How attackers use it
Before an attack, criminals research their target: staff names and roles from LinkedIn to craft spear phishing, email address formats, technologies mentioned in job offers, subdomains and exposed services from DNS records and search engines like Shodan, credentials from previous leaks and secrets accidentally published in public code repositories.
How defenders use it
The same techniques show a company its own digital footprint: which systems are visible from the internet, which employee credentials appear in leaks, which documents are publicly indexed and which lookalike domains have been registered. This view is the basis of attack surface management and an input for threat intelligence. Our article on what your company exposes online shows typical findings.
Reducing exposure
Limit technical detail in job offers and public documents, train staff on what they share about their work, monitor leaked credentials and enforce MFA, remove forgotten subdomains and test environments, and register lookalike domains of the brand.
Limits
Information being public does not make every use of it lawful. OSINT on people must respect data protection law, and any testing beyond passive collection requires authorisation.




