ANALYSIS

What Monitoring Cannot See: Known Identifiers vs Digital Exposure

Most people who ask us about ongoing protection already pay for monitoring. Some of it is bundled with a bank account, some is a subscription, some sits inside a corporate security stack. The question they ask is whether they need anything else.

This is not another examination of which breach sources a provider covers, or how quickly an alert arrives. Both matter, and we have looked at which sources a provider actually covers and what stealer-log monitoring catches in time separately. This concerns a different limitation: how the provider decides which identities and relationships belong in the search at all.

What seeded monitoring does well

A consumer or bundled monitoring service takes a set of identifiers and watches for them. Your email address appears in a breach corpus, and you get an alert. A credential pair turns up in a dump, and you are told which account to rotate. This is real work, it runs at a scale no analyst can match, and the alerting is usually fast.

It also has a precise boundary. Seeded monitoring works on data you already know about, because it has to be told what to look for.

The researchers behind one of the largest deployments of this kind put the underlying problem plainly. Writing about credential-stuffing defence, a Google and Stanford team described "an asymmetry of knowledge: attackers have wide-scale access to billions of stolen usernames and passwords, while users and identity providers remain in the dark as to which accounts require remediation."

That asymmetry is the subject. Monitoring closes part of it. It cannot close the part that depends on knowing what to watch in the first place.

The list is your own memory

When you set up monitoring you provide a seed: name, current email addresses, perhaps a phone number and a home address. Whatever you give it, that list records the exposure you can remember on the day you sign up.

What tends not to be on it:

  • the personal address on a company filing from 2011, still in the register
  • a maiden name that survives on an old electoral roll
  • a forum handle nobody has logged into in a decade, still tied to a reusable username
  • a dormant mailbox that receives nothing but still works as an account-recovery route

None of these are exotic. They are ordinary residue. And not on the list means not watched.

A fair qualification here. The more capable enterprise platforms do more than match a fixed list: they enrich identifiers, expand aliases and resolve entities across records, and that genuinely widens the net. The products most individuals and most executives actually hold do not work that way, and even the ones that enrich are extending outward from identifiers someone supplied.

The list ages, and it is rarely re-seeded

A seed is a snapshot. Your exposure is not.

A board appointment adds a filing. A house purchase adds a record. A relative starts a business and your surname acquires a new public association. A service you used in 2019 is breached in 2027. Each of these arrives after the seed was written, and in most consumer products nothing goes back and revisits it.

So the blind spot does not hold still. It grows, quietly, while the alerting stays green because everything on the list is being watched exactly as promised.

Why adding more to the list does not close it

The instinct is to seed harder: give the service more identifiers, cover more ground.

It does not converge, for a structural reason rather than a lack of effort. The risk in an exposed profile is rarely in any single item. It is in the combination. An employer, a general location, a routine, a family name: each unremarkable alone, and together they are what lets someone sound like they already know you. We have written about that mechanism separately.

A watchlist holds items, and the risk lives in the relationships between them. Entity-resolution systems do model relationships, and the good ones do it well. But they resolve outward from identifiers someone supplied, which means the graph they build is anchored to what was known at the start. A relationship to something nobody named is not a weaker edge in that graph. It is absent from it.

MITRE catalogues this from the attacker's side as Reconnaissance: the phase where an adversary gathers information to plan the operation. Note the asymmetry again. They are not working from your list. They start with a name and follow whatever surfaces, and what surfaces is rarely what you would have nominated as important.

For an individual

The research on targeted phishing is instructive because of what it measures. A 2019 study in ACM Transactions on Computer-Human Interaction ran simulated phishing against 158 participants over 21 days, recording clicks through a browser plugin. Forty-three per cent were caught at least once.

The variable it isolates is not volume but fit. It measures "life domains", meaning a specific topic or aspect of an individual's life that an attacker can build the message around. An approach lands when it is about something true.

Finding what is true about a person is discovery work. It is not a lookup against a list they provided.

For an organisation

The corporate version carries an additional constraint, and it is not a capability problem.

A security stack watches corporate identifiers well. Extending that to an executive's personal exposure is different in kind, because the data is personal rather than corporate. The Article 29 Working Party's opinion on data processing at work sets out why this is careful ground: an employer needs a lawful basis, and has to satisfy necessity, proportionality and transparency. Employee consent is treated as particularly delicate, since it may not be freely given in an employment relationship. Later EDPB guidance has kept that direction of travel.

The practical consequence is not that an organisation may never look. It is that personal exposure cannot be treated as though it were corporate telemetry, and that accumulating a store of an executive's personal data inside the company creates the concentration it was trying to avoid. This is why our own Corporate Audit runs on explicit written authorisation from each named individual rather than on the organisation's say-so.

Meanwhile the exposure that matters most sits on the personal side. Verizon's Data Breach Investigations Report has the human element in the substantial majority of breaches, and tracks pretexting as an initial-access route in its own right. Pretexting requires knowing things about a person. We have written separately about where the corporate boundary falls.

The part nobody says out loud

There is a cost to seeding harder, and it runs against the reason you were doing any of this.

Every identifier you hand a monitoring service is another copy of your personal data, held by another company, for as long as that company exists. The more completely you seed, the more thorough the resulting file. To reduce your exposure you would be assembling, in one place, a tidy summary of exactly the things you did not want assembled.

That is not an argument against monitoring. It is an argument against the idea that the blind spot can be closed by disclosure. Whatever addresses it has to work without accumulating you.

That is buildable, and it has been built. The Google and Stanford protocol mentioned earlier lets a client check whether a specific credential appears in a repository of over four billion records "without revealing the information queried". A different mechanism from ours, and we make no claim to theirs. The point is the design goal: checking need not mean handing over.

Our own version of that discipline is what a Guardian cycle keeps between runs. Not a dossier. A minimal encrypted profile, a pseudonymous ledger, and keyed cryptographic fingerprints that can tell us a record has reappeared without keeping the record itself. Findings, screenshots, broker correspondence and working notes are purged within 48 hours of each cycle's delivery, and each cycle closes with a purge receipt confirming what went without restating any of it.

What this does and does not replace

An investigation is point-in-time. It tells you what is findable now. It does not watch anything between engagements, and it is not a substitute for continuous alerting on data you already know was leaked.

Keep the monitoring. The two layers do different jobs. The failure we see is not people having monitoring; it is people believing the seeded layer answers the unseeded question.

Where the work actually sits

Three steps, in order.

Discovery comes first, unseeded, working from what is findable rather than what you remember. For an individual that is the Mirror, or the Shield where there is active targeting. For an organisation it is a Corporate Audit across the leadership surface.

Reduction comes second, and it is the step people skip. Discovery produces a map; the map removes nothing. Independent measurement here is worth stating plainly, with its limits. A 2025 study in Proceedings on Privacy Enhancing Technologies found the commercial removal services it measured cleared 48.2% of the records they found, and that only 41.1% of the records those services surfaced were actually about the participant; that study ran 71 participants across four services. Consumer Reports' 2024 field test found manual opt-outs removing about 70%, against a range of 6% to 68% for the paid services. That test is the smaller of the two by design: 32 volunteers split into four groups, which meant each service, and the manual control, was evaluated with four participants.

Two things follow, and the second is why the first is worth paying for. Removal is partial, and doing it by hand outperformed every paid service in the one independent test we have. That is what the Eraser is.

Maintenance comes third, and only third. There has to be a reduced surface before there is anything to keep reduced, which is why the Guardian retainer begins after removal work rather than instead of it. Each cycle re-checks the sources that were worked and re-scans for credential exposure, quarterly on Core and monthly on Plus; the wider Mirror re-audit runs annually on every tier, and Executive adds event-driven checks around travel, transactions and media. The point is that the broader discovery is repeated on a schedule rather than the original watchlist simply being left running.

None of that removes the need for monitoring on the things you already know about. It answers the other question: what is out there that you never thought to name.

Sources

  1. Thomas, K., Pullman, J., Yeo, K., Raghunathan, A., Kelley, P. G., Invernizzi, L., Benko, B., Pietraszek, T., Patel, S., Boneh, D., Bursztein, E. “Protecting Accounts from Credential Stuffing with Password Breach Alerting.” USENIX Security Symposium, 2019. Distinguished Paper Award. USENIX.
  2. Lin, T., Capecci, D. E., Ellis, D. M., Rocha, H., Dommaraju, S., Oliveira, D., Ebner, N. C. “Susceptibility to Spear-Phishing Emails: Effects of Internet User Demographics and Email Content.” ACM Transactions on Computer-Human Interaction, 2019. 100 younger and 58 older participants over 21 days; 43% clicked at least once. doi:10.1145/3336141.
  3. MITRE ATT&CK. “Reconnaissance, Tactic TA0043 — Enterprise.” attack.mitre.org.
  4. Article 29 Data Protection Working Party. “Opinion 2/2017 on data processing at work” (WP249). European Commission.
  5. Verizon. “Data Breach Investigations Report.” On the human element in breaches and pretexting as a tracked initial-access vector. verizon.com.
  6. He, J., Snyder, P., Haddadi, H., Bustamante, F. E., Tyson, G. “Measuring the Accuracy and Effectiveness of PII Removal Services.” Proceedings on Privacy Enhancing Technologies 2025(4), 166–182. Removal and coverage: 71 participants across four services; record accuracy: a 25-participant sub-group across three services, self-assessed. doi:10.56553/popets-2025-0125.
  7. Grauer, Y., Kauffman, V., Honeywell, L. “Data Defense: Evaluating People-Search Site Removal Services.” Consumer Reports, 8 August 2024. 32 volunteers in California and New York split into four groups of eight; within each group seven were assigned one removal service and the eighth opted out manually, so each service and the manual control was evaluated with four participants, across 13 people-search sites over four months. Full report (PDF).

If this is your situation

If you have already reduced your exposure and want it kept that way, the Guardian retainer re-checks the worked sources each cycle and re-audits the wider surface annually.

Keep exposure from rebuilding Request a free Snapshot Scan

Share this briefing

If this was useful, sharing it helps others protect themselves. It also helps keep the intelligence briefings free.

Or get the quarterly intelligence brief — significant breaches, OSINT technique shifts, and executive privacy risks, once a quarter. Read the briefing →