← All terms

OSINT (Open-Source Intelligence)

OSINT is intelligence gathered from publicly available sources. Attackers use it to research targets and build convincing social engineering pretexts.

OSINT — open-source intelligence — is information collected from publicly available sources: websites, social media, press releases, corporate filings, conference recordings, job postings, code repositories, and leaked databases. The term comes from the intelligence community, but in a security context OSINT is the reconnaissance phase of nearly every targeted social engineering attack. Before the first email is sent or the first call is made, the attacker already knows who reports to whom, who is traveling, which vendor just won a contract, and what the CEO sounds like.

How it works

Attackers assemble a target picture from fragments that are individually harmless. LinkedIn provides the org chart, job titles, and new joiners — ideal spear phishing targets who don't yet know internal norms. Press releases and earnings calls reveal deals, deadlines, and executive voices; conference videos and podcasts supply clean audio for deepfake voice cloning, a technique we break down in our guide to deepfake voice attacks on finance teams. Job postings expose the internal technology stack. Social media supplies personal details — hobbies, family names, travel plans — that make a pretexting call feel authentically personal. Automated tooling can compile much of this in minutes.

The result is precision: a lure referencing a real project, sent while the real approver is verifiably on stage at a conference, is categorically harder to spot than generic spam.

How to defend against it

  • Audit your organization's footprint. Periodically review what an outsider can assemble about your executives, finance team, and infrastructure from public sources — and treat that view as the attacker's starting point.
  • Minimize needless exposure. Trim role details in auto-reply messages, avoid publishing direct lines and internal email conventions, and coach high-risk roles on social media hygiene.
  • Assume the pretext will be good. Verification procedures — callbacks on known numbers, dual approval for payments — must hold even when the caller knows convincing details.
  • Train against researched attacks. Simulations built on the same public information attackers would use show employees how convincing a targeted lure really is.

Related terms

Spear PhishingSpear phishing is a targeted phishing attack that uses personalized information about the victim to increase its effectiveness.PretextingPretexting is a social engineering technique where the attacker creates a fabricated scenario to gain the victim's trust and extract information or access.DeepfakeA deepfake is AI-generated synthetic media — audio, video, or images — used in social engineering to impersonate trusted individuals convincingly.WhalingWhaling is a spear phishing attack specifically targeting senior executives or high-value individuals within an organization.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo