A single-family office running the affairs of a public-facing principal engaged LeakTrace after a family-office consultant recommended a principal-focused exposure audit as a precondition to onboarding a new domestic staff cohort. The audit surfaced the correlation graph an operator would use to construct a plausible pretext against the household. The findings led to a durable rewrite of the family office's household security baseline.
Engagement origin
The family office consultant, retained by the principal's counsel, had observed a pattern of principal-adjacent incidents at peer offices in the same asset tier. The consultant introduced LeakTrace as a specialist in the correlation-graph and public-record aggregation surface that most cyber vendors treat as out of scope. The family office operates as a single-family entity, managed by a chief of staff, with a small internal team supporting the principal's household, philanthropic vehicle, and directorships.
Discovery scope
Principal-focused external exposure across three surfaces: the principal's individual identity and its personal accounts, the household surface including domestic staff and adjacent persons named on public records, and the philanthropic and directorship surface from which a targeting attacker constructs a pretext. LeakTrace did not touch the principal's devices, did not access any accounts, and did not request any information from the household directly. All discovery was through public and monitored sources.
Findings summary
The audit produced findings across five categories. The correlation-graph finding is the most material.
- Correlation graph across surfaces. Public records, philanthropic disclosures, corporate directorships, real estate filings, and press mentions combined to disclose the principal's household composition, primary residence range, philanthropic causes, adjacent staff names, and the operating pattern of the household in a form legible to an operator. The combined view was sufficient to construct a pretext for a targeted social-engineering approach against domestic staff.
- Personal credential exposure. The principal's personal email address, which had been used to register several personal accounts prior to the family office being established, appeared in multiple consumer breach indexes with recovered passwords. The pattern of reuse across personal accounts extended the exposure to the principal's philanthropic vehicle.
- Domestic staff exposure. Two long-tenured domestic staff members were listed by name on public records adjacent to the principal's household. Both had personal breach exposure that connected their household roles to their personal identities in criminal-marketplace indexes.
- Household-adjacent digital surface. A vendor supporting the household's property management had a publicly reachable client portal that disclosed the property address, staff names, and service schedule.
- Philanthropic vehicle infrastructure. The philanthropic vehicle's mail infrastructure was misconfigured in a way that permitted a targeting attacker to send messages that appeared to originate from the philanthropic entity.
Client actions
The family office implemented a household security baseline covering personal account authentication, domestic staff onboarding, vendor exposure review, and the philanthropic vehicle's mail infrastructure. The principal's personal email address was retired and replaced with a segregated identity architecture. Domestic staff signed updated confidentiality agreements that addressed their public exposure alongside their role. The property management vendor's client portal was reconfigured to require authenticated access. The philanthropic vehicle's mail infrastructure was corrected. LeakTrace was retained for continuous monitoring covering the principal, the household, and the philanthropic vehicle.
Outcome
The family office's chief of staff later described the audit as the first time the household's exposure was documented on paper, in a form the principal could read directly, and used as the anchor for a household security policy. The onboarding process for new domestic staff was modified to include the exposure audit as a baseline.
All findings were drawn from public records, corporate registry filings, philanthropic disclosures, real estate filings, press mentions, and monitored breach databases. No devices, accounts, or private communications were touched. Domestic staff were not contacted directly at any point in the audit. The findings were reviewed with counsel before delivery to the family office.