A cybercriminal can gather detailed information about a small or medium-sized enterprise (SME) by analyzing the content employees post online. Platforms like LinkedIn, Facebook, and job forums often contain seemingly harmless details—such as job titles, arrival dates, or travel schedules—that can be pieced together to create a detailed map of a company. This method, known as OSINT (Open-Source Intelligence), allows attackers to collect data without hacking or leaving digital footprints. The information is often freely shared by employees, making it easy for fraudsters to exploit. Before launching a president fraud or a targeted phishing attack, a cybercriminal does not need to break into a system. Instead, they simply need to read and analyze publicly available information. On LinkedIn, for example, an employee’s profile may reveal their exact role, their manager’s name, and even the arrival date of the company’s accountant. When multiplied across dozens of employees, this information can reconstruct a complete organizational chart. Attackers may then create fake email addresses that mimic a company’s domain to trick employees into initiating unauthorized transfers. Social media platforms also provide valuable insights. A post on Facebook showing a team photo from a meeting can help fill in gaps in a company’s structure, while travel photos or vacation updates can reveal when key personnel are away. These details can be exploited during busy or vulnerable times, such as holidays, when fewer people are available to verify unusual requests. In one case, a fraudster used such data to divert over 61 million euros in a single year through a president fraud. Additionally, job listings and reviews on forums can reveal the software a company uses, which attackers can then exploit to find known vulnerabilities. To reduce the risk of such attacks, companies can take several steps. Limiting the visibility of employee lists on LinkedIn and delaying the posting of vacation photos can help minimize exposure. Creating an internal charter to control what information is shared in job postings and establishing a plan with the bank—such as a 48-hour delay before initiating transfers—can add critical layers of protection. Monitoring domain name registrations and training employees to verify the identity of anyone requesting unusual actions are also essential. Regularly checking the internet for mentions of executives and key employees can help detect any unwanted information that may be used against the company.