Security Threats Don’t Stop at the Office: Why Executives’ Families Need Training, Too

Cybersecurity threats don’t stop at the office door. In fact, they often begin with a seemingly innocuous attack on an executive’s family member or friend. The notion that security training is limited to corporate networks and employees is no longer tenable. With the rise of cyberattacks targeting executives’ personal lives, their loved ones are now a critical vulnerability in the fight against online threats.

The consequences of these attacks can be severe, extending far beyond digital compromise. A stolen itinerary or home address can lead to physical surveillance, break-ins, or extortion. Even something as seemingly harmless as a child’s school play on a shared calendar can provide an attacker with the perfect timing for a fraudulent wire request. This is not just a security issue; it’s a family matter.

The tactic of using executives’ confidants to conduct social engineering campaigns, assist with account takeovers, or provide clues that help an attacker guess passwords is nothing new. In fact, research from 2023 showed that 42% of respondents had experienced at least one attack on key executives and family members. Moreover, a Ponemon Institute study in conjunction with BlackCloak revealed that 51% of organizations reported attacks on their business leaders in 2025, up from 43% in 2023.

The statistics are alarming, but the reality is even more pressing. In many cases, these attacks begin with compromised devices belonging to family members or friends who may not have received proper security training. This lack of awareness creates a vulnerability that attackers can exploit. According to Brian Hill, field chief information security officer (CISO) at BlackCloak, “Even something as harmless as a child’s school play on a shared calendar can give an attacker exactly the timing they need for a fraudulent wire request.”

The use of artificial intelligence has further complicated these attacks. AI offers new tools that enable attackers to map out a household’s relationships, routines, and locations without ever touching a network. This not only puts family members at risk but also creates opportunities for physical threats like surveillance or break-ins.

It’s essential for executives to recognize the vulnerability their loved ones pose. A 2023 Ponemon Institute study showed that 39% of executives had devices that were already compromised without their knowledge, and 20% had unmonitored, open-access home networks. Every one of these gaps is shared with the people they live with, making them an attractive target for attackers.

The takeaway from this alarming trend is clear: security awareness training must extend beyond corporate walls to include family members and friends. Executives can no longer afford to ignore the risks their loved ones pose or assume that security protocols are sufficient to protect against these types of attacks. By acknowledging this vulnerability and taking proactive steps, executives can reduce the risk of a cyberattack on their personal lives and better protect their families.


Source: Dark Reading — 2026-10-09