What is doxxing? Definition, how it works, and how to protect yourself

Doxxing is the malicious identification and online publication of information about an individual1. Threat actors commonly use it to harass, intimidate, or shame particular individuals by exposing their email address, phone number, or whereabouts (including physical address). Unfortunately, it’s not something you can completely ignore, so in this article we go into how doxxing works and how to best protect yourself from it.

personal data being doxxed

What is doxxing?

Doxxing (sometimes spelled “doxing”) is the act of gathering someone’s private personally identifiable information (PII) and publishing it online without their consent, usually to harass, intimidate, or shame them. The term comes from the 1990s hacker phrase “dropping dox” (short for “documents”), originally used to strip away a rival’s anonymity.

Cybersecurity experts consider doxxing a serious cyberattack because it weaponizes personal data, such as real name, home address, phone number, workplace, or photos. Even if individual details are publicly available, aggregating them into a single profile and publishing it with malicious intent is what constitutes doxxing.

What information are doxxers looking for?

Doxxers look for any data that can be used to identify, locate, or contact a target, including:

  • Home address and phone number. Used for physical harassment or “swatting.”
  • Social Security number. Useful for identity theft.
  • Banking and credit card details. Used for financial fraud.
  • Workplace details. Used to contact the target’s employer to get them fired.
  • Private photos and videos. Used for humiliation or blackmail.
  • Family member details. Used to broaden the scope of harassment.

How harmful can doxxing be?

Doxxing is more than just a violation of privacy — it can have life-altering consequences. Small, cherry-picked pieces of information can be used to form a negative portrait of anyone, leading to:

  • Reputational harm by ruining professional or personal relationships.
  • Identity theft through stolen PII, allowing attackers to open accounts in your name.
  • Physical harm through exposed addresses, potentially leading to stalking or home visits.
  • Risk of swatting — a dangerous follow-on attack in which doxxers make false emergency reports to send armed police to a target’s home.

How do doxxers gather your information?

Doxxers generally gather information through a few primary methods, ranging from simple harvesting to advanced technical intercepts.

Method

What the doxxer does

Public records

Mines voter rolls, court records, and property records for names and addresses.

Data brokers

Buys aggregated profiles from data brokers — files that combine your history in one place.

Social media

Harvests photos, check-ins, and posts you or your friends share.

File metadata

Reads metadata (EXIF data) in photos to find your GPS location and device info.

WHOIS lookups

Pulls the contact name and email tied to a domain you registered.

Wi-Fi sniffing

Intercepts traffic on public Wi-Fi to capture unencrypted data, monitor browsing activity, or facilitate man-in-the-middle attacks that can compromise logins.

IP logging

Uses a link that points to an attacker-controlled server, which logs your IP address (and approximate location) when you click it.

Breached data

Cross-references your email against data-breach dumps from leaked databases.

Social engineering

Tricks you or a support agent into revealing private details through deception.

Is doxxing illegal?

As a standalone act, doxxing is not universally illegal in most places (you could doxx yourself, for example as a cyber hygiene practice). However, the issue arises when doxxers use illegal ways to obtain information or use it for harassment and intimidation.

Is doxxing illegal in the US?

Doxxing is not a single standalone federal crime in the United States, but it can be illegal depending on what has been exposed and the method the doxxer used to obtain the information. It may not be a crime if used for open-source intelligence (OSINT), but it crosses into criminal territory when it involves true threats, stalking (or cyberstalking), and unauthorized access to protected data.

Under federal law, doxxing someone performing certain official duties is illegal under 18 U.S.C. § 1192. However, according to Cornell Law School’s Legal Information Institute “there is currently no comprehensive federal law that makes doxxing someone a crime.”3 Other statutes may cover components of doxxing (such as stalking under 18 U.S.C. § 2261A opens in a new tab) as long as an individual engages in a course of conduct that would cause, attempt to cause, or be reasonably expected to cause substantial emotional distress to a person.  

In addition, the Stop The Doxx Act (H.R. 8927) — a bipartisan federal bill introduced in May 2026 by the US Representative Josh Gottheimer is currently under consideration in the US House Committee on the Judiciary. If voted into legislation, it would criminalize publishing home addresses, phone numbers, or personal emails of public safety officials and their families to facilitate threats or violence4.

Which US states have anti-doxxing laws?

While there is no overarching federal law covering the practice of doxxing, several US states have passed specific laws against doxxing-related cyber harassment to provide victims with criminal or civil recourse. 

As of June 2025, three states — Alabama, California and Illinois — have established doxxing as a standalone crime and ascribed an explicit definition for the act5. In addition, fourteen states ( Colorado, Florida, Missouri, Oklahoma, Pennsylvania, Virginia, Oregon, Delaware, Kentucky, Minnesota, Nevada, New Jersey, Utah and Washington) have established doxxing as a standalone offense, but do not explicitly define or reference the term “doxxing” in statute. Instead, these states refer to doxxing as the “dissemination of personal information on the internet,”6 “the improper disclosure of private information,”7 or “cyberintimidation by publication.”8

State

Type of Recourse

Notable Provision

Alabama

Criminal

One of three states to establish doxxing as a standalone crime.

Arizona

Criminal

Makes it a criminal offense for any individual to publish another person’s personal information, without their consent and to cause unwanted physical contact, injury or harassment.

California

Criminal and Civil

Explicitly defines doxxing in statute and allows victims to both press charges and sue for damages.

Colorado

Criminal

Provides extensive protections for peace officers, judges, firefighters, social workers, and election officials (HB 02-1113).

Connecticut

Civil and Criminal

Provides extensive protections for election officers (while in process of their duties) and extends the crime of second-degree stalking to include certain electronic disclosures of personal identifiable information without consent

Delaware

Civil and Criminal

Establishes that it is a crime to share, solicit, sell, or trade the personal information of a judicial officer or their family with the intent to pose an imminent and serious threat to the health and safety of the judicial officer or their family.

Florida

Criminal

Establishes that it is unlawful to electronically publish an individual's personal identification information when done with the intent to cause harm or harassment, or with the intent that a third party will use the information to do so.

Illinois

Civil

Establishes doxxing as a standalone crime with an explicit statutory definition.

Kentucky

Criminal and Civil

Classifies “dissemination of personal information” as a Class A felony in some cases.

Missouri

Criminal and Civil

Codifies as a criminal offense with penalties starting at a Class C misdemeanor.

Nevada

Criminal and Civil

Classifies unlawful PII dissemination as class E felony in some cases.

New Jersey

Civil and Criminal

Protects judicial and law officers and their families deeming it “unlawful for any person to disseminate the home address or phone number [...] without their consent and with the intent to cause bodily harm or stalking.”

Oklahoma

Criminal

Protects public officials, election officials, and medical care providers, prohibiting any individual from “publishing identifying information [...] with the intent to threaten, intimidate, harass or stalk.”

Oregon

Civil

Protects all individuals establishing a civil cause of action for people whose private information was published without their consent and with the intent to cause harm.

Pennsylvania

Criminal

Offers protections to all citizens in cases when an individual electronically publishes, posts, or otherwise discloses PII of another person, in a public online site or forum, without that person's permission.

Utah

Civil and Criminal

Recognizes doxxing as a form of “electronic communication harassment," offering protection to all citizens that suffer harm from unlawful disclosure of personal information.

Virginia

Criminal

Classifies doxxing as Class 1 misdemeanor.

Washington

Criminal and Civil

Establishes a definition of doxxing, sets damages of $5,000 per violation (knowingly posting an individual's PII with intent to harm), costs, and reasonable attorneys' fees.

Anti-doxxing penalties vary significantly by jurisdiction, ranging from Class C misdemeanors to Class A felonies. In states like Nevada, New Jersey, and Oregon, victims have the right to pursue civil action to recover costs and damages even if the perpetrator is already facing criminal charges.

Can you dox yourself?

Self-doxxing means searching for your own personal data online to see what details are public. It’s a useful first step when cleaning up your digital footprint.

  1. 1.Google your name. Use incognito mode to see what others see.
  2. 2.Do a targeted search. Search your name combined with “phone number” or “address.”
  3. 3.Check image results. Use image search to see where your photos appear.
  4. 4.Audit data brokers. Use services like Incogni to find and remove your profiles from broker databases.
  5. 5.Check WHOIS. If you own a website, check whether your home address is listed in the public domain registry.

How to protect yourself from doxxing

You can take proactive steps to avoid doxxing and minimize your online risk, such as limiting the data you share online, safeguarding your passwords, or removing yourself from data broker websites.

1. Limit the information you share online

To make your social media more private, be mindful of what you post online. Tighten your privacy settings to ensure only friends can see your posts, and avoid sharing geotagged photos that reveal your location in real-time. Use a privacy-oriented search engine to reduce tracking and long-term profiling of your search behavior.

2. Think before you comment

Forums and news sites often log IP addresses, which can be linked to your identity. Avoid using social-login (like “Sign in with Facebook”) for third-party sites, as this creates data links between accounts. Using a VPN can change your virtual location to safeguard your true IP.

3. Remove yourself from data broker websites

Data brokers scrape the web to build profiles on you. You can manually opt out of these sites, though it is often a lengthy process. Using data removal services can automate the removal of your PII from these platforms.

4. Protect your passwords

Use strong and unique passwords for every account and store them in an encrypted vault. Enable two-factor authentication (2FA) whenever possible. We recommend using authenticator apps over SMS-based 2FA, which is vulnerable to SIM-swapping attacks.

5. Use a virtual private network (VPN)

Connecting to a virtual private network (VPN) encrypts your traffic and changes your real IP address by replacing it with that of a VPN server. This helps protect you from packet sniffing on public Wi-Fi and makes IP-based location tracking much harder.

NordVPN encrypts your connection and changes your IP address, removing one of the easiest ways doxxers geolocate a target. Beyond the VPN, NordVPN's all-in-one app includes a next-generation antivirus (NGAV)  that blocks ads, trackers, malicious websites, and scans downloads for malware.

What to do if you’ve been doxxed

If your information has been exposed, act quickly to contain the damage:

  • Do a data breach scan. Find a reliable data breach scanner and do a thorough checkup. Check if your Social Security number is exposed.
  • Document everything. Screenshot the posts, URLs, and timestamps as evidence.
  • Report the content. Contact the platform (Twitter, Facebook, etc.) and request an immediate takedown.
  • Lock down accounts. Change your passwords and update your 2FA settings.
  • Contact law enforcement. If you receive threats or fear for your physical safety, call the police.
  • Alert your bank. If financial data was leaked, put a fraud alert on your credit.

How to report doxxing

If you find your private information shared online, most major platforms have specific reporting tools to handle doxxing (often categorized under “harassment” or “sharing private information”). Follow these steps to report it effectively:

  • Social media platforms. Navigate to the specific post or profile, click the “Report” button (usually three dots or a flag icon), and select the option similar to “harassment” or “sharing private information.”
  • Search engines. You can request that Google or Bing remove search results that contain your highly sensitive PII (like your home address or bank details) through their “Remove personal information” request forms.
  • Web hosts. If your data is on a standalone website, use a WHOIS lookup to find the site's hosting provider and file an abuse report directly with them.
  • Data brokers. If the information is appearing on “people search” sites, look for the “Opt-out” or “Remove my info” link, usually located in the footer of the page.
  • Law enforcement. If the doxxing includes a “true threat” or specific intent to cause physical harm, bring your documented evidence (screenshots and URLs) to your local police department to file an official report.

Online security starts with a click.

Stay safe with the world’s leading VPN

FAQ

References

  1. 1.Center for Internet Security. (n.d.). EI-ISAC cybersecurity spotlight: Doxing. opens in a new tabhttps://www.cisecurity.org/insights/spotlight/ei-isac-cybersecurity-spotlight-doxing opens in a new tab
  2. 2.Cornell Law School, Legal Information Institute. (n.d.). 18 U.S.C. § 119 – Protection of individuals performing certain official duties. opens in a new tabhttps://www.law.cornell.edu/uscode/text/18/119 opens in a new tab
  3. 3.Cornell Law School, Legal Information Institute. (Last reviewed in July of 2026). Doxxing. Wex Legal Dictionary. https://www.law.cornell.edu/wex/doxxing opens in a new tab
  4. 4.U.S. Congress. (2026, May 20). H.R. 8927 – Stop the Doxx Act, 119th Congress (2025–2026) [Legislation]. opens in a new tabhttps://www.congress.gov/bill/119th-congress/house-bill/8927/text opens in a new tab
  5. 5.Porter, C. (2025, October 31). Doxing: State protections against digital threats. The Council of State Governments. opens in a new tabhttps://www.csg.org/2025/10/31/doxing-state-protections-against-digital-threats/ opens in a new tab
  6. 6.Kentucky General Assembly. (n.d.). KRS § 525.085 – Dissemination of personally identifying information. Justia US Law. opens in a new tabhttps://law.justia.com/codes/kentucky/chapter-525/section-525-085/ opens in a new tab
  7. 7.Oregon State Legislature. (n.d.). ORS § 30.835 – Civil action for improper disclosure of private information. Justia US Law. opens in a new tabhttps://law.justia.com/codes/oregon/volume-01/chapter-030/section-30-835/ opens in a new tab
  8. 8.Florida Legislature. (n.d.). Florida Statutes § 836.115 – Unlawful publication of personal identification information. Justia US Law. opens in a new tabhttps://law.justia.com/codes/florida/title-xlvi/chapter-836/section-836-115/ opens in a new tab

Also available in: Dansk,Deutsch,Español Latinoamericano,Español,Suomi,Français,Bahasa Indonesia,日本語,‪한국어‬,Nederlands,Polski,Português Brasileiro,Português,Svenska,Türkçe,繁體中文 (台灣).

Jomilė Nakutavičiūtė | NordVPN

Jomilė Nakutavičiūtė

Jomilė is a content writer who loves to investigate the latest Internet privacy and security news. She thrives on looking for solutions to problems and sharing her knowledge with NordVPN readers and customers.

Trending articles