
The term self-disclosure refers to the process by which a person shares personal information about themselves. Self-disclosure is a fundamental component of human relationships: sharing personal information helps build trust, strengthen bonds, and maintain social relationships.
With the shift from offline to online – and in particular with the rise of social media – the nature of self-disclosure has changed significantly.
Several studies1 have shown that, due to the perception of distance and anonymity, people tend to reveal more personal information online than in face-to-face interactions. Furthermore, digital self-disclosure occurs in many forms: sharing photos, places visited, opinions, relationship statuses, emotions, but also highly sensitive information such as health or financial data.
This combination – greater amount of information and greater variety of data shared – has significantly increased people’s vulnerability to risks such as identity theft, profiling, and data use for fraudulent purposes.
Forms of online self-disclosure
In the digital context we can distinguish three main types of self-disclosure.
Active self-disclosure occurs when a person voluntarily shares content that reveals personal information: posts, comments, stories, images, check-ins, but also participation in quizzes, surveys, or online discussions.
Alongside this, there is passive self-disclosure , which occurs when the user consents – often implicitly – to the collection and processing of their behavioral data by digital platforms, apps, news sites, chatbots, and other online services. In this case, the information is not communicated directly, but rather inferred from the user’s behavior.
Finally, we there is involuntary self-disclosure, which concerns the unintentional revelation of personal information as a result of deception (such as phishing or social engineering), security breaches, or cyberattacks on digital devices and services.
Exploitation of personal data
One of the most critical aspects of active self-disclosure, especially on social media, is that the data shared can be collected and analyzed through AI data mining techniques .
This information is processed by artificial intelligence systems for analysis, prediction, and decision-making purposes. For cybercriminals, this means they can select targets more quickly and accurately, including assessing the likelihood of a person becoming a victim.
By combining AI scraping and AI analysis , it’s possible to build psychological profiles based on personality models, which can be used to identify individuals most vulnerable to specific types of scams. Specifically, these profiles are exploited in social engineering activities to personalize interactions and build trust.
In long-term scams, continuously updating data also allows for the identification of the most opportune moment for the scam to take place, based on the victim’s vulnerabilities in real time.
Another risk associated with active self-disclosure is identity theft . The collected information can be used to impersonate a real person, including through the creation of deepfakes, and target other victims by leveraging existing relationships of trust.
Passive and involuntary self-disclosure
Passive self-disclosure, when users agree to platforms sharing information with third parties, allows for increasingly effective targeting, particularly for scams using targeted advertising or sponsored content on social media.
Feedback provided to chatbots and language-model-based services also contributes to the training and improvement of AI systems, which become progressively more effective for both legitimate and illicit uses.
Data obtained through involuntary self-disclosure can be directly used for criminal activities such as account takeovers, identity theft, and cyber fraud. Today, as highlighted by several European reports, personal data is no longer simply a target or a tool, but has become a true commodity , exchanged and reused within the digital criminal economy.
A look beyond
Understanding how and why we share personal information online is crucial to understanding many of the dynamics of contemporary cybercrime. Even when people claim to value privacy, their digital behavior often follows a different logic. This apparent contradiction will be explored in an article dedicated to the Privacy Paradox .
Further reading
If you want to go a little deeper into some of the topics mentioned:
Self-disclosure and digital privacy awareness:
A study of how college students perceive and manage personal information sharing online.
👉 https://dx.doi.org/10.47772/IJRISS.2024.8100255
Self-disclosure and social media:
Why we share so much online and what psychological mechanisms drive this behavior.
👉 https://doi.org/10.1016/j.copsyc.2019.08.019
Personality and Victimization in Cybercrime:
How Certain Personality Traits Can Influence the Risk of Being a Victim of Cybercrime.
👉 https://doi.org/10.1089/cyber.2017.0028
Personal data as a commodity in cybercrime:
A Europol report on how stolen data is traded and reused in the digital criminal economy.
👉 https://www.europol.europa.eu/publication-events/main-reports/steal-deal-and-repeat-how-cybercriminals-trade-and-exploit-your-data
What is credential stuffing?
An automated attack that uses stolen credentials to gain access to victims’ accounts.
👉 https://www.fortinet.com/resources/cyberglossary/credential-stuffing
- M. Luo and J.T. Hancock,
Self-disclosure and social media: Motivations, mechanisms and psychological well-being , in
Current Opinion in Psychology , vol. 31, 2020, pp. 110–115, https://doi.org/10.101/10.1016/j.copsyc.2019.08.019 ↩︎