• Login
NORVANREPORTS.COM |  Business News, Insurance, Taxation, Oil & Gas, Maritime News, Ghana, Africa, World
  • Home
  • News
    • General
    • Political
  • Economy
  • Business
    • Agribusiness
    • Aviation
    • Banking & Finance
    • Energy
    • Insurance
    • Manufacturing
    • Markets
    • Maritime
    • Real Estate
    • Tourism
    • Transport
  • Technology
    • Telecom
    • Cyber-security
    • Cryptocurrency
    • Tech-guide
    • Social Media
  • Features
    • Interviews
    • Opinions
  • Reports
    • Banking/Finance
    • Insurance
    • Budgets
    • GDP
    • Inflation
    • Central Bank
    • Sec/Gse
  • Lifestyle
    • Sports
    • Entertainment
    • Travel
    • Environment
    • Weather
  • NRTV
    • Audio
    • Video
No Result
View All Result
No Result
View All Result
NORVANREPORTS.COM |  Business News, Insurance, Taxation, Oil & Gas, Maritime News, Ghana, Africa, World
No Result
View All Result
Home Business

Employees’ Social Media Habits Are Becoming a Cybersecurity Risk Businesses Can No Longer Ignore

1 hour ago
in Business, Cyber-security, Economy, Editor's pick, Environment, Features, General, highlights, Home, home-news, latest News, Lifestyle, News, Political, Technology
3 min read
0 0
0
4
VIEWS
Share on FacebookShare on TwitterShare on Linkedin
  • Employees’ Social Media Habits Are Becoming a Cybersecurity Risk Businesses Can No Longer Ignore

Employees’ everyday social media activity is emerging as a growing cybersecurity vulnerability for companies, with publicly shared information increasingly giving criminals the material they need to impersonate staff, construct targeted scams and exploit artificial intelligence tools.

John Pepper, founder and chief executive of UK technology company Managed247, is warning businesses to treat employees’ digital footprints as part of their wider security architecture rather than merely a matter of personal social-media behaviour.

His concern is that individually harmless details can become valuable intelligence when combined.

The risk begins with information that many employees routinely publish without considering it sensitive. Names, job titles, workplaces, office locations, colleagues, clients, projects and areas of responsibility can all help fraudsters understand an organisation’s internal structure. Once those details are pieced together, criminals may be able to pose convincingly as a manager, supplier or senior executive and request money, credentials or access to company systems.

“Employees can unintentionally give criminals a lot of useful information about themselves and the people they work with,” Mr Pepper said. “When those details are brought together, it can make it much easier for someone to convincingly impersonate a colleague or senior member of staff.”

He said companies should therefore include social-media awareness within cybersecurity training and help staff understand how apparently innocuous disclosures could be used by outsiders.

The warning comes against a broader rise in fraud-related activity. Cifas data cited by Managed247 show more than 220,000 fraud-risk cases were recorded on the UK National Fraud Database during the first six months of 2026, with identity fraud accounting for 59.00% of cases.

RelatedPosts

US$60m Fuel Demurrage Bill Exposes Costly Cracks in Port Logistics – CUTS International 

GIRSAL Calls for Cheaper Farm Credit as Technical Gaps Keep Smallholders Outside Formal Finance

Charles Nyaaba Warns Rigid Bank Rules Are Keeping Small Farmers Away from Credit

Although those figures do not establish that social-media oversharing caused the cases, they illustrate the scale of the identity-based fraud environment in which publicly available personal information can become useful.

Social engineering is one of the clearest routes through which that information can be weaponised. A post celebrating a new client, announcing a role change or discussing an upcoming project can tell an attacker who works with whom, what transaction might plausibly occur next and which person would appear credible making a request.

Armed with that context, a phishing email can look less like a generic scam and more like a genuine instruction from somebody the employee knows.

“Social engineering works because criminals are trying to make their messages feel familiar and trustworthy,” Mr Pepper said. He advised employees receiving unusual requests involving money, confidential information or system access to verify them using a second, trusted communication channel rather than relying solely on the message received.

That simple verification step can become particularly important when the attacker has enough contextual information to mimic normal business behaviour.

Artificial intelligence is making impersonation more sophisticated. Managed247 cited research suggesting scammers may need only about three seconds of audio to begin creating a cloned voice, while photographs and videos available online can also be used to generate synthetic images or deepfakes.

For senior executives, public-facing employees and staff who regularly appear in video content, the potential attack surface is therefore growing alongside the adoption of generative AI.

Mr Pepper stressed that the answer is not to retreat from technology or assume every AI-generated communication is fraudulent. “AI is a useful technology and there are plenty of positive ways businesses can use it, but like any technology, it can also be misused,” he said.

The practical response, he argued, is to strengthen verification procedures around high-risk requests, particularly transactions involving money, confidential information or changes to payment instructions.

The implications extend beyond direct financial fraud. Employees who list their employer publicly, use company branding or regularly discuss their professional lives can also create reputational exposure when personal posts are interpreted as reflecting on the organisation.

Comments intended to be private or informal can be copied, shared and preserved long after the original post has been deleted, creating consequences for customer relationships, recruitment and corporate reputation.

“Employees are often seen as representatives of a business whether they intend to be or not,” Mr Pepper said. He argued that individuals should consider how personal content might be interpreted when their social-media profiles are visibly connected to their employer.

For companies, that creates a difficult balance between respecting employees’ personal expression and protecting corporate reputation and confidential information.

Physical workplace imagery poses another underappreciated risk. Office photographs can reveal access-control systems, security badges, documents, computer screens or physical layouts, while posts about software systems, suppliers or forthcoming projects can provide attackers with information that would otherwise require deliberate reconnaissance.

Even a celebratory photograph from a workplace event may disclose details about who holds particular roles, who has access to certain areas or which organisations are working together.

“Employees don’t necessarily need to share confidential documents to reveal useful information about a business,” Mr Pepper said. “Sometimes it can be the small details that add up.”

He suggested that staff develop the habit of checking both captions and backgrounds before publishing workplace-related content, asking whether any element reveals information they would not willingly provide to an unknown outsider.

The challenge for employers is to address that risk without turning cybersecurity policy into blanket surveillance of employees’ personal lives.

Clear guidance on confidential information, executive impersonation, payment verification and workplace photography can be more effective than vague prohibitions, particularly when combined with realistic phishing simulations and procedures for escalating suspicious requests.

Businesses also need controls that assume some information about employees will inevitably remain publicly available.

That means cybersecurity cannot rely solely on secrecy. Multi-factor authentication, independent payment approval, role-based access controls and verbal confirmation for sensitive transactions can reduce the damage an attacker can cause even after gathering substantial personal information online.

The objective is to ensure that knowing who the finance director is, where an employee works or which supplier the company uses is not enough to authorise a payment or gain access to a critical system.

The broader lesson is that the line between personal digital behaviour and corporate security is becoming increasingly difficult to maintain. Social media has made professional networking, marketing and recruitment easier, but the same information that helps legitimate contacts understand an organisation can help criminals map it.

As AI lowers the cost of producing convincing impersonations, companies may need to treat an employee’s digital footprint as part of the organisation’s attack surface.

For businesses, the most effective response may therefore be cultural rather than technological alone.

Employees need to understand why seemingly harmless information matters, while companies need processes strong enough to withstand an attack even when criminals know names, roles and relationships.

In an environment where a photograph, job update or short voice clip can contribute to a credible fraud attempt, the safest assumption is that anything posted publicly may eventually be used by somebody who was never meant to see it.

Tags: Employees’ Social Media Habits Are Becoming a Cybersecurity Risk Businesses Can No Longer IgnoreFrom Office Selfies to Voice Clones: How Everyday Posts Are Feeding a New Generation of Cyber ScamsIT Expert WarnsOversharing Online Could Expose Companies to FraudPhishing And AI ImpersonationThe Harmless Workplace Post That Could Help a Criminal Impersonate Your BossThree Seconds of Audio May Be Enough: Social Media Is Giving Cybercriminals New Ways into Businesses
No Result
View All Result

Who we are?

NORVANREPORTS.COM |  Business News, Insurance, Taxation, Oil & Gas, Maritime News, Ghana, Africa, World

NorvanReports is a unique data, business, and financial portal aimed at providing accurate, impartial reporting of business news on Ghana, Africa, and around the world from a truly independent reporting and analysis point of view.

© 2020 Norvanreports – credible news platform.
L: Hse #4 3rd Okle Link, Baatsonaa – Accra-Ghana T:+233-(0)26 451 1013 E: news@norvanreports.com info@norvanreports.com
All rights reserved we display professionalism at all stages of publications

No Result
View All Result
  • Home
  • Business
    • Agribusiness
    • Aviation
    • Energy
    • Insurance
    • Manufacturing
    • Real Estate
    • Maritime
    • Tourism
    • Transport
    • Banking & Finance
    • Trade
    • Markets
  • Economy
  • Reports
  • Technology
    • Cryptocurrency
    • Cyber-security
    • Social Media
    • Tech-guide
    • Telecom
  • Features
    • Interviews
    • Opinions
  • Lifestyle
    • Entertainment
    • Sports
    • Travel
    • Environment
    • Weather
  • NRTV
    • Audio
    • Video

Welcome Back!

Login to your account below

Forgotten Password?

Create New Account!

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
NORVANREPORTS.COM | Business News, Insurance, Taxation, Oil & Gas, Maritime News, Ghana, Africa, World
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.