You Can Pull Anyone's Personnel File. So Can They.
HR professionals spend their careers as custodians of other people's most sensitive data: Social Security numbers, salaries, medical leave, disciplinary records, home addresses. It is easy to assume the same locked systems protect you. They do not, because your exposure does not run through the HRIS. It runs through the same public records and people-search sites as everyone else's, and your job adds two things most people never face: you are the named target when a company does something an employee hates, and you are the specific person criminals impersonate to steal payroll data. Here is how both threats find you and what actually reduces them.
Why HR gets targeted by criminals
Because you hold the keys. The IRS and FTC have warned for years about W-2 phishing, in which someone impersonates an executive and emails HR or payroll requesting employee tax forms or a change to direct deposit details. The scam works because the request sounds routine, the sender name looks right, and HR staff are trained to be responsive. It has hit small businesses, school districts and hospitals, and one successful message can expose every employee's Social Security number at once.
What makes the impersonation convincing is research. The attacker knows who runs HR, who the CEO is, the company's email format, and often when the CEO travels. Much of that comes from public profiles and business directories, and the rest from a people-search lookup on the names involved. Your public footprint is part of the attack surface for the whole company.
Why HR gets targeted by employees
Because you are the face of the decision. When someone is terminated, denied a promotion, disciplined, or laid off, the executive who decided is often invisible and the HR person who delivered the news is not. Grievance attaches to a name. Most of the time that ends with an angry email. Occasionally it does not, and the difference between an unpleasant week and a safety problem is often whether the person can find where you live.
The chain is short. They have your full name from the meeting and the paperwork. They have your city from the office. A people-search site returns your home address, your age, and the names of the people you live with. No hacking, no special access, and no record that anyone searched.
What exposes HR specifically?
- Professional network profiles. Your role, employer and often your photo are public by design, which is useful for recruiting and equally useful for anyone building a target list.
- Company directories and org charts, internal and external, that name the HR contact.
- Job postings that list you as the contact, tying your name to the company in search results indefinitely.
- Professional certifications, some of which are searchable in public registries.
- People-search profiles, which take any of the above and return your residence and household.
How do I separate work from home?
- Verify every payroll or tax-form request out of band. Call the requester on a known number before sending W-2s or changing deposit details, no matter how senior the sender appears. Make that a written policy so nobody has to feel awkward following it.
- Keep personal accounts private and switch off the settings that let people find you by phone number or email. Do not accept connection requests from current employees on personal accounts, and be deliberate about who can see your posts.
- Use a work number for anything employee-facing, so a personal mobile is never on a document a departing employee keeps.
- Ask that terminations and difficult conversations be handled with a second person present, and that your organization has a plan for employees who make threats. Document any concerning contact with dates.
- Remove your people-search listings, which is the step that breaks the link from your name to your front door.
What if an employee is already contacting me at home?
Treat it as a workplace safety matter, not a personal one. Document every contact with screenshots and timestamps, report it to your own leadership and security function, and do not respond outside official channels. If there are threats, or the person appears at or near your home, contact law enforcement and keep the report reference. HR professionals often absorb this because they see themselves as the ones who handle problems, and that instinct is exactly what should be overridden here.
Why removal has to be maintained
Being clear about the boundary: removal does not touch your professional profile, your certifications, or the company directory, and it should not, since those are how the job works. What it addresses is the last link, the profile that converts a name into a home address and a household. Because people-search sites rebuild from fresh public records, that link reforms over time. Consumer Reports found that opt-outs done by hand or by automation cleared roughly 27 percent of exposed listings, while removals handled by real people who monitor and refile reached about 70 percent. For someone whose name is attached to every hard decision a company makes, the maintained version is the one that holds.
You protect everyone's file. Nobody is protecting yours.
The employee you terminated last month can look up your home address in seconds. A free scan shows exactly what they would find, and our team of real people removes those listings and keeps checking as they return.
Run my free scan Start free trialFrequently asked questions
Can my employer help protect my personal information?
Increasingly yes. Some organizations now cover data removal for staff in exposed roles as part of their duty of care, alongside security training. It is a reasonable request to raise, particularly if your role involves terminations or investigations.
Should I use a different name on professional profiles?
It is impractical for most HR roles, since your name is on documents employees receive. The workable approach is keeping your professional presence professional and your personal presence private, and removing the public listing that bridges the two.
How do I spot a W-2 phishing email?
Urgency, a request to bypass normal process, a sender address that is close to but not exactly right, and a request for bulk employee data or a change to payment details. The defence is procedural rather than perceptual: verify by phone on a known number, every time, without exception.
Is this only a risk for HR in large companies?
Smaller organizations are often more exposed, since one person may handle HR, payroll and the difficult conversations, and there is no security team behind them. The steps above matter more when you are the whole department.