What the Internet Already Knows About Your Business: The 5 Searches Attackers Run First

Before anyone attacks a business, they research it. Not with exotic hacking tools, but with the same free websites you use every day. In security circles this is called open source intelligence, or OSINT, and it is how a generic scammer becomes a convincing one: they learn who your bookkeeper is, what software you run, which vendor you pay monthly, and when the owner is on vacation.

The best defense is to run the same searches on yourself before they do. Here are the five an attacker starts with, what each one reveals, and what to do about what you find. Budget an hour for all five.

Search 1: Google your own domain with operators

Plain Googling your company name shows you what customers see. Operators show you what attackers see. Try these in Google, replacing the domain with yours:

  • site:yourcompany.com filetype:pdf and the same with xls, xlsx, and docx. This surfaces every document Google has indexed on your site. Businesses are routinely shocked to find price lists, internal forms, employee handbooks, and the occasional spreadsheet with customer data sitting in a forgotten uploads folder.
  • site:yourcompany.com -www to spot subdomains you forgot about, like an old staging site or a test portal that never got taken down.

Anything sensitive that shows up should be taken down or moved behind a login, and you can ask Google to remove the cached copy through Search Console.

Search 2: Check your domain against breach data

Every address at your domain that appears in a known breach, along with what leaked, is searchable for free. This one is important enough that we gave it its own walkthrough: check if your company email is already in a breach. If you have not done that check, do it first. Leaked credentials are the single most actionable thing an attacker can find about you.

Search 3: Look up your office IP on Shodan

Shodan (shodan.io) is a search engine for things connected to the internet. Attackers use it to find exposed services; you can use it to check yourself. Find your office public IP by searching what is my IP from an office computer, then look that IP up on Shodan.

The result should be boring. If you see remote desktop (port 3389), a security camera system, a NAS login page, or your firewall’s admin console listed there, those are doors facing the street. Exposed remote desktop in particular is one of the most common entry points for ransomware in small businesses. Anything you find should be closed off or moved behind a VPN, which is exactly the kind of change your IT provider can make in an afternoon.

Search 4: Study your own people on LinkedIn

Attackers build the org chart before they write the email. Ten minutes on LinkedIn tells them who owns the company, who handles the money, and who just joined and does not know the routines yet. New hires in finance roles are prime targets for the fake CEO gift card text in their first week.

You cannot and should not stop your team from having profiles. Instead, assume the org chart is public and build habits that make it useless:

  • Agree that payment instructions never change based on an email or text alone. Any change gets a phone call to a number you already had.
  • Warn new hires in week one that impersonation texts are a matter of when, not if.
  • Train the team on the tells. Our phishing red flags guide covers the seven that matter.

Search 5: Check your DNS records and public listings

Run your domain through a WHOIS lookup and a DNS checker (mxtoolbox.com is a good free one). Three things to look for:

  • Registrant details. If your personal cell and home address are on the domain registration, enable WHOIS privacy with your registrar. It is usually free and takes two minutes.
  • Email security records. Ask your IT provider whether SPF, DKIM, and DMARC are set up for your domain. Without them, anyone can send email that appears to come from your domain, to your customers, in your name. This is the mechanism behind most invoice fraud.
  • Your Google Business Profile. Make sure the phone number and hours are right and claimed by you. Scammers have been known to edit unclaimed listings so that customers calling the business reach the scammer instead.

Turning the findings into fixes

Most of what these searches surface is fixable for free: take down the indexed documents, close the exposed ports, reset the leaked passwords, enable WHOIS privacy, claim your listings. The pattern to internalize is that attackers count on nobody ever looking. A business that runs these five searches twice a year is a harder target than most, simply because the easy doors are shut.

Key Takeaways

  • Attackers research before they attack, using free tools anyone can use. Running the same searches on yourself removes their head start.
  • Google operators reveal forgotten documents and subdomains on your own site.
  • Shodan shows which of your systems face the open internet. Exposed remote desktop is a ransomware invitation.
  • Your public org chart is a spear phishing toolkit, so build verification habits that make impersonation fail.
  • SPF, DKIM, and DMARC records decide whether criminals can send email as your domain.

Want a second set of eyes on what your business exposes? Start with the free cyber-risk self assessment, or request a consultation and we will walk your exposure with you in plain English.


LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.

Scroll to Top