Your Digital Footprint

Every account, post, photo and leaked record adds up to a picture of you that strangers can find. This guide shows you how that picture gets used against people, how to see your own, and what to keep off the public web.

Your « digital footprint » is not just the stuff you deliberately post. It is everything the internet holds about you: the accounts you opened and forgot, the photos other people tagged you in, the phone number sitting in a leaked database, and the profile a data-broker built and sells without ever asking you.

None of this is about being paranoid or going offline. It is about knowing what is visible, because the same details that feel harmless in isolation are the raw material for scams, account takeovers and, in the worst cases, real-world harm. This guide is for adults and kids alike. Wherever your risk is different from an adult’s, we say so.

1What a digital footprint actually is

Three streams feed it. You control the first one. The other two are mostly out of your hands, which is exactly why they matter.

What you post

Photos, comments, reviews, your bio, who you follow, the places you check in. This is the part you can see and control. It is also the part people most often over-share, because each post feels small.

What other people post about you

Tags, group photos, a friend’s birthday shout-out that names your workplace, a parent posting a first-day-of-school photo in uniform. You did not choose any of it, but it is searchable and it is about you.

Data collected about you

This is the invisible stream, and often the largest:

  • Old and breached accounts. Sites you signed up to years ago get hacked, and your email, password, phone number and more end up in databases that circulate freely. Have I Been Pwned tracks over 17.7 billion accounts exposed across more than a thousand breached sites.
  • Data brokers and people-search sites. Companies like Spokeo, Whitepages and dozens of others compile your name, age, past addresses, relatives and phone numbers from public records and other sources, then publish it for anyone to look up, often for a few dollars.
  • Metadata you cannot see. Photos can carry GPS coordinates and timestamps. A post’s « when and where » can be as revealing as its content.

The honest bottom line: you will never have a full, tidy inventory of everything online about you. The goal is not perfection. It is to shrink the easy-to-find, high-risk stuff and know where to look.

2How bad actors actually use this information

Security professionals call it OSINT: open-source intelligence, the practice of building a profile of a target purely from public information. Attackers do the same thing, aimed at you. Here is how the pieces get used.

The key point: attackers rarely need to « hack » anything first. They gather the details you and others already made public, then use them to sound convincing, guess your answers, or convince a company that they are you. Your footprint is the starting weapon, not an afterthought.

Social engineering and spear-phishing

A generic scam email is easy to ignore. A message that names your boss, references a project you posted about, and lands the day you mentioned travelling is not. Security researchers describe LinkedIn and social profiles as a blueprint for building targeted « spear-phishing » that references real people, roles and events. The FBI’s 2024 Internet Crime Report logged 859,532 complaints and a record 16.6 billion US dollars in losses, and fraud built on social engineering makes up the bulk of it.

Guessing passwords, security answers and account recovery

« What was your first pet’s name? » « What street did you grow up on? » « What is your mother’s maiden name? » People post the answers to these without realising. The same public details help attackers pass a company’s account-recovery checks, or convince a mobile carrier to move your number to their SIM card, a SIM-swap. Once your number is theirs, the security codes texted to you go to them, and one after another your accounts fall.

Doxxing, stalking and physical safety

Doxxing is publishing someone’s private details, home address, workplace, phone, to expose or intimidate them. The building blocks are your address from a people-search site, your routine from check-ins, your gym from a tagged photo. For anyone dealing with an abusive ex, a stalker or online harassment, a live location tag or a « we’re on holiday » post is a map. Real-time location is the single most dangerous thing to broadcast.

Sextortion and blackmail

Hits teens hardest

Attackers pose as an attractive peer, build quick rapport, and pressure the target into sending an explicit image, then threaten to send it to family and friends unless paid. The FBI recorded more than 13,000 reports of financial sextortion of minors between October 2021 and March 2023, victims overwhelmingly teenage boys, and is aware of more than 20 related suicides. Paying rarely stops it. The demands escalate.

Identity theft

Full name, date of birth, address and a few account details are enough to open credit, hijack accounts or impersonate you. Older adults are hit hardest in dollar terms: in 2024 the FBI logged nearly 4.9 billion US dollars in losses among people aged 60 and over. A leaked date of birth plus an address, both easy to find, is a large part of what a fraudster needs.

For kids: small details, pieced together

Under-18s

No single post about a child looks dangerous. Put them together and a stranger has a lot: the school crest on a jumper, the sports team and match times, the pet’s name (also a password answer), the daily walk to school, a geotagged birthday photo. That is enough to know where a child will be, when, and to start a conversation that sounds like they already know them. Attackers assemble the mosaic; each parent only ever posts one tile.

3Check what’s online about you

Do this like an attacker would. Set aside 30 minutes and work through the list. You cannot manage what you have not looked at.

  • Search your own name. Try it in quotes (« Jane Smith »), with your town, your employer, your school, and any nicknames or a maiden name. Search on more than one engine. Note what a stranger can learn on page one.
  • Use Google’s « Results about you. » At myactivity.google.com/results-about-you you can register your name, phone, address and email, get alerts when they appear in Google results, and request removal of results that expose your contact details. Note: Google won’t remove content from government, school or news sites, and availability varies by country.
  • Check for breached accounts. Enter your email addresses at haveibeenpwned.com (built by security researcher Troy Hunt) to see which breaches exposed you. Turn on « Notify me » to be warned about future ones, and change the password anywhere you reused a leaked one.
  • Reverse image search your photos. Drop your profile picture into Google Lens or TinEye to see where else it appears. Face-search engines such as PimEyes will find your face across the wider web, useful to know it exists, and worth checking whether your own images turn up where you did not expect.
  • Look yourself up on people-search sites. Search your name on Spokeo, Whitepages, BeenVerified and similar. Most have an opt-out page (for example spokeo.com/optout). Consumer Reports maintains a plain-English guide to removing yourself from these sites.
  • Audit your own accounts. On each platform, open privacy settings and check what is public: posts, friends list, tagged photos, past check-ins. Set old posts to private, review tags, and delete accounts you no longer use rather than leaving them to be breached.
  • Turn off photo geotagging. In your phone’s camera and location settings, stop apps from writing GPS into your photos, and think before posting anything that shows your home, street sign or car plate.
Make it a habit, not a one-off. New breaches happen, brokers re-list you after you opt out, and new photos get tagged. Re-run the top three checks, name search, Have I Been Pwned, and one people-search site, a couple of times a year.

4What to publish, and what to keep off the public web

You do not have to disappear. Most of what people share is fine. The trick is knowing the small set of things that should never be public, and posting those, if at all, only to people you trust.

Usually fine

  • Interests, hobbies, opinions and general life updates
  • Photos after an event or trip, once you are home
  • Your city or region, in broad terms
  • Professional history you have chosen to make public
  • Work you’re proud of, kept free of home and routine details

Think twice, or never public

  • Home address, or photos that reveal it (street signs, house number, the view from your door)
  • A child’s school combined with their routine or timings
  • Real-time location and live check-ins (« here right now »)
  • Full date of birth (year included)
  • Phone number and personal email in public bios
  • Financial details, cards, or « just got paid » screenshots
  • Photos of documents: passports, driving licences, boarding passes, tickets with barcodes
  • Other people’s information, or their children’s, without consent

Permanence is the rule, not the exception. « Disappearing » messages and Stories can be screenshotted, saved and re-shared before they vanish. Anything you send can be forwarded. Assume that what you post could be public, permanent, and copied, and decide with that in mind. The pause before you hit « post » is your best security control.

The oversharing patterns to watch

  • Live-posting your location. Post the holiday photos when you’re back, not while your home sits empty.
  • The « answer these fun questions » trend. First car, first pet, street you grew up on, these are security-question answers dressed up as a game.
  • Backgrounds that leak. Documents on the desk, a delivery label, a school crest, a screen with a code visible.
  • Tagging that widens the circle. A public tag turns a private moment into something searchable by strangers.

5Short notes: for teens, and for parents

If you’re a teen or younger: the people who cause the most harm online are good at seeming friendly and in a hurry. If a new « friend » quickly steers things toward photos, money, or your location, that is the warning sign, not a coincidence. Never feel you have to send an image because someone pressured or flattered you into it, and if someone threatens to share something, do not pay and do not go silent. Tell a trusted adult straight away. This is a scam that works on smart people, and you will not be in trouble for reporting it.
For parents, on « sharenting »: your child’s footprint starts with you. The eSafety Commissioner notes some children have around a thousand images online by age five, none of it their choice. Before you post: avoid school uniforms and location tags, skip real-time « we’re at… » updates, don’t name their school alongside their routine, and turn off photo geotagging. For grandparents and close friends, a private message or shared album beats a public post. As kids get older, ask them before you share, it teaches consent, and it is their footprint too.

Sources