7 WAY SECURITY

7 WAY SECURITY

(+57) 3007265036
Email: [email protected]

7WAY SECURITY
Bogotá, Cra 49 # 128B - 31 - My desk - Of. 201

GET IN TOUCH WITH ONE OF OUR EXPERTS: 3007265036
  • HOME
  • ABOUT US
  • SECTORS
    • FINANCIAL
    • ENERGY
    • TELECOMMUNICATIONS
    • HEALTH
    • TRANSPORT
  • SERVICES
    • OFFENSIVE
      • Ethical Hacking
      • Red Team Testing plans
      • 7Way Ops
      • Pentesting on Demand
      • Anguilla
      • Certified Testing
    • DEFENSIVE
      • Training
    • INTELLIGENCE
      • Cattleya
      • Threat Hunting
    • INCIDENT RESPONSE
      • Incident Response
      • Digital Investigations
      • CSIRT 711
    • CONSULTANCY
      • Black Team
  • JOIN THE TEAM
    • Supply Network Team
    • Offer Blue Team
    • Offer Black Team
    • Offer Orange Team
    • Offer Green Team
    • Offer Practitioners
    • Offer Gray Team
    • Offer White Team
  • PRICES
  • CONTACT
  • BLOG
  • Home
  • Cybersecurity
  • Digital Footprint of Executives: OSINT-Based Assessment and Risk Control
June 3, 2026

Digital Footprint of Executives: OSINT-Based Assessment and Risk Control

2
Gray Team
Gray Team
Thursday, 02 October 2025 / Published in Cybersecurity, Threat Intelligence, Security monitoring, Defensive Security

Digital Footprint of Executives: OSINT-Based Assessment and Risk Control

Huella_digital_de_ejecutivos_riesgos_y_protección_con_OSINT_7way_security

Scams and impersonations are constantly evolving. Attackers take advantage of publicly available data and, through social engineering, manage to carry out fast, cheap, and highly effective fraud.

Executives (CEO, CISO, CFO, VP) are top-priority targets for social engineering and 👉all types of phishing. efore launching an attack, threat actors collect large amounts of publicly accessible information: emails, phone numbers, calendars, travel details, photos, suppliers, assistants, technologies in use, relatives, and even credentials. We call this the OSINT footprint.

The attacker’s first goal is to earn your trust. While doing so, they validate and cross-check data from open sources such as:

  • SOCMINT (social media intelligence),
  • IMINT (imagery and metadata),
  • GEOINT (geolocation, events, travel),
  • FININT (financial and payment traces).

Common scams include:

  • New boss/supplier number: request to change the bank account “just for today.”.
  • Urgency + confidentiality: “don't tell anyone”, “resolve this immediately”.
  • Impersonation with real details: mentioning your hotel, event, or meeting (taken from social media).
  • 6-digit codes / QR tricks: attempts to hijack WhatsApp or authorize payments.
  • Audio/video (sometimes AI-generated deepfakesused to reinforce credibility.
  • Fake groups with “colleagues” and “suppliers” (bots) supporting the scam narrative.

Recent scams observed in Colombia and Latin America:

  • The first scheme is a financial fraud modality known as the “M&A Worldwide Scam” previously reported by our cyber-intelligence service Cattleya. In this attack, cybercriminals impersonate senior executives (e.g., CEO/CFO) to induce transfers, request bank account changes, and obtain payment approvals outside protocol, primarily through WhatsApp numbers with stolen photos of the impersonated individuals.
OSINT_1
  • The second scheme is impersonation assisted by “bots” for data extraction. The attack begins with a phone call where the actor poses as a financial advisor and warns of transactions in a different city than that of the account holder. Using real data previously collected to build trust, they then redirect the victim to a supposed “official bank chatbot” on WhatsApp. There, they request OTP, codes, credentials, card data, or redirect to phishing sites, completing the fraud.
OSINT_2

When facing a possible scam, the main question is: how did they get my data? Remember, scammers often come armed with real information about the victim (job title, schedule, suppliers, family) to build credibility. The key is to reduce your exposure level on social media and online.

Quick recommendations:

  • Privacy on social media: control who can see your posts, photos, and contact list.
  • Searches of your own footprint (“Google dorking”).
    • Search for your name and job title in quotes: “Name, Lastname” AND “Company“. Search alias/mail/phone number.
    • Check if your ID appears in public documents and, if possible, request removal.
  • Avoid posting sensitive information online: no desk photos, screens, QR codes, itineraries, or visible documents.
  • Don’t reuse the same alias/username across platforms; vary usernames and, ideally, emails for registrations.
  • Use a password manager (KeePassXC); and update all accounts periodically.
  • Check if your emails are in data leaks and change any reused password; activate 2FA.
  • Check if your emails appear in data breaches and change any reused password (Haveibeenpwn). Enable 2FA/MFA and review active sessions and connected apps.

👉At Cattleya, we provide VIP Monitoringan exclusive service for executives and high-profile individuals that measures and reduces their public footprint and impersonation risks.

We continuously analyze open sources centered on the individual:

• Social networks
• Messaging apps (public indicators)
• Mentions in media/forums
• Audiovisual content (photos and videos)

Our goal is to identify sensitive data (routines, locations, close circles, aliases, communication styles) that can be exploited in fraud.

For each executive, we generate a personalized exposure report and risk list (identities/aliases, social networks, credentials). We deliver tailored recommendations, immediate alerts for critical events such as information leaks, and a monthly progress report showing exposure reduction.

Monitor your digital assets in real-time . Get results from day one: stay ahead of fraud, impersonation, data leaks, and malicious activities across the Clear, Deep, and Dark Web with the platform that 👉protects leading brands in the financial sector.

Gray Team

Jerome Echeverri – @n0r37urn

Gray Team

Share the knowledge:
Tagged under: CEO, CFO, CISO, fingerprint, OSINT footprint, risks, VP

What you can read next

Es_vulnerable_tu_IA?_riesgos_del_prompt_Injection_y_más
Is your AI vulnerable? Risks of prompt Injection and more...
migración de infraestructura TI — 5 pasos para modernizarla
Is Your Infrastructure Already Migrated? 5 Steps to Modernize It
Suplantaciones_en_latinoamerica_7way_security
Website Cloning: Phishing Attacks in Colombia and Latin America

SEARCH

RECENT ARTICLES

  • Proveedor_ciberseguridad_Colombia_7way_security

    Avoid Risks: How to choose your Cybersecurity Provider in Colombia?

    En el sector financiero, donde la información s...
  • protección_de_datos_personales_en_Colombia_y_ciberseguridad_empresarial_7way_security

    Data Protection: Risk Management and Compliance in Colombia

    Every January, is commemorated in Colombia the Day of l...
  • Ciberseguridad_2026_ SOC_e_inteligencia_de_amenazas_7WS

    Cybersecurity 2026: SOC and Threat Intelligence

    The start of 2026 reinforces a reality as cone...
  • migración de infraestructura TI — 5 pasos para modernizarla

    Is Your Infrastructure Already Migrated? 5 Steps to Modernize It

    When the speed of evolution of the threat...
  • Week of Cybersecurity 2025: digital Culture safe

    During the most recent Week of the Cibersegur...

FILES

  • February 2026
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • April 2021

CATEGORIES

  • Blue Teams
  • Cybersecurity
  • Development
  • Secure development
  • Documentation
  • Hardering
  • Threat Intelligence
  • Security monitoring
  • MVP
  • Networking
  • Orange Team
  • Pentesting
  • Penetration testing advanced
  • Network Team
  • Incident Response
  • Defensive Security
  • Startup
  • Technology
  • Threat Intelligence

TOPICS OF INTEREST

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

ASK FOR ADVICE FROM OUR EXPERTS

Please, fill out this form and we will contact you as soon as possible

7way_security_ciberseguridad_de_la_manera_correcta_4

7WAY SECURITY

CIBERSECURITY THE RIGHT WAY.

POLICY FOR THE MANAGEMENT OF PERSONAL DATA

CONTACT us

Bogotá: Cra 49 # 128b 31 Office 201 – (601) 805 24 02

Whatsapp: (+57) 300 726 5036

E-mail: [email protected]

Business Developer: [email protected]

Resumes / CVs [email protected]

 

 

  • GET SOCIAL

© 2022 All rights reserved. 7WAY SECURITY.

TOP
EN
ES