OSINT (Open Source Intelligence)
Gathering information from publicly available sources — search engines, public records, social media, breach-notification services — rather than hacking or stealing anything. A breach checker like Have I Been Pwned is OSINT. A site that sells you the actual leaked passwords is not OSINT, it's trafficking in stolen data. A huge amount of "hacker tool" content online blurs "checks if you were exposed" together with "lets you access what was stolen." They're not the same thing legally or ethically, and knowing the difference is the whole skill.
Older than the term
"OSINT" as a phrase is generally traced to the US military and intelligence community, gaining common use through the late 1980s and early 1990s.[1] The practice it names is much older than the name itself — military intelligence services have drawn on newspapers, journals, press clippings, and public radio broadcasts for generations, and both sides of the American Civil War openly read each other's newspapers for troop movements and supply information. What changed with the internet wasn't the concept, it was the volume and speed: a technique that used to mean waiting for tomorrow's paper now means a public social media post can be geolocated and cross-referenced within minutes of going live.
A real investigation, not a hypothetical
In 2014, the volunteer-run investigative outlet Bellingcat took on the downing of Malaysia Airlines Flight 17 over eastern Ukraine using nothing but open sources: photos and videos posted publicly online, satellite imagery, and mapping tools like Google Earth. By cross-referencing the visible background of a video showing a Buk missile launcher on a flatbed truck — specific buildings, road markings, terrain — against satellite imagery, the team traced its route back to a Russian military base near Kursk.[2] Four years later, in 2018, the Dutch-led international Joint Investigation Team's own official findings confirmed the same conclusion Bellingcat had reached with public information alone, before any government investigation had concluded.[3] It's one of the clearest demonstrations that OSINT isn't a lesser, amateur version of "real" intelligence work — done rigorously, it can out-pace agencies with classified resources, because the constraint was never access, it was whether anyone put in the work to actually cross-reference what was already public.
A rough version of the actual method
Professional OSINT work generally follows something like the intelligence cycle: define what you're actually trying to find out, collect from multiple independent public sources, cross-reference and corroborate rather than trusting any single source, and only then draw a conclusion — explicitly flagging what's confirmed versus what's merely plausible. The corroboration step is the one amateur "internet detective" efforts skip most often, and it's the one that turns a plausible-looking coincidence into either a real finding or a debunked one — the same corroboration gap that undoes most amateur attempts at reverse-image verification too.
Where the legal and ethical line actually sits
Looking up what's already public is generally legal — it's the digital equivalent of reading a published newspaper. The line moves once a method stops being "look at what's already visible" and starts being "get access to something that wasn't meant to be visible": logging into an account that isn't yours, using a leaked-credential database to test other accounts, or treating Google Dorking's results (technically public, functionally exposed by accident) as an invitation rather than a finding to report responsibly. Most OSINT tools are ethically neutral — a reverse image search doesn't care whether you're debunking a hoax or stalking someone — which is exactly why the intent and the target matter more than the tool.
See also
- Google Dorking
- Reverse Image Search & Metadata
- Browser Fingerprinting
- Digital Preservation & Link Rot — the archived-page side of the same verification habit