Doxing

Doxing

Doxing means collecting private data about a person on the internet and making it public in order to harm them. Often affected are address, employer, or phone number, and the consequences are frequently threats and harassment.

Doxing means publishing private information about a person on the internet without their consent. This typically includes the home address, mobile number, employer, school, or photos of the family. The name comes from the English word for documents, that is “docs”, which was shortened to “dox”. The special thing about it: usually nothing is hacked and nothing is stolen. The individual pieces of information are often already openly available somewhere online, scattered across many sources. It is only the assembling of these fragments into a complete profile that makes the matter dangerous.

When an online dispute becomes a real problem

Doxing moves a conflict out of the internet and into a person’s real life. Someone who is insulted online can close the page. Someone who has been doxed cannot close their home address. Victims report calls in the middle of the night, ordered deliveries of goods, threatening letters, and strangers showing up at their front door.

A particularly dangerous consequence is called swatting. In this, someone calls the police and reports a fabricated hostage situation at the published address. A special forces unit shows up, even though nothing has happened there. In the USA, people have already died during such operations.

By no means are only celebrities affected. Frequent targets are female journalists, local politicians, scientists, and people who speak out on controversial topics. Disputes in school classes or in online games also sometimes end in the publication of private data. In Germany, doxing has been explicitly punishable since 2021, regulated under Section 126a of the Criminal Code.

How data crumbs become a wanted poster

The usual path begins with a single clue, such as a username. Many people use the same name on several platforms. Using a search engine, one can quickly find several accounts belonging to the same person. Each account provides another piece of the puzzle.

Then comes the combining. A vacation photo shows the house, a comment mentions the neighborhood, a club profile names the full name. Technical traces help too: photo files often contain location data that the camera automatically records. Experts refer to this kind of research in openly accessible sources as OSINT, meaning “Open Source Intelligence”.

Artificial intelligence significantly speeds up this process. Language models can search through huge amounts of posts and establish connections that used to take hours to find. Image recognition estimates the location of a photo from background details. A common misconception is therefore that doxing is a hacker attack. In reality, it is usually patient, painstaking work using public information.

From news topic to one’s own profile

The term regularly appears in the news when activists, female politicians, or employees of large tech companies become targets. In 2019, the personal data of hundreds of politicians and celebrities in Germany was published via a Twitter account. The perpetrator was a twenty-year-old student who worked without any special technical means.

Platforms such as Instagram, TikTok, Discord, or X prohibit doxing in their rules and delete corresponding posts. The problem: once data is out there, it gets copied and reappears elsewhere. Deletion therefore often has only limited effect. That’s why prevention is more important than reaction.

In practice, this means: different usernames for different areas, no photos with a recognizable house number, sparing details about school and place of residence. Anyone who is personally affected should save screenshots as evidence and file a police report. Doxing is not a technical mishap, but a deliberate act with someone responsible.

Related Products

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.