What an OSINT investigator finds about you in 30 minutes. And how to break their workflow.
Short answer
An OSINT investigator with a working email address or a phone number rebuilds a meaningful profile of you in roughly thirty minutes. The toolchain is automated and the underlying data is purchased from commercial breach and aggregator services, which makes the same workflow reproducible by anyone who can pay for the subscriptions.
The standard workflow
An OSINT investigation against a private individual usually starts with one identifier: an email, a phone number, a username, a real name, or a single photo. The next thirty minutes follow a sequence that has been the same for the last several years.
Step 1. Pivot from the seed
The investigator runs the seed identifier through the breach datasets. Have I Been Pwned for confirmation, then commercial breach search engines (Constella Intelligence, Spycloud, IntelX, Snusbase) for full content. The breach data returns historical passwords, which themselves are seeds: the password “Mountain42!” appearing across breaches lets the investigator pivot to other accounts that used the same password. Reused passwords compress months of investigation into seconds.
The breach data also returns associated identifiers: the phone number you used to register a forum account in 2014, the alternate email you provided as recovery, the IP address you registered from. Each one is a new seed.
Step 2. Username correlation
Tools like Sherlock, WhatsMyName, and Maigret check a single username against several hundred sites simultaneously. The same username on Reddit, Steam, GitHub, an old forum, and a real-estate listing site links the accounts. The investigator now has a username history. Most people reuse usernames across decades. The pattern is the easiest break in most investigations.
Step 3. Reverse-image and reverse-phone
If a profile photo exists, PimEyes runs it across the indexed face-search database and returns other places that face appears. Older photos surface adolescent profiles you forgot. Phone numbers run through commercial reverse-lookup services (Spokeo, BeenVerified, Whitepages Premium, TrueCaller business tier) return name, address, age, and known associates. None of this is illegal or requires a subpoena.
Step 4. Aggregator subscriptions
The professional layer. Maltego, Spiderfoot, OSINT Industries (popular among investigators in 2025-2026) bundle dozens of API integrations into a single workflow. A single username goes in and forty queries run in parallel. The output is a graph that shows accounts, addresses, phone numbers, vehicle registrations, and known associates linked to the seed identifier. The investigator has now spent fifteen minutes and has a fuller profile than most relatives could assemble.
Step 5. Manual finishing
The final fifteen minutes are manual. Confirm the identity by cross-referencing two or three independent signals (a LinkedIn that matches a Strava that matches a property record). Pull the dox-ready summary. The product the investigator delivers to whoever hired them looks like a single well-written page with citations. The work behind it is the sequence above.
What breaks the workflow
The countermeasures match the steps. Each one closes a specific gap.
Email aliases
Use a different email per service. SimpleLogin (now owned by Proton), AnonAddy (rebranded as addy.io), and iCloud Hide My Email give you unlimited aliases that forward to one inbox. The breach corpus that previously lit up your real email now lights up an alias used for one defunct service. The pivot dies at the alias because no other service used it.
This is the highest-leverage countermeasure available. It does not stop a determined investigator. It does break the automated tools that make the first thirty minutes cheap.
Phone number compartmentation
Use a different phone number for accounts that do not need to know your real number. MySudo (US/UK/CA), JMP.chat, or a paid VoIP number give you separate numbers for separate identity contexts. Your bank gets your real number. The forum you join for an unrelated hobby gets a different number. The reverse-phone search on the forum number does not return your name. The framework is the same one we cover in operational identity separation between the surface that an investigator can pivot from and your private accounts.
Username discipline
Use a different username per identity context. Same logic as email aliases. The username for professional networking, the one for a political forum, and the one for a support group should never be the same string. Sherlock-style tools do not return correlation when the usernames do not collide.
Photo metadata stripping
Photos uploaded to social platforms and dating apps frequently retain EXIF data with GPS coordinates. Some platforms strip this on upload, but coverage is inconsistent across smaller forums and direct messaging apps. The fix is to strip EXIF before uploading: Settings, Camera, Format, Most Compatible on iPhone reduces the metadata; on Android, the Photos app or a tool like Scrambled Exif removes it explicitly. Reverse image search remains a vulnerability for photos that are themselves identifying, but that is a separate problem.
Data broker opt-outs
Spokeo, BeenVerified, Whitepages, Intelius, and the rest of the consumer broker ecosystem maintain searchable profiles built from public records and commercial data. Each has an opt-out flow. DeleteMe and similar paid services automate the process. Manually it is several hours of work and recurring upkeep because the brokers re-list profiles when new data triggers a re-match. The frame for understanding the broker ecosystem is in our piece on data brokers that publish your address, and the structural reason removal is partial rather than absolute is in the broader pattern: the brokers are cheaper to scrape than to keep clean.
Breach hygiene
Run your own emails through Have I Been Pwned. For every breach, change the password on the affected account. For every password that you have reused elsewhere, change it everywhere. The investigator’s most useful pivot is the password that you used in 2014, that leaked, and that you still use today. Closing that pivot is one password manager away.
What does not work
The countermeasures that the search results recommend that do not actually break the workflow.
Setting your social media to private. The investigator already has the data from before the privacy change. Aggregator services have cached your posts. The privacy switch closes new exposure, not historical exposure. This closes future exposure without addressing the historical record.
Using a VPN. The VPN affects the network path. None of the steps above depend on the network path. The investigator is querying commercial databases populated by other people uploading data about you. Your VPN is irrelevant to that data.
Asking a service to delete your old account. This works some of the time. The service often deletes the live account while retaining the underlying data, which is the layer the investigator’s tools actually query. The deletion request is sometimes worth doing for other reasons. As an OSINT countermeasure, it is unreliable.
Frequently asked questions
If I am a journalist or activist, where do I start?
Email aliases first, password hygiene second, broker opt-outs third. The first two close the active pivots that make automated investigation cheap. The third is recurring work that prevents your home address from being one search away from your byline. The framework for thinking about which exposure matters most is in how to build a threat model in 20 minutes.
Are paid OSINT services like LexisNexis Accurint a different category?
Yes. Accurint and similar professional-grade tools require accredited access (law enforcement, licensed investigators, certain corporate compliance teams). They aggregate data from many of the same sources but with broader breadth and less consumer-facing opt-out. If your threat model includes someone with Accurint access, the consumer countermeasures help less. The principle is the same; the surface area is larger.
Does Aleph or other journalist-tooled OSINT cover the same workflow?
Aleph is closer to a corporate-records and leaks aggregator than a person-of-interest investigation tool. It is excellent for investigating institutions and well-known figures whose dealings appear in leaked corporate documents. It is less useful against private individuals. The workflow above is what you defend against; Aleph is not the typical tool against you unless your name appears in leaked corporate data.
How often should I refresh the countermeasures?
The static parts (email aliases, phone compartmentation) need maintenance only when you add new accounts. The recurring parts (data broker opt-outs, breach checks, password changes) are quarterly work for most people, monthly for higher-exposure profiles. Tools like DeleteMe automate the broker side. The breach side is manual and adds maybe twenty minutes a quarter.
There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.
