Information and big data flow
Vertigo3d via Getty Images
By John Wyman and Mond Mugiya, Control Risks
In July, the New York City Department of Finance published a supplemental market value roll, as part of the implementation of the city’s new non-primary residence property surcharge, an annual tax on certain high-value residences that are not used as their owners’ primary homes. The roll covers a broad universe of residential properties, including single-family homes, condominiums, and cooperative units, although city officials have emphasized that most listed properties will ultimately not be subject to the surcharge.
Whatever the eventual outcome of the policy debate surrounding the surcharge, the episode illustrates a broader reality: once information has been published, copied and circulated, its security implications can persist long after the original disclosure.
The publication quickly drew attention for reasons extending beyond tax policy. By linking named individuals to residential addresses, it highlighted a growing security challenge: how government disclosure can create unintended exposure in an environment of heightened political polarization, declining trust in institutions and increasingly personalized grievance.
The problem isn’t that the information is searchable
For most people, a disclosure of this kind is unremarkable, entirely legitimate and even useful: a basis for advocacy, lawful protest or debate about how wealth is taxed.
The concern is not disclosure itself. It is that a government-generated list can link a group of individuals, defined by wealth or property ownership, with residential addresses. That makes personal information easier to access and act upon at a time when grievances are becoming more personal and public anger is increasingly directed at individuals.
Three immediate pathways to harm
The significance becomes concrete when you consider how such a disclosure can be used. It creates three immediate risks:
- Physical exposure. It reveals residential locations, including homes that may sit vacant for extended periods.
- Fraud and impersonation. It enables false tax notices, payment demands, removal schemes and pretext calls, trading on the credibility of an “official” list.
- Downstream amplification. People-search sites and data brokers ingest, enrich and redistribute the information. This can weaken the privacy created by an LLC, trust or family-member ownership structure by reconnecting an entity to a physical address.
Misidentification makes this worse, not better. The roll includes, but is not limited to, properties that may be subject to the surcharge, and exemptions may apply. But an inaccurate entry still creates a durable public profile. To a bad actor, the label does not need to be correct for the name and address to be useful.
A threat environment transformed by aggregation and grievance
Twenty years ago, locating a high-net-worth individual and connecting them to a home took time and specialist effort. Today, public records can be combined with social media, corporate disclosures, data-broker information and AI-enabled search tools in minutes. Information that looks innocuous in isolation becomes operationally useful once aggregated.
This is unfolding against a backdrop of declining institutional trust, economic pressure and grievance-based mobilisation. In what Control Risks describes as “activated societies,” some view governments as captured, business as unaccountable and prominent individuals as symbols of an unjust system. As a result, a single disclosure can be amplified through viral content and affinity networks faster than conventional security planning can react.
The overwhelming majority of criticism and protest remains lawful. The concern lies with the small subset for whom public grievance becomes personal, target-focused and self-authorising. For these people, a name joined to an address is all the starting point they need. Fragmented online communities complicate detection: hostile rhetoric and misinformation create noise, while the rapid circulation of violent acts and perpetrator narratives can offer scripts, validation or notoriety to susceptible individuals.
An evolving attacker profile
Recent targeted attacks raise questions about whether some attacker behaviours are changing, though the available cases do not yet establish a settled typology or a clean break from earlier patterns. With that caution in mind, some contemporary attackers have appeared less resigned to dying or being captured, more willing to confront visible security, more focused on a named leader than an institution, and more deliberate about concealment and escape.
These are observations to inform planning, not assumptions to apply to every person of concern. But they matter, because an offender who intends to survive and escape changes the calculus for protection, response and law enforcement coordination.
The vigilante lens
One useful way to understand this shift is the longstanding concept of the vigilante: someone who believes the social order is under threat and that established institutions are unwilling or unable to hold those responsible to account.
This motivation is not tied to a single ideology. It can emerge when a person adopts a morally absolute grievance, identifies an individual or group as responsible, and comes to regard unilateral action as legitimate justice. Relevant features may include a need for recognition, black-and-white moral reasoning, limited empathy and sustained fixation.
What makes these individuals especially difficult to spot is that the act itself can give them the sense of control or moral worth they’re seeking, so they may never seek a group’s approval or telegraph their intent. Nor do they need a personal connection to the grievance; they can adopt someone else’s cause and cast themselves as the one to answer it.
This is a lens, not a label. Moral outrage or activism alone does not establish a threat. Its value is in showing how grievance, fixation, perceived institutional failure, target selection, preparation and self-authorised action can come together on the path towards violence.
From symbol to target
Target selection makes the security significance clearer. Executives, investors, board members and wealthy property owners are rarely singled out for personal reasons alone. They may be chosen as symbols of a system someone holds responsible. Once a name is tied to an address, the gap between symbolic hostility and a physical approach narrows, pulling family members, staff and neighbours into the exposure too.
The real question
Information that is harmless in isolation can take on new significance once it is consolidated, easily searchable and attached to emotionally charged grievances. For those affected, the priority now is to understand the exposure it creates and to assess what it means for them.
That starts with a clear-eyed view of the risk: what a motivated outsider can discover, how that information could be used and who around the principal might be drawn in. From there, exposure can be reduced, monitored and managed well before elevated attention becomes a security concern.
For individuals, families and organizations whose names or addresses appear in public records, the pressing question is practical: what now? Removing a single record rarely settles the issue, and aiming for total invisibility is neither realistic nor a reliable defense.
What works is a disciplined approach to exposure: understanding what is visible, limiting what need not be public and preparing to act the moment attention becomes a concern.
This requires two related but distinct capabilities: protection and threat assessment.
Two questions, two disciplines
That disciplined approach rests on understanding two distinct capabilities, because protective measures and behavioural threat assessment answer different questions, and mature programmes run both.
Protection seeks to reduce immediate vulnerability: securing a residence, hardening a routine, controlling access. Threat assessment examines the person of concern, the context and trajectory of their behaviour, the stressors and stabilisers around them, their access and capability, and the opportunities for intervention.
A searchable list organized around second homes can provide a pre-generated universe for research and make grievance-based target selection easier. While most people who view public records will never misuse them, risk management focuses on the few who might and on identifying concerning behavior before intent becomes action. A strong program activates both protective and threat assessment functions and ensures each informs the other.
When information has been exposed
When records have been made public, the aim for security functions is to identify where and when exposure is being converted into fraud, surveillance or targeting.
If you are affected, it’s important to first confirm what has actually been published. Screenshots, URLs and communications should be preserved, with the aim of establishing whether the information is merely available or actively circulating alongside hostile commentary, threats or attempted contact. This distinction matters enormously when it comes to forming a response.
From there:
- Request correction, removal or reduced visibility where processes exist, recognising that copies may persist elsewhere.
- Coordinate decisions across security, legal, communications and cybersecurity, rather than in isolation.
- Review residential security and reduce unnecessary disclosure of travel and family routines.
- Harden accounts with unique passwords, multifactor authentication and carrier protections.
Those affected should treat any unsolicited communication about the tax, an exemption or list removal as suspect until independently verified. They should not use supplied links, confirm ownership to a caller or enter details into unofficial lookup tools. All questions on liability, exemptions or appeals should be referred to qualified tax counsel.
Finally, brief the people most likely to receive contact: personal assistants, family-office staff, household managers and family members. Concerning communications should be recognized, preserved and routed through a controlled process. A single official-looking letter can join a name, address and listing status on one page, so such correspondence should not be handled casually.
Monitoring for exposure
High-net-worth individuals and family offices should commission a digital risk profile. This is a clear picture of what a motivated outsider can learn about the principal, family, residences, business interests, travel, staff and trusted relationships, drawing on open, deep and dark web sources, public records, data brokers, breached credentials, social media, corporate filings and image-based clues, with findings prioritised by operational relevance.
Two principles matter here. First, data removal should be recurring, not one-time, because information repopulates. Specialist providers can suppress data-broker records and monitor for their return. Second, assessments must extend beyond the principal to spouses, children, assistants, drivers and household staff, because a principal is often identifiable indirectly through others.
These digital findings should inform residential security and an exposure-response playbook, with named decision-makers, after-hours contacts, evidence procedures and clear triggers for additional protection. A playbook should also be tested, through scenarios involving threatening communications, suspicious approaches, protests at a residence, fraud or a disclosure affecting a family member.
Build a proactive threat intelligence and management function
Protective intelligence cannot be limited to online monitoring. Threat actors may contact the principal directly or reach assistants, household staff, reception teams and security officers. Effective collection must span both digital and physical channels: mail and email, voicemail, calls, social media messages, deliveries and in-person encounters, alongside open, deep and dark web sources.
A centralised process should gather and preserve relevant communications and metadata, correlate activity across locations and affiliated organisations and allow seemingly minor contacts to be viewed together.
Patterns rarely reveal themselves one incident at a time. The people most likely to receive contact should know what to report, how to preserve it and where to send it. Governance should be clear on who receives information, performs initial triage, convenes a broader assessment, and retains responsibility for person-of-interest management. A multidisciplinary pathway should be ready for structured behavioural threat assessment and coordinated management when a case warrants it.
Crucially, planning should also account for an offender who intends to escape, through rapid sharing of suspect descriptions, preservation of video and access records, protection of secondary locations, and coordination with law enforcement.
The bottom line
Transparency serves important purposes, and the answer is not to retreat from public life. The challenge is to manage risk, not eliminate visibility. Public information can be legitimate, useful and still operationally significant when it is consolidated, searchable and attached to emotionally charged grievances. The organizations and families that respond best will be those that understand their exposure, monitor how it changes and act before visibility becomes vulnerability.
John Wyman is a Principal at Control Risks specializing in workplace violence prevention, threat management and behavioral threat assessment.
Mond Mugiya is a Director at Control Risks and a behavioral threat assessor specializing in targeted violence, insider threats and complex human-driven security risks.

Leave a comment