The term  self-disclosure refers to the process by which a person shares personal information about themselves. Self-disclosure is a fundamental component of human relationships: sharing personal information helps build trust, strengthen bonds, and maintain social relationships.

With the shift from offline to online – and in particular with the rise of social media – the nature of self-disclosure has changed significantly.

Several studies1 have shown that, due to the perception of distance and anonymity, people tend to reveal  more personal information online  than in face-to-face interactions. Furthermore, digital self-disclosure occurs in many forms: sharing photos, places visited, opinions, relationship statuses, emotions, but also highly sensitive information such as health or financial data.

This combination – greater amount of information and greater variety of data shared – has significantly increased people’s vulnerability to risks such as identity theft, profiling, and data use for fraudulent purposes.

Forms of online self-disclosure

In the digital context we can distinguish three main types of self-disclosure.

Active self-disclosure  occurs when a person voluntarily shares content that reveals personal information: posts, comments, stories, images, check-ins, but also participation in quizzes, surveys, or online discussions.

Alongside this, there is  passive self-disclosure , which occurs when the user consents – often implicitly – to the collection and processing of their behavioral data by digital platforms, apps, news sites, chatbots, and other online services. In this case, the information is not communicated directly, but rather inferred from the user’s behavior.

Finally, we there is  involuntary self-disclosure, which concerns the unintentional revelation of personal information as a result of deception (such as phishing or social engineering), security breaches, or cyberattacks on digital devices and services.

Exploitation of personal data

One of the most critical aspects of active self-disclosure, especially on social media, is that the data shared can be collected and analyzed through  AI data mining techniques .

This information is processed by artificial intelligence systems for analysis, prediction, and decision-making purposes. For cybercriminals, this means they can select targets more quickly and accurately, including assessing the likelihood of a person becoming a victim.

By combining  AI scraping  and  AI analysis , it’s possible to build psychological profiles based on personality models, which can be used to identify individuals most vulnerable to specific types of scams. Specifically, these profiles are exploited in social engineering activities to personalize interactions and build trust.

In long-term scams, continuously updating data also allows for the identification of the most opportune moment for the scam to take place, based on the victim’s vulnerabilities in real time.

Another risk associated with active self-disclosure is  identity theft . The collected information can be used to impersonate a real person, including through the creation of deepfakes, and target other victims by leveraging existing relationships of trust.

Passive and involuntary self-disclosure

Passive self-disclosure, when users agree to platforms sharing information with third parties, allows for increasingly effective targeting, particularly for scams using targeted advertising or sponsored content on social media.

Feedback provided to chatbots and language-model-based services also contributes to the training and improvement of AI systems, which become progressively more effective for both legitimate and illicit uses.

Data obtained through  involuntary self-disclosure  can be directly used for criminal activities such as account takeovers, identity theft, and cyber fraud. Today, as highlighted by several European reports, personal data is no longer simply a target or a tool, but has become a true  commodity , exchanged and reused within the digital criminal economy.

A look beyond

Understanding how and why we share personal information online is crucial to understanding many of the dynamics of contemporary cybercrime. Even when people claim to value privacy, their digital behavior often follows a different logic. This apparent contradiction will be explored in an article dedicated to the  Privacy Paradox .

Further reading

If you want to go a little deeper into some of the topics mentioned:

Self-disclosure and digital privacy awareness:
A study of how college students perceive and manage personal information sharing online.
 👉 https://dx.doi.org/10.47772/IJRISS.2024.8100255

Self-disclosure and social media:
Why we share so much online and what psychological mechanisms drive this behavior.
👉  https://doi.org/10.1016/j.copsyc.2019.08.019

Personality and Victimization in Cybercrime:
How Certain Personality Traits Can Influence the Risk of Being a Victim of Cybercrime.
👉  https://doi.org/10.1089/cyber.2017.0028

Personal data as a commodity in cybercrime:
A Europol report on how stolen data is traded and reused in the digital criminal economy.
👉  https://www.europol.europa.eu/publication-events/main-reports/steal-deal-and-repeat-how-cybercriminals-trade-and-exploit-your-data

What is credential stuffing?
An automated attack that uses stolen credentials to gain access to victims’ accounts.
👉  https://www.fortinet.com/resources/cyberglossary/credential-stuffing


  1. M. Luo and J.T. Hancock,  
    Self-disclosure and social media: Motivations, mechanisms and psychological well-being , in  
    Current Opinion in Psychology , vol. 31, 2020, pp. 110–115, https://doi.org/10.101/10.1016/j.copsyc.2019.08.019 ↩︎