Your Public Record Is Someone Else's Weapon: Inside the Data Aggregation Attacks Targeting Ordinary Americans
Photo: Photograph by Mike Peel (www.mikepeel.net)., CC BY-SA 4.0, via Wikimedia Commons
In December 2017, a SWAT team descended on a home in Wichita, Kansas, acting on an anonymous tip about a hostage situation. The tip was fabricated. The caller had obtained the address through a dispute over a ten-dollar wager in an online video game. Police shot and killed an innocent man named Andrew Finch on his own doorstep. The caller had the wrong address to begin with—a fact that underscores how little precision these attacks require to cause irreversible harm.
The Wichita swatting incident is now a landmark case in discussions of coordinated online harassment. But it is far from isolated. Swatting calls—false emergency reports designed to dispatch armed law enforcement to a target's home—have been logged in nearly every U.S. state. Members of Congress, school principals, judges, and private individuals with no public profile have all been targeted. And in virtually every case, the attacker's first step was not hacking. It was research.
The Aggregation Problem: When Public Data Becomes a Dossier
No single piece of publicly available information is particularly dangerous in isolation. Your name is public. Your approximate neighborhood might appear in a local news story. Your employer is listed on LinkedIn. Your car is registered with the state DMV. You may appear in the background of a photograph someone else posted on Instagram.
The threat emerges from aggregation—the systematic combination of individually innocuous data points into a comprehensive profile that reveals your home address, your daily schedule, your family members' identities, your vehicle, and your vulnerabilities. This process, which security researchers refer to as open-source intelligence gathering, or OSINT, requires no technical sophistication. It requires only patience and knowledge of where to look.
The sources are almost entirely legal. Voter registration rolls, which are public records in most U.S. states, typically contain a registrant's full name, home address, date of birth, and party affiliation. Property tax records, maintained by county assessors and searchable online in most jurisdictions, link names to physical addresses and often include purchase prices and mortgage information. Court records—available through PACER at the federal level and through state portals—can reveal prior addresses, family relationships, and financial disputes.
Social media compounds the problem exponentially. A Facebook post tagged at a local restaurant establishes a neighborhood. A LinkedIn profile confirms an employer and job title. An Instagram photograph taken in a backyard may contain enough visual detail—a distinctive fence, a glimpse of a street sign, the angle of afternoon shadows—to confirm a precise location when cross-referenced with satellite imagery.
Data Broker Ecosystems: The Infrastructure of Exposure
Above this layer of directly public records sits a commercial infrastructure that has aggregated, cleaned, and packaged personal data into searchable products. Data brokers—companies including Spokeo, BeenVerified, Whitepages, and dozens of lesser-known operators—compile profiles from public records, commercial transactions, and purchased datasets, then sell access to anyone willing to pay a subscription fee.
These services were designed for background checks, tenant screening, and reconnecting with lost contacts. They are also among the first tools a motivated harasser will consult. For a fee of roughly $20 to $40 per month, a subscriber can query a target's name and receive a report containing current and previous addresses, phone numbers, email addresses, relatives' names, and in some cases, estimated income ranges.
The Federal Trade Commission has taken enforcement action against specific data brokers for deceptive practices, and several states—including California under the California Consumer Privacy Act and Virginia under the Consumer Data Protection Act—have enacted opt-out rights. But the opt-out process is fragmented, requiring individual requests to dozens of separate companies, and the legal landscape remains inconsistent across state lines.
How Doxxing Campaigns Are Constructed
In documented cases studied by journalists and researchers at organizations including the Anti-Defamation League and the Stanford Internet Observatory, coordinated doxxing campaigns typically follow a recognizable sequence.
The attacker begins with a known identifier—a username, a real name, or an email address. From there, cross-platform searches identify other accounts associated with the same handle or writing style. Voter records or property databases confirm a home address. Relatives are identified through public genealogy databases or tagged social media photographs. The assembled profile is then published—typically on anonymous imageboards, Telegram channels, or dedicated harassment forums—accompanied by calls for others to contact, threaten, or report the target.
In swatting scenarios, the assembled address is submitted alongside a fabricated emergency report to local law enforcement, often using spoofed caller ID services to disguise the origin. The goal is to provoke a rapid, armed police response. Given the documented outcomes of such calls—including the Wichita fatality and a 2022 incident in which a Georgia man was shot during a swatting response—the potential for lethal harm is not hypothetical.
Which Public Records Pose the Greatest Risk
Not all public data is equally exploitable. Security researchers and privacy attorneys consistently identify several record categories as particularly high-value for malicious aggregation.
Voter registration records are among the most dangerous. Twenty-seven states make voter rolls available to the general public with minimal restriction. These records frequently combine a full legal name, residential address, and date of birth—sufficient information to initiate identity theft, locate a physical address, and authenticate against other databases.
Property records are universally public in the United States, maintained at the county level, and increasingly searchable through free online portals. They are a reliable source of home addresses even for individuals who have taken steps to minimize their social media presence.
Business registration records expose home addresses for sole proprietors and small business owners who register without a separate commercial address—a common situation for freelancers and home-based entrepreneurs.
Court filings can reveal prior addresses, domestic relationships, and financial information through divorce proceedings, small claims cases, and bankruptcy filings.
Reducing Your Digital Footprint: Practical Measures
Complete elimination of public exposure is not achievable for most Americans. The goal is reduction—raising the cost and complexity of aggregation to a level that deters opportunistic attackers.
Submit opt-out requests to major data brokers. The process is labor-intensive but meaningful. Services including DeleteMe and Privacy Bee automate the submission process for a subscription fee. Alternatively, the nonprofit Privacy Rights Clearinghouse maintains a directory of data brokers with direct opt-out links. Requests must be renewed periodically, as brokers re-acquire data from new sources.
Use a P.O. box or registered agent address for public-facing registrations. Business filings, voter registration in states that permit address confidentiality programs, and online purchases can use an address that does not correspond to your residence. Many states offer address confidentiality programs specifically for domestic violence survivors, election workers, and public officials.
Audit your social media for location signals. Review tagged photographs, check-ins, and background details in images you have posted. Disable location metadata on your smartphone camera. Avoid posting photographs that establish your home's exterior appearance or precise neighborhood.
Separate your online identifiers. Using distinct usernames across platforms makes cross-platform aggregation significantly more difficult. A unique email address per service limits the ability to link accounts through breach data.
Inform local law enforcement if you believe you are a swatting target. Several police departments now maintain registries of individuals who have self-identified as likely swatting targets, allowing dispatchers to apply additional verification before responding to emergency calls at those addresses.
The Legal Landscape and Its Limits
Federal law does not comprehensively criminalize doxxing. The Interstate Stalking statute and the Computer Fraud and Abuse Act have been applied in some cases, but prosecution requires federal prosecutorial interest and is rarely pursued for individual harassment incidents. Several states—including California, Nevada, and Kentucky—have enacted statutes specifically addressing doxxing or cyberstalking, with varying definitions and penalty structures.
Swatting is more uniformly criminalized. The Telecommunications Act and state-level false report statutes have been used to prosecute swatting callers, and sentences have ranged from probation to, in the Wichita case, twenty years in federal prison for the primary perpetrator.
Legislative proposals for federal doxxing prohibitions have been introduced in multiple congressional sessions without advancing to passage. In the interim, the burden of protection falls substantially on individuals—which makes understanding the mechanics of these attacks not merely an academic exercise, but a practical necessity.