- by x32x01 ||
Imagine someone knows your full name, phone number, workplace, and other personal details. Then they call you and say, "I know things about you that you never told me."
They show you old photos, mention details about your apartment, and somehow know what you ordered from a restaurant a few minutes ago.
Your first question would probably be: How did they get all of this information?
This is where two important cybersecurity terms come into the picture: OSINT and Doxxing.
They can sometimes involve similar types of information, but they are not the same thing. OSINT is a legitimate research method when used responsibly, while doxxing involves exposing someone's private or sensitive information, often with harmful intent.
Security teams, threat intelligence researchers, journalists, investigators, and cybersecurity professionals can use OSINT to understand people, organizations, websites, online accounts, and potential threats.
For example, imagine a company discovers a Telegram account claiming that it has stolen the company's data.
Before assuming that the claim is real, a threat intelligence team may investigate the account using publicly available information.
They might examine:
For example, if an account uses the username
The goal is not simply to collect as much information as possible. The goal is to connect relevant public information and determine what it actually means.
A threat intelligence team may eventually determine that the person behind an account is connected to a particular identity or organization. If the investigation is conducted properly, the findings can be documented in a report and provided to the appropriate authorities or internal security teams.
That is a legitimate use of OSINT.
OSINT focuses on collecting and analyzing publicly available information for legitimate purposes such as security research, threat intelligence, journalism, investigations, or risk assessment.
Doxxing involves exposing or publishing personal or sensitive information about an individual without their consent, especially when the disclosure is intended to harass, threaten, intimidate, expose, or otherwise harm them.
In other words, finding information and publishing someone's private information are two very different actions.
Depending on the situation, the information may include:
The attacker may then combine these pieces of information to create a detailed profile of the victim.
It is the combination of multiple pieces of information.
For example, knowing someone's name alone may not be particularly dangerous. But combining their name with their workplace, phone number, home address, family members, and daily routines can create a much more serious privacy and safety risk.
An attacker may use this information for:
That is not always true.
Personal information can come from many different sources, including:
This is one reason information security and privacy are closely connected.
The same publicly available information can be used by a security researcher to investigate a threat or by an attacker to identify a target.
The difference is the purpose, authorization, and way the information is handled.
For example, a security team may investigate a suspicious account to determine whether it is connected to a real threat.
That investigation can help an organization:
An attacker might tell a victim that they have collected personal information and threaten to publish it unless the victim pays money or does something demanded by the attacker.
This creates a serious situation because the attacker may use information from multiple sources to make the threat appear more convincing.
For example, knowing someone's workplace or an old photograph does not necessarily mean the attacker has compromised their current accounts.
Attackers may deliberately combine public information with leaked information to make their access appear much greater than it actually is.
Start with these basic steps:
The goal is to reduce the amount of information that can be connected to you and misused.
The important distinction is simple: OSINT is a research methodology, while doxxing is the harmful exposure of someone's personal information.
Not every OSINT investigation is doxxing, and simply finding publicly available information does not automatically make someone a doxxer.
What matters is the context, purpose, authorization, and how the information is handled.
They show you old photos, mention details about your apartment, and somehow know what you ordered from a restaurant a few minutes ago.
Your first question would probably be: How did they get all of this information?
This is where two important cybersecurity terms come into the picture: OSINT and Doxxing.
They can sometimes involve similar types of information, but they are not the same thing. OSINT is a legitimate research method when used responsibly, while doxxing involves exposing someone's private or sensitive information, often with harmful intent.
What Is OSINT?
OSINT stands for Open-Source Intelligence. It is the process of collecting and analyzing information that is publicly available.Security teams, threat intelligence researchers, journalists, investigators, and cybersecurity professionals can use OSINT to understand people, organizations, websites, online accounts, and potential threats.
For example, imagine a company discovers a Telegram account claiming that it has stolen the company's data.
Before assuming that the claim is real, a threat intelligence team may investigate the account using publicly available information.
They might examine:
- The username and its presence across public websites.
- Public social media profiles.
- Previous posts and activity.
- Publicly shared files or links.
- The history of the account's online presence.
- Whether previous claims appear credible.
- Connections between publicly available pieces of information.
For example, if an account uses the username
0xHamada, researchers might check whether that username appears on other publicly accessible platforms.The goal is not simply to collect as much information as possible. The goal is to connect relevant public information and determine what it actually means.
A threat intelligence team may eventually determine that the person behind an account is connected to a particular identity or organization. If the investigation is conducted properly, the findings can be documented in a report and provided to the appropriate authorities or internal security teams.
That is a legitimate use of OSINT.
OSINT Is Not the Same as Doxxing
The key difference is what happens with the information and why it is being collected.OSINT focuses on collecting and analyzing publicly available information for legitimate purposes such as security research, threat intelligence, journalism, investigations, or risk assessment.
Doxxing involves exposing or publishing personal or sensitive information about an individual without their consent, especially when the disclosure is intended to harass, threaten, intimidate, expose, or otherwise harm them.
In other words, finding information and publishing someone's private information are two very different actions.
What Is Doxxing?
Doxxing, sometimes written as "doxing," refers to the malicious or harmful exposure of someone's personal information online.Depending on the situation, the information may include:
- Full name.
- Phone number.
- Home address.
- Workplace.
- Personal photographs.
- Email addresses.
- Family information.
- Other identifying or sensitive details.
The attacker may then combine these pieces of information to create a detailed profile of the victim.
How Can Doxxing Become Dangerous?
The real danger is often not a single piece of information.It is the combination of multiple pieces of information.
For example, knowing someone's name alone may not be particularly dangerous. But combining their name with their workplace, phone number, home address, family members, and daily routines can create a much more serious privacy and safety risk.
An attacker may use this information for:
- Harassment.
- Threats and intimidation.
- Identity-related attacks.
- Social engineering.
- Blackmail or extortion.
- Targeted phishing.
- Stalking.
- Reputation damage.
Where Can Personal Information Come From?
A common misconception is that attackers must use the dark web to obtain detailed information.That is not always true.
Personal information can come from many different sources, including:
- Public social media profiles.
- Previously leaked databases.
- Data breaches.
- Public records.
- Data broker services.
- Exposed accounts.
- Previously published documents.
- Information shared across different websites.
This is one reason information security and privacy are closely connected.
Why OSINT Can Be Used for Good or Bad
OSINT itself is not inherently malicious.The same publicly available information can be used by a security researcher to investigate a threat or by an attacker to identify a target.
The difference is the purpose, authorization, and way the information is handled.
For example, a security team may investigate a suspicious account to determine whether it is connected to a real threat.
That investigation can help an organization:
- Identify potential threats.
- Verify suspicious claims.
- Understand an attacker's infrastructure.
- Detect exposed information.
- Improve security controls.
- Provide evidence to the appropriate authorities.
Doxxing and Digital Extortion
Doxxing can become even more dangerous when it is combined with digital extortion.An attacker might tell a victim that they have collected personal information and threaten to publish it unless the victim pays money or does something demanded by the attacker.
This creates a serious situation because the attacker may use information from multiple sources to make the threat appear more convincing.
For example, knowing someone's workplace or an old photograph does not necessarily mean the attacker has compromised their current accounts.
Attackers may deliberately combine public information with leaked information to make their access appear much greater than it actually is.
How to Protect Yourself From Doxxing
You cannot always prevent your information from appearing online, but you can make it harder for someone to build a detailed profile about you.Start with these basic steps:
- Review the privacy settings on your social media accounts.
- Avoid publicly sharing your home address, phone number, or other sensitive information.
- Use strong and unique passwords for important accounts.
- Enable multi-factor authentication whenever possible.
- Be careful about what information you reveal through public posts and photos.
- Review old accounts and remove information you no longer need to expose.
- Be cautious about suspicious messages requesting personal information.
- Monitor your accounts for unusual activity.
- If your personal information is exposed, document what was published and report it to the relevant platform or authorities.
The goal is to reduce the amount of information that can be connected to you and misused.
The Difference Between OSINT and Doxxing
| OSINT | Doxxing |
|---|---|
| Collects and analyzes publicly available information | Exposes personal or sensitive information |
| Can be used for legitimate security research | Often used to harm, threaten, or harass someone |
| Used by security teams, researchers, and investigators | Commonly associated with abuse and targeted harassment |
| Focuses on research and intelligence | Focuses on exposing information about a person |
| Should follow legal and ethical boundaries | Can create serious privacy and safety risks |
Not every OSINT investigation is doxxing, and simply finding publicly available information does not automatically make someone a doxxer.
What matters is the context, purpose, authorization, and how the information is handled.
