OSINT

OSINT

OSINT stands for "Open Source Intelligence" and refers to the systematic analysis of publicly accessible information, such as websites, social media posts, satellite imagery, or corporate registries. From many individually harmless pieces of information, an overall picture emerges that no one had before.

OSINT is short for “Open Source Intelligence,” meaning roughly “insights from open sources.” What’s meant is everything that anyone can legally view: news articles, government data, photos on Instagram, flight-tracking websites, trade registers, satellite images. No one hacks into a system for this, and no one is secretly handed documents. The work isn’t in obtaining the information but in connecting it. Anyone who combines a vacation photo with a street sign, a timestamp, and a map service suddenly knows where a person was on a particular day. Incidentally, the term “open source” has nothing to do with free software here; it simply means “openly accessible source.”

Why open sources reveal more today than they used to

Thirty years ago, intelligence gathering was almost always secret. Anyone wanting to know whether a factory was producing needed a spy or a spy satellite image. Today, companies publish supply chains online, employees post pictures from factory grounds, and commercial satellite imagery costs very little. The bottleneck has shifted: data exists in abundance, and what’s scarce is the time to sort through it.

That’s why OSINT has long ceased to be a niche topic for intelligence agencies. Journalists use videos from war zones to prove where a rocket struck. Banks check whether a business partner appears on a sanctions list. IT departments search for which of their own company’s servers are accidentally reachable from the internet. Stock market analysts count cars in retail chain parking lots to estimate revenue.

The flip side: the same methods work against private individuals. Stalking, extortion, and targeted scam emails often begin with an OSINT investigation into the victim. Being legal doesn’t automatically make research harmless, and data protection rules also apply to publicly findable data.

From puzzle piece to solid finding

A good OSINT investigation proceeds in steps. First, one defines the question, because without a clear question one collects endlessly. Then sources are searched for, saved as a copy or screenshot, and noted with when and where they were found. Next comes comparison: do shadows, weather, language, and license plates match the claimed time and location? Only at the end comes the assessment of how certain the finding is.

Two techniques come up constantly. With reverse image search, one uploads an image and lets a search engine look for other instances of the same image. This is how old photos passed off as current are identified. With geolocation, one determines the location of a shot using details in the image, such as mountain silhouettes, billboards, or the design of streetlamps.

Artificial intelligence comes into play at two points here. Language models — programs that understand and generate text — summarize and translate thousands of posts. Image recognition sorts photos by objects or faces. This speeds up the work enormously but also produces false hits. Experts call it hallucination when a language model freely invents a plausible-sounding claim. Without verification against the original source, an AI result is therefore not proof.

OSINT in the news, in products, and in your own profile

OSINT is most visible in journalism. Investigative groups like Bellingcat have used open sources to reconstruct the shooting down of flight MH17 over Ukraine, based solely on videos, photos, and social media traces. Newsrooms work similarly when debunking false reports or tracing movements of refugees.

Commercially, an entire market has emerged. There is software that probes company networks from an outside perspective, tools for monitoring brand abuse, and platforms for sanctions and anti-money-laundering checks. In job postings, OSINT shows up at security agencies, insurance companies, and consultancies. When tech news talks about “threat intelligence” — that is, knowledge about attackers — OSINT is often behind it.

You can also encounter the topic as someone affected by it. HR departments google applicants; attackers read company websites in order to forge emails in the boss’s name. A simple self-test: search your own name, usernames, and old email addresses and see what matches up. Precisely these connections are the raw material of OSINT.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.