How Can OSINT Compromise a Fortune 500 Firm?

TL;DR
Publicly available information can give social engineers enough context to impersonate employees, vendors, or trusted contacts without technically hacking a system. Organizations can reduce this risk by controlling exposed details, including badges, software versions, vendors, phone numbers, workplace complaints, photo metadata, and geolocation data, while preparing employees to recognize phishing and pretexting attempts.
Transcript
So my name is Rachel Tobac. I'm Joe Gray. And let's get into it. First, the cold, hard facts. So we know people lose a lot of money to social engineering, so let's talk a little bit about how much money that is. We know that Ubiquity Networks in 2015 lost $39.1, .1 million to social engineering. It happened in the span of about 30 minutes over emai... Read More
Key Insights
- Social engineering can cause substantial losses without a technical intrusion. Ubiquiti Networks lost $39.1 million through an email-based incident completed in about 30 minutes, demonstrating that attackers can obtain valuable outcomes by manipulating people and organizational processes.
- Phishing is a major route into organizations. The presenters state that phishing enabled the SWIFT banking attacks and cite it as the leading vector in espionage, while also noting increased use of secure websites and inexpensive domain names for deceptive campaigns.
- A decline in unique phishing websites does not necessarily mean phishing is disappearing. The presenters interpret the trend as evidence that social engineers may be spending more time on open source intelligence to create better context and conduct more effective spear-phishing attacks.
- OSINT is collected from far more than social media. Useful sources include the internet, mass media, conference proceedings, photographs, embedded metadata, geospatial services, job postings, employee resumes, reviews, public forums, and maps showing facilities or delivery activity.
- Photo metadata can reveal operationally useful details. One example exposed the building where a photograph was taken, the iPhone 6 used, the camera orientation, and whether the rear camera was active, while visible reflections can provide additional environmental information.
- Social media posts can expose sensitive organizational details. Instagram locations and hashtags can connect photographs to addresses, while Facebook and Glassdoor images may disclose badge designs, including side-by-side comparisons of old and new employee credentials.
- Employment platforms can reveal technologies and business relationships. LinkedIn helps identify company vendors, while Indeed resumes and job postings can expose deployed technologies or name security providers through descriptions of an employee's current or previous work.
- Specific software versions are more valuable than general product names. Social engineers seek details about VPNs, computer models, operating systems, service packs, PDF readers, browsers, mail clients, disk encryption, and other software because precise versions help tailor attacks.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: How can OSINT help compromise a large company?
OSINT can provide the context needed to impersonate an employee, vendor, security provider, delivery company, or other trusted party. Public sources may reveal names, phone numbers, email addresses, badge designs, workplace complaints, technologies, software versions, vendors, and facility details. A social engineer can combine these fragments into a believable phishing message or telephone pretext without first penetrating a technical system.
Q: What public sources are useful for social engineering research?
Useful sources include internet searches, mass media, conference proceedings, photographs, photo metadata, mapping services, geospatial information, and social media. The presenters also use LinkedIn, Indeed, Glassdoor, Quora, and Reddit. These sources can expose professional interests, contact information, workplace grievances, vendor relationships, badge photographs, deployed technologies, addresses, and details about how a facility receives deliveries.
Q: Why are social media posts dangerous to organizations?
Social media posts can unintentionally expose information that makes impersonation easier. Instagram locations, hashtags, and address-related posts can connect employees to specific workplaces. Facebook and Glassdoor photographs can reveal badge designs, while old group conversations may contain phone numbers posted years earlier. Attackers can aggregate these details even when each individual post appears harmless or outdated.
Q: How does LinkedIn support a social engineering pretext?
LinkedIn can reveal which vendors work with a target company by connecting employee roles, professional histories, and business relationships. A social engineer can then pose as a vendor representative because employees may recognize the vendor's name without knowing every person who works for it. The presenters recommend that organizational social media policies account for vendors as well as internal employees.
Q: What information can job sites expose about a company?
Job sites can disclose technologies, service providers, and operational relationships through job advertisements, uploaded resumes, reviews, and employee histories. The presenters found a target company's security provider because an employee's prior experience identified Allied Barton and described a gate-guard role for that company. Such disclosures can help an attacker choose a credible identity and build a convincing story.
Q: Why do social engineers look for exact software versions?
Exact software versions help social engineers tailor exploits or deceptive requests to a target's actual environment. The desired information includes VPN products, computer makes and models, operating systems, service packs, PDF readers, browsers, mail clients, disk-encryption products, and other installed software. A browser name is useful, but its specific version is more valuable because it provides greater technical precision.
Q: How can photographs reveal information beyond their visible content?
Photographs can contain metadata describing where and how they were captured. In one example, metadata revealed the relevant building, that an iPhone 6 took the picture, the direction in which the device was tilted, and that the rear camera was used. Visible details such as reflections can also disclose surroundings, while photographs of badges may expose credential designs.
Q: How should organizations prepare for social engineering threats?
Organizations should treat publicly exposed information as part of their security risk and prepare employees for phishing and pretexting. The examples indicate that policies should cover social media, vendor information, badge photographs, contact details, software disclosures, job postings, reviews, and location data. Employees should understand that attackers combine small public clues to establish trust and make fraudulent requests appear legitimate.
Summary & Key Takeaways
-
Social engineering can produce major financial and security consequences without exploiting technical systems directly. Ubiquiti Networks lost $39.1 million through email-based social engineering in about 30 minutes, while phishing also enabled the SWIFT banking attacks and remained a leading vector for espionage according to sources cited by the presenters.
-
Open source intelligence comes from internet searches, mass media, conference proceedings, photographs, metadata, geospatial services, social media, employment sites, and public discussions. These sources can reveal employee identities, contact details, delivery companies, badge designs, workplace issues, vendors, and specific technologies that help an attacker create a convincing pretext.
-
Rachel Tobac and Joe Gray describe how targeted research supported successful social engineering competition calls against large companies. Their examples show that defenses must address information exposure as well as employee behavior, because seemingly harmless posts, old comments, job listings, reviews, photographs, and professional histories can collectively enable impersonation and phishing.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator