The Internet is a space where we share information daily. Social networks, forms, online purchases… Each action leaves a slight digital trace. Most of the time, we are unaware of how much we reveal about ourselves. This is where an increasingly well-known and feared concept comes into play: doxing.
What is doxing, and why should you care?
Doxing (short for dropping dox or “dropping documents”) is the practice of collecting and publishing a person’s personal information without their consentwith the aim of exposing, intimidating, or harming them. This may include her full name, address, phone number, email address, place of work, private photos, family information, and even financial data.
What distinguishes doxing from a simple Google search is the intention: the doxer gathers scattered information from multiple sources such as social networks, leaked databases, public records, the dark web… to build a detailed profile of a person and use it against them.
These types of attacks, which initially emerged in very specific online communities, have spread in recent years and can have serious consequences: from harassment, threats, and identity theft… up to and including job loss or legal problems.
Doxing on the internet is not just a simple hacking game. It is a form of digital violence classified in Spain and many other countries with penalties that can reach up to four years in prison.
Qondar: Personal cyber-surveillance to know when you’re being doxed before it’s too late
Before continuing, it is worth stopping at our featured tool: Qondar, a solution for personal cyber surveillance.
Qondar has been developed for anyone who wants to maintain control over their information on the network without needing advanced technical knowledge. It works like a Continuous Threat Exposure Management (CTEM) platform. It lets you detect if your data is being shared without permission in forums, leaked databases, social networks, or even the dark web.
Even if you don’t know what doxing on the internet is, you may still suffer an attack. If so, Qondar will tell you before it’s too late.
Why does someone decide to dox another person?
There is no single attacker profile or motivation. Doxing, as this phenomenon is also known, can have many faces:
- Personal revenge: Ex-partners, ex-friends, or work conflicts can lead to malicious leaks.
- Extreme ideology or activism: Some users publish data about opponents to intimidate or silence them in political or social debates.
- Practical jokes or viral challenges: especially among teenagers or in toxic online communities.
- Extortion and blackmail: Once they have your data, some attackers try to obtain money or favors in exchange for not disclosing it.
- Coordinated harassment. Organized groups (sometimes called hate brigades) simultaneously attack the same person, especially journalists, activists, or public figures.
- Professional cybercrime. Personal information such as DOB, address, and phone number is sold on specialized forums to facilitate identity fraud.
Whatever the reason, the result is the same: your privacy and security are compromised.
What type of data is typically exposed when doxing?
Although the degree of exposure varies, the most common data that is published or sold in doxing cases are:
- Full name and physical address
- Phone number
- Profiles on social networks (including anonymous accounts linked to the person)
- Personal photos
- Information about the family environment
- Employment or academic data
- Purchases, searches, donations, or affiliations
A simple cross-referencing of leaked databases, like those circulating on the dark web, can be enough to build a complete profile in minutes. That’s why prevention is more effective than reaction.
Bonus: Where is doxed data published? Primarily on platforms like Doxbin (accessible from the open web, with nearly 200,000 registrations), dark web forums, Telegram channels, and, in cases of coordinated harassment, directly on social networks like X or Reddit.
How to avoid being doxed: good practices to protect your privacy
To know how to protect yourself from doxing involves changing certain digital habits.. Here are some practical tips that you can start applying today, now that you understand what doxing is:
-
Audit your digital footprint regularly
Enter your first and last name into search engines and see what comes up. Also search for combinations with your email address, phone number, and most-used username. If you find data that shouldn’t be public, request its removal by exercising your right to be forgotten through your national Data Protection Agency.
Tools like Qondar automate this process by monitoring any new occurrences in your data in real time and notifying you immediately.
-
Review the privacy settings of your social media accounts
- Activate private profiles on Instagram, TikTok, and Facebook.
- Check what information is public on LinkedIn (date of birth, phone number, location).
- Delete or limit your Facebook posting history.
- Do not post documents, plane tickets, or photos that show your address or car registration.
You might be interested in→ 5 social media security strategies.
-
Use strong, unique passwords and enable 2FA
- Do not reuse passwords across multiple services.
- Enable two-step authentication (2FA) whenever possible.
Learn how to manage passwords properly.
-
Beware of online forms and contests
- Do you really need to give your phone number to enter that raffle?
- Use secondary or temporary email addresses whenever possible.
-
Protect your anonymity in public debates and forums
Many doxing victims are targeted precisely because of their opinions expressed online. If you participate in polarized debates, avoid using the same username on multiple platforms and don’t post unnecessary personal details.
-
Protect your immediate surroundings
Doxing often involves information about family members. Talk to people in your life about what information they post that could locate you (mentions of your workplace, photos taken at your home, geolocation of joint posts).
-
Continuously monitor with specialized tools
Manual protection has its limits. Continuous monitoring solutions like Qondar allow you to detect exposures in real time, including the appearance of your data on the dark web or in leaked databases, before the damage becomes irreversible.
What do you do if you have been doxed?
If you’re already a victim of doxing, act quickly. Every hour counts.
- Document everything before requesting withdrawals. Take screenshots of all published content, including URLs.
- Contact the platforms where the information has been published. Use the content removal forms from Google, Meta, X, and any other involved platforms.
- Report it to the National Security Authorities, especially if there are threats, blackmail, or sexual content. Doxing can be classified as discovery and disclosure of secrets, harassment, or threats.
- Contact your national Data Protection Agency if your data protection rights have been violated. In 2025, the Spanish AEPD imposed a record 40 million euros in sanctions, reflecting its growing activity in defense of citizens.
- Inform those around you so that they are alert to possible attempts at social engineering using your information.
- Seek psychological support if the emotional impact is intense. Cyberbullying can cause anxiety, post-traumatic stress, and social isolation.
Is there any definitive protection against doxing?
There is no 100% foolproof barrier. But you can drastically minimize your exposure and be prepared to act before the damage becomes serious.
The key lies in early detection. On the internet, published data is indexed, copied, and distributed within minutes. What takes hours to publish can take years to disappear. That’s why continuous and proactive monitoring of your digital identity is the most effective measure available today.
This is precisely what Qondar does: to continuously and automatically monitor whether your information appears where it shouldn’t, and alert you in real time so you can take action. No technical knowledge required. No interruptions to your daily routine.
Now that you know what doxing is, it’s clear that it’s not a problem exclusive to celebrities or public figures. In a world where identity theft on social media is growing year after year, protecting your personal information is crucial.
Your privacy is part of your security. Start protecting it today.
Frequently Asked Questions
What does it mean to dox someone?
Doxing someone means collecting and publishing that person’s personal information (name, address, phone number, workplace, etc.) without their consent, with the aim of exposing, intimidating, or harming them.
Is it a crime to dox someone?
Yes. Although most penal codes around the world do not use the term “doxing,” the practice can be classified as disclosure of secrets, harassment, or threats, with penalties of up to four years in prison. It can also lead to sanctions for violations of the Data Protection Acts and the Data Protection Regulations.
How do I know if I’m being doxed?
The most common signs are receiving threatening messages from strangers, noticing that people you don’t know know details of your private life, or finding posts with your personal information on forums or social networks.
Tools like Qondar allow you to detect it proactively, before the effects are visible.
How to avoid being doxed?
The most effective measures are to audit your digital footprint regularly, properly configure privacy settings on social networks, use unique passwords with 2FA, be cautious with the data you provide in forms, and use continuous monitoring solutions like Qondar.
What do I do if someone has published my personal data without my permission?
Document everything with screenshots, request the removal of the content from the platform and Google through the right to be forgotten, report it to the Security Authorities, and go to the Data Protection Agency if your data protection rights have been violated.



