July 19, 2026
How Much Can a Stranger Learn About You From Public Information Alone? An OSINT Case Study
A walkthrough of how open-source intelligence techniques can build a surprisingly detailed profile of someone — using only information…

By Yassin Hamada
3 min read
A walkthrough of how open-source intelligence techniques can build a surprisingly detailed profile of someone — using only information they've already made public.
Introduction
People tend to think of hacking as something technical — a password cracked, a system breached, code exploited. But some of the most effective investigations, and some of the most dangerous social engineering attacks, never touch a single system. They're built entirely from information people have willingly, if unknowingly, made public.
This piece walks through a fictional practice scenario — a composite profile built to demonstrate methodology, not a real person — to show exactly how much a patient researcher can learn using nothing but publicly available sources.
A note on ethics before we start:_ everything described here uses passive, legal techniques only. No private accounts were accessed, no one was contacted, and no systems were touched. This is the same standard that separates legitimate OSINT research from stalking or harassment — and it's a line worth taking seriously._
Starting Point: Almost Nothing
Every real investigation — whether it's a threat intelligence analyst tracking an actor, or a journalist verifying a source — usually starts from very little. For this scenario, assume the starting point is just a first name and a city.
The instinct for beginners is to jump straight to a name search. That's usually a dead end on its own. The real work starts with building outward from small, verifiable anchors.
Step 1: Finding the Anchor
The first useful anchor is usually a username, not a real name. People reuse handles across platforms far more than they realize — a gaming account, a forum post from years ago, a comment on a niche hobby site. Once one consistent handle is found, it becomes the thread that pulls everything else together.
In this scenario, a distinctive handle used on a public forum led to a match on a professional networking profile using a stylized version of the same handle in the profile's vanity URL — a small detail, easy to overlook, but a strong correlating signal.
Step 2: Building the Timeline
With an identity anchor established, the next step is chronological — not thematic. Laying every public post, photo, and comment on a timeline (rather than reading them in whatever order a platform's algorithm shows them) reveals patterns that are otherwise invisible: a job change, a relocation, a recurring weekly routine.
In the scenario, three years of public posts revealed a consistent pattern: the same coffee shop tagged almost every Tuesday morning. That single detail — trivial on its own — becomes significant the moment it's combined with anything else.
Step 3: The Metadata Nobody Thinks About
Photos carry more information than most people realize. Even with GPS metadata stripped (which most social platforms now do automatically), visual details often do the same job: a reflection in a window, a partially visible piece of mail, a street sign in the background of an otherwise unremarkable photo.
In the scenario, a photo posted to celebrate a new apartment included a partial street view through a window — enough, combined with the earlier city-level starting point, to narrow the general neighborhood.
Step 4: The Professional Footprint
Professional networking profiles are often the richest — and most underestimated — source in any investigation. People are far more careful about what they post on personal accounts than what they list on a resume-equivalent public profile: employer history, job responsibilities, direct reports, even specific software and internal tools mentioned in a "skills" section.
In the scenario, a detailed job description referencing a specific internal ticketing platform gave a strong hint about company size and industry — information the person never intended to be "sensitive," but which, combined with everything else, meaningfully narrows down who they are and where they can be reliably found.
What This Adds Up To
None of these four data points — a reused handle, a weekly coffee shop tag, a partial street reflection, a job description — is remotely sensitive on its own. That's exactly the point. Individually, each piece looks like nothing worth worrying about. Combined and placed on a timeline, they form a profile detailed enough to know where someone works, where they live within a few blocks, and where they can reliably be found on a given day of the week.
This is the core lesson of OSINT work, whether it's used defensively or by a threat actor building a pretext for a social engineering attack: the risk isn't any single post. It's aggregation.
What Actually Reduces This Exposure
- Periodic self-audits — search your own name, common handles, and reused usernames the way a stranger would
- Break the pattern deliberately — routine (the same coffee shop, every Tuesday) is one of the most exploitable signals in this entire methodology
- Treat "professional" profiles as public, not semi-private — assume anything on a LinkedIn-style profile will be read by someone other than a recruiter
- Review old photos before posting — reflections, mail, visible documents, and background details leak more than people expect
Closing Thoughts
This exercise isn't about paranoia — it's about proportional awareness. Most people will never be the target of a dedicated investigation. But understanding this methodology matters for two audiences at once: defenders who need to know what a motivated attacker can actually piece together, and everyday people deciding what's actually worth thinking twice about before posting.
This case study describes a fictional, composite scenario created for methodology demonstration. No real individual is referenced. Written as part of my ongoing OSINT research and practice.
— Yassin Hamada Cybersecurity Researcher | OSINT · Malware Analysis · Threat Intelligence