices that were already compromised without their knowledge, and 20% had unmonitored, open-access home networks.
“Every one of those gaps is shared with the people they live with,” Hill says. Targeting family members “is not only common, it is one of the most predictable paths an attacker will take.”
Bad actors have always been opportunistic, and nobody is off the table when it comes to using family or friends to get to a [very important person] VIP, warns Erich Kron, CISO advisor at KnowBe4.
Executive-targeted social engineering, known as “whaling”, has been around for quite some time, he adds, explaining that threat actors target someone close to the executive to exploit their family’s or friend’s trust and relationship, while trying to harvest sensitive data.
“Family members and friends tend to be less trained and less protected than high-level executives, therefore it is easier for cybercriminals to earn their trust and perform malicious actions,” Kron tells Dark Reading.
The Less Information, the Better
AI is compounding the problem, especially when it comes to reconnaissance. Threat actors can scan social media platforms or public records seven times faster versus doing manual reconnaissance. That allows attackers to identify family and friends far easier than before, Kron warns.
NCC Group has tracked the trend over the years, and what is important to remember is that that attackers don’t necessarily view someone’s personal and professional lives as separate, reveals Matt Hull, vice president of cyber intelligence and response at NCC Group.
They look for whatever information gives them an opportunity, Hull adds. Details that appear harmless like interests, hobbies, or even fitness and location-based services such as Strava can potentially reveal routines, or patterns of behaviors, he warns,
“NCC Group has previously described how cybercriminals tend to target people based on the information they can gather, rather than beginning with a fixed method of attack,” Hull tells Dark Reading.
Although an indirect attack, like compromising an executive’s loved one or executive assistant, increases the number of actions that may fail, it actually increases the likelihood of success, explains Jeremy Banon, The Cyber Health Company CEO and founder.
“The last 12 months, we have seen this pick-up significantly,” Banon tells Dark Reading.
Tips and Tricks
Addressing the challenge begins by acknowledging the reality, says Banon, adding how important it is for relatives to tighten their security postures because “hopping from vulnerable family member to the eventual target is easier than ever.”
While the top advice is to reduce digital footprints, that’s nearly impossible these days. But there are steps people can take toward that direction.
Regarding social media accounts, remove legal names from usernames and profile photos. Same is true for WhatsApp, Apple contact cards, and personal emails, adds Banon, who emphasizes that “aliases are your friend.”
Excellent password management and MFA adoption means ideally don’t use SMS, which attackers can intercept and abuse, and ensure SIM swap protection for the entire family.
Some social media accounts and experts promote the idea of crafting and using family safe words to prove legitimacy, but Banon is skeptical.
“I don’t think they’re harmful, but I’m pessimistic this works,” Banon says. “If you text your safe word once, it’s burned. Then you need a new safe word.”
Family members must be mindful of podcasts or social videos they create because attackers can abuse just a few seconds to conduct impersonation scams, cloning the voice and calling the spouse with an urgent request, explains Hill.
Less technically inclined family members need to be aware of QR code lures, fake delivery notices, and messages impersonating banks or schools. If attackers control their accounts, they can access family chats, calendars, and email threads that contain travel plans, financial details, and business information.
“Encourage family and friends to learn about scams and how modern cyberattacks work so they can quickly identify and ignore or report social engineering attempts,” Kron advises. “In our modern digital world, just knowing someone important can put you on a much more targeted list.”