EXECUTIVES’ families are increasingly deemed a soft underbelly for corporate security, with attackers pivoting from the office to the home through social engineering and device compromises. The piece cites March 2026 findings from Google Cloud’s Office of the CISO and industry voices warning that personal attacks against executives are rising, aided by AI-powered reconnaissance that maps household relationships, routines and locations without touching a corporate network.
The narrative outlines three main attack vectors: impersonation and social engineering aimed at trusted relatives, compromising household devices, and phishing or smishing targeting less technically savvy family members. The consequences span digital and physical domains, with leaked travel itineraries or home addresses potentially enabling surveillance, burglary or extortion.
Notably, examples and expert commentary describe how a compromised family member or executive assistant can give criminals enough footholds to facilitate account takeovers or pressure ransom payments.
The article draws on prior studies and industry commentary to quantify the risk: a 2023 Ponemon/BlackCloak study found 42% of respondents had experienced at least one attack involving key executives or their families; Dragos reported a ransomware incident that targeted family members after an executive’s ransom non-compliance; and Mandiant cautioned about SIM swapping attacks affecting executives’ children.
In 2025, Ponemon/BlackCloak reported 51% of organisations experienced attacks on business leaders, up from 43% in 2023, with 39% of executives’ devices already compromised and 20% with unmonitored home networks.
Practical responses emphasise tightening family security postures: avoid SMS for MFA and enable SIM swap protections, trim digital footprints where feasible, use aliases on social profiles and contact cards, and educate relatives about scams, impersonation risks, QR code phishing, and the dangers of shared calendars or personal travel details that could be exploited.