Your Personal Brand Is an Attack Surface
Every talk, bio, and commit you publish to build a name is also recon and impersonation fuel. A vCISO's founder-scale checklist for hardening your identity.
In this post
- The thing you’re building is also a dossier
- This has already happened to companies bigger than yours
- How much of your voice does someone need to clone it?
- Should founders stop posting to avoid being deepfaked?
- The three attacks your visibility feeds
- The hardening checklist
- Where this sits in the rest of your security program
- The takeaway
TL;DR: Founders and senior engineers get told to build in public: give talks, post on LinkedIn, ship open source, go on podcasts. That advice is right, and every piece of it also hands an attacker something. Your conference talk is voice-clone training data. Your LinkedIn history is an org chart. Your GitHub profile can make you a target for fake-recruiter lures. The accounts that carry your reputation are worth taking over because they carry it. Wiz, LastPass, and WPP have all had their CEOs’ voices or faces used against their own staff, and FBI complaints mentioning AI carried more than $893 million in adjusted losses in 2025. The fix is not to go quiet. It’s to secure the identity you’re building as seriously as the product you’re shipping. That means phishing-resistant auth on every profile that carries your name, one public page listing where the real you lives, written verification rules for any request involving money or access, and a short list of things you stop publishing. Most of it takes an afternoon, and none of it requires a security team.
The thing you’re building is also a dossier
Every playbook for getting known as an engineer or founder says the same things. Pick a lane, publish consistently, put your face and voice out there, make every profile agree, and point it all back to a site you own. I follow that playbook. This site exists so my name is easy to find.
Here’s the part the playbook leaves out. Everything that makes you easy to find also makes you easy to profile. An attacker scouting a target does the same research a recruiter or investor does, with a different goal. Nothing in that research requires a breach. You published all of it on purpose.
Look at a founder’s public footprint from the attacker’s side and this is what you see:
| What you published to build a name | What it gives an attacker |
|---|---|
| Conference talks, podcasts, YouTube interviews | Clean audio and video of you speaking, which is exactly what a voice or video clone needs |
| LinkedIn role history, team shout-outs, “welcome our new Head of Finance” posts | Who reports to whom, who can move money, and who is new enough not to know how you really communicate |
| Headshot, bio, one-line description | Everything needed for a convincing fake profile or WhatsApp account in your name |
| GitHub activity, open-source repos, stack posts | Your languages, tools, and habits, which is enough to pitch you a believable “collab” or a job with a take-home repo |
| “Speaking in Lisbon next week” posts | A window when you’re traveling, busy, and hard to reach, which is the ideal cover for “I’m on a plane, just approve it” |
| The profiles themselves, with followers and history | An asset that’s worth more hijacked than any fake profile, because its reach is already real |
None of this is a reason to delete your LinkedIn. It’s a reason to treat your public identity as a system with an attack surface, and to harden it with the same discipline you’d use on anything else you’re responsible for.
This has already happened to companies bigger than yours
This isn’t a hypothetical threat model. Large companies with public-facing leaders have been hit, and several of them went public about it.
Wiz. In October 2024, Wiz CEO Assaf Rappaport said on stage that dozens of his employees had received a voice message from “him” asking for their credentials. The attacker had built the clone from a public conference recording. It failed for a very human reason: Rappaport has public-speaking anxiety, so his conference voice doesn’t sound like his everyday voice, and his staff noticed. The attacker used his most visible audio, and that turned out to be the least representative sample.
LastPass. In April 2024, a LastPass employee received a series of WhatsApp calls, texts, and at least one voicemail with an audio deepfake of the CEO. The employee ignored it and reported it. Two things gave it away: the fake urgency, and the fact that it came over WhatsApp, outside LastPass’s normal business channels. The detection wasn’t technical. The employee knew WhatsApp wasn’t a normal business channel, and noticed the forced urgency.
WPP. In May 2024, WPP CEO Mark Read disclosed that attackers had set up a WhatsApp account using CEO Mark Read’s public photo, used it to set up a Microsoft Teams meeting with a senior executive, and ran a voice clone plus YouTube footage of Read during the call. The goal was to get money and personal details out of the executive under the cover of setting up a new business. It failed, again because people were paying attention.
Arup. This is the one that didn’t fail. A finance employee in Arup’s Hong Kong office made transfers totaling about $25 million after a video call where the CFO and the other “colleagues” were deepfakes. The employee was reportedly suspicious of the initial request and was convinced by the call.
Engineers get a different version. According to people who spoke to The Block, attackers got into Axie Infinity’s Ronin network by approaching a senior engineer on LinkedIn with a fake job: several interview rounds, a generous offer, and an offer letter PDF that carried spyware. Roughly $540 million in crypto left the network, and The Block reports that the US government later tied the attack to North Korea’s Lazarus Group. GitHub later warned about a North Korea-linked group it calls Jade Sleet that poses as developers or recruiters on GitHub, LinkedIn, Slack, and Telegram. The group invites targets to collaborate on a repo, then gets them to clone it and run code with malicious npm dependencies. GitHub also noted that some of those “personas” were real accounts the group had taken over. GitHub doesn’t say why those accounts were chosen. My read: a reputation is exactly what makes an account worth stealing.
The aggregate numbers track the anecdotes. The FBI’s 2025 IC3 annual report logged $3.05 billion in business email compromise losses. It also received more than 22,000 complaints mentioning AI, with adjusted losses above $893 million. Only a slice of the BEC losses, over $30 million, involved AI, so don’t read this as “deepfakes are the whole problem.” The larger losses still come from old-fashioned impersonation. AI makes that impersonation cheaper to produce and harder to spot.
How much of your voice does someone need to clone it?
Not much, and one podcast episode is well past it. When OpenAI previewed its Voice Engine model in March 2024, it said the model could generate natural-sounding speech from a single 15-second audio sample. A founder with a handful of conference talks online has handed over far more than that.
Video is the harder half, and it’s already being used. The FBI’s December 2024 PSA on generative AI fraud describes criminals generating video for real-time chats with alleged company executives. The Arup call shows that this works on a finance employee who went in suspicious.
The practical conclusion: assume your voice and face can be faked convincingly, and stop treating “it sounded like them” as verification. A familiar voice, a familiar face on a video call, and a familiar writing style no longer prove who is on the other end.
Should founders stop posting to avoid being deepfaked?
No. For a founder, going quiet costs more than it protects, and it doesn’t remove the audio and video that are already public. The FBI’s consumer guidance does say to “limit online content of your image or voice” and make accounts private. That’s reasonable advice for someone whose livelihood doesn’t depend on being findable. If your pipeline, your hiring, and your fundraising run on people recognizing your name, it’s the wrong trade. You’d be giving up something real to shrink an attack surface that’s already exposed.
The better move is to change what verifies you. An attacker can copy your voice. They can’t copy a rule your team and partners already know: money requests never arrive by WhatsApp, and every real profile is listed on one page you control. So stop depending on a secret you can’t keep (your likeness) and start depending on a process everyone knows.
This is where the personal-brand playbook and the security playbook agree. The branding advice says to make every profile consistent: same name, same role, same one-line description, same headshot, all linking back to one domain you own. The point is that people and AI answer engines form one clear picture of you. It also makes impersonation easier to spot. When every real profile agrees and points to one address, a fake account using a different handle, an old photo, and a slightly wrong title stands out. A scattered identity gives an impersonator cover.
Your voice is no longer proof. Your process still is.
The three attacks your visibility feeds
Before the checklist, it helps to separate the attacks, because each one needs different controls.
Impersonation of you, aimed at people who trust you. Your team, your finance contractor, your investors, your customers. The attacker is you, asking for a wire, a gift-card run, an MFA code, a password reset, or admin access “for a vendor.” Wiz, LastPass, WPP, and Arup were all this attack. The FBI’s May 2025 warning about AI voice messages impersonating senior U.S. officials describes the same pattern at government scale: build rapport, move the target to a different messaging platform, then collect credentials. The defense is a verification rule, not detection.
Pretexting aimed at you. A fake recruiter, a fake collaborator, a fake sponsor, a fake investor who wants you to “just review this deck.” The Axie Infinity breach and the Jade Sleet campaign both worked this way. The more specific your public footprint, the more tailored the lure can be. The defense is an isolation habit: unsolicited code and documents don’t get opened on the machine that holds your production credentials.
Takeover of the accounts that carry your name. Your LinkedIn, your X account, your GitHub, your YouTube channel. The payoff is borrowed credibility at scale: a crypto scam broadcast to your followers, a malicious repo pushed under your name, or DMs to your whole network from an account they already trust. Google’s Threat Analysis Group documented a long-running campaign that hijacked YouTube creators’ channels with fake collaboration offers. The malware stole browser session cookies, which let attackers into accounts with a stolen session instead of a login, and the stolen channels were resold for up to $4,000 or used for crypto scams. The SEC’s own X account was taken over in January 2024 after an apparent SIM swap moved its phone number to an attacker. MFA had been turned off since the previous July, when staff were having trouble accessing the account. The defense is account hardening that assumes both your password and your phone number can be taken.
The hardening checklist
This is sized for a founder or senior engineer without a security team. None of it is exotic. Most of it is an afternoon, plus a conversation with the people who could move money or grant access on your behalf.
1. Lock the accounts that carry your reputation.
- Put a passkey or hardware security key on every account that carries your name: email, LinkedIn, X, GitHub, YouTube, your domain registrar, your DNS host, and your password manager. CISA’s guidance names FIDO/WebAuthn as the phishing-resistant standard and treats app codes and push notifications as interim options. Where a platform only offers an authenticator app, use it. SMS is the last resort.
- Take your phone number out of account recovery wherever you can. The SEC incident started with what the SEC called an apparent SIM swap. If a carrier employee can move your number, a recovery flow that trusts your number trusts the attacker.
- Your registrar and DNS host matter most. Whoever controls your domain controls your email, your “where to find me” page, and the password resets for everything else. Enable registrar lock and give it your strongest authentication.
- Keep recovery codes offline, and store them somewhere other than the device you’d lose.
- Remove old sessions and connected apps from each profile. An OAuth grant you approved years ago and forgot about may still be a live key.
- Assume session theft can get past MFA. A stolen session cookie skips the login, and the YouTube campaign ran on stolen cookies. So don’t install “demo software” a would-be collaborator emails you, and keep a separate browser profile for the accounts that carry your reputation.
2. Publish a “where to find me” page.
Put one page on the domain you own. List every real profile you have, with exact links and handles. Then state plainly how you contact people and how you never do. For example: “I will never ask you to move money, share a login code, or install software over DM, WhatsApp, or text. If a message from ‘me’ asks for any of that, it isn’t me.” Link every profile back to that page. When someone gets a strange message from “you,” they now have somewhere to check that you control. When a fake account appears, you have a canonical list to point the platform to in your report. This is the security version of the branding advice to own the one address everything points back to.
3. Write out-of-band verification rules for money and access.
This is the control that actually stops the Arup outcome, and it has to be written down before the call comes in, because nobody invents a policy mid-panic.
- Any request to move money, change payment details, share a credential or MFA code, or grant access gets verified on a different channel, using contact details you already had, not ones supplied in the request. The FBI’s advice is the same: hang up and call back on a number you’ve independently confirmed.
- Urgency and secrecy make verification mandatory. “I’m boarding, just do it” and “keep this quiet until the deal closes” are the classic pretexts. Arup’s employee was first asked for a secret transaction, and after WPP’s attempt, Mark Read warned staff about any “secret acquisition, transaction or payment”. Say out loud that the more a request insists on skipping the process, the more certain it is to go through it.
- Two people approve payments above a threshold you choose. One of them should not report to the person making the request.
- Name the channels that are real. LastPass’s employee caught the fake partly because it came over WhatsApp, outside the company’s normal business channels. Decide where real requests from you come from, and tell everyone that requests from anywhere else are presumed fake.
- Consider a verbal codeword for the small group who can move money. The FBI recommends a secret word or phrase for families. A founder, a co-founder, and a finance lead are a family for this purpose.
If you read that list and realized nobody at your company could tell you today who is allowed to approve a wire, and how they’d confirm it’s really you asking, that’s the gap. Closing it early is the kind of work a fractional security lead does. The vCISO cost calculator will tell you whether that’s a few hours a month or a bigger engagement at your stage. It’s also worth checking whether your insurance covers the bad outcome. Some carriers now explicitly address deepfake-driven fraudulent instructions, so read yours for it.
4. Decide what you stop publishing.
Keep publishing your opinions, your talks, your code, and your face. Stop publishing the operational details that turn a generic lure into a targeted one:
- Who can move money, and who they report to. “Welcome our new finance lead, reporting to our CEO” is a targeting brief. Announce the hire without the approval chain.
- Real-time travel. Post about the conference after you get back, not while you’re unreachable.
- Your personal phone number and personal email on any public profile, slide deck, or podcast show notes.
- Your commit email. GitHub lets you keep your email address private and commit with a no-reply address. Turn that on, and remember that old commits already carry whatever address you used back then.
- Internal tool and vendor screenshots. A demo screenshot that shows your admin panel, your SSO provider, or your Slack workspace name tells a phisher exactly which login page to fake.
- Family voices and names. The FBI’s 2025 report describes distress scams that use voice cloning to mimic a loved one. Your kid’s voice in a public video is a separate risk from yours.
5. Tell your team the rule out loud, and make reporting cheap.
Written rules don’t protect anyone if the person getting the fake call is afraid of looking stupid or of annoying you. Every failed attack above failed because the person targeted noticed something was off and said so. A team that’s scared of its founder complies first and verifies never, which is exactly what an impersonator is counting on. I’ve written about why a scared team is your biggest attack surface. It applies twice as hard here, because the voice giving the scary order is yours.
Say it in an all-hands: “Someone will eventually impersonate me. If a request from me feels off, verify it through the channel we agreed on, and I will thank you every time, even when it really was me.” Then actually thank them.
Where this sits in the rest of your security program
None of this replaces product security. In my experience it’s the layer small-company security programs skip, because it doesn’t look like engineering. If you’re building the broader program, how I’d run security at an AI-native company covers the stack this sits beside. The account-hardening habits here are the human-identity version of what secrets management for AI agents does for machine credentials: the narrowest credential that does the job, short-lived tokens where they’re easy, and a named owner for rotation. And if you’re deciding which controls a small team can actually staff, this belongs on the list that doesn’t wait. Impersonation doesn’t care about your headcount. It gets more likely as your name gets better known.
The takeaway
Building a public name is one of the highest-leverage things a founder or senior engineer can do, and I’m not going to tell you to stop. But be honest about the trade: the more trust your name carries, the more that trust is worth stealing. Your likeness can’t be kept secret anymore. It stopped being proof. Your verification process is proof, along with the accounts behind your reputation and the operational details you choose not to post.
Harden the identity like you’d harden a production system. Lock the accounts, publish the canonical list, write the verification rules, cut the operational details, and make it safe for your team to say “that doesn’t sound like you.”
If you want a second set of eyes on your public footprint and the money-and-access rules behind it, that’s the kind of work I do with founders who’d rather set this up before the first fake call than after it.