SWR

Oversharing on social media is a cybersecurity risk: Where can EAs and PAs help?

Over 80% of employees overshare on social media, potentially exposing themselves and their employer to cybersecurity breaches and online fraud. How can EAs and PAs help to highlight the risks to their teams?

Now, IT expert John Pepper, CEO and founder at Managed247 is warning that employees could be unintentionally giving cybercriminals valuable information about their organisations through everyday social media posts. He urges businesses to pay closer attention to what employees are sharing online, and offers practical advice for businesses and employees on how to reduce the risks associated with their digital footprint.

Five ways oversharing work information can put businesses at risk

1.Employees could be impersonated

More than 220,000 fraud-risk cases were recorded to the UK National Fraud Database (NFD) in the first six months of 2026, with identity fraud accounting for 59% of cases according to Cifas. Social media can provide cybercriminals with a wealth of information about employees and the organisations they work for, including names, job titles, places of work, company locations, colleagues, clients and professional responsibilities.

This information could be used to impersonate a member of staff, manager or company director and make convincing requests for money, sensitive information or access to business systems.

Why is oversharing on social media by colleagues an issue EAs and PAs can influence?

For PAs and EAs, this is particularly relevant when supporting senior executives who may be more likely to be targeted by impersonation scams. Knowing what information is publicly available about the people they support can help assistants spot potential risks and encourage greater caution around unusual requests.

John Pepper advises: “Employees can unintentionally give criminals a lot of useful information about themselves and the people they work with. When those details are brought together, it can make it much easier for someone to convincingly impersonate a colleague or senior member of staff.

“Businesses should think about employees’ digital footprints as part of their wider cybersecurity strategy and make sure staff understand what information could potentially be useful to someone outside the organisation.”

2. A social media post could help build a targeted scam

The more criminals know about an organisation, the easier it can be to make a scam appear genuine. Social engineering often involves attackers using information gathered online to make fraudulent messages appear genuine. By monitoring employees’ social media activity, criminals can identify who works for an organisation, what their responsibilities are and who they regularly interact with.

For example, an employee posting about a new role, project or business relationship could inadvertently give criminals enough information to create a convincing message that appears to come from a colleague, customer or supplier.

To reduce the risk, PAs and EAs can remind colleagues that even seemingly harmless updates can provide useful information to someone trying to impersonate a trusted contact. This is particularly important for assistants managing communications, diaries and relationships with clients and suppliers.

Pepper states: “Social engineering works because criminals are trying to make their messages feel familiar and trustworthy. The more information they can find about an organisation and its employees, the easier that becomes.

“If an employee receives an unusual request involving money, confidential information or access to a system, it’s always worth checking through another trusted channel before taking action.”

3. How AI can be used in employee impersonation

Scammers need just three seconds of audio to clone a person’s voice, and with so many videos available on social media, it is becoming increasingly easy for criminals to generate convincing voice clones. Similarly, publicly available photographs and videos can be used to create AI-generated images and deepfakes.

For businesses, this could mean criminals attempting to impersonate employees, directors or other company representatives.

For PAs and EAs who regularly talk to senior leaders, this is another reason to be cautious when receiving unexpected requests – particularly those involving payments, confidential information or asking for urgent action are the ones to be aware of the most. Having extra verification processes in place or a point of contact can help assistants and their executives tell genuine requests from sophisticated scams.

“AI is a useful technology and there are plenty of positive ways businesses can use it, but like any technology, it can also be misused.

“Businesses should be aware that publicly available photos, videos and recordings can potentially be used to make an impersonation more convincing. The important thing is not to panic, but to have sensible processes in place so that unusual requests are independently checked, particularly when money or sensitive information is involved.”

4. What employees post can affect a company’s reputation

Oversharing on social media can also create significant reputational risks for businesses. Employees may unintentionally associate their personal accounts with their employer by listing their workplace, using company branding or discussing their professional lives.

“Employees are often seen as representatives of a business whether they intend to be or not, so it’s worth thinking about how personal social media activity could be perceived. What you post online can sometimes have a much longer life than you expect, especially when your social media profile is linked to your workplace. Something shared in a personal capacity can still influence how customers, colleagues or potential clients view you and the business you work for.””

5. A harmless post could reveal more about your business than you realise

One of the biggest risks of oversharing is inadvertently revealing information that could be useful to cybercriminals or competitors.

Employees may not realise that seemingly harmless posts can provide valuable intelligence about an organisation. Photos from inside an office could reveal security systems, access points, screens or documents. Posts about upcoming projects could disclose confidential business plans, while announcing new clients, suppliers, software systems or company locations could give attackers useful information about the organisation’s operations. Even seemingly innocent posts, such as celebrating a new contract or sharing photographs from a workplace event, can reveal information that businesses may not yet want to make public.

For PAs and EAs, this is particularly relevant when organising meetings, events or travel involving senior executives. Even a photo, location tag or guest list could reveal useful information to someone with malicious intent.

“Employees don’t necessarily need to share confidential documents to reveal useful information about a business. Sometimes it can be the small details that add up.

“A photo from the office, a post about a new client or even an update about an upcoming project could give someone outside the organisation a better understanding of how that business operates.

“It’s about encouraging employees to take a second before posting and think about whether there’s anything in the background or in the caption that they wouldn’t want a stranger to know.”

 

Half of employees admit making mistakes when it comes to cybersecurity – and they shouldn’t. This is an area that needs more focus as cyber threats increase in teh AI area.

SWR