Aegean Intelligence Group
Research · PMR-2026-0714-USA-001
Publishable Market Research · 2026

The Footprint Before the Threat

A Principal's Digital Exposure, Mapped Before an Adversary Maps It

The Footprint Before the Threat: A Principal's Digital Exposure
PMR-2026-0714-USA-001 · Principal Exposure

An assessment of the open-source footprint that exists on a principal before any threat does: what an adversary can assemble from data brokers, breach corpora, and a family's own feeds; the documented cases where that assembly ended at a front door; what the new deletion regimes do and do not close; and the baseline a principal, family office, or protection team should actually commission.

Author
Zacharias · Principal
Pages
12
Timeliness
Durable (structural, multi-year)
Issue date
2026-07-14
Classification
Public
Sources
19 cited, allowlisted Tier 1 to 4
Read the full PMR (PDF)
Durable read · Update Addendum on the August 1, 2026 DROP compliance milestone, a publicly attributed data-to-doorstep case, or a material change in attack tempo

Key Judgments

Six judgments anchor this assessment. Each is tied to cited evidence in the body of the brief and carries an explicit confidence level.

  • High confidence. A working targeting package on a typical principal can be assembled from open and commercially available sources alone, with no intrusion required. Vendor research across roughly 200 broker and aggregator sites found an average of 95 exposed personal data instances per executive, property information visible for 98 percent, and breach-database email coverage of the full sample examined.
  • Moderate confidence. The open-source footprint is now the documented enabling vector in real attacks on principals, not a hypothetical: the accused in the June 2025 Minnesota political assassinations worked from a handwritten list of people-search sites, and the 2025 to 2026 wave of violent attacks on holders of liquid wealth is fed by leaked and brokered identity-address-balance data. The full chain is rarely proven end to end in any single case, but the direction is unambiguous.
  • High confidence. The exposure surface is the household, not the individual. Family members, household staff, and vendors continuously regenerate location, routine, and wealth signal, and the family-office structures that concentrate a principal's data are measurably the least defended: 43 percent have experienced a cyberattack while 63 percent carry no cyber insurance and 31 percent have no incident-response plan.
  • High confidence. The strongest deletion instrument yet built, California's DROP, becomes enforceable against brokers on August 1, 2026, and still does not close the exposure: only four states maintain broker registries at all, roughly 750 brokers are registered somewhere with large gaps between state lists, deletion rights stop at state lines, and brokers re-acquire data continuously.
  • Moderate confidence. Suppression works as a maintained cycle and decays as a one-time project. Removal across the broker layer measurably shrinks what an adversary can assemble cheaply, but records repopulate within months as brokers re-acquire data, so the value sits in the cadence, baseline, removal, re-audit, monitoring, not in any single pass. Confidence is moderate because repopulation is documented by practitioners and vendors rather than by independent controlled study.
  • High confidence. The decision-relevant metric for a principal is the live footprint: what an adversary can assemble today and how fast it reassembles after removal. That number must be owned by one accountable function spanning physical security, cyber, and privacy; a deletion receipt or an annual audit is a record of the past, not a security state.
Related coverage