Privacy
Personal information and family safety

Doxxing and Oversharing: Protecting Personal Information Online

UrbanX Digital Safety & Privacy
26 Aug 2026
12 min read
Quick Answer

Doxxing is the exposure of identifying or sensitive information about someone, often to cause harm. Reduce the risk by limiting the clues that connect usernames, real names, routines, addresses, schools, workplaces and family members. If information is published, prioritise immediate safety, preserve evidence, request removal and involve the relevant platform, institution or South African authority where necessary.

Read the full Digital Safety guide

Last reviewed: 26 August 2026 · 12 min read

What doxxing means

Australia’s eSafety Commissioner describes doxxing as the intentional online exposure of an individual’s identity, private information or personal details without consent. The information may already exist somewhere online; the harm can come from collecting, connecting and publishing it in a threatening context.

Exposed information may include:

  • a home or work address;
  • an identity or phone number;
  • a school, employer or daily routine;
  • private photographs or family information;
  • financial or account details;
  • location data; and
  • usernames that connect separate online identities.

Not every unwanted mention has the same severity. Assess what was exposed, who can see it, whether a threat accompanies it and whether anyone is approaching the person or location.

How small clues combine

A single gaming username may appear anonymous. The same username on a public social profile may reveal a first name. A race screenshot may show a club, a delivery photograph may show a street, and a regular stream may establish when the home is occupied.

Common connecting clues include:

  • reused usernames and profile photographs;
  • visible school or employer branding;
  • geotagged images and live location;
  • car registrations, street signs and house numbers;
  • public birthday and family posts;
  • voice, language and time-zone patterns;
  • event registrations and public leaderboards;
  • data-broker or directory entries; and
  • friends who tag or name the person.

Privacy is therefore cumulative. Changing one setting cannot erase every clue.

A practical exposure audit

Search like a stranger

Search your full name, common usernames, email address and phone number. Combine them with a city, school, employer or gaming handle. Check image results and the profiles visible while signed out.

Do not enter sensitive details into an unknown “people finder” merely to test it.

Review each profile separately

For every account, check:

  • who can see posts, stories and friend lists;
  • whether search engines can index the profile;
  • old biographies, tagged photographs and check-ins;
  • contact-discovery settings;
  • public comments on other accounts; and
  • apps with access to profile data.

Inspect images and live content

Look beyond the main subject. Screenshots and streams can expose notifications, email addresses, account IDs, map locations, school names, delivery labels and background landmarks. Post an event after leaving rather than announcing an unattended home or exact live location.

Separate identities where needed

Use different public names, profile images and contact addresses when a gaming, creator or community identity does not need to connect to a legal identity. This is separation, not a guarantee of anonymity.

What to do if information is published

1. Deal with immediate danger first

If there is a credible threat, someone is travelling to the location or a person is in immediate danger, contact emergency services. In South Africa, the SAPS emergency number is 10111. Move to a safer place if appropriate and tell trusted people at the location.

2. Preserve evidence

Before content changes, record:

  • the full URL;
  • username and profile address;
  • date, time and time zone;
  • screenshots showing the surrounding context;
  • direct messages or threats; and
  • any platform report or police reference.

Keep originals. Avoid repeatedly sharing the exposed information while documenting it.

3. Request platform removal

Use the platform’s privacy, harassment, personal-information or safety reporting path. Be specific about what identifies the person and whether the post includes threats, a minor, intimate content or financial information.

After the source is removed, search engines may still show an old result temporarily. Use the search provider’s removal or outdated-content process where appropriate.

4. Protect the exposed points

Contact the people or organisations connected to the information:

  • alert household members, reception or security;
  • ask a school or employer not to confirm details;
  • tell the bank if financial information is exposed;
  • contact the mobile provider if SIM fraud is a risk;
  • change account-recovery information when it is public; and
  • review answers to security questions.

5. Report threats, harassment or crime

South Africa’s Cybercrimes Act covers defined cyber offences, while the Protection from Harassment Act provides a process for applying for a protection order. Whether particular conduct meets a legal test depends on the facts. Preserve evidence and seek current guidance from SAPS or a qualified legal professional instead of relying on a general article as legal advice.

ISPA also publishes guidance on reporting online crime and notes that certain matters should be reported at a police station.

Reducing future exposure

  • Remove unnecessary phone numbers, addresses and birthdays from public profiles.
  • Restrict friend, follower and gaming activity visibility.
  • Disable precise location access where an app does not need it.
  • Strip location metadata or use services that do so before sharing files.
  • Avoid posting travel and routines in real time.
  • Ask friends not to tag locations without consent.
  • Use a separate public contact address.
  • Protect email and social accounts with unique passwords and MFA.
  • Review old posts rather than changing only current settings.
  • Avoid using identity-document details as public verification.

Supporting someone who has been doxxed

Do not blame the person for an old post or weak setting. Help them document the exposure, report it, contact affected institutions and reduce immediate visibility. Do not confront the suspected perpetrator or amplify the post in an attempt to defend the victim.

For a child or teenager, involve a trusted adult and the relevant platform safety process promptly. A threat involving a child, sexual exploitation or immediate danger requires specialist or law-enforcement support.

What this guide does not cover

It does not diagnose IP exposure, peer-to-peer game architecture, DDoS attacks or router security. Those technical network topics are covered by Competitive Security, Edge Configuration & Continuity.

Sources

Related guides

Frequently Asked Questions

Still experiencing issues? Run a diagnostic check or reach out to our support team with a structured ticket.