You are using an outdated browser. Please upgrade your browser to improve your experience.
Skip to content

Request a Demo

The Future of Due Diligence is Here.

Register Your Interest

Executive protection

Widespread assumptions underpinning corporate executive protection have been rewritten since the targeted killing of a major health insurance CEO in New York in December 2024. But the more important story for corporate security decision makers is what has happened since. Executive targeting incidents roughly doubled last year, reaching their highest rates on record, according to the Security Executive Council. That trajectory has yet to slow in 2026.

The common thread across these incidents is that they rarely begin in the physical world. They originate on social media, fringe forums, messaging channels, often days or weeks before anything manifests at a residence or an office lobby or a shareholder meeting. That reality repositions social media and broader open-source intelligence (OSINT) from a nice-to-have monitoring function to the analytical core of any credible executive protection program. Below are the trends corporate security and intelligence teams should be tracking now, and how intelligence-led teams are getting ahead of them.

1. VIOLENT RHETORIC AGAINST EXECUTIVES HAS BEEN NORMALIZED

The most significant shift since late 2024 is not the volume of online hostility toward corporate leaders. It is the mainstreaming of it. Glorification of anti-executive violence, “fan” communities celebrating attackers, and grievance narratives that frame executives as legitimate targets now circulate openly across mainstream and alt-tech platforms alike. Threat researchers describe a feedback loop in which each high-profile attack generates content that inspires and instructs the next actor, including nihilistic individuals motivated less by ideology than by the pursuit of viral infamy.

For protective intelligence teams, this creates a signal-to-noise problem at a scale humans cannot manually triage. Millions of posts may reference an executive or brand during a controversy, but only a small fraction contain genuine pre-attack indicators: leakage of intent, fixation, references to weapons or travel, or knowledge of an executive’s movements. This is where AI-enabled risk analytics earn their place in the security stack. Fivecast ONYX allows analysts to run persistent, near real-time collection across millions of online sources and apply customizable risk detectors, spanning text, keywords, imagery, and objects, that automatically surface the posts exhibiting genuine threat indicators from the mass of digital noise. Instead of drowning in mentions, analysts start their day with a prioritized queue of content that actually warrants assessment under established threat management frameworks.

2. INDUSTRIALIZED DOXXING

Doxxing is no longer the work of a determined individual manually piecing together an executive’s life. In 2025, aggregation sites published the names, contact details, and compensation data of executives across more than 1,000 companies, and even after takedowns, archived and re-indexed copies persist. Automated scraping tools and unregulated data brokers now allow hostile actors to assemble a 360-degree profile of a target, including home address, family members, and daily routines, in a fraction of the time it once took. Critically, the gap between first exposure and first exploitation has collapsed from days to hours.

The operational implication is that periodic digital footprint audits, conducted quarterly or annually, are structurally too slow. Security teams that detected the 2025 executive database exposures within hours were able to initiate removal requests while the content was still containable; teams that found out later are still managing the fallout. Continuous monitoring changes that equation. By maintaining standing collection requirements against each protected principal, their family members, and their known identifiers, Fivecast ONYX enables teams to rapidly map an executive’s exposed digital footprint, resolve identities across platforms, and receive alerts when new personal information surfaces, giving protective teams the earliest possible window to act before exposure becomes exploitation.

3. AI-GENERATED IMPERSONATION IS NOW A PHYSICAL SECURITY PROBLEM

Deepfakes crossed a threshold in 2026, moving from novelty to routine tradecraft in fraud and influence operations targeting executives. Synthetic video and audio of corporate leaders have been used to push fabricated investment advice, authorize fraudulent transactions, and manufacture reputational crises. Fake executive profiles on professional and social networks are proliferating, yet a majority of security leaders report having no visibility into impersonation activity at all.

While impersonation is often categorized as a fraud or brand problem, it belongs in the executive protection portfolio for two reasons. First, impersonation accounts are frequently used to socially engineer information about an executive’s location, schedule, or family. Second, synthetic content that inflames grievance narratives can convert an executive into a target overnight. Detecting this activity requires analytics that work across multimedia, not just text. Fivecast MATRIX applies generative AI across text, images, and video with configurable rules and confidence scoring, enabling teams to screen for misuse of an executive’s likeness, corporate logos, and brand assets at scale, while Fivecast ONYX supports the identity resolution work needed to distinguish authentic accounts from imposters and map who is behind coordinated impersonation activity.

4. THE THREAT ACTOR LANDSCAPE IS CONVERGING.

Executive protection teams can no longer build assessments around a single threat archetype. Issue-motivated activism, violent extremist movements on both the far right and far left, transnational organized crime, and lone grievance-driven actors increasingly borrow each other’s tactics: doxxing, dehumanizing rhetoric, and celebration of attacks. At the same time, the population requiring protection has expanded well beyond the CEO. Targeting of non-CEO leaders has surged, and family members, executive assistants, board members, and leaders visible in litigation, layoffs, or M&A activity are all credible targets.

Understanding whether hostility toward an executive is opportunistic noise or connected to an organized network is one of the hardest analytical judgments in protective intelligence, and one of the most consequential for resourcing decisions. Fivecast LUNEX supports this judgment by providing curated foundational networks of global threat groups, including violent extremist movements and transnational organized crime, maintained by expert intelligence analysts. When a threatening account surfaces in monitoring, analysts can rapidly establish whether it connects to known high-risk communities, transforming an isolated data point into network-level insight that informs both the threat assessment and the protective posture.

5. EVENTS, TRAVEL AND ANNOUNCEMENTS CREATE PREDICTABLE RISK SPIKES

Earnings calls, shareholder meetings, layoff announcements, product launches, conference keynotes, and litigation milestones all generate measurable surges in hostile online activity, and hostile actors know executives are most exposed when they are on the move or on a stage. Recent incidents involving armed individuals intercepted at corporate headquarters during executive meetings underscore how quickly online grievance converts to physical approach.

Mature programs now treat these moments the way public safety agencies treat major events: with a defined intelligence battle rhythm. That means establishing a pre-event baseline of relevant online sentiment and known persons of interest, surging collection in the days before and during the event, geographically and thematically focusing monitoring around venues and travel routes, and conducting post-event review to update the threat picture. The near real-time collection and customizable detection in Fivecast ONYX are built for exactly this operating tempo, letting teams stand up focused, time-bound monitoring missions around high-exposure moments without abandoning their persistent baseline coverage.

BUILDING THE INTELLIGENCE-LED EXECUTIVE PROTECTION PROGRAM

Boards increasingly view executive safety as a governance and fiduciary issue, not a discretionary perk. For corporate security leaders, that translates into a mandate to demonstrate a defensible, proactive capability. In practice, an intelligence-led executive protection program rests on four disciplines:

  • Baseline: Map each principal’s digital footprint, exposed personal data, and existing hostile narratives to establish what normal looks like.
  • Monitor: Maintain persistent, AI-enabled collection across social media, forums, and the deep and dark web against principals, family members, facilities, and high-risk themes.
  • Assess: Triage flagged content through structured threat assessment, using network context to separate transient outrage from genuine fixation and capability.
  • Act: Feed validated intelligence into protective operations, from adjusting travel plans and residential security to takedown requests and law enforcement referrals.

Equally important is doing this responsibly. Executive protection monitoring should be grounded in publicly and commercially available information, governed by clear policies on purpose and retention, and conducted on platforms designed for auditable, compliant intelligence workflows. This is not only an ethical obligation but a practical one: intelligence that cannot withstand legal and reputational scrutiny cannot support decisive protective action.

Executive protection for corporate leaders must confront an environment where threats proliferate at scale, driven by automation. The organizations best positioned to protect their people are those that meet it where it starts: online, at scale, and ahead of the moment a threat reaches the front door.


About Fivecast

Fivecast delivers intelligence solutions built for clarity, powered by AI and trusted to surface what matters. Engineered to solve complex intelligence challenges our platform cuts through digital noise to help those protecting nations, borders, businesses and communities uncover critical insights – before risk becomes reality.

Trusted by agencies and enterprises across national security, law enforcement, defense, corporate security and financial crime, Fivecast was born from collaboration between governments and research institutions. Headquartered in Australia with a global footprint, we support the world’s most critical missions.

Fivecast. Engineered for Intelligence.