Every account, post, photo and leaked record adds up to a picture of you that strangers can find. This guide shows you how that picture gets used against people, how to see your own, and what to keep off the public web.
Your « digital footprint » is not just the stuff you deliberately post. It is everything the internet holds about you: the accounts you opened and forgot, the photos other people tagged you in, the phone number sitting in a leaked database, and the profile a data-broker built and sells without ever asking you.
None of this is about being paranoid or going offline. It is about knowing what is visible, because the same details that feel harmless in isolation are the raw material for scams, account takeovers and, in the worst cases, real-world harm. This guide is for adults and kids alike. Wherever your risk is different from an adult’s, we say so.
1What a digital footprint actually is
Three streams feed it. You control the first one. The other two are mostly out of your hands, which is exactly why they matter.
What you post
Photos, comments, reviews, your bio, who you follow, the places you check in. This is the part you can see and control. It is also the part people most often over-share, because each post feels small.
What other people post about you
Tags, group photos, a friend’s birthday shout-out that names your workplace, a parent posting a first-day-of-school photo in uniform. You did not choose any of it, but it is searchable and it is about you.
Data collected about you
This is the invisible stream, and often the largest:
- Old and breached accounts. Sites you signed up to years ago get hacked, and your email, password, phone number and more end up in databases that circulate freely. Have I Been Pwned tracks over 17.7 billion accounts exposed across more than a thousand breached sites.
- Data brokers and people-search sites. Companies like Spokeo, Whitepages and dozens of others compile your name, age, past addresses, relatives and phone numbers from public records and other sources, then publish it for anyone to look up, often for a few dollars.
- Metadata you cannot see. Photos can carry GPS coordinates and timestamps. A post’s « when and where » can be as revealing as its content.
The honest bottom line: you will never have a full, tidy inventory of everything online about you. The goal is not perfection. It is to shrink the easy-to-find, high-risk stuff and know where to look.
2How bad actors actually use this information
Security professionals call it OSINT: open-source intelligence, the practice of building a profile of a target purely from public information. Attackers do the same thing, aimed at you. Here is how the pieces get used.
Social engineering and spear-phishing
A generic scam email is easy to ignore. A message that names your boss, references a project you posted about, and lands the day you mentioned travelling is not. Security researchers describe LinkedIn and social profiles as a blueprint for building targeted « spear-phishing » that references real people, roles and events. The FBI’s 2024 Internet Crime Report logged 859,532 complaints and a record 16.6 billion US dollars in losses, and fraud built on social engineering makes up the bulk of it.
Guessing passwords, security answers and account recovery
« What was your first pet’s name? » « What street did you grow up on? » « What is your mother’s maiden name? » People post the answers to these without realising. The same public details help attackers pass a company’s account-recovery checks, or convince a mobile carrier to move your number to their SIM card, a SIM-swap. Once your number is theirs, the security codes texted to you go to them, and one after another your accounts fall.
Doxxing, stalking and physical safety
Doxxing is publishing someone’s private details, home address, workplace, phone, to expose or intimidate them. The building blocks are your address from a people-search site, your routine from check-ins, your gym from a tagged photo. For anyone dealing with an abusive ex, a stalker or online harassment, a live location tag or a « we’re on holiday » post is a map. Real-time location is the single most dangerous thing to broadcast.
Sextortion and blackmail
Attackers pose as an attractive peer, build quick rapport, and pressure the target into sending an explicit image, then threaten to send it to family and friends unless paid. The FBI recorded more than 13,000 reports of financial sextortion of minors between October 2021 and March 2023, victims overwhelmingly teenage boys, and is aware of more than 20 related suicides. Paying rarely stops it. The demands escalate.
Identity theft
Full name, date of birth, address and a few account details are enough to open credit, hijack accounts or impersonate you. Older adults are hit hardest in dollar terms: in 2024 the FBI logged nearly 4.9 billion US dollars in losses among people aged 60 and over. A leaked date of birth plus an address, both easy to find, is a large part of what a fraudster needs.
For kids: small details, pieced together
No single post about a child looks dangerous. Put them together and a stranger has a lot: the school crest on a jumper, the sports team and match times, the pet’s name (also a password answer), the daily walk to school, a geotagged birthday photo. That is enough to know where a child will be, when, and to start a conversation that sounds like they already know them. Attackers assemble the mosaic; each parent only ever posts one tile.
3Check what’s online about you
Do this like an attacker would. Set aside 30 minutes and work through the list. You cannot manage what you have not looked at.
- Search your own name. Try it in quotes (« Jane Smith »), with your town, your employer, your school, and any nicknames or a maiden name. Search on more than one engine. Note what a stranger can learn on page one.
- Use Google’s « Results about you. » At myactivity.google.com/results-about-you you can register your name, phone, address and email, get alerts when they appear in Google results, and request removal of results that expose your contact details. Note: Google won’t remove content from government, school or news sites, and availability varies by country.
- Check for breached accounts. Enter your email addresses at haveibeenpwned.com (built by security researcher Troy Hunt) to see which breaches exposed you. Turn on « Notify me » to be warned about future ones, and change the password anywhere you reused a leaked one.
- Reverse image search your photos. Drop your profile picture into Google Lens or TinEye to see where else it appears. Face-search engines such as PimEyes will find your face across the wider web, useful to know it exists, and worth checking whether your own images turn up where you did not expect.
- Look yourself up on people-search sites. Search your name on Spokeo, Whitepages, BeenVerified and similar. Most have an opt-out page (for example spokeo.com/optout). Consumer Reports maintains a plain-English guide to removing yourself from these sites.
- Audit your own accounts. On each platform, open privacy settings and check what is public: posts, friends list, tagged photos, past check-ins. Set old posts to private, review tags, and delete accounts you no longer use rather than leaving them to be breached.
- Turn off photo geotagging. In your phone’s camera and location settings, stop apps from writing GPS into your photos, and think before posting anything that shows your home, street sign or car plate.
4What to publish, and what to keep off the public web
You do not have to disappear. Most of what people share is fine. The trick is knowing the small set of things that should never be public, and posting those, if at all, only to people you trust.
Usually fine
- Interests, hobbies, opinions and general life updates
- Photos after an event or trip, once you are home
- Your city or region, in broad terms
- Professional history you have chosen to make public
- Work you’re proud of, kept free of home and routine details
Think twice, or never public
- Home address, or photos that reveal it (street signs, house number, the view from your door)
- A child’s school combined with their routine or timings
- Real-time location and live check-ins (« here right now »)
- Full date of birth (year included)
- Phone number and personal email in public bios
- Financial details, cards, or « just got paid » screenshots
- Photos of documents: passports, driving licences, boarding passes, tickets with barcodes
- Other people’s information, or their children’s, without consent
The oversharing patterns to watch
- Live-posting your location. Post the holiday photos when you’re back, not while your home sits empty.
- The « answer these fun questions » trend. First car, first pet, street you grew up on, these are security-question answers dressed up as a game.
- Backgrounds that leak. Documents on the desk, a delivery label, a school crest, a screen with a code visible.
- Tagging that widens the circle. A public tag turns a private moment into something searchable by strangers.
5Short notes: for teens, and for parents
Sources
- Google Search Help, Find and remove personal info with « Results about you »
- Have I Been Pwned, check whether your accounts have been in a data breach
- FBI, The Financially Motivated Sextortion Threat
- FBI IC3 2024 Internet Crime Report, summarised by CyberScoop (full report: ic3.gov)
- FBI, Criminals Increasing SIM Swap Schemes
- eSafety Commissioner (Australia), Privacy and your child
- Consumer Reports, How to remove your info from people-search sites
- Mitnick Security, How social engineers use your digital footprint against you