What is doxxing and what can you do about it?
Doxxing is publishing someone's private identifying information without consent, typically to enable harassment. The name derives from "dropping docs".
What is typically published: home address, workplace, phone number, email, family members' names, children's school, vehicle details, or the real name behind a pseudonym.
Why it is dangerous. Doxxing is rarely the end point — it is an enabler. It converts online conflict into real-world risk: harassment at home and work, unwanted deliveries, threats, stalking, contact with employers to get someone dismissed, and swatting, where a false emergency call sends armed police to an address. Swatting has resulted in deaths.
Where the information comes from. Usually not hacking. It is assembled from:
Public records — in the UK the electoral register's open version, and Companies House, which historically published directors' addresses.
Data brokers aggregating and selling personal data.
Old accounts and forgotten posts, and usernames reused across services.
Photo metadata and identifiable backgrounds.
Social engineering of the target or people around them.
Previous data breaches, cross-referenced.
What to do if it happens:
Document everything first — screenshots with URLs, timestamps and usernames, before anything is deleted. This is the step people skip and later need.
Report to the platform under harassment and personal information policies. Most prohibit it explicitly and act relatively quickly.
Contact the police. In the UK this can constitute harassment, malicious communications, or an offence under stalking legislation. Get a crime reference number.
Tell your employer and anyone who might be contacted, so they are not caught unprepared.
Alert your bank and consider extra account security, since identity fraud frequently follows.
Preventatively: opt out of the open electoral register; use Companies House's service address provisions; audit what old accounts expose; use unique usernames; strip photo metadata; and enable two-factor authentication everywhere.