Skip to main content
The Wire
CyberNews by Zentrya One
Security

πŸ”Ž How Do They Find It?

OSINT FILES β€” 02/05

In the previous episode, we explored a simple but important question: How much does the internet know about you?

We looked at how information such as your name, workplace, job title, photographs, social media activity and professional connections can collectively reveal a surprisingly detailed picture of your digital identity.

But this leads to another question: If someone knows only your name, how can they discover so much about you? The answer is surprisingly simple. They search, compare and connect.

🌐 It Starts With One Piece of Information

Imagine that someone knows only your name. They search for it online and discover a professional profile showing where you work. That leads them to your organization's website, where they may find your job title or department. A social media profile may reveal your interests, professional connections or recent activities. A public photograph may show where you were, while another online profile may connect the same username to a different platform. Individually, these details may not appear particularly important. However, when they are connected together, they can create a much clearer picture of who you are, what you do and who you interact with.

🧩 One Clue Leads to Another

Think of it like putting together a puzzle. A person's name can lead to their workplace. Their workplace can reveal their job role. Their job role can identify colleagues or departments. Those colleagues may lead to social media profiles, photographs, events or other publicly available information.

Name β†’ Workplace β†’ Job Role β†’ Colleagues β†’ Social Media β†’ Interests β†’ Locations

No single piece necessarily tells the whole story. But when several pieces are connected, they can reveal considerably more than each piece would reveal on its own.

This is one of the fundamental ideas behind Open-Source Intelligence, or OSINT. It is not simply about finding information. It is about finding, comparing, analysing and connecting information that is already publicly available to understand what that information reveals.

πŸ” Where Can Information Come From?

Publicly available information can exist across many different parts of the internet. It may come from websites, professional networking platforms, social media accounts, news articles, public documents, photographs, videos, company websites, event pages, public announcements and search engines. Sometimes people publish the information themselves. Sometimes organizations publish it as part of their normal activities. In other cases, information may be shared by colleagues, friends, event organizers or media organizations.
Another important factor is time. Something that was posted several years ago may still be searchable today. An old photograph, a previous job announcement, an outdated professional profile or an old social media post may continue to contribute to someone's digital footprint long after the person has stopped thinking about it.

πŸ”— The Power Is in the Connection

Consider a simple example. A public company website identifies David as a Finance Manager. A professional profile identifies several people working within the same department. A public social media post shows David attending a company event with Sarah, another employee. Another publicly available source reveals the organization's email format.

None of these discoveries necessarily provides direct access to a company's systems.

However, together they provide something extremely useful to an attacker: context.

The attacker now has a better understanding of who David is, who Sarah is, where they work and how they may be connected. That information could potentially be used to create a more convincing phishing message or impersonation attempt. The attacker may not need to know everything about the organization. They may only need enough information to make a message appear believable.

This is why the first stage of an attack is not always a malicious link, malware or stolen password.

Sometimes, it starts with a search.

⚠️ Why Should You Care?

OSINT itself is not malicious. Cybersecurity professionals use publicly available information for security assessments, threat intelligence, reconnaissance, incident investigations and exposure assessments. Journalists, researchers and investigators may also use OSINT for legitimate purposes.

However, attackers can use many of the same sources and techniques to understand their potential targets. The more information they can connect, the easier it may become to create a convincing phishing message, impersonation attempt or social engineering scam.

Imagine receiving a message saying:

"Hi, I'm from your company's IT team. We noticed an issue with your account..."

A generic message might immediately appear suspicious. But imagine that the sender already knows your name, workplace, department or the name of someone you work with. The message may suddenly feel much more legitimate.

The attacker did not necessarily gain access to your organization first.

They may have researched it first.

πŸ•΅οΈ Searching Is Only the Beginning

Search engines are often one of the first places people look for publicly available information. A simple search for a person's name, organization or username can sometimes reveal professional profiles, old posts, photographs, news reports, public documents and other references.

Cybersecurity professionals can use this information during reconnaissance to understand what an organization or individual is publicly exposing. The objective is not to collect information simply because it exists. The real objective is to determine whether any of that information could create a security risk if misused.

This is why understanding your public digital footprint can be an important part of cybersecurity awareness.

πŸ›‘οΈ The Lesson

The answer is not to stop using social media or disappear from the internet. Being visible online is a normal part of modern professional and personal life. The important thing is to understand what information you are making available and how those individual pieces could be connected.

Before publishing something publicly, take a moment to consider what it could reveal. Could someone identify where you work? Could they identify your colleagues? Could they understand your professional responsibilities? Could they determine places you recently visited? Could the information make a future impersonation or phishing attempt more convincing?

One piece of information may seem harmless.

Several connected pieces can tell a very different story.

πŸ‘€ Try Looking at Yourself

There is a simple way to understand the concept. Search for your own name online and look at the results from the perspective of someone who has never met you. What could they learn? Could they identify where you work? Could they connect your different social media accounts? Could they identify your colleagues, interests or publicly shared locations?

You might be surprised by how much information is already visible.

And that is the central lesson of OSINT.

Your information may be public. Your security doesn't have to be.

🚨 OSINT FILES β€” 02/05

NEXT: HOW DO ATTACKERS USE OSINT? 🎣

In Episode 03, we move from discovery to exploitation and explore how publicly available information can be used in phishing, impersonation and social engineering attacks.
Because sometimes, the most convincing attack isn't built with sophisticated technology.
It's built with information.

All parts of this series

  1. 01 How Much Does the Internet Know About You?
  2. 02 πŸ”Ž How Do They Find It?You are here
Filed by Zentrya One Desk Β· CyberNews desk  Β·  Follow Zentrya One on LinkedIn
The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.