First day at a new job, brand-new badge around your neck: the LinkedIn photo practically takes itself. We get the appeal, it’s a nice moment to share. The problem is that this photo, and other habits we don’t even notice anymore, hand out information that’s genuinely useful to someone looking to target your company.

In shortA photographed badge, a visible screen in the background, a sticky note with a password: every detail shared without thinking can feed a targeted scam or a physical intrusion into your offices. A separate work phone limits what a hack can expose, but lighter alternatives exist too. This kind of manipulation that plays on trust rather than technical skill, social engineering, feeds on these small public details, which professionals are sometimes paid to exploit under real conditions.

The badge you shouldn’t post

A photo of a company badge looks harmless. Yet it contains your full name and job title, often the company’s email format, guessable from the name shown, sometimes a QR code or RFID badge number readable if the photo is taken up close, and the badge’s internal design, enough to put together a convincing fake.

An attacker preparing an operation never starts from zero: they begin by gathering as much public information as possible, what security professionals call reconnaissance. Every badge photo, multiplied by the number of employees doing the same thing over the months, ends up sketching a fairly accurate portrait of the organisation. The fix stays simple: share your excitement about joining a company without showing the badge, or blur it out.

Work life, personal life: when the mix says too much

Many people share their professional life on social media, LinkedIn especially: a new job, business trips, conferences. Taken alone, each post looks harmless. Cross-referenced with posts from other employees over time, though, it says a lot about the company: who works with whom, when certain offices empty out during a group trip. A post about being “at a conference in Lyon all week” can also serve as the pretext for a targeted scam. A fake “urgent” email pretending to come from that absent colleague then gains credibility with whoever’s left at the office, who has no quick way to check with the person directly.

What’s lurking behind you in a photo

The badge is just one instance of a broader problem: what shows up in the background of a photo taken at the office. A “team vibes” snapshot can reveal, without anyone meaning to:

  • a screen left on with an email still open;
  • a badge sitting right next to the keyboard;
  • a sticky note with a password stuck to the monitor;
  • a whiteboard showing a product roadmap, caught in the background of a video call.

It happens simply because the frame is a bit too wide. A quick glance at the background before posting is usually enough; when in doubt, crop it, blur it, or skip the photo altogether.

The same problem carries over onto public transit, where a screen left in plain view is the most underrated risk: a laptop open with an internal document, perfectly readable by whoever’s sitting right next to you without even trying to look. A screen privacy filter (a thin sheet that makes the screen unreadable the moment you look at it from an angle) fixes this for a few dozen francs.

A conversation held loudly in public carries just as real a risk, whether it’s what’s on screen or what’s said out loud.

Real caseIn May 2022, a senior Swiss army officer made several phone calls on a packed train between Bern and Zurich, openly criticising political officials and discussing sensitive military matters, without noticing a journalist sitting nearby who followed the entire conversation. The case, revealed in January 2023 by the Aargauer Zeitung, ended in immediate dismissal, officially presented by the army as a termination “by mutual agreement”.

One phone for work, one for personal use

Keeping work and personal life on two separate phones cuts down the number of doors open to an attacker: personal apps (social media, games, dating apps) are more often the starting point of a hack than work tools, which IT tends to watch more closely, and a compromised personal phone doesn’t automatically hand over access to your work email. On a single device, the most concrete risk is a personal session left logged in right next to the work inbox, or a personal cloud backup that scoops up work documents without you meaning it to.

A second phone isn’t realistic for everyone, between the cost and the hassle of carrying and charging one more device. If a single device is your only option, lighter alternatives exist: a separate work profile on Android (Android Work Profile), which walls off work data in its own encrypted space, strictly separate accounts and passwords between work and personal life kept in separate vaults of a password manager, or simply avoiding risky personal apps on the device that also holds the company inbox.

Social engineering, in practice

Social engineering is the art of manipulating someone into granting access to something without realising it: a password, a door, a piece of information. Contrary to what you might picture, it almost never looks like a hacker movie.

The fake delivery driver or the fake technician shows up at reception, box under one arm or toolbox in hand, explaining they’re delivering a package for HR or fixing the printer on the third floor. Nobody wants to be the one holding up a delivery driver in a hurry, and the door opens, often without any check.

A call pretending to be IT, urgent and professional in tone: “We’ve detected suspicious activity on your account, I need to verify your password.” Legitimate IT support never asks for a password over the phone, but with the right tone, the request feels normal in the moment. This is the phone version of phishing, known as vishing: the same reflex applies, never verify someone’s identity through the contact details they give you themselves, but through a trusted channel you already know, like the official internal number for support.

The new hire who doesn’t have a badge yet works surprisingly well too: “I just started, could you let me in?” It’s remarkably effective, because it plays on the instinct to be helpful and because in a large company nobody knows everyone. An attacker who knows a few colleagues’ names, what a badge actually looks like, or the internal jargon makes these scenarios all the more convincing.

Physical pentesting, or testing the humans

A classic IT penetration test is simple in principle: authorised professionals get paid to try to break into a company’s systems, so the weak spots get found before a real attacker finds them. Physical penetration testing is the counterpart, focused on premises and people: professionals genuinely try to get into the offices or walk out with sensitive information, using exactly the scenarios above. The value is that it complements purely technical testing: a server audit never reveals what happens when someone carrying a box simply walks up to reception.

What the company itself can do

Physical pentesting is a good place to start: it’s already something driven by the company, not just an individual habit. A clear policy on what does or doesn’t get posted on social media already helps a lot, with a simple guideline (“no visible badge, no screen in the background”) communicated from day one, rather than an unwritten rule nobody really knows.

Awareness training works better repeated than one-off: a single reminder during onboarding fades fast. An occasional simulated phishing campaign, with no consequences for whoever falls for it, anchors the habit far more durably than a slide seen once in training. This is also where a simple individual habit gets reinforced: not holding the door open out of politeness for someone who hasn’t badged in themselves, a move known as tailgating, slipping into the building right behind an authorised person without ever presenting your own badge.

Finally, verification processes at access points matter just as much as individual vigilance: badges with photos checked at reception, visitors escorted, and a clear procedure for an outside delivery driver or technician, calling the relevant department to confirm the visit.

If the damage is already done

How you react depends on what actually happened. For a compromising photo already circulating online (a badge posted last year, a sticky note readable once you zoom in), the right reflex isn’t guilt, it’s action: delete it or blur it, and if an RFID badge or sensitive information was clearly readable in it, tell your security team without waiting. Only they can judge whether an access needs deactivating, and the sooner the alert comes in, the sooner that window closes.

If you suspect you were the target of a social engineering attempt, a strange call from “IT” that hangs up abruptly the moment you ask a question, a “new colleague” pushing a little too hard to get a door opened, it’s worth reporting even without certainty. Shame at almost having been fooled, or fear of raising a false alarm for nothing, holds plenty of people back. Security teams would far rather check a dead end in five minutes than discover the incident months later; the process is the same as when you report a cyber incident in general.

The habits worth keeping

No need to become paranoid to stay protected. A handful of habits go a long way:

  • The badge doesn’t belong on social media, blur it out if the photo really needs to show it, and a quick glance at the background before posting is enough to catch a screen, a sticky note, or a whiteboard.
  • A screen privacy filter protects what’s displayed on public transit and in other public places.
  • Verify someone’s identity before opening a door or sharing information, even in the face of a friendly or urgent-sounding pretext: over the phone or by email, legitimate IT support never asks for a password.
  • A suspicious attempt, or a compromising photo already posted, is worth reporting to your security team, even without full certainty.
  • On the company side, a clear policy and regular awareness training anchor these habits far better than an unwritten rule.

These ordinary gestures, individual and organisational alike, are what end up making a company a hard target.