Loading

How Fraudsters Use Public Records

Public records can help fraudsters identify targets, personalize scams, and impersonate legitimate people or businesses — but public exposure alone does not equal compromise.

Why Public Information Can Become a Fraud Tool

Public records exist for legitimate reasons. Property registers support land ownership and transactions. Company registers show who controls businesses. Court records support an open justice system. Professional registers help consumers verify qualifications and licenses.

The problem is simple: information does not have to be secret to be useful to a fraudster.

Names, addresses, company roles, property ownership, professional credentials, business relationships, and historical details can all provide context about a person or organization. A criminal can combine those facts with social media, data-broker profiles, breached information, stolen credentials, phishing responses, or compromised accounts.

That combination can make a scam far more believable.

Public records are therefore best understood as a source of intelligence and credibility. They usually do not give a criminal direct access to your bank account or email. They can, however, help a fraudster decide whom to target, verify information they already possess, impersonate someone convincingly, or construct a story that is difficult to dismiss.

What Counts as a Public Record?

A public record is generally information held by a government agency, court, regulator, or official registry that members of the public can legally access.

Depending on the country and jurisdiction, public records may include:

  • Company registrations and corporate officers
  • Property ownership and land records
  • Court, bankruptcy, and insolvency records
  • Professional and occupational licenses
  • Business registrations
  • Planning and permit records
  • Probate and certain civil records
  • Some political or electoral information
  • Regulatory and disciplinary records

Access varies substantially.

A record that is searchable online for free in one jurisdiction may require payment, identification, a legitimate purpose, or an in-person request somewhere else. Even within the same country, rules can differ between states, provinces, territories, municipalities, and individual agencies.

Public records are also different from publicly available information.

A LinkedIn profile, obituary, company biography, personal website, social media account, online directory, and news story may all be publicly visible without being official government records.

Fraudsters rarely care about the legal distinction. Their practical question is:

What can I learn about this person, business, or transaction from information that is available to me?

What Can Fraudsters Learn From Public Records?

Different records can reveal different pieces of a person’s or organization’s identity.

Record typeInformation it may revealHow fraudsters may use it
Company recordsDirectors, officers, registered addresses, company numbers, filing historyExecutive impersonation, supplier fraud, targeting decision-makers, clone-business scams
Property recordsOwnership, property details, transaction informationOwner impersonation, targeted property scams, verification of addresses or assets
Professional registersName, occupation, license status, business detailsImpersonating professionals or selecting high-value targets
Court or insolvency recordsLegal disputes, bankruptcies, parties involvedCreating convincing legal or financial pretexts
Business registrationsTrading names, addresses, ownersImpersonating legitimate businesses or validating other information
Public permits and planning recordsAddresses, projects, contractors, applicationsTargeting property owners or businesses with timely scams

The most important point is that these records become more powerful when linked together.

One record may confirm an address. Another may identify an employer. A company register may reveal that the person is a director. Social media may show an upcoming trip. A breached database may contain an email address and old password.

Individually, those facts may appear harmless. Together, they create a detailed target profile.

How Fraudsters Use Public Records

1. Building a More Complete Identity Profile

One of the most common uses of public information is identity enrichment.

A fraudster may begin with only a name, email address, telephone number, or username. Public sources can then help confirm whether that information belongs to a real person and reveal additional connections.

Records may help establish links between:

  • A person and an address
  • An individual and a company
  • Directors and other corporate officers
  • Former and current names
  • Property ownership
  • Professional roles
  • Business partners
  • Geographic locations

This does not necessarily let the criminal access an account. Instead, it helps determine whether other information they possess is accurate.

That can be especially valuable when criminal datasets are incomplete, outdated, or assembled from multiple breaches.

2. Choosing More Valuable Targets

Fraudsters do not always choose a victim first and research them afterward.

Public records can also be used to decide who is worth targeting.

Company registers can identify directors, executives, and people who may control money or approve payments. Property information can identify owners. Professional registers can reveal doctors, lawyers, accountants, financial professionals, and other people whose roles may make them attractive targets.

Court or insolvency information can show that someone is involved in a financial or legal process, giving a criminal a possible pretext for contact.

From a fraudster’s perspective, public information can therefore act as a filtering system.

A person who owns valuable assets, runs a company, manages payments, or has decision-making authority may attract more carefully prepared fraud attempts than someone selected at random.

3. Making Phishing and Social Engineering More Convincing

A generic scam saying “your account has a problem” is relatively easy to recognize.

A message that correctly names your employer, business partner, property, professional role, or colleague can feel very different.

Fraudsters use accurate information to give their messages credibility. Instead of relying on a completely fabricated story, they can anchor the scam in facts the victim knows are true.

For example, a fraudulent message might appear to concern:

  • A company you genuinely work for
  • A supplier your organization actually uses
  • A property you really own
  • A colleague or executive you recognize
  • A professional registration you hold
  • A genuine legal or financial process

The Canadian Centre for Cyber Security warns that threat actors frequently collect publicly available information to tailor social-engineering messages and increase their credibility. It also notes that generative AI can help criminals analyze public information and create highly personalized phishing communications.

A scammer does not need to know everything about you. A few accurate details can be enough to make the rest of the story seem plausible.

4. Impersonating Executives, Employees, and Suppliers

Public corporate information can reveal who matters inside an organization.

Company registers, corporate websites, professional profiles, press releases, and conference listings can expose:

  • Executive names
  • Job titles
  • Reporting relationships
  • Company locations
  • Suppliers
  • Email formats
  • Travel or event schedules

Criminals can use these details in business email compromise, invoice fraud, payroll diversion, executive impersonation, and supplier impersonation.

The FBI describes business email compromise as one of the most financially damaging online crimes. A typical scam involves a message that appears to come from a trusted executive, vendor, title company, or other legitimate source and requests a payment or change in banking instructions.

Public information does not have to be the only source used in the attack. A compromised mailbox may provide much more intelligence. But public records can help criminals identify the right people to impersonate and the employees most likely to authorize a transaction.

That is why unusual financial requests should always be verified independently rather than trusted because an email contains correct company information.

5. Copying Real Businesses to Create “Clone” Scams

Fraudsters do not only research victims.

They also research legitimate organizations so they can pretend to be them.

This is one of the most important ways public registers can be misused.

A criminal may copy genuine details such as:

  • A registered company name
  • Company or license number
  • Office address
  • Director or adviser name
  • Professional credentials
  • Regulatory registration
  • Logo and branding
  • Website content

The fraudster then creates a fake website, email address, advertisement, social media account, or telephone operation that appears connected to the legitimate organization.

In the United Kingdom, the Financial Conduct Authority calls these clone firms. The FCA warns that scammers may copy the name, address, Firm Reference Number, and other details of an authorized firm, while changing the telephone number, email address, or website used to contact victims.

The problem remains current. The FCA continued publishing warnings about new clone firms in August 2026.

Australia faces the same type of impersonation. ASIC says criminals increasingly copy the names, license numbers, and websites of Australian Financial Services licensees to create fake sites and investment advertisements. In 2026, ASIC began publishing verified licensee website addresses through its professional register to make these impostor sites easier to identify.

This creates an important security lesson:

Finding a business on an official register does not prove that the person contacting you actually represents that business.

If someone contacts you unexpectedly, compare the phone number, website, email domain, and other contact information against details obtained independently from the regulator or organization’s genuine website.

Do not rely only on a registration number supplied by the person trying to gain your trust.

6. Supporting Account-Recovery and Identity-Verification Attacks

Some organizations still use biographical facts to verify identity or recover accounts.

That becomes dangerous when those facts are publicly discoverable.

Examples can include:

  • ZIP or postal code
  • Birthplace
  • Mother’s maiden name
  • Previous addresses
  • Date of birth
  • Employer
  • Other personal history

The U.S. Federal Trade Commission specifically advises consumers to avoid security questions whose answers can be found online or in public records, including ZIP codes, birthplace, and a mother’s maiden name. If such questions cannot be avoided, the FTC recommends treating the answers like passwords rather than using predictable factual responses.

A public fact should not function as a secret credential.

Where available, passkeys, authenticator apps, hardware security keys, and other stronger forms of authentication provide better protection than identity checks based solely on information someone else may be able to research.

7. Combining Public Records With Stolen Data for Identity Fraud

Public records rarely provide everything needed for serious identity fraud.

The greater risk arises when they are combined with information obtained through:

  • Data breaches
  • Phishing
  • Malware
  • Stolen mail
  • Compromised accounts
  • Stolen identity documents
  • Criminal data markets
  • Data brokers
  • Social media

For example, a public record may confirm a person’s name and address. A breach may reveal an email address and telephone number. A phishing attack may obtain credentials. A stolen document may provide a government identifier.

The Canadian Centre for Cyber Security notes that once criminals accumulate enough identity attributes, they may be able to create fraudulent identity credentials or take control of existing credentials.

This is why discovering that your address or company affiliation is publicly visible is not the same as discovering that your identity has been stolen.

The risk depends heavily on what other information is available and what security controls protect your accounts and assets.

8. Property and Title Fraud

Property ownership records can create another form of exposure.

A criminal who successfully impersonates a property owner may attempt to arrange a fraudulent sale, mortgage, transfer, or other change involving the property.

In England and Wales, HM Land Registry says the risk can be higher when:

  • The owner’s identity has already been stolen
  • The property is rented out
  • The owner lives overseas
  • The property is empty
  • The property has no mortgage
  • The property is not registered

HM Land Registry allows owners to monitor activity through its free Property Alert service and, in some circumstances, place restrictions on the title.

The risk should not be exaggerated.

In the 2024–25 financial year, HM Land Registry received 4,429,092 applications to create or update the Land Register and identified 86 as fraudulent — just over 0.0019%. It nevertheless prevented fraudulent applications involving more than £59 million worth of property.

Property fraud can be extremely serious, but those figures show why public property records should not be treated as evidence that title theft is common or easy.

9. Misusing Business Registers

Business registries illustrate the tension between transparency and privacy particularly well.

Their purpose is partly to help the public understand who owns, controls, or represents a business. The same transparency can reveal information useful to criminals.

United Kingdom

Companies House makes substantial company information publicly searchable.

The United Kingdom has introduced reforms intended to make that information more reliable and reduce misuse of the register. Identity verification became a legal requirement from November 18, 2025, with new directors subject to verification and existing directors and people with significant control entering a phased 12-month transition based on their applicable deadlines.

Companies House also allows certain personal information to be removed from public filings in qualifying situations, including some home addresses, signatures, business occupations, and the day component of older dates of birth.

Australia

ASIC’s registers contain information about companies, businesses, and officeholders.

Australia changed some access rules on February 2, 2026. ASIC removed officeholders’ residential addresses from current and historical company extracts available through its website. However, residential addresses can still appear in other publicly purchasable lodged documents unless they have been formally suppressed.

That distinction matters. A register may reduce access to information without removing every historical occurrence of it.

ASIC also provides mechanisms for suppressing residential addresses where the safety of an officeholder or their family is at risk.

How Public-Record Risk Differs by Country

There is no single international system governing public records.

CountryExamples of exposureUseful protections or considerations
United StatesProperty, court, corporate, licensing, and other records vary widely by state and local jurisdictionStrong account security, fraud alerts, and credit freezes can reduce identity-fraud risk
United KingdomCompanies House, land records, professional registers, and other official systems provide different levels of public accessCompanies House privacy measures, identity verification, FCA verification tools, and HM Land Registry Property Alert can reduce specific risks
AustraliaASIC business and professional registers disclose company and officeholder information subject to current access rulesAddress suppression may be available in qualifying cases; ASIC now publishes participating AFS licensees’ website details to counter impersonation
CanadaAccess varies across federal, provincial, territorial, municipal, corporate, and professional systemsCredit monitoring, fraud alerts, strong authentication, and independent verification remain important

The details matter because advice that applies in one jurisdiction may be impossible or unnecessary in another.

You should always check the rules of the specific registry involved rather than assuming a record can be removed, hidden, or changed.

Why Public Records Are Only Part of the Risk

A useful way to think about fraud exposure is to divide the information criminals may gather into four categories.

Official records

  • Company information
  • Property records
  • Court information
  • Licensing records
  • Regulatory filings

Open-web information

  • Employer biographies
  • News stories
  • Personal websites
  • Obituaries
  • Directories
  • Social media

Commercial information

  • People-search services
  • Marketing databases
  • Data brokers

Illicit information

  • Breached passwords
  • Stolen identity documents
  • Malware logs
  • Compromised financial information
  • Criminal marketplace data

The danger often lies in linking these sources together.

Someone who knows only your name may have little ability to harm you. Someone who knows your name, address, employer, job title, property holdings, relatives, telephone number, old credentials, and current activities has a much stronger basis for impersonation.

How to Reduce the Risk From Public Records

You usually cannot — and often should not — remove yourself from every legitimate public record.

A better strategy is to reduce unnecessary exposure while ensuring publicly available facts cannot easily be used as proof of identity.

Audit What Is Publicly Visible

Search for information associated with your:

  • Full name
  • Current and previous addresses
  • Phone numbers
  • Email addresses
  • Business names
  • Professional registrations
  • Company directorships
  • Property records where publicly searchable

Check both search engines and the official registries relevant to your location.

The objective is simple: understand what a stranger could learn without contacting you.

Remove or Suppress Information Where Appropriate

Some registries allow certain information to be hidden or replaced.

If local law allows it, consider whether a business or service address can be used instead of a residential address.

Do not assume every record can be deleted. Many public registers exist because transparency is legally required.

Instead, investigate the specific privacy or suppression mechanisms provided by the relevant registry.

Stop Treating Biographical Facts as Secrets

Your birthplace, ZIP code, mother’s maiden name, employer, property ownership, or date of birth may be discoverable.

They should not be relied upon as strong authentication factors.

If a website requires security questions and permits arbitrary answers, consider using unique, unrelated responses stored in your password manager rather than literal biographical facts.

Strengthen High-Value Accounts

Prioritize protection for:

  • Email
  • Banking
  • Government services
  • Cloud storage
  • Domain registration
  • Business administration systems
  • Social media
  • Password managers

Use unique passwords, multifactor authentication, passkeys where supported, and secure recovery methods.

Your email account deserves particular attention because access to email can allow an attacker to reset passwords across many other services.

Verify Important Requests Through a Separate Channel

Correct personal information does not prove that a message is genuine.

If someone requests a:

  • Bank-account change
  • Wire transfer
  • Payroll update
  • Large purchase
  • Password reset
  • Confidential document
  • One-time authentication code

verify the request through a contact method you already trust.

For businesses, this should be a formal process rather than an informal precaution.

The FBI recommends independently confirming payment and purchase requests instead of relying on email alone.

Verify Businesses Beyond the Registration Number

When dealing with an unfamiliar financial firm, adviser, supplier, or professional, do not stop after confirming that the organization exists.

Check:

  1. Whether the business is genuinely registered or licensed.
  2. Whether it is authorized to provide the specific service being offered.
  3. Whether the website and telephone number match official records.
  4. Whether the email domain belongs to the genuine organization.
  5. Whether the payment details are consistent with independently verified information.

Clone-firm scams work precisely because victims find a real business on an official register and assume the scammer must therefore be connected to it.

Monitor High-Value Assets and Records

Where available, enable alerts for:

  • Bank transactions
  • Credit-file changes
  • New financial accounts
  • Property-register activity
  • Corporate filing changes
  • Domain changes
  • Important account logins

In the United States, the FTC says anyone can place a free credit freeze, which blocks new credit accounts from being opened while the freeze remains in place.

In England and Wales, HM Land Registry’s free Property Alert service can notify owners of significant activity involving monitored properties.

What to Do If Someone Uses Your Public Information for Fraud

Seeing your information in a legitimate public record does not mean you are a victim of identity theft.

Evidence of misuse is different.

Possible warning signs include:

  • Credit applications you did not make
  • Unexpected password resets
  • Unfamiliar financial accounts
  • Unauthorized company filings
  • Suspicious property activity
  • Collection notices for debts you do not recognize
  • Invoices or messages being sent in your company’s name
  • Customers reporting contact from an impostor website or email address

If you discover fraud, act quickly.

1. Preserve Evidence

Save relevant:

  • Emails
  • Messages
  • Screenshots
  • Website addresses
  • Transaction records
  • Account notifications
  • Registry entries
  • Telephone numbers

Do not delete useful evidence simply because the contact was fraudulent.

2. Contact the Affected Organization Directly

Use independently verified contact information.

Do not call a number, click a link, or reply to an email supplied by the suspected fraudster.

3. Secure Affected Accounts

Change compromised credentials, review recovery settings, sign out unknown sessions, and strengthen multifactor authentication.

If your email account may be compromised, secure it first because it can provide access to many other accounts.

4. Contact Your Financial Institution Immediately

If money has been transferred, contact your bank or payment provider as quickly as possible.

Early reporting may improve the chance of stopping or tracing a transaction.

5. Check Credit Information Where Appropriate

If the fraud could involve new accounts or loans, review your credit information and use the protections available in your country.

6. Correct Fraudulent Registry Information

If someone has made an unauthorized corporate, property, professional, or other official filing, contact the agency responsible for that register.

7. Report the Fraud Through the Correct National System

Reporting routes differ by country.

United States: IdentityTheft.gov allows victims to report identity theft to the Federal Trade Commission and receive a personalized recovery plan.

Australia: Scamwatch accepts scam reports, while ReportCyber is used where a scam has resulted in information or financial loss.

Canada: The National Fraud Reporting System, jointly managed by the RCMP and Canadian Anti-Fraud Centre, accepts reports of fraud and cybercrime. Canadian financial authorities also recommend notifying affected financial institutions, credit bureaus, and police where appropriate.

United Kingdom: Report Fraud replaced Action Fraud on December 4, 2025, for England, Wales, and Northern Ireland. People in Scotland should continue to report fraud through Police Scotland.

Property fraud in England and Wales should also be reported directly to HM Land Registry where relevant.

You Do Not Need to Disappear From Public Records

Public records are not inherently a security failure.

They support property ownership, commerce, legal transparency, professional accountability, regulatory oversight, and fraud prevention itself.

The weakness appears when information that is publicly discoverable is treated as though only the legitimate person could know it.

An address should not work like a password.

Knowing a director’s name should not authorize a payment.

A date of birth should not prove identity by itself.

Finding a license number should not prove that the person contacting you owns that license.

Modern security works best when it assumes attackers may already know basic facts about the people and organizations they target.

Conclusion: Make Public Information Less Useful to Fraudsters

Fraudsters use public records primarily to research, verify, target, and impersonate.

Official records can help identify where you live, what company you operate, what property you own, what professional role you hold, or which organization a fraudster could convincingly imitate. Other sources can then fill in the missing pieces.

The answer is not necessarily to remove yourself from every public database.

Instead, understand what information is visible, suppress unnecessary details where legitimate options exist, use strong authentication, stop relying on public facts as identity checks, verify financial requests independently, and monitor the accounts and assets that would be costly to lose.

You may not be able to control every fact that is public.

You can control how much trust, access, and authority those facts are allowed to provide.