In July, the New York City Department of Finance published a supplemental market value roll as part of the implementation of the city's new non-primary residence property surcharge. The surcharge is an annual tax on certain high-value homes that are not used as their owners' primary residences. The roll covers a broad universe of residential properties, including single-family homes, condominiums, and cooperative units, although city officials have emphasized that most listed properties will ultimately not be subject to the surcharge.
The publication quickly drew attention for reasons extending beyond tax policy and has become the subject of legal challenge. Regardless of how these debates are resolved, the episode illustrates a broader reality: once information has been published, copied and circulated, it cannot be totally recalled. By linking named individuals to residential addresses, disclosures like this create unintended, long-term exposure in an environment of heightened political polarization, declining trust in institutions and increasingly personalized grievance.
The problem isn't that the information is searchable
For most people, a disclosure of this kind is unremarkable, entirely legitimate and even useful: a basis for advocacy, lawful protest or debate about how wealth is taxed.
The concern is not necessarily disclosure itself. It is that this government-generated list links a group of individuals, defined by their wealth, with their residential addresses. The roll makes this information easier to access and act upon at a time when grievances are becoming more personal and public anger is increasingly directed at individuals.
Three immediate pathways to harm
The significance becomes concrete when you consider how such a disclosure can be used. It creates three immediate risks:
- Physical exposure. It reveals residential locations, including homes that may sit vacant for extended periods.
- Fraud and impersonation. It enables false tax notices, payment demands, removal schemes and pretext calls, trading on the credibility of an "official" list.
- Downstream amplification. People-search sites and data brokers ingest, enrich and redistribute the information. This can weaken the privacy created by an LLC, trust or family-member ownership structure by reconnecting an entity to a physical address.
Misidentification makes this worse, not better. The roll includes, but is not limited to, properties that may be subject to the surcharge, and exemptions may apply. But an inaccurate entry still creates a durable public profile. To a bad actor, the label does not need to be correct for the name and address to be useful.
A threat environment transformed by aggregation and grievance
Twenty years ago, locating a high-net-worth individual and connecting them to a home took time and specialist effort. Today, public records can be combined with social media, corporate disclosures, data-broker information and AI-enabled search tools in minutes. Information that looks innocuous in isolation becomes operationally useful once aggregated.
This is unfolding against a backdrop of declining institutional trust, economic pressure and grievance-based mobilisation. In what Control Risks describes as "activated societies," some view governments as captured, business as unaccountable and prominent individuals as symbols of an unjust system. As a result, a single disclosure can be amplified through viral content and affinity networks faster than conventional security planning can react.
The overwhelming majority of criticism and protest remains lawful. The concern lies with the small subset for whom public grievance becomes personal, target-focused and self-authorising. For these people, a name joined to an address is all the starting point they need. Fragmented online communities complicate detection: hostile rhetoric and misinformation create noise, while the rapid circulation of violent acts and perpetrator narratives can offer scripts, validation or notoriety to susceptible individuals.
An evolving attacker profile
Recent targeted attacks raise questions about whether some attacker behaviours are changing, though the available cases do not yet establish a settled typology or a clean break from earlier patterns. With that caution in mind, some contemporary attackers have appeared less resigned to dying or being captured, more willing to confront visible security, more focused on a named leader than an institution, and more deliberate about concealment and escape.
These are observations to inform planning, not assumptions to apply to every person of concern. But they matter, because an offender who intends to survive and escape changes the calculus for protection, response and law enforcement coordination.
The vigilante lens
One useful way to understand this shift is the longstanding concept of the vigilante: someone who believes the social order is under threat and that established institutions are unwilling or unable to hold those responsible to account.
This motivation is not tied to a single ideology. It can emerge when a person adopts a morally absolute grievance, identifies an individual or group as responsible, and comes to regard unilateral action as legitimate justice. Relevant features may include a need for recognition, black-and-white moral reasoning, limited empathy and sustained fixation.
What makes these individuals especially difficult to spot is that the act itself can give them the sense of control or moral worth they're seeking, so they may never seek a group's approval or telegraph their intent. Nor do they need a personal connection to the grievance; they can adopt someone else's cause and cast themselves as the one to answer it.
This is a lens, not a label. Moral outrage or activism alone does not establish a threat. Its value is in showing how grievance, fixation, perceived institutional failure, target selection, preparation and self-authorised action can come together on the path towards violence.
From symbol to target
Target selection makes the security significance clearer. Executives, investors, investor conferences, board members and wealthy property owners are rarely singled out for personal reasons. They are chosen as symbols, representatives of a system someone holds responsible. And once a name is tied to an address, the gap between symbolic hostility and a physical approach narrows, pulling family, staff and neighbours into the exposure too.
The real question
Information that is harmless in isolation can take on new significance once it is consolidated, easily searchable and attached to emotionally charged grievances. For those affected, the priority now is to understand the exposure it creates and to assess what it means for them.
That starts with a clear-eyed view of the risk: what a motivated outsider can actually discover, how that information could be used and who around the principal might be drawn in. From there, exposure can be reduced, monitored and managed, well before elevated attention becomes a security concern. In Part 2, we set out what individuals, families and organisations can do about it.
Turn exposure into a managed risk. Control Risks helps individuals, family offices and organisations understand what they are exposed to, reduce unnecessary discoverability, and build the monitoring, assessment and response capabilities to stay ahead of emerging threats.
Explore your risk and options with a threat management expert or email [email protected]
This is Part 1 of a two-part series. Part 2 sets out what individuals, family offices and organisations can do to manage the risk.