For journalists, the attack may begin long before the first threatening message arrives. A phone number buried in an old student website, an abandoned social media account, a photograph revealing parts of your home in the background, or information about a family member can all become pieces of a much larger picture.
That was the starting point for a workshop on identifying digital vulnerabilities and understanding the online attacks that can target journalists, held during IJ4EU’s recent UNCOVERED Conference.
The aim was not to offer a single security checklist or a silver bullet. (Spoiler alert: there’s not such a thing against these attacks.) Instead, the session explored how journalists can develop the analytical skills to understand their own exposure — and recognise when apparently random online abuse is actually part of a coordinated campaign.
Titled Defending the Beat when the Backlash Comes Online, the workshop was led by Javier Luque, head of digital media and online safety at the International Press Institute.
Looking at yourself through an attacker’s eyes
One of the central exercises was a self-doxxing exercise: stepping into the shoes of someone who wants to expose your personal data and information in an attempt to intimidate you or discredit your work.
Participants looked at the information that can be pieced together from public records, professional profiles, media organisations’ websites, personal blogs, social media and old versions of websites. Phone numbers, email addresses, home and workplace locations, family connections and forgotten social media accounts can all become useful pieces of information for someone trying to build a profile of a journalist.
The important point is that much of this information doesn’t need to be secret or hacked. It can simply be scattered across the internet, waiting to be connected.
That is why the workshop encouraged journalists to regularly scan their own digital footprint. The objective is not necessarily to delete everything — particularly personal material that people have a legitimate reason to keep online — but to understand what is exposed and where potential vulnerabilities lie. This can be particularly important for investigative journalists before publishing sensitive stories.
How a rumour becomes a campaign
The session also looked at the disinformation cycle: how a message targeting a journalist can move from a relatively small group of actors into something that appears to be a much wider public consensus.

It can start with a target and a message. Influential figures and bots amplify that message, while thousands of accounts can share or repeat it. The objective is not necessarily to convince everyone that the original claim is true. It can be enough to create the impression that everyone is talking about it — a suffocating atmosphere in which a rumour shared by a relatively small number of people begins to look like the dominant view of society.
The first wave of such a campaign will often last 24 to 48 hours, but the same journalist can continue to be labelled and targeted with the same message afterwards.
From there, the narrative can jump between platforms — from niche social media channels like Gab or Telegram, to mainstream platforms such Facebook or X — and into more traditional media.
Articles may report on the rumours, television shows may discuss them, and columns by purported “experts” can give the false claims an additional layer of credibility. The campaign can then escalate from online attacks into cyberattacks, legal harassment or even physical threats.
Turning the attack into something that can be investigated can also help reduce its personal impact. Instead of experiencing an apparently chaotic stream of abuse, the journalist can begin to see the structure behind it once she or he has got some healthy distance from it — and potentially expose the agenda driving the campaign: Who is involved? What are they trying to achieve? Where is the narrative spreading? Which accounts and channels are amplifying it? And how did it begin?
The AI paradox
The discussion took an interesting turn towards the end of the workshop, when participants considered whether some of this work could itself be automated.
One suggestion was to create an AI agent that regularly conducts a digital background check, searching for publicly available information about a journalist and flagging new vulnerabilities as they emerge. In principle, such a system could make the self-doxxing exercise much easier: rather than conducting a manual check every few months, an AI agent could continuously monitor the digital footprint.
But the idea immediately raises a difficult paradox: how much privacy are we willing to sacrifice in order to protect our privacy?
An AI agent designed to find everything publicly available about us would, by definition, need to collect and process a considerable amount of information about us. Where would that information be stored? Who would have access to it? Could the data collected by such a system itself become a new vulnerability? And could information gathered by the agent subsequently be used to train AI models?
There was another question too: what is the environmental cost? If journalists begin relying on AI agents to continuously search, analyse and monitor their digital footprints, could the additional computing and energy consumption contribute, however indirectly, to the climate crisis?
The conversation left participants with a useful tension at the heart of the workshop. AI may become an increasingly powerful tool for journalists trying to understand and protect their digital footprint. But the tools we use to protect ourselves also need to be scrutinised. Security, privacy and sustainability cannot necessarily be treated as separate questions — particularly when the technology doing the protecting is itself capable of collecting vast amounts of personal data.


And perhaps that was the most interesting discussion to end on: how do we use AI to make journalists safer without creating a new set of vulnerabilities in the process?
Visit the UNCOVERED 2026 microsite for more information about the conference.
Useful links and resources:
- Mapping key disinformation narratives against the media
The Observatory of Disinformation Narratives against the Media monitors key disinformation narratives targeting journalists and fact-checkers in Europe. It seeks to expose how spreaders of disinformation use these narratives to discredit journalists’ work and serve their own agendas. - Measures for Newsrooms and Journalists to Address Online Harassment: IPI’s Ontheline Platform