← BOOJEE Shield
Sample — Fictional Data
BOOJEE Shield · Monthly Exposure Report

Digital Exposure Report — July 2026

Client The Hargrove Household (Sample)
Tier Premier — up to 4 family members
Coverage period July 1–23, 2026
Analyst BOOJEE Shield Team
People monitored 4 (see intake)
01 — Executive Summary

This month's sweep identified 3 medium-severity findings and 1 high-severity finding requiring prompt action. The high-severity item is a confirmed credential leak for the primary account holder's work email address in the RetailDB-2025 breach. Immediate password rotation is recommended.

Two data-broker listings for a household member were found active at Spokeo and Whitepages; opt-out submissions were noted in recommendations. A social platform impersonation account was identified on Instagram; reporting steps are detailed in Section 04. No deepfake or likeness-misuse findings were identified this cycle.

Overall household exposure posture: Moderate — action required. All findings have recommended actions with prioritization below.

1 High severity
3 Medium severity
2 Informational
02 — Credential Leak Findings

Breach database results

Person Email / Identifier Breach Data Exposed Date Severity
Marcus H. (primary) m.hargrove@nexacorp.com
(fictional)
RetailDB-2025 Email, hashed password, name, phone Dec 2025 High
Marcus H. (primary) marcush1972@gmail.com
(fictional)
LinkedSocial-2023 Email, username, public profile data Mar 2023 Info
Diana H. (spouse) diana.hargrove@proton.me
(fictional)
None found this cycle Clear
Tyler H. (child, 19) tyler.h.2007@icloud.com
(fictional)
GamingForum-2024 Username, email, IP address range Aug 2024 Medium
Elena H. (child, 16) Not monitored at this email None found this cycle Clear

Sources checked: Have I Been Pwned aggregator, public breach paste aggregators, manual credential-dump searches. We check only publicly disclosed breach data — not private law-enforcement databases. The 2023 LinkedSocial breach contained no passwords; the GamingForum-2024 breach exposed hashed credentials and IP ranges with no financial data.

03 — Impersonation Account Scan

Social platform results

Instagram
Finding — action needed
Account @marcushargrove_official (fictional handle) uses a photo consistent with Marcus H.'s public LinkedIn profile image and describes itself as the "official" account of a real-estate professional in Palm Beach. The account has 214 followers and no posts linking to verified properties.

Recommended action: Report the account via Instagram's "Impersonation" reporting path (Settings → Report → It's pretending to be someone → Me). Screenshot and preserve before reporting. If not resolved within 14 days, submit to Meta Business Support with the URL.
Facebook
Clear
No accounts impersonating household members found this cycle.
X (Twitter)
Clear
No accounts impersonating household members found this cycle.
TikTok
Clear
No accounts impersonating household members found this cycle.
LinkedIn
Clear
No accounts impersonating household members found this cycle.

Platforms searched: Instagram, Facebook, X (Twitter), TikTok, LinkedIn, Threads, Pinterest. Search method: name variants + profile-image reverse-search (where public photos were provided at intake).

04 — Data-Broker Exposure

People-search site results

Spokeo Marcus H. — address, phone, relatives listed Exposed
Whitepages Marcus H. — current address, 2 phone numbers Exposed
BeenVerified Searched — no listing found Clear
Intelius Searched — no listing found Clear
TruthFinder Searched — no listing found Clear
FastPeopleSearch Diana H. — previous address listed (prior residence) Review
FamilyTreeNow Family unit listed with names and approximate ages Exposed
Radaris Searched — no listing found Clear
MyLife Opt-out pending from prior cycle — processing (up to 30 days) Pending
Acxiom Consumer profile present; opt-out form submitted this cycle Submitted

Opt-out submissions for Spokeo, Whitepages, and FamilyTreeNow are recommended (see actions). MyLife opt-out submitted last cycle; allow up to 30 days per their published policy. Data brokers repopulate from public records every 3–6 months — re-sweep is included quarterly on Premier tier.

05 — Deepfake & Likeness Sweep

Quarterly likeness check

Cycle status: Quarterly deepfake and likeness sweep was conducted this cycle (Q3 2026). Reverse-image and platform searches were run for Marcus H. and Diana H. using reference photos provided at intake.

No findings. No synthetic, altered, or unauthorized uses of household members' photos or video likeness were identified on Google Images, Bing, YouTube, Instagram, Facebook, or TikTok. The Instagram impersonation account (Section 03) used a photo copied from a public professional profile — this is profile-photo misuse, not a deepfake.

Next quarterly likeness sweep: October 2026.

06 — Recommended Actions

Prioritized action list

  1. Urgent
    Rotate the nexacorp.com work email password immediately. The RetailDB-2025 breach exposed a hashed password; treat it as compromised. If this password was reused on any other account (banking, personal email, cloud storage), rotate those passwords as well. Enable a hardware security key or app-based MFA on the work account if not already active.
  2. Urgent
    Report the Instagram impersonation account. Use Instagram's in-app reporting path (Settings → Report → Pretending to be someone → Me) and take screenshots of the account before reporting. If unresolved in 14 days, escalate via Meta Business Support with the account URL.
  3. This month
    Submit opt-out requests for Spokeo and Whitepages. Spokeo opt-out: spokeo.com/optout. Whitepages: whitepages.com/suppression-requests. These typically process within 24–48 hours. We recommend doing this yourself (or replying to this email if you would like us to handle it as part of your next Cloak add-on).
  4. This month
    Submit FamilyTreeNow opt-out for the household unit listing. familytreenow.com/optout — this listing includes relative names and age ranges. Processing typically within 24 hours.
  5. This month
    Rotate Tyler's gaming account password (GamingForum-2024). The breach exposed a hashed password and IP address range. If that password was reused on other services, rotate those as well. Recommend enabling MFA on any accounts Tyler uses with the same email address.
  6. Monitor
    Allow MyLife and Acxiom opt-outs to process. No further action needed this cycle — we will verify removal at the next sweep. MyLife can take up to 30 days; Acxiom up to 30 days as well.
07 — Next Cycle Plan
August 2026 sweep will include:
  • Verify MyLife and Acxiom removal; re-submit if still active
  • Confirm Spokeo, Whitepages, and FamilyTreeNow opt-outs resolved
  • Check Instagram for impersonation account removal; escalate to Meta if still live
  • Re-run full credential sweep on all household email addresses
  • Full impersonation scan on all monitored platforms
  • Data-broker spot-check on 10 highest-repopulation brokers

Questions about this report? Reply to your report delivery email or write hello@BOOJEE.estate. Details changed (new address, email, additional person to add)? Let us know before the next cycle.

Important — nature of this report: BOOJEE Shield produces informational monitoring reports based on publicly available breach databases, open-source intelligence tools, and manual platform searches. We are not a licensed private investigation service, a security operations center, a law-enforcement coordination service, or a guarantee of protection against any harm. All findings and recommendations are for informational purposes — act on them with your own counsel, security team, or law-enforcement contacts as appropriate. All data in this sample document is entirely fictional and created for illustration only.