# Doxxing and Oversharing: Protecting Personal Information Online

Source: https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection/doxxing-oversharing-personal-information

**Answer:** Doxxing is the exposure of identifying or sensitive information about someone, often to cause harm. Reduce the risk by limiting the clues that connect usernames, real names, routines, addresses, schools, workplaces and family members. If information is published, prioritise immediate safety, preserve evidence, request removal and involve the relevant platform, institution or South African authority where necessary.

Part of [Digital Safety, Privacy & Account Protection](https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection) · 12 min read · by UrbanX Knowledge Hub

**Last reviewed: 26 August 2026 · 12 min read**

### What doxxing means

Australia’s eSafety Commissioner describes doxxing as the intentional online exposure of an individual’s identity, private information or personal details without consent. The information may already exist somewhere online; the harm can come from collecting, connecting and publishing it in a threatening context.

Exposed information may include:

- a home or work address;
- an identity or phone number;
- a school, employer or daily routine;
- private photographs or family information;
- financial or account details;
- location data; and
- usernames that connect separate online identities.

Not every unwanted mention has the same severity. Assess what was exposed, who can see it, whether a threat accompanies it and whether anyone is approaching the person or location.

### How small clues combine

A single gaming username may appear anonymous. The same username on a public social profile may reveal a first name. A race screenshot may show a club, a delivery photograph may show a street, and a regular stream may establish when the home is occupied.

Common connecting clues include:

- reused usernames and profile photographs;
- visible school or employer branding;
- geotagged images and live location;
- car registrations, street signs and house numbers;
- public birthday and family posts;
- voice, language and time-zone patterns;
- event registrations and public leaderboards;
- data-broker or directory entries; and
- friends who tag or name the person.

Privacy is therefore cumulative. Changing one setting cannot erase every clue.

### A practical exposure audit

#### Search like a stranger

Search your full name, common usernames, email address and phone number. Combine them with a city, school, employer or gaming handle. Check image results and the profiles visible while signed out.

Do not enter sensitive details into an unknown “people finder” merely to test it.

#### Review each profile separately

For every account, check:

- who can see posts, stories and friend lists;
- whether search engines can index the profile;
- old biographies, tagged photographs and check-ins;
- contact-discovery settings;
- public comments on other accounts; and
- apps with access to profile data.

#### Inspect images and live content

Look beyond the main subject. Screenshots and streams can expose notifications, email addresses, account IDs, map locations, school names, delivery labels and background landmarks. Post an event after leaving rather than announcing an unattended home or exact live location.

#### Separate identities where needed

Use different public names, profile images and contact addresses when a gaming, creator or community identity does not need to connect to a legal identity. This is separation, not a guarantee of anonymity.

### What to do if information is published

#### 1. Deal with immediate danger first

If there is a credible threat, someone is travelling to the location or a person is in immediate danger, contact emergency services. In South Africa, the SAPS emergency number is 10111. Move to a safer place if appropriate and tell trusted people at the location.

#### 2. Preserve evidence

Before content changes, record:

- the full URL;
- username and profile address;
- date, time and time zone;
- screenshots showing the surrounding context;
- direct messages or threats; and
- any platform report or police reference.

Keep originals. Avoid repeatedly sharing the exposed information while documenting it.

#### 3. Request platform removal

Use the platform’s privacy, harassment, personal-information or safety reporting path. Be specific about what identifies the person and whether the post includes threats, a minor, intimate content or financial information.

After the source is removed, search engines may still show an old result temporarily. Use the search provider’s removal or outdated-content process where appropriate.

#### 4. Protect the exposed points

Contact the people or organisations connected to the information:

- alert household members, reception or security;
- ask a school or employer not to confirm details;
- tell the bank if financial information is exposed;
- contact the mobile provider if SIM fraud is a risk;
- change account-recovery information when it is public; and
- review answers to security questions.

#### 5. Report threats, harassment or crime

South Africa’s Cybercrimes Act covers defined cyber offences, while the Protection from Harassment Act provides a process for applying for a protection order. Whether particular conduct meets a legal test depends on the facts. Preserve evidence and seek current guidance from SAPS or a qualified legal professional instead of relying on a general article as legal advice.

ISPA also publishes guidance on reporting online crime and notes that certain matters should be reported at a police station.

### Reducing future exposure

- Remove unnecessary phone numbers, addresses and birthdays from public profiles.
- Restrict friend, follower and gaming activity visibility.
- Disable precise location access where an app does not need it.
- Strip location metadata or use services that do so before sharing files.
- Avoid posting travel and routines in real time.
- Ask friends not to tag locations without consent.
- Use a separate public contact address.
- Protect email and social accounts with unique passwords and MFA.
- Review old posts rather than changing only current settings.
- Avoid using identity-document details as public verification.

### Supporting someone who has been doxxed

Do not blame the person for an old post or weak setting. Help them document the exposure, report it, contact affected institutions and reduce immediate visibility. Do not confront the suspected perpetrator or amplify the post in an attempt to defend the victim.

For a child or teenager, involve a trusted adult and the relevant platform safety process promptly. A threat involving a child, sexual exploitation or immediate danger requires specialist or law-enforcement support.

### What this guide does not cover

It does not diagnose IP exposure, peer-to-peer game architecture, DDoS attacks or router security. Those technical network topics are covered by [Competitive Security, Edge Configuration & Continuity](/knowledge-hub/competitive-security-edge-config-continuity).

### Sources

- [eSafety Commissioner: Doxxing](https://www.esafety.gov.au/industry/tech-trends-and-challenges/doxing)
- [South African Department of Justice: Cyber Safety](https://www.justice.gov.za/cybersafety/cybersafety.html)
- [South African Government: Cybercrimes Act 19 of 2020](https://www.gov.za/documents/acts/cybercrimes-act-19-2020-english-afrikaans-01-jun-2021)
- [Department of Justice: Protection from Harassment](https://www.justice.gov.za/forms/form_pha.html)
- [SAPS: Cybercrime Prevention Tips](https://www.saps.gov.za/alert/cybercrime_prev_tips.php)
- [ISPA: How to Report Online Crime](https://ispa.org.za/consumer-support/how-to-report-online-crime/)

### Related guides

- [All Digital Safety, Privacy & Account Protection guides](/knowledge-hub/digital-safety-privacy-account-protection)
- [What to Do If Your Personal Data Appears in a Breach](/knowledge-hub/digital-safety-privacy-account-protection/personal-data-breach-response)
- [How to Spot a Phishing Email, SMS or WhatsApp Message](/knowledge-hub/digital-safety-privacy-account-protection/spot-phishing-email-sms-whatsapp)
- [A Parent’s Guide to Safer Online Gaming](/knowledge-hub/digital-safety-privacy-account-protection/parents-guide-safer-online-gaming)

## Frequently Asked Questions

**Is information still private if it is already on another public website?**

Public availability does not make every reuse harmless. Collecting and publishing details in a threatening or targeted context can create new risk.

**Should I delete a doxxing post myself before taking screenshots?**

If you control it and danger is immediate, reduce exposure, but preserve enough reliable evidence first where safely possible. Do not delay urgent safety action for perfect documentation.

**Can I remove my information from search results?**

Search engines provide removal routes for some personal information and outdated results, but removing a result may not remove the source page. Address both where possible.

**Is changing my username enough?**

No. Old posts, images, friends, reused profile details and cached pages may still connect identities. Review the whole information trail.

**Does South African law protect someone who is harassed online?**

South African laws may apply depending on the conduct and evidence. Use official guidance or legal advice for the specific facts; this article is not a legal assessment.
