Recommended action: Report the account via Instagram's "Impersonation" reporting path (Settings → Report → It's pretending to be someone → Me). Screenshot and preserve before reporting. If not resolved within 14 days, submit to Meta Business Support with the URL.
Digital Exposure Report — July 2026
This month's sweep identified 3 medium-severity findings and 1 high-severity finding requiring prompt action. The high-severity item is a confirmed credential leak for the primary account holder's work email address in the RetailDB-2025 breach. Immediate password rotation is recommended.
Two data-broker listings for a household member were found active at Spokeo and Whitepages; opt-out submissions were noted in recommendations. A social platform impersonation account was identified on Instagram; reporting steps are detailed in Section 04. No deepfake or likeness-misuse findings were identified this cycle.
Overall household exposure posture: Moderate — action required. All findings have recommended actions with prioritization below.
Breach database results
| Person | Email / Identifier | Breach | Data Exposed | Date | Severity |
|---|---|---|---|---|---|
| Marcus H. (primary) | m.hargrove@nexacorp.com (fictional) |
RetailDB-2025 | Email, hashed password, name, phone | Dec 2025 | High |
| Marcus H. (primary) | marcush1972@gmail.com (fictional) |
LinkedSocial-2023 | Email, username, public profile data | Mar 2023 | Info |
| Diana H. (spouse) | diana.hargrove@proton.me (fictional) |
None found this cycle | — | — | Clear |
| Tyler H. (child, 19) | tyler.h.2007@icloud.com (fictional) |
GamingForum-2024 | Username, email, IP address range | Aug 2024 | Medium |
| Elena H. (child, 16) | Not monitored at this email | None found this cycle | — | — | Clear |
Sources checked: Have I Been Pwned aggregator, public breach paste aggregators, manual credential-dump searches. We check only publicly disclosed breach data — not private law-enforcement databases. The 2023 LinkedSocial breach contained no passwords; the GamingForum-2024 breach exposed hashed credentials and IP ranges with no financial data.
Social platform results
Recommended action: Report the account via Instagram's "Impersonation" reporting path (Settings → Report → It's pretending to be someone → Me). Screenshot and preserve before reporting. If not resolved within 14 days, submit to Meta Business Support with the URL.
Platforms searched: Instagram, Facebook, X (Twitter), TikTok, LinkedIn, Threads, Pinterest. Search method: name variants + profile-image reverse-search (where public photos were provided at intake).
People-search site results
Opt-out submissions for Spokeo, Whitepages, and FamilyTreeNow are recommended (see actions). MyLife opt-out submitted last cycle; allow up to 30 days per their published policy. Data brokers repopulate from public records every 3–6 months — re-sweep is included quarterly on Premier tier.
Quarterly likeness check
Cycle status: Quarterly deepfake and likeness sweep was conducted this cycle (Q3 2026). Reverse-image and platform searches were run for Marcus H. and Diana H. using reference photos provided at intake.
No findings. No synthetic, altered, or unauthorized uses of household members' photos or video likeness were identified on Google Images, Bing, YouTube, Instagram, Facebook, or TikTok. The Instagram impersonation account (Section 03) used a photo copied from a public professional profile — this is profile-photo misuse, not a deepfake.
Next quarterly likeness sweep: October 2026.
Prioritized action list
-
Urgent
Rotate the nexacorp.com work email password immediately. The RetailDB-2025 breach exposed a hashed password; treat it as compromised. If this password was reused on any other account (banking, personal email, cloud storage), rotate those passwords as well. Enable a hardware security key or app-based MFA on the work account if not already active.
-
Urgent
Report the Instagram impersonation account. Use Instagram's in-app reporting path (Settings → Report → Pretending to be someone → Me) and take screenshots of the account before reporting. If unresolved in 14 days, escalate via Meta Business Support with the account URL.
-
This month
Submit opt-out requests for Spokeo and Whitepages. Spokeo opt-out: spokeo.com/optout. Whitepages: whitepages.com/suppression-requests. These typically process within 24–48 hours. We recommend doing this yourself (or replying to this email if you would like us to handle it as part of your next Cloak add-on).
-
This month
Submit FamilyTreeNow opt-out for the household unit listing. familytreenow.com/optout — this listing includes relative names and age ranges. Processing typically within 24 hours.
-
This month
Rotate Tyler's gaming account password (GamingForum-2024). The breach exposed a hashed password and IP address range. If that password was reused on other services, rotate those as well. Recommend enabling MFA on any accounts Tyler uses with the same email address.
-
Monitor
Allow MyLife and Acxiom opt-outs to process. No further action needed this cycle — we will verify removal at the next sweep. MyLife can take up to 30 days; Acxiom up to 30 days as well.