The Jerusalem PostTrump’s Gaza peace plan faces a bigger threat than a pre-election clash with Netanyahu - opinionESPN DeportesOhtani pasa a IL; Dodgers convocan a De Paulaוואלהבתום מצוד: לוחמי יחידת דובדבן עצרו מחבל שתכנן לבצע פיגוע יריESPN⚾ MLB Power Rankings: Which teams are rising? Which are falling?CNN TürkCNN TÜRK Tayvan'ın savunma sistemlerini görüntülediRTP Desporto18h30 A forma de Prestianni e o “efeito” PalhinhaPunchLagos-Ibadan expressway commuters lament as Kara-Berger bridge repairs trigger massive gridlockInquirerBrian Poe, Margarita Gutierrez share blessings before wedding dayBBC SportCricket: Today at the TestScreen RantSyfy's 5-Season Space Opera Is Everything Firefly Should Have BeenColliderCollider Media Studio Officially Returns to TIFF for a Star-Studded Weekend
The Daily Newsstand · Free, Always
Thursday, September 10, 2026

I'm a cyber security expert and a mother of four - these are the 5 things I'd never share about my own children online

Translate

It starts with an innocent baby photo – a proud mum broadcasting her newborn’s arrival to loved ones. But that single snap could be a ticking time bomb.

With every detail about your children you share online, whether through photos or otherwise, you could be opening them up to identity theft when they reach adulthood. So how do we protect ourselves and our children from deepfakes and identity theft online?

Izabella Stueflotten is a cyber security expert and mother of four. She says that ‘sharenting’ is handing dangerous cybercriminals the ultimate blueprint to hijack your child’s identity. From school updates to innocent birthday posts, millions of parents are unknowingly weaving a digital paper trail for automated bots scanning the web for personal data.

Stueflotten has taken the drastic step of completely wiping her children from social media, but says she realises that ‘isn’t for everyone’.

Izabella Stueflotten has now completely removed her children from her social media.

She says, ‘As an expat mum, living abroad for more than half of my life, I naturally want to share milestones and pictures of my children with my Swedish and Norwegian families, but this is rarely on social media.

‘By sharing a photo of your newborn baby, you are giving away crucial information about your child: their date of birth, gender and first name – possibly also their last name and place of birth. This might seem innocent enough, but really is just the start of a series of strands of information being gathered automatically by bots scanning the internet for exactly this type of information.’

Stueflotten, a VP of strategy at one of the world’s largest cyber security agencies, says that once the digital footprint has been laid, every uploaded picture adds to the ‘digital shadow’ of your child. More information is compiled and soon, a cybercriminal could know the name of their first pet, the name of their first school, their first car and many other personal security questions we all recognise from online banking checks.

She says, ‘The problem with this is that a threat actor can create a synthetic identity of your child – often referred to as automated doxxing, derived from the shortened word “docs” – long before they’re online. And bank account fraud won’t trigger until the child is 18.

‘Your child is the one who is facing the long-term consequences of having this digital footprint before they have even said their first words.’

So how do apparently harmless social media posts lead to becoming a victim of crime? Stueflotten says so-called threat actors follow digital trails using OSINT (Open-Source Intelligence) and piece together information from various sources to build a picture.

5 seemingly innocent ways you might be increasing your child’s risk of becoming a cybercrime victim

  • ‘Johnny is turning 7 today!’ = exact birth date
  • First school day post in school uniform = their school year and school, as well as their physical routine and location if you share pictures or videos of the school run
  • ‘We got a furry friend named Poppy that surprised Johnny this Christmas!’ = name and date of first pet
  • ‘My big boy bought his first car today after passing his licence!’ = name or type of first car (pet and car are often used as security questions)
  • ‘My baby got his first passport / first ID! Look how adorable’ = a direct key to taking over an entire ID

‘These breadcrumbs are then used together with all the facial markers of your child that have been gathered thanks to the thousands of photos you’ve uploaded to social media.’

Facial markers are also known as facial landmarks and are used to piece together a puzzle of a person’s face. They map the eyes, ears, nose, jawline and even mouth corners to help AI analyse facial structure and movement.

Sharing your milestones like your child's exact birth date online can create a dangerous breadcrumbs for hackers.

These facial markers can then be used for ‘face spoofing’ to create a fake digital version of a face, which can be used for face ID ‘presentation attacks’ or security validation.

While technology may not yet have reached the point of recreating 3D facial recognition such as Apple Face ID, it is already possible to fool 2D facial recognition software commonly found on Android phones by using a high-resolution photo.

Experts warn that many other traps exist in the online world that many of us don’t realise could compromise our cyber safety.

For example, when signing up to a new website, there will be a box to tick before you are allowed access, and most will click the T&Cs box without ever bothering to read them.

What follows can be years of seeing an email with an update to the T&Cs, where you are agreeing to them by continuing to use the platform. However, Stueflotten says we can be giving away more than we realise.

Meta owns Facebook, Instagram, WhatsApp and Ray-Ban Meta (smart glasses). Its terms and conditions include a clause: ‘you grant us a non-exclusive, transferable, sub-licensable, royalty-free and worldwide licence to host, use, distribute, modify, run, copy, publicly perform or display, translate and create derivative works of your content (consistent with your and settings). This means, for example, that if you share a photo on Facebook, you give us permission to store, copy and share it with others (again, consistent with your settings) such as Meta Products or service providers that support those products and services. This licence will end when your content is deleted from our systems.’

‘The implications can be severe because the default option is to opt in to various experimental features, such as the much criticised – and now removed – Muse Image tool that allowed Meta to use public Instagram profiles and pictures to create AI images of other people without their permission,’ says Stueflotten.

Opt in features can allow Meta to use public Instagram profiles and pictures to create AI images of other people without their permission.

‘If you knew that Meta were going to take photos that you published on Instagram and allow strangers worldwide to create, for example, adult AI versions of your child’s picture, would you have opted in?’

Any public profile photos or public albums can be ‘scraped’ to train AI models without explicit consent.

‘While parents legally still own their photos, the platform decides who gets to use them. It’s only when you remove the photos from the platform that the sharing of your content is stopped.’

5 ways to protect yourself and your child from online crime

1. Don’t share

Knowing the consequences, is it worth the risk? Don’t share that photo of your child. Start deleting photos of your children based on the identifying factors above.

2. Strip your photos of identifying data

If you are tech-savvy enough, at a minimum you should turn off location tagging and strip your photos of their metadata / EXIF data – the who, what, where and when information automatically uploaded with your photos – before uploading them to social media.

3. Remove identifying details

If you absolutely must share a photo, do it without any identifying details: no school logos, visible landmarks, street names or number plates, and never share your child’s passport or ID. Avoid posting on actual birthdays, if at all.

4. Check the T&Cs and privacy settings

Check T&Cs for image retention rules. For example, Meta deletes photos after you delete your account or the photo, but they might still be indexed by hundreds of other sites.

Check if the social media platform trains AI models. If it does, opt out of these settings on all platforms. Set all your accounts to strict private mode and routinely go through and delete older photos and inactive connections from your social media accounts.

5. Keep your accounts separate

Create a dummy email account with a false date of birth that you use only for social media accounts. Keep all social media accounts separate from your banking, NHS, HMRC, GOV.UK and school logins.

‘There are many more steps you can – and should – take, such as never reusing passwords or clicking on links that demand urgent action, but these are the five steps I would take today,’ she says.

‘Keeping your child’s personal digital identity safe is just as important as keeping their physical body safe from harm. Real harm can be done – financially, in terms of personal safety and reputationally.’

View the original on Daily Mail

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.