December 23, 2022By TozettaCybercrime

How Do Criminals Use OSINT?

How do criminals use OSINT? Learn how they gather information about targets and carry out targeted attacks and threats.

Before we tell you how criminals use OSINT, let's first explain a bit more about what OSINT actually is. OSINT stands for Open Source Intelligence. It's the gathering of data from public sources. If you want to know more about OSINT and exactly what it is, first read our blog about what is OSINT?

How do criminals use OSINT?

Criminals use OSINT to gather information about their targets. They can use this information to determine where their targets live, what their financial situation is, and what security measures they've taken. With this information, criminals can determine the best way to carry out their (cyber)attack. Don't be mistaken โ€” OSINT is applied to both private individuals and organizations.

How does OSINT work?

OSINT is fundamentally very simple โ€” I'd even dare say almost everyone reading this blog has used OSINT themselves at some point. OSINT is nothing more than consulting public sources. So if you look up an old classmate on, say, Facebook or LinkedIn, you're already carrying out an OSINT investigation!

Why do criminals use OSINT?

Cybercriminals use OSINT to gather information about people or businesses they want to threaten or blackmail. There are countless ways cybercriminals can misuse your public information. They can steal your photos, create a fake profile, and use it to scam people. They can use the information on your profile to crack your password. The possibilities are endless....

Criminals don't just use OSINT to carry out criminal activities against individuals โ€” they also use it to gather information about businesses they want to attack. With this information, they can determine where the businesses are located, what their security measures are, what their financial situation is, and what their valuable assets are. This allows hackers to target a business with a precise attack.

What can you do about this?

Awareness, awareness, awareness... Employees and people who use the internet need to be aware of the online risks. Nowadays, there are so many different forms of cybercrime. Think of phishing, smishing, and other forms of social engineering that trick people. The input for these various forms of cybercrime is often an OSINT investigation carried out by cybercriminals.

If employees are aware of the risks that come with sharing information online, they'll pay closer attention the next time before sharing privacy-sensitive information.

For example, have employees conduct an OSINT investigation into themselves โ€” what can they find out about themselves? An OSINT investigation sounds complicated, but start by simply consulting Google, Bing, or other search engines.

Cyber Security Awareness Training

During a cyber security awareness training at Tozetta, we give the client the opportunity to communicate many content-related wishes and requirements. Think of zooming in on the topic of OSINT and actively carrying out exercises with employees, in order to raise awareness around cybercrime and cyber security!

Curious? Read more about our cyber security awareness training!

Related articles