Glossary
What is doxing?
Doxing is the publication of someone's private information, such as a home address, phone number, workplace, or family details, without their consent and usually to enable harassment or intimidation. Evidence of doxing needs the original post plus the wider spread across mirrors, reposts, and screenshots before it disappears.
A doxing incident is rarely contained to a single post. The same private details typically spread to reposts, screenshots forwarded through chat apps, paste sites, forums, and search-engine snippets, often faster than any single removal request can keep pace with. Evidence work in a doxing matter has to capture that spread pattern deliberately: the earliest observed source, then outward to each mirror and repost, with its own timestamp and capture record, so a later reviewer can see how the exposure moved rather than just that it happened once.
The evidence file itself can become a secondary risk if it repeats the private details it is documenting. The practical answer is to keep original captures in restricted storage with logged, role-based access, and to build redacted working copies for anyone who does not need to see the raw private data, such as an intake coordinator triaging the matter. Redactions should be derivative copies that point back to an unredacted original, never silent edits to the source capture itself.
Finium's doxing workflow separates what was observed (the visible post and its spread), what was reported (client or witness context), and what is inferred (a suspected connection between accounts), so the affected person is not asked to repeatedly relive or re-collect the material themselves.