LinkedInThreat Intelligence

Social Engineering Readiness Assessment: How Many Employees Overshare on LinkedIn?

March 28, 2025
Outcome

73% of employees found oversharing; 12 critical information leaks identified; company-wide security awareness training deployed.

Background

A defense contractor preparing to submit a major government contract bid needed to demonstrate a functioning social engineering awareness program. The contracting agency required documented evidence that the organization understood how its own workforce could be targeted through publicly available information. The contractor engaged TraxIntel to assess, using only public sources, how exposed the company was to LinkedIn-based social engineering. The objective was never to surveil employees or evaluate individuals, but to measure the aggregate public footprint an outside actor could assemble without any privileged access, then translate that exposure into concrete, defensible risk the security team could act on.

Investigation Methodology

  1. Public profile census. Working exclusively from information any logged-in visitor could view, we cataloged company-affiliated LinkedIn profiles and recorded the categories of information each disclosed: job titles, project descriptions, technology stacks, building or site locations, and organizational relationships. No connection requests, pretext accounts, or private data were used.
  2. Cross-source corroboration. To confirm that exposures were genuinely public rather than artifacts of a single platform, we checked overlapping open sources against the profile data: the company's own public web pages and press releases, corporate registry filings, conference speaker listings, and open project repositories. Where breach-exposure reference indices flagged that a work email had appeared in a prior public data incident, we noted it as an added reused-credential consideration.
  3. Information sensitivity classification. Every disclosed item was classified against the company's existing information classification policy, separating routine professional detail from content that policy designated as non-public.
  4. Image and metadata review. Profile and post imagery was reviewed for incidental disclosures such as badge designs, interior signage, equipment, or location cues visible in the background of otherwise ordinary photographs.
  5. Attack scenario modeling. Using only the assembled public material, we modeled five realistic social engineering scenarios to demonstrate how disparate, individually harmless facts could be combined into a single credible pretext.

Key Findings

  • 73% of employees shared job titles and project descriptions specific enough to reconstruct the company's internal organizational structure from the outside.
  • 12 employees described classified or sensitive projects in their experience sections, including program code names and technology specifications that policy classified as non-public.
  • From public profile data alone, we assembled the company's reporting hierarchy, identified members of the security team by name, and inferred which buildings housed which programs.
  • 5 employees listed their security clearance levels directly on their profiles.

Each finding was tied back to the specific public artifact that evidenced it, so the security team could independently verify every claim rather than take a summary figure on trust.

Evidence and Sources

The assessment relied entirely on classes of openly accessible material: self-published professional profiles, the organization's own public web presence, corporate registry records, public conference and event listings, and reference indices of previously disclosed breach data. Photographic evidence was treated as corroborating rather than primary, and each aggregate figure traces back to enumerable individual observations. No finding depended on non-public correspondence, paid data brokers, or any access an ordinary member of the public would not have.

Limitations and Review Notes

Public-source exposure is a moving target: profiles change, and this assessment reflects a point-in-time snapshot, not continuous monitoring. Coverage is bounded by what individuals chose to publish, so the absence of a finding is not evidence of security. Automated collection surfaces candidate exposures, but a human analyst reviewed every classification, discarded false matches, and confirmed that flagged content genuinely conflicted with policy. Critically, this review measures aggregate public exposure and pretext feasibility only; it does not establish that any attack occurred, that any individual acted improperly, or that any system was accessed.

Outcome

A company-wide LinkedIn security policy was established and mandatory awareness training was deployed to all employees. The 12 critical information leaks were addressed through individual meetings focused on remediation rather than blame. The assessment results were included in the government contract bid as documented evidence of a working security awareness program, giving the agency a defensible basis to judge the contractor's posture. Total investigation time: 3 weeks.