Ep 79: Open Source Intelligence Exposed: How Hackers Use Public Data to Target People, Passwords, and Critical Systems | PrOTect IT All
HomeEpisodes › Episode 79
Episode 79
Episode 79 Solo

Open Source Intelligence Exposed: How Hackers Use Public Data to Target People, Passwords, and Critical Systems

Nov 4, 2025 00:24:25
OT SecurityRisk ManagementRansomwareLeadership

Watch This Episode

Think your company’s private data is safe? Think again.

In this episode of Protect It All, host Aaron Crow pulls back the curtain on one of cybersecurity’s most underestimated frontiers - Open Source Intelligence. He reveals how attackers leverage publicly available data from LinkedIn profiles to leak passwords, mapping out targets, infiltrating systems, and exploiting the human attack surface.

Drawing from real-world incidents and years of experience across IT and OT security, Aaron explains:

Whether you’re a cybersecurity professional, executive, or simply digital-curious, this episode will change how you think about “public information.”

Tune in to learn how Open Source Intelligence can both expose and empower your cybersecurity strategy - only on Protect It All.

Key Moments: 

06:17 Securing Domain Admin Accounts

09:09 Proactive Employee Security Monitoring

12:19 "Protecting Human Attack Surfaces"

16:48 "Enhancing Cybersecurity with Open Source Intelligence

18:49 Exposed Data Response Process

Connect With Aaron Crow:

 

Learn more about PrOTect IT All:

 

To be a guest or suggest a guest/episode, please email us at [email protected]

 

Please leave us a review on Apple/Spotify Podcasts:

Apple   - https://podcasts.apple.com/us/podcast/protect-it-all/id1727211124

Spotify - https://open.spotify.com/show/1Vvi0euj3rE8xObK0yvYi4

Chapters

06:17Securing Domain Admin Accounts
09:09Proactive Employee Security Monitoring
12:19Protecting Human Attack Surfaces
16:48Enhancing Cybersecurity with
18:49Exposed Data Response Process
Read the full transcript

Aaron Crow (0:1.134): Hey everybody. Welcome to another episode of the Protect It All podcast. Today I wanted to dive into kind of blind spot in cyber and why OSINT needs to be part of your security program. If we really look at, if you haven't worked in the military, you haven't worked with agencies and organizations and I would...

Aaron Crow (0:30.848): other gave it may just all the things right. OSINT word could be, you know, a little opaque in that, you know, we don't necessarily use open source intelligence. Obviously we're getting data sources from, you know, a lot of our providers that are getting that intelligence. But we're not necessarily using it outside of, know, your firewall or, you know, maybe the products that have it built in. But

Aaron Crow (1:0.542): If you, if you take a, if you take a step back and you look at how an attacker is going to, you know, go after someone, an organization, or, know, even a person, you know, go all the way back to, you know, the old hackers movie, right? you, you see they, the first thing they do is investigate the building and where are they trying to get to and the people that are going into, and they find the weakest link.

Aaron Crow (1:25.206): somebody that can get their badge from somebody that can get onto their device. Somebody that can steal their, you know, their phones, somebody that, you know, has a, a, a risk in their environment, whether they're having an affair or all this type of stuff, right? Those are all, that's all information. I remember sitting at a, an incident response tabletop exercise and our CISO was asking, you know, who's the, you know, who's the person that if somebody had a gun to their head that, know, would be the biggest risk. And I raised my hand and said, me or my team, just because we know all the

Aaron Crow (1:53.912): passwords of all the secure devices that power plants and all the different places. And, you know, I don't get paid enough to risk my family, and, and not give away a password to, you know, a system like it's just not, not the case. And, so, you know, it's one of those things that, if you're not thinking about it, it's definitely not the first thing you should do if you're building an OT program or a cyber security program, it's not like check one, but it should definitely be something that you're considering. So

Aaron Crow (2:22.350): You know, most companies build walls like exterior walls to protect your network. Like in your house, you have a front door. but you know, the real threat usually is on, you know, it is already, you know, inside, right? It's, it's the insider threat. And, and, and I don't mean insider threat. Like it's a, you know, you have a, you know, nation state attacker inside your environment you've hired and they're, they're, know, they're a spy. I literally mean, you know, your employees are bringing things in unknowingly.

Aaron Crow (2:51.666): or they are your risk, right? know, sitting in your employees' social media, their home Wi-Fi, like all of those things, you're literally connecting many times. If you're doing BYOD, even if they're using a corporate device, are they plugging that into their home network? Do they have protections on their home network? What other things are on their home network that could be an impact, right? So these are all things that you have to consider.

Aaron Crow (3:17.644): when you're building out your program, like you look at most attacks, they don't come in the front door, like the target attack. Again, I know that's an old one, but you look at the target attack and it came from a, you know, a third party consultant contractor that had access VPN access to the, the, the target network. And they, they attack the, the supplier, they don't attack target because the front door is barricaded and all the things they always find the back door access, the easiest way to get in, right? You're going to find the path of least resistance. It's like electricity.

Aaron Crow (3:48.044): So, you know, that's where OSINT and you know, which is open source intelligence, just FOI, that's where it comes in, right? So, you know, OSINT is, why does it matter or what does it really mean? know, OSINT isn't just for investigators or law enforcement or, you know, doing criminal background checks or, you know, tracking down hackers or anything like that, right? It's collection and analysis of publicly available data, social media.

Aaron Crow (4:15.438): forums, dark web chatter, public records, but it's also breach data, right? A lot of times when we do an assessment, that's one of the things we're looking at. And we just do a very, very wide spread. And that's going to be, you know, hey, company A, you know, Acme Corporation. Acme Corporation's domain name has been in this many, you know, releases and this many accounts have been associated in those things. And there's passwords associated with them, right? That's an example.

Aaron Crow (4:43.230): but I'm not diving into your employee list and saying, Aaron Crow, his Facebook account was, was impacted and now, or his email or whatever, like all of those things matter, especially if I have access to things, administrator, et cetera. Right. So it doesn't mean you necessarily have to have that information on all of your, all of your employees, especially if you're a large company, but it's definitely something you need to consider executives, high profile, not high profile in that like public facing.

Aaron Crow (5:12.814): Could be, obviously if you have those, that's something to consider. But somebody that has the keys to the kingdom, like somebody that is the administrator, somebody that has, that knows all of those things, there should be a, you know, operational security consideration. you know, their accounts shouldn't have, they shouldn't have domain level access. This is 101 security. My account should not be domain admin. I should have a separate account that's domain admin. And that account should be a different name, it should be a different app.

Aaron Crow (5:40.297): you know, password, I should have multi-factor authentication, like all those types of things. And also, I should be monitoring those people's accounts and I should be monitoring Aaron's devices and I should have a different set of, you know, for Aaron and whoever has that level of access to ensure that, you know, nothing bad is happening in that space, right? So, you know, every attacker is going to start with OSINT. They're going to find

Aaron Crow (6:8.366): who is the person or people or team that I would want to infiltrate or I would need to get a hold of or pretend to be or get access to or be next to, to be able to get to the thing that I'm looking for. Access to the network, data, whatever that thing may look like. And they'll use, attackers will use OSET to map your people, your network, your infrastructure, your physical buildings. And they're going to, that's what they're going to use.

Aaron Crow (6:37.198): to find weak links. And it's not that difficult. Like they are, again, open source. It doesn't cost them anything. Most of this stuff is publicly available, free. Anybody can do it, right? I can search for Aaron's Facebook account. I can search for Aaron's Instagram, et cetera, et cetera, et cetera, et cetera, right? And I know where he works. I know his route to work. I know which coffee shop he's eating at, like.

Aaron Crow (7:1.366): You know, I heard an entrepreneur the other day talking about how how he got into he was starting an airline business and you know, he wanted to go to this conference, but it was all sold out. So he found where the conference was going to be. And there was one coffee shop outside of that. So he went in that coffee shop that morning and bought every bagel, you know, every bit of food they had and bought it all and put it in a basket. So when everybody came in to buy, you know, a muffin or whatever, they didn't have any because he had bought them all out.

Aaron Crow (7:30.275): But then he's like, Hey, you guys looking for a bagel? Here you go. You looking for a croissant? Here you go. Right. And it was an introduction for him to be able to talk to them. That's OSINT. Obviously it wasn't used in a malicious way, but he was very intelligent about where people were going to be, who was going to be there. Everybody was wearing their badge. So he knew the people that he wanted to talk to and the ones that he would just, you you know, hand a bagel to, right. There's no reason why,

Aaron Crow (7:57.495): attackers wouldn't use that same scenario. Most of us, you know, if you go to a corporation, you probably have a badge. That badge probably has your company name on it. They know that you're going into this building. It doesn't take much to figure out who the right people are in that space. So all that to say, that's great. Now what, so what, what do I do with that? where, where can OSINT fit into a, a cyber program? You know, you can integrate OSINT into, you know, your risk assessments.

Aaron Crow (8:26.206): into your threat modeling. And again, that's where you say, Hey, these key people, we should have a extra level of monitoring. And again, I don't mean getting into their personal information, but it's more around, Hey, I'm going to monitor the dark web to see if any of this type of stuff comes up with Aaron's name attached to it and his accounts. I'm going to monitor those accounts. I'm going to monitor for, you know, anything that is, you know, using Aaron and you know, the company.

Aaron Crow (8:53.238): Right. And I'm going to, there's certain ways that you could do that again, without breaking into people's personal, you know, private information, not trying to have recommend anybody dive into people's personal and private information. Cause everybody wants that privacy in their own home. at the same time, there is a risk as a person, as an employee, as a, as a worker at, at, at company, acne corporation.

Aaron Crow (9:17.634): that I can bring in unknowingly again, as I'm bringing these devices into my network, as I'm going to Starbucks, as I'm traveling, like whatever those things are. So, you know, use it to understand what an attacker can already see about your organization. Right. So you should be looking at this. What can I see from the outside looking in publicly available? I'm going to, can I find business locations? Can I find, you know, information about who my providers are? Can I find my source? Like what is the information that I can find? Because that's what the attackers are going to be doing.

Aaron Crow (9:46.839): If I want to go after Acme Corporation, I'm going to start searching, looking at Google and publicly available information to find all of those factors and what can I use that can benefit me to get me to my goal. But you can't just do it once, right? It's not a static thing. I can't do it once and say, I've already done that search. I'm good, right? There needs to be some level of recurring component to doing this. Does it need to be daily, hourly? That depends how critical your system is.

Aaron Crow (10:15.938): you know how critical your environment is, et cetera, but you know, probably not, but it can't be once and it shouldn't be annual. It should be more than that, right? You should, cause things are so dynamic and things change so quickly. that information could get leaked in a heartbeat. every time a leak comes out on, on, you know, the news, it should be almost a triggering factor of is any of our information in that leak or any of the, any of our employees information in that leak, did they use their corporate?

Aaron Crow (10:44.238): address to sign up for Facebook or, you know, Academy or whatever. Um, and maybe they use the same password on their personal accounts as they do their business account. Like there's, these are all just things to consider as you're doing these things. Right. So align that monitoring, uh, with identity protection, um, dark web and then like brand intelligence. Right. So, you know, thinking about, you know, making sure nobody's creating fake web accounts or a domain names that are, that are similar, you know, acne corporation.co.

Aaron Crow (11:13.708): you know, ACME corporation dot AI, like, you know, ACME spelled differently with a dash or whatever. There's, all those types of things that you can monitor for. And all of those things should be kind of red flags of what's going on here. Right. Maybe it's not malicious, but it's probably not something I want happening. And then tie all that stuff into your vulnerability management, insider threat, and you know, kind of executive protection workflows and what that looks like. Right. So are you monitoring your executives stuff?

Aaron Crow (11:41.251): you know, executive that word, you know, it's, the term that's normally used, but it doesn't have to mean just my C-suite. Again, if you have a person, an Aaron, a Bob, a Sam, somebody that has the keys to the kingdom, you probably want to make sure that you're monitoring their stuff and make sure. And again, I'm not talking about their personal stuff, but just monitoring what's available, about their, their, their names, their accounts, their systems, their locations, that kind of

Aaron Crow (12:7.118): So kind of what's next is that human attack surface. We all know anybody that's been in cybersecurity or even technology, the weakest link is always the people. And that's not an insult, but it's just the reality, right? Your most at-risk assets are your people. So, you we need to be, you need to be asking those questions. You know, is their home network secure? Do they just have, you know, AT &T?

Aaron Crow (12:31.682): providers, wifi, and it's the default credentials and password and the default SSID. And it's a simple SSID and all their home stuff, you know, all the, the, you know, IOT stuff and stuff that they, you know, their Alexa and their TVs and their smart refrigerator and their smart toaster is on the same network as your corporate device. Cause that's probably not what you want. Right. Do they, are they using operational security OPSAC on personal devices?

Aaron Crow (13:1.078): Obviously they're probably being intentional on their work devices, but are they also on their home devices? Are they going to sites that are more risky? Are they connecting to wifi at Starbucks without using a VPN? Do they connect their work laptops to the home wifi or smart devices? Are they using a VPN for remote access? People post their roles, locations and projects online. It's on LinkedIn.

Aaron Crow (13:29.090): I know who you work for, like it's super easy to track this stuff down. And because it's part of our world today, know, everybody can look on my LinkedIn and see, I work for Morgan Franklin. You know, they can see exactly, you know, what they can link that to what company I'm doing. And maybe they can figure out what clients that Morgan Franklin has, or, know, whatever that looks like. So these are all things that people can use in this OSINT to find. So making sure that your employees are using OPSEC on not just their corporate devices, but also their work ones.

Aaron Crow (13:59.053): Not even to count. you using BYOD? You know, are you allowing people to bring their own devices? And that can be in their cell phone. Are they allowed to connect their cell phone to the Wi-Fi? Or do they have their corporate email on their own phones and their laptops and all that type of stuff, right? These are all things to consider and you need to have policies around those things. You know, so what is the real world impact of this?

Aaron Crow (14:23.980): So OSINT can reveal exposed credentials, open ports, there's all the time hacks and releases going out with credentials and passwords that were released, open ports, there's all sorts of open source portals that showcase open ports and things like that, internal documents that are left on GitHub.

Aaron Crow (14:51.226): policies and procedures, like all sorts of things that get into that you just, you can't imagine how it got there. And many times it's probably accidental. My, one of my former alma mater's, I don't have to name it, but you know, you can look it up recently, just got a SQL database backup released. That was two terabytes, I think of a, of a SQL database. think it was SQL SQL database. was the backup, but it wasn't encrypted. So it got access.

Aaron Crow (15:20.792): Who knows what was in it? I don't know. didn't, I didn't dive further into it, but it's things like that, that you just don't realize or you don't, you don't necessarily know at the time that something bad like that is going to happen. And especially as you have more and more and more employees, again, most of the time it's not malicious. Most people are not putting those things out there to be at risk. They just don't know the impact. They put something someplace to make a workaround and they don't realize that now they just opened the keys to the kingdom or they, they, they allowed a, you know, a bad actor in, the door.

Aaron Crow (15:50.247): you know, in executive protection and again, executive being those high critical type people, OSINT identifies physical and digital threats before they hit, right? You should be monitoring those critical folks to make sure that, you know, they don't have, people tracking them. you know, all the things that you can imagine. And I'm not just talking about the Jason Bourne movies or, you know, that kind of thing. It's really just simple. do they have people monitoring their systems? Do they have people monitoring their activities? Are they watching them? That kind of thing.

Aaron Crow (16:19.404): All those things are things that you need to at least be looking at, especially for those highly critical people in your environment. In OT environments, can uncover supplier vulnerabilities. LinkedIn posts can reveal control system vendors and versions and all that can link to, hey, this has got an XP system that can't be patched and A plus B equals C, So all this to say, it's a big target that is really hard if you're...

Aaron Crow (16:46.158): If you're already struggling in your OT program or your cyber program or your IT program, whatever those things are, thinking about this can be overwhelming. It doesn't have to be though, right? There's obviously services and consultancies that can help you with this stuff, but just bigger than that, just think about like who, what are some of the entry level small things? Do some of these searches, use some of these open source tools, see what you can find and see if it's something that's concerning, right? And then what can you do about it? How can you adjust it, shift it, change it, right?

Aaron Crow (17:14.114): You know, build OSINT capabilities internally, or you can also build them through, you know, again, a consultant, a trusted partner, you know, smart start small, you know, focus on high risk groups, those critical folks, executives, admins, developers, systems administrators, plant managers, whatever that type of folks may be. But you need to understand who those critical people are, just like you're supposed to be mapping out your asset inventory.

Aaron Crow (17:43.311): around what are my critical systems. This system is critical. These people are also critical to my system. That's all part of that system and understanding because if Bob gets taken or, you know, it gets hit by a bus, let's say that they kidnap him or they hold him by gunpoint or they grab his family. Like these are all things that you just need to think about in these spaces, especially if you start talking about international and all that type of stuff. Like all of these things just get exponentially worse. know, create a process for reporting.

Aaron Crow (18:12.026): and removing exposed data. As these alerts are coming out about a new exposure or leak, Proton just released like 300,000. They didn't do the release. They did a study that showed the release of like 300,000 credentials that were exposed.

Aaron Crow (18:32.810): Is any of your people on that list? Do you even have a method that you could search that list to see if any of your people are on that list? Your employees, your contractors? The answer more than likely is no. If it is no, that's probably a great place to start. How could I start searching these already disclosed locations and breaches for any of the people in my organization or adjacent to my organization that can potentially impact this?

Aaron Crow (19:1.046): It could just be as simple as Aaron was in a breach. It was his personal account. But since he was in that breach, we're going to have him. We're going to force him to change his password. Simple as that, Aaron, you got to change your password. Make sure that you're using multifactor authentication. And even if you're using multifactor authentication, you're going to change your password because your your credentials, not your business ones, but your your other credentials were in a breach. We're going to go ahead and do it it's an easy change and it can it can impact.

Aaron Crow (19:27.810): things that you don't even know downstream, but making the changes is low risk, right? know, combine OSINT with training, really teaching employees what oversharing looks like, you know, talking about business, you know, what their projects are, you know, all of that type of stuff. Like what are the types of things that they should and shouldn't be talking about for just the good of the business and the entity, right? But make it continuous, not reactive, right? So it shouldn't just be a,

Aaron Crow (19:56.671): After something bad happens, we talk about this. It shouldn't just be once a year. It should be something that you're repeating, something that you're keeping in the focus of people. So that every day is something they're considering when they're going into a situation. Hey, when I walk into the Starbucks, I shouldn't be connecting to the Wi-Fi. And if I do, I need to make sure that I have a VPN. And if I don't, then...

Aaron Crow (20:20.716): I don't really need to be on the wifi. And if I'm traveling internationally, I probably don't need to take my work laptop unless I have to be at work. And if I do, I should probably reach out and ask them which device should I take or should I connect remotely and set up remote access? And like all of these are types of questions, but do your employees know that? Or are they going to take a trip because they are going to be over, they've only got five days of vacation and the last day is going to be a travel day. So they're going to take their work laptop so they can log into meetings because they don't have another day off.

Aaron Crow (20:47.904): So, you know, but they're traveling back. So it's not a big deal, right? It's not as long as you understand what it means and that they're following that that opsec, right? So, you know, kind of in closing, know, attackers use OSINT because it works. It's super simple. It's low hanging fruit. Doesn't cost them much. They get a huge return on investment for the time that they spend researching your people, your organization, your systems. And if they're if you're not using it, your your

Aaron Crow (21:17.758): you're fighting with, you one or two hands tied behind your back, right? You don't know the day that you have exposed that attackers can use against you, right? You you get, you see the, the legal, shows or whatever, and everything you say can and will be used against you in a court of law. It's the same thing in, in, in cyber, everything that you say, or someone says, or is available can and will be used against you. And that means they're going to take all that information and use it to plot their attack.

Aaron Crow (21:47.330): And it doesn't have to be nation states. doesn't have to, it could just be a board kid. It can be a, you know, somebody, a disgruntled employee. Like there's any number of use cases where having that information isn't, valid or, or would be, can, would and can be used against you and your program. So build it into your cyber core cyber program before someone else, you know, builds, builds it against you and takes advantage of it. So anyways, all that to say, sent.

Aaron Crow (22:15.374): It's something we talk about in the cyberspace. It's not always really part of a program, at least not until it's more mature, but it's such a low hanging fruit. It really should be incorporated early on. And you can obviously mature that as it goes, but you should be doing basic searches constantly, right? And if you're getting an assessment, you should ask for a deep dive of OSINT. should, you know, depending on the size of your company, you should be giving them your accounts and say, hey, check for anything with these, you know, account.

Aaron Crow (22:44.910): domain names and et cetera, et cetera, et cetera, right? So, you know, start doing that. And again, once a year is not enough. So really start incorporating that. Love to hear from anybody that is using OSINT in their programs. How are they using it? What have you found? And maybe some of the things that maybe you've found some holes or some gaps because of that OSINT research and you've able to make a change to better and strengthen your environment.

Aaron Crow (23:13.165): With all that, until next time, definitely reach out, let me know how you're using OSINT in your cyber practice.

Transcript lightly edited for readability.

Want your brand in front of OT, IT, AI, and cloud security decision-makers?
PrOTect IT All listeners are the practitioners and leaders making security buying decisions across critical infrastructure.
See Sponsorship Packages →

Never Miss an Episode

Subscribe to PrOTect IT All and stay ahead of the threats targeting critical infrastructure.