Originally published in Romanian in 2025. Revised on 26 September 2026 and translated into English on 27 September 2026.
OSINT, short for Open Source Intelligence, means collecting and analysing information from publicly accessible sources. It is used in journalism, research and security, but the same information can also help someone prepare a fraud.
What public information can reveal
Posts, company pages, published documents and registers can point to roles, contact addresses, professional relationships or the technologies in use. Photos and metadata left in files can add further clues. Correlation does not guarantee that a conclusion is correct, though: sources can be outdated, incomplete or attributed to someone else.
Accessing a compromised mailbox is not the same thing as research from public sources. The fact that information can be found online does not remove the obligations around processing personal data and does not authorise access to private systems.
Five practical measures
- Check what you publish. Avoid documents that needlessly expose home addresses, identifiers, access details or infrastructure details. Remove metadata you do not need.
- Review visibility. Check your profiles and application permissions. A private profile limits direct access, but it does not prevent resharing or screenshots.
- Protect your accounts. Use unique passwords, a password manager and multi-factor authentication. These reduce the risk of compromise; they do not erase information that is already public.
- Limit the data you hand over. Fill in only the fields that are required and check the recipient before you send documents. Do not publish your real-time location without a reason to.
- Search regularly. Check what public searches show about you and your organisation. Alerts can help, but they do not cover every source. Ask for information to be corrected or removed where that is justified and possible.
Reducing risk, not becoming invisible
Not all public information needs to be hidden: a company needs contact details and may have publication obligations. The aim is to separate necessary information from unnecessary exposure and to verify sources before drawing conclusions. Security research is carried out within a defined purpose and a clear mandate.