OSINT: how attackers research your company before they touch it

Reconnaissance is the longest phase of a social engineering attack and the only one you can disrupt for free. Here is what gets collected, and from where.

7 min read

Nobody competent begins with the phishing email. They begin with a map. The quality of that map determines whether the eventual attack reads as obviously fake or as an ordinary Tuesday.

#What they are building

The objective is a model of your organisation detailed enough to impersonate someone inside it. Specifically:

  • Who works there, in what role, reporting to whom, and who joined in the last three months.
  • Who can authorise a payment, a password reset, an access grant or a contract change.
  • Which suppliers and contractors you use, how often they invoice, and what their emails look like.
  • Which systems you run, visible from job adverts, support forum posts, certificate transparency logs and public repositories.
  • Which credentials belonging to your staff already appear in breach corpora, and which of those passwords follow a guessable pattern.
  • What is happening right now: a funding round, an acquisition, a product launch, an office move, a leadership change. Every one of these makes an unusual request plausible.

#Where it comes from

Almost none of this is stolen. Professional networking sites supply the org chart. Your own careers page supplies the technology stack. Conference programmes supply voice samples. Data brokers supply home addresses and personal phone numbers. Old breach dumps supply credentials. Public code repositories supply internal hostnames, and occasionally an access key. Your suppliers' press releases confirm the relationship.

An automated pipeline collects all of it and produces per-employee dossiers in an afternoon. The scarce resource used to be analyst time. It no longer is.

#Turning the map into an attack

A finished pretext is usually mundane. A new starter in finance receives a message from a name they recognise from the org chart, referencing a real supplier, about an invoice consistent with the real billing cycle, sent during a week when their manager is genuinely travelling. Nothing in that message is false except the bank details.

The most effective pretexts contain almost no lies. That is what makes them hard to detect and easy to build.

#What you can actually reduce

Not everything. Your staff list is largely public and trying to hide it is a losing fight. Focus on the items that are both removable and high leverage:

  • Personal data on brokers and people-search sites, especially for finance, IT and executive staff. This requires ongoing removal, since records reappear.
  • Direct dial numbers and individual email addresses published on the website. Route through a single contact point instead.
  • Technology detail in job adverts. Describe the role, not the exact versions you run.
  • Metadata in published documents, which routinely leaks internal usernames, paths and software versions.
  • Repository history. Rotating a leaked key is not enough if the commit is still public.
  • Automatic out-of-office replies that disclose who is covering, for how long, and how to reach them.

#Defend what you cannot remove

Some exposure is simply the cost of doing business. Your CEO speaks publicly; that audio exists forever. The answer is not silence, it is procedure: assume the attacker knows your structure, your suppliers and your travel schedule, and build verification steps that hold even when the caller gets every detail right.

Run the reconnaissance against yourself first, on a schedule. Reading your own dossier is the fastest way to understand why the last suspicious email was so convincing.

Want this tested against your own organisation?

Book a free call and we will talk through which of these techniques would actually work against your team.

Book a free review