Industry the September 2026 issue

Cyberstalking

Business leaders must harden their cyber defenses alongside their physical defenses.
By Russ Banham Posted on September 1, 2026

The proliferation of personal data available to them makes digital tracking a real threat.

Historically, tracking executive routines required physical reconnaissance, which ran a high risk of detection by security personnel or CCTV. By comparison, digital stalking requires no physical presence. Today, public data brokers give adversaries instantaneous, unvetted access to an executive’s private life. “Threat actors can easily aggregate disparate data points—home addresses, vehicle models, family identities, and personal emails—into a highly actionable intelligence mosaic,” explains Trinity Davis, chief security officer at data security provider 360 Privacy.

Digital tracking allows both state-sponsored operatives and lone radicalized individuals to orchestrate physical harm from afar. Tom Aldrich, 360 Privacy’s chief operating officer, cites the case of Vance Boelter, a former security professional who used data brokers to access information enabling him to stalk and shoot multiple Minnesota lawmakers in 2025, assassinating House Speaker Emerita Melissa Hortman and her husband.

“Federal investigators confirmed that Boelter used commercial data broker sites to bypass typical privacy barriers, mapping out his targets’ exact addresses, routing, and family names right from his keyboard,” Aldrich says. “To counter this threat, companies must eliminate the online data points that threat actors harvest from commercial [data] brokers to build their tactical plans.”

Minimizing the severity of this cyberstalking requires a rigid commitment to personal digital hygiene and layered perimeter defense. Executives must strictly limit their predictability by varying travel routes, departure times, and public routines so they do not inadvertently advertise a static schedule to a spotter. For high-visibility leaders, security professionals strongly advise a two-account social media strategy: a single forward-facing, public profile used strictly for marketing and brand promotion, and a secondary, completely unattributable account reserved for family communication.

According to 360 Privacy, organizations must implement a multilayered risk management strategy across four critical domains:

  • Corporate Verification: Enforce hardware tokens and require in-person onboarding or certified physical identity verification to eliminate remote infiltration of their systems.
  • Residential Isolation: Segment home offices using enterprise-grade routers to establish dedicated, encrypted networks that isolate corporate devices.
  • Family Education: Conduct specialized training on social engineering and digital extortion to prevent domestic security compromises.
  • Asset Shielding: Scrub personally identifiable information continuously from online data brokers using automated data-erasure services, and mask real estate holdings using legal trusts.

Finally, if and when an executive suspects active digital monitoring, corporate protocol must require a professional security firm to initiate investigations, conduct automated digital sweeps, and implement countersurveillance measures before latent digital stalking escalates into physical contact. “Systematically removing these digital breadcrumbs greatly reduces actionable intelligence used to transition from online activity to physical harm,” Davis says.

More in Industry

Target: CEO
Industry Target: CEO
From murder and character assassination to home invasion and state-sponsored det...
Industry Things Fall Apart
Corporate threats aren't limited to the C-Suite.
Parametric Reputation Policies
Industry Parametric Reputation Policies
For corporations, a personal attack can have severe financial effects.