Short answer: most of your online exposure comes not from hackers but from open-source research: public records, data brokers, old posts, and breach dumps stitched together. You can shrink that surface dramatically with a short list of high-impact moves. Stop using SMS for two-factor authentication (it is vulnerable to SIM-swapping), switch to an authenticator app or a hardware key, use an offline password manager, keep software updated, and clean up what is already out there. None of it requires being technical, and none of it requires fear. Below is the checklist I would give a friend, tool-specific, in priority order, plus an honest note on when a problem is past the DIY stage and needs professional help.
A quick word on why a private investigator is writing this: my day job includes finding people and information through lawful open-source research. Turning that lens around, showing you how you would look to someone doing the same to you, is the most useful privacy advice I can give.
What can someone actually find out about you online?
Before you defend anything, understand the attack. When I build a background picture on someone, the vast majority of it comes from OSINT, open-source intelligence, not hacking. The raw material is everywhere:
- Data brokers. Companies that aggregate and sell profiles: names, addresses, ages, relatives, phone numbers, sometimes far more.
- Public records. Property records, business registrations, court filings, professional licences.
- Social media. Not just what you post, but what you like, who you are tagged with, check-ins, and the friends-of-friends map.
- Old accounts and posts. Forums, reviews, and defunct profiles you forgot exist.
- Photo metadata. Images can carry GPS coordinates and device details unless stripped.
- Breach data. When a service you used gets breached, your email and, sometimes, passwords end up in dumps that are trivially searchable.
Individually, each item is minor. Stitched together, they become a detailed map of where you live, work, and go, who matters to you, and which of your passwords are already exposed. Reducing that map is what the rest of this checklist does.
What are the highest-impact steps to reduce your digital footprint?
Not everything matters equally. Start here.
- Check what is already exposed. Go to HaveIBeenPwned and enter your email addresses to see which breaches you are in. One rule: never enter a password you currently use into any checking site, only enter email addresses.
- Change any password that has been breached, and stop reusing passwords. Reuse is how a single old breach becomes a takeover of your important accounts. Every account gets its own long, unique password.
- Opt out of data brokers. Tedious but effective. Work through the major broker sites’ removal processes; it meaningfully thins your profile.
- Prune and lock down social media. Set profiles private, remove old posts and check-ins, and tighten who can see your friends and tags. Assume anything public is being read by the wrong person.
- Strip metadata from photos before posting, and turn off location tagging in your camera app.
If you only did these five, you would be ahead of most people.
Why should I stop using SMS for two-factor authentication?
This is the one I will say twice: do not use SMS text messages as your second factor. Two-factor authentication is essential, but the method matters enormously.
Here is the problem. SMS codes are tied to your phone number, and phone numbers can be stolen through SIM-swapping: an attacker convinces, or bribes, a carrier to move your number to their SIM, or exploits a port-out. Once they control your number, every SMS code flows to them, and they can walk into accounts you thought were protected. This is not theoretical. It is a routine, well-documented attack.
The fix is straightforward, in order of strength:
- Hardware security key (best): a physical key like a YubiKey. It is phishing-resistant, and there is no code to intercept. Use it on your most important accounts: email, password manager, banking.
- Authenticator app (very good): an app that generates time-based codes on your device. Far safer than SMS because nothing is sent over the phone network.
Move your important accounts off SMS to one of these. If a service only offers SMS, that tells you something about how seriously it takes your security.
How do I secure my accounts, phone, computer, and email?
Work outward from the accounts that would hurt most if lost.
- Use an offline password manager. Unique passwords for everything are only practical with a manager. I favour KeePassXC: it is open-source and keeps your vault as a local, offline file rather than in someone else’s cloud. Protect it with a strong master passphrase and a hardware key.
- Protect your email like it is the master key, because it is. Your email can reset every other account. Give it a hardware key, a unique password, and your full attention. For a privacy-respecting provider with end-to-end encryption, ProtonMail is a strong choice.
- Use a privacy-respecting browser. Firefox ships with sensible privacy defaults and strong tracker controls out of the box.
- Keep everything updated. Phone, computer, browser, apps: automatic updates are not nagging, they are free defence. A large share of real compromises exploit known flaws that a pending update would have closed.
- Lock your devices. Strong device passcodes, not a four-digit PIN, disk encryption on your computer, and a short auto-lock. If a device is lost or stolen, this is what stands between a thief and everything on it.
- Use a reputable VPN where it helps. A VPN like ProtonVPN hides your IP and protects traffic on untrusted networks such as public Wi-Fi. Be clear about what it does not do: it will not stop tracking tied to your logged-in accounts, and a sketchy free VPN can be worse than none. You are routing all your traffic through whoever runs it.
One practitioner detail people rarely hear: factory resets do not always clean a compromised device. Most malware is wiped by a proper reset, but some sophisticated malware persists below the operating system and survives it. If you have genuine reason to believe a device was deliberately targeted, not just caught ordinary malware, trusting a wipe is a mistake. Replace the device. I would rather a client buy a new phone than keep confiding in a compromised one.
When should I get professional help?
The whole checklist above is DIY. Most people never need more. But some situations are past the point of another app, and it is worth naming them honestly so you do not wait too long.
Get professional help when the threat is a specific person, not random crime:
- A stalker, ex, or someone who knows things they should not: your location, your plans, contents of private conversations.
- Signs of persistent compromise after you have done a thorough cleanup: accounts that keep getting accessed, a device that behaves as though it is monitored.
- A concern about hidden cameras, microphones, or trackers in your home, vehicle, or office.
Those situations call for specific disciplines: digital forensics to examine a device properly and preserve evidence lawfully (see our digital forensics service), or technical surveillance countermeasures (TSCM) to sweep a space for hidden devices (see technical surveillance countermeasures). If you want to go deeper on locking down communications specifically, our practical guide to PGP encryption covers it in detail. The line to remember is simple: if you feel targeted rather than merely at risk of ordinary crime, that is the moment to bring in someone who does this professionally.
The Ontario legal context, in one place
To keep the boundaries clear: the steps in this article are things you can lawfully do to protect yourself, checking your own breach exposure, hardening your own accounts and devices, and reducing your own footprint. If you engage a professional for digital forensics or a TSCM sweep, that work is done under Ontario’s licensing framework (the PSISA) and with respect for privacy law, including PIPEDA. A licensed investigator has no police powers or database access; what we bring is lawful method. Nothing here is a licence to surveil or access anyone else’s accounts or devices. That is where the criminal law, including the Criminal Code’s provisions on intercepting private communications, comes in.
Not legal advice
This article is general information about investigative practice in Ontario, not legal advice. Laws change and every situation is different. For advice about your specific circumstances, consult a licensed Ontario lawyer or contact a licensed investigator directly.
Frequently asked questions
What’s the single most important change I can make?
Stop using SMS text messages for two-factor authentication. Phone numbers can be hijacked through SIM-swapping, and an attacker who controls your number can intercept SMS codes and take over accounts. Move your two-factor codes to an authenticator app or, better, a hardware security key like a YubiKey. That one change closes off a large share of real-world account takeovers.
What can someone actually find out about me online?
More than most people expect, and usually without any hacking: just open-source research (OSINT). Public records, data-broker profiles, old forum posts, photo metadata, social media, breach dumps, and property or business filings can be stitched together into a detailed picture: where you live, work, and go, who you’re connected to, and passwords exposed in past breaches. The good news is that reducing that surface is mostly about a handful of high-impact steps.
Do I need a VPN?
A reputable VPN is useful for hiding your IP address and protecting traffic on untrusted networks like public Wi-Fi, and ProtonVPN is a solid choice. But a VPN is not privacy on its own: it doesn’t stop tracking tied to your accounts, it doesn’t fix reused passwords, and a shady "free" VPN can be worse than none. Treat it as one layer, not the whole solution.
If my device is infected, does a factory reset fix it?
Usually, but not always. Most malware is cleared by a proper reset, but some sophisticated malware can survive a factory reset by embedding below the operating system. If you have real reason to believe a device was targeted by someone capable, not just ordinary malware, the safest move is to replace the device and get professional help rather than trust a wipe.
When should I hire a professional instead of doing this myself?
Most people can do the whole checklist themselves. Get professional help when the threat is a specific person rather than random crime: a stalker or ex who seems to know things they shouldn’t, signs of persistent device compromise after you’ve cleaned up, or concerns about hidden recording or tracking devices. Those situations call for digital forensics or technical surveillance countermeasures, not another app.

