Your CEO's Home Address Is Online.
So Is Their Daily Routine. Is Anyone Watching?

On December 4, 2024, UnitedHealthcare CEO Brian Thompson was shot and killed outside a Midtown Manhattan hotel as he walked to an investor conference. The attack was planned. Investigators determined that the alleged shooter had used publicly available information, such as Thompson’s conference schedule, his professional background, and his predictable movements in a location he had announced, to identify his target, track his arrival, and execute the attack in a matter of seconds (ASIS International, 2024; SecAlliance, 2025). Thompson had no personal protective detail assigned to him that morning. He was one of the most visible executives in one of the most politically exposed industries in the United States, and the threat against him had been building in plain sight on social media for months before anyone connected the indicators to a physical risk. His death did not create the executive protection crisis. It revealed one that had been developing for years, one in which the digital exposure of corporate leaders had far outpaced the security programs designed to protect them. In the months that followed, embedded executive security services at major protection firms grew 30 percent. Ad hoc travel security for executives surged 300 percent. The share of S&P 500 companies reporting personal security perquisites in their proxy filings jumped 21 percent in a single year (Fortune, 2025; OfficerList, 2026). The boards had finally done the math. The question now is whether the programs being built in response to that calculation are actually designed to address the threat they face, or whether they are buying the appearance of protection while leaving the mechanism that enables modern attacks entirely unaddressed.

The Digital Exposure Problem Is Structural, Not Incidental

The first thing a sophisticated threat actor targeting a corporate executive does is not acquire a weapon. It is conducting research. Open-source intelligence — the systematic collection and analysis of publicly available information from social media, data broker databases, public records, corporate filings, flight tracker applications, and online forums — provides a threat actor with a detailed operational picture of their target before they have taken a single covert action. The data available through this research is, by any measure, alarming. A VanishID analysis of the publicly exposed digital footprints of more than 10,000 chief executives across 65 industries found that the vast majority have contact details, home addresses, personal email addresses, and social media accounts accessible without any specialized tools, and that the average executive has been involved in 12 separate data breaches. each one expanding the available intelligence picture (VanishID, 2025). Brightside AI’s analysis found that 99 percent of executives have personal information exposed on more than 36 data broker websites, including home addresses and family details, and that executive-level employees are consistently 25 to 30 percent more exposed online than the general workforce (Brightside AI, 2025). DeleteMe’s analysis of executive privacy profiles concurred: organizations spend upwards of $500,000 per year per executive on physical security and threat detection while leaving the primary enabler of those threats, the open web exposure that makes targeted attacks possible, almost entirely unaddressed (DeleteMe, 2025).

The operational consequence of this exposure is not theoretical. Between June and December 2024, CEOs faced over 1,560 direct threats on social media. In the five weeks that followed Thompson’s assassination, that figure surged to more than 2,200 — as platforms like “The CEO Database” emerged, publishing the personal details of senior executives across more than 1,000 companies, including home addresses, mobile numbers, and family information, specifically to facilitate targeting (ZeroFox, 2025; Kaseware, 2026). The SecAlliance analysis of the post-Thompson threat environment documented a specific pattern of escalation: supporters of the alleged attacker amplified his ideology online, running campaigns under tags like “Luigi Was Right” and using his case as a template for new targeting research against executives in industries perceived as similarly exploitative (SecAlliance, 2025). A nation-state dimension compounds the individual grievance threat: the International Security Journal documented a foiled Russian intelligence plot to assassinate Armin Papperger, CEO of German defense contractor Rheinmetall, linked to the company’s role supplying Ukraine with weapons, establishing that executive targeting by state actors has moved from espionage tradecraft to direct kinetic planning (SecAlliance, 2025). For corporate security directors who have spent careers managing physical security programs designed around workplace violence and VIP logistics, the threat landscape of 2026 looks fundamentally different from the one those programs were built for. 

Why Most Executive Protection Programs Are Misaligned with the Threat 

The ASIS International and Everbridge joint study on executive protection, published in 2025, provides the most comprehensive diagnosis of the gap between the threat and the program response. Forty-two percent of security professionals reported a significant increase in focus on executive protection in just the past 18 months — a surge driven by high-profile incidents (69%) and the amplification of threats through social media and online forums (72%) (Everbridge, 2025; Security Magazine, 2025). Those headline figures describe organizations that have recognized the problem. The implementation findings describe how poorly most of them are solving it. Eighty-two percent of organizations reported using OSINT for executive protection, but most lack the tools for real-time analysis or behavioral threat detection. This means they are conducting periodic research snapshots rather than the continuous monitoring required by the threat environment (Everbridge, 2025). Eighteen percent rarely or never assess travel risks in advance, leaving executives vulnerable at precisely the moment — departure from predictable routines, exposure in unfamiliar environments, dependence on local logistics  when they are most accessible to threat actors (Everbridge, 2025). Only 24 percent of businesses have a travel risk management program that meets the ISO 31030 standard, despite the fact that travel remains the highest-risk operational context in executive protection (Kaseware, 2026). Thirty-four percent of organizations lack a formal process to evaluate whether their protection programs are effective, meaning they are investing in security measures whose actual performance against real threats has never been assessed (OfficerList, 2026). 

The cultural problem underlying these gaps was identified precisely by Rick Mercuri, Senior Advisor for Corporate Security at Rebel Global Security: many companies have spent years on “performative” security measures — the visible, reassuring elements of an executive protection program that satisfy a board inquiry or an insurance requirement without necessarily creating genuine protection against the threat categories that have actually generated harm (OfficerList, 2026). A close protection agent at the CEO’s side in the office provides a visible security presence that photographs well and satisfies the instinct to respond to a visible threat with a visible countermeasure. It does not address the stalker who has been monitoring the executive’s LinkedIn posts for three months to determine their home neighborhood, the dark web forum where a fixated individual has been building a targeting package using breached credential data, or the deepfake audio clip impersonating the executive that has been used to transfer $2.1 million from the corporate treasury. These are the mechanisms of the actual threat, and they operate in the digital layer that most executive protection programs are still treating as a cybersecurity department problem rather than a physical security imperative.

The Digital-Physical Threat Intelligence Model

The operational reality every serious executive protection practitioner now operates within is that digital exposure leads to physical risk through a pipeline that is faster, more accessible, and harder to monitor than any previous threat channel. “There are no physical risks without digital risks, and vice versa,” David Dezso, CEO of Banyan Risk Group, told the International Security Journal, a formulation that captures the integrated architecture that effective 2026 EP programs require (International Security Journal, 2026, para. 5). That architecture combines three mutually reinforcing functions: digital security, human intelligence and analysis, and on-the-ground protective operations, with each function continuously informing the others rather than operating as separate departmental lanes (International Security Journal, 2026).

The digital security function begins with the executive’s personal footprint. A comprehensive digital exposure audit, mapping every data broker listing, every public record, every social media account for family members, every property record, every professional directory listing, and every breach dataset that has captured the executive’s personal information, establishes the baseline of what a threat actor can assemble in an afternoon of open-source research. Suppression and opt-out campaigns that work to remove the most operationally dangerous data from the most accessible sources reduce the precision of targeting packages before they can be assembled. Continuous monitoring of surface web, deep web, and dark web sources for the executive’s name, address, family members’ names, workplace, and associated identifiers provides the early-warning signal that allows intervention before digital fixation translates to physical action (OSINT Industries, 2025; Security Boulevard, 2025). The North Group’s documentation of real-world OSINT-based threat detection illustrates how this works in practice: a Fortune 500 CEO was the subject of social media posts escalating from vague grievances to explicit threats, which analysts flagged, investigated, and escalated to law enforcement — neutralizing the threat before any physical contact occurred (The North Group, 2025). Organizations using OSINT-enhanced executive protection have documented up to 80% higher threat-prevention rates and 60% fewer false positives than traditional programs (The North Group, 2025).

The human intelligence and analysis function is what transforms data collection into protective decision-making. The Kaseware analysis of effective 2026 EP program architecture is explicit on this point: OSINT monitoring without trained analytical professionals interpreting the signal produces noise, not intelligence (Kaseware, 2026). Behavioral threat profiling, the structured assessment of whether an individual’s online activity indicates fixation, escalation, or operational planning rather than general grievance expression, requires the same clinical judgment that drives effective BTAM programs in other security contexts. The difference between a threatening social media post that represents venting and one that represents the early stage of target surveillance is not visible in the content alone. It is visible in the pattern of activity, the level of research the poster has conducted into the executive’s routines, the network of other accounts the poster is connected to, and the trajectory of escalation over time, all of which require trained analytical professionals, not automated keyword alerts, to assess accurately.

Pattern-of-Life and the Travel Window

The moment of greatest executive vulnerability is not in the corporate office, with its access controls, security cameras, and proximity to trained personnel. It is in transit — at airports, in hotel lobbies, at conference venues in unfamiliar cities, during the predictable gaps in a published schedule when an executive is between protected environments and dependent on ad hoc local security arrangements that have not been pre-assessed against the specific threat profile of the individual being moved. The ZeroFox analysis of physical security threats facing Fortune 500 executives documented the specific operational advantage that publicly available schedule information provides to threat actors: social media and event announcements provide criminals with real-time location pinpointing capability, making executives who maintain visible public profiles predictable in ways that no amount of ground-based security can offset if the travel security architecture has not been built around intelligence-led route planning and itinerary protection (ZeroFox, 2025). The Blackstone and Rudin Management executives shot in Manhattan in July 2025, killings that Fortune’s analysis described as part of the cascade effect following the Thompson assassination, were killed at a public location in a predictable professional context (Fortune, 2025).

Pattern-of-life analysis, the systematic mapping of an executive’s routines, recurring locations, predictable schedules, and exposure windows, is the protective intelligence function that closes the gap between digital threat monitoring and physical security deployment. A threat actor who has assembled an executive’s home address, vehicle registration, preferred gym, children’s school, and typical departure time from a combination of social media posts, property records, and data broker databases has constructed a targeting package that a bodyguard responding to a visible threat cannot retroactively protect against. The protective intelligence professional who has conducted the same analysis — from the inside, before the threat actor has completed theirs — can identify and mitigate the specific exposure points that the targeting package would exploit: varying routes, adjusting public schedule visibility, relocating predictable activities, and ensuring that the security detail’s deployment matches the threat environment rather than the calendar. This is the analytical function that distinguishes intelligence-led executive protection from reactive physical security — and it is the function most conspicuously absent from the majority of programs that respond to the Thompson assassination by adding a close protection agent and calling the problem solved.

The Family Dimension and Residential Exposure

One of the most consistent findings in executive threat analysis is that the principal’s family members and residential environment represent a more accessible attack surface than the principal themselves — precisely because they are typically less protected, follow more predictable patterns, and provide a leverage point that threat actors can exploit to reach an executive who is otherwise difficult to access directly. The International Security Journal documented the mechanism with multiple real-world cases: Kim Kardashian’s 2017 Paris robbery was facilitated by social media monitoring that confirmed she was alone and the location of her valuables; footballer Jack Grealish’s home was burgled in December 2024 while he was playing a publicly scheduled match; Lionel Messi’s Ibiza property was targeted by activists who had identified it through public records and property listings (SecAlliance, 2025). These patterns apply directly to corporate executives: a spouse’s social media account revealing the family’s home neighborhood, a child’s school identified through a parent’s Instagram post, and a property listing showing the layout of a residence to anyone who searches the address. Each represents a vector that a sophisticated threat actor will exploit before directly approaching the executive themselves.

The Goldman Sachs Ayco 2025 survey found that the most common personal security measures being added by large corporations include home security fortification and protection of family members, a recognition that the executive’s residential and family environment is now understood as part of the protection perimeter that the program must encompass (Fortune, 2025). The 2025 Security Benchmark Report documented that 27 percent of respondents now provide personal security for their CEOs — a 59 percent increase in the share providing the benefit from two years earlier — but the majority of those programs have not yet extended comprehensive protection to the family members whose digital exposure and predictable routines create the most accessible targeting vectors in the entire protection architecture (Fortune, 2025; Security Magazine, 2025).

Conclusion

The executive protection program that was adequate in 2022 is not adequate in 2026. The threat environment has changed in three fundamental ways simultaneously: the digital infrastructure for targeting individual executives has become dramatically more accessible and comprehensive; the ideological and political landscape has produced a sustained culture of grievance-driven executive targeting, generating both high-profile attacks and a persistent challenge of online threat monitoring. The speed at which digital intelligence translates to physical action has compressed from months to days. The ASIS International research finding that 42 percent of security professionals are reporting significantly more emphasis on executive protection than 18 months ago is the industry recognizing that these changes require a response (Security Magazine, 2025). What that response looks like, whether it is a close protection agent assigned to the public appearances of a CEO whose home address, family routine, and daily schedule are accessible to anyone with an internet connection, or an integrated digital-physical intelligence program that monitors the threat environment, suppresses the executive’s exposure, and aligns protective deployment with actual intelligence,  will determine whether the investment creates genuine security or the appearance of it. The threat actors who target corporate executives in 2026 begin their work online, months before any physical action is taken. The protection programs that will actually protect those executives must begin their work in the same place, at the same time, and with the same analytical discipline. 

References

ASIS International. (2024, December 10). Alleged UnitedHealthcare CEO assassin captured: Implications for security. https://www.asisonline.org/security-management-magazine/latest-news/today-in-security/2024/december/alleged-unitedhealthcare-assassin-captured/

Brightside AI. (2025, November 19). OSINT for executives: How hackers use your digital footprint against you. https://www.brside.com/blog/osint-for-executives-how-hackers-use-your-digital-footprint-against-you

DeleteMe. (2025). Executive exposure: How publicly available personal data endangers cybersecurity in 2025. https://www.gbiimpact.com/news/executive-exposure-how-publicly-available-personal-data-endangers-cybersecurity-in-2025

Everbridge. (2025, October 19). Executive protection: Safeguarding leaders in a connected world. https://www.everbridge.com/blog/executive-protection-safeguarding-leaders-in-a-connected-world/

Fortune. (2025, October 21). Fear sweeps the C-suite — companies pour millions into security as threats against executives surge. https://fortune.com/2025/10/21/ceo-security-costs-surge/

International Security Journal. (2026). The new frontiers of executive protection. https://internationalsecurityjournal.com/data-executive-protection-rowan/

Kaseware. (2026). Executive protection in 2026. https://www.kaseware.com/post/what-is-executive-protection-and-why-it-matters-in-2026

OfficerList. (2026, April 11). Executive protection trends in 2025. https://officerlist.com/blog/executive-protection-trends-2025/

OSINT Industries. (2025). Beyond bodyguards: OSINT for executive protection and risk management. https://www.osint.industries/post/beyond-bodyguards-osint-for-executive-protection-and-risk-management

SecAlliance. (2025, October 8). The expanding threat landscape for executives. https://www.secalliance.com/blog/the-expanding-threat-landscape-for-executives

Security Boulevard. (2025, April 24). Beyond cybersecurity: OSINT for executive protection. https://securityboulevard.com/2025/04/beyond-cybersecurity-osint-for-executive-protection/

Security Magazine. (2025). The rising tide of executive protection: Corporations ramp up security in an era of heightened threats. https://www.securitymagazine.com/articles/102199-the-rising-tide-of-executive-protection-corporations-ramp-up-security-in-an-era-of-heightened-threats

The North Group. (2025, September 4). How OSINT is revolutionizing executive protection. https://tngdefense.com/executive-protection/how-osint-is-revolutionizing-executive-protection/

VanishID. (2025, December 23). VanishID executive digital privacy snapshot: Leadership at risk. https://vanishid.com/resources/blog/vanishid-executive-digital-privacy-snapshot-leadership-at-risk/

ZeroFox. (2025, March 26). Top physical security threats facing Fortune 500 executives in 2025. https://www.zerofox.com/blog/physical-security-threats-facing-executives/