
Are your details available online? Run a 25 Minute OSINT check.
A safe 25 minute personal OSINT check to understand, reduce and better control your digital footprint. Working only with lawful public sources, this focused routine walks you through breach checks, name and username searches, reverse image lookups, social profiles and web archives - then helps you verify every match and take one useful action.
Your online presence is more revealing than any single post or profile. A name, a reused username, an old photograph, a public document, or a breached email address may look harmless on its own; but when connected together, those clues can expose your identity, relationships, routines, and locations.
That collection of clues is your digital footprint. Some of it is active information you choose to post or submit. Some is passive, contributed by other people or inferred by services from your behaviour. It can include accounts, searches, purchases, location signals, tags, app permissions and records exposed in a data breach.
You cannot prevent every trace from being created, and Private or Incognito browsing modes only limit what is saved on your device. The practical goal is control: understanding what a stranger can find, removing unnecessary exposure, securing the accounts connected to you and sharing less data in future.
This guide turns that goal into a focused 25 minute check where you will work only with lawful public sources, verify every match and finish by taking one useful action.
“The practical goal is control.”
Your 25 Minute Plan and Toolbox
In 25 minutes, you will check the main places where personal clues surface: breach notifications, search engines, reused usernames, copied images, public profiles and web archives.
Use the table below as your route map. Each activity pairs the check with linked tools, the expected outcome and the caution that matters most. Full details of each activity can be found in Section 5 of this guide.
At the end of 25 minutes you will have created a short, verified evidence log and a prioritised next step - not a permanent dossier about yourself.
Your 25-minute plan and toolbox
| Time (mins) | Check | Linked tools and method | What to do |
|---|---|---|---|
| 0-2 | Prepare | OSINT Framework; private window or separate browser profile; evidence log | Set boundaries, choose identifiers and write “verify before acting” at the top of the log. |
| 2-5 | Check breach exposure and passwords – and from now on, always use a password manager | Entering a personal email into Have I Been Pwned (alternative tool – Intelligence X) commonly reveals multiple historical breaches. Cross-referencing with DeHashed can show exactly which pieces of information (passwords, phone numbers) were leaked. Some tools offer free tiers with optional paid upgrades for deeper results. For password managers, many are already on your devices Apple Passwords, Google Password Manager or Microsoft Password Manager | Enter email addresses only. Treat a match as a prompt to change passwords, enable MFA and close unused accounts. If you've used the same password for other accounts, change them (and stop reusing passwords!) |
| 5-9 | Search names and contact details | Google, Bing, DuckDuckGo, Brave Search; Google search operators. The ability to refine your searches using advanced search operators, a technique referred to as “dorking”, can help you search more precisely and identify relevant data more quickly. For more precise searching, use advanced search operators. The SANS Google Hacking and Defence Cheat Sheet. | Search exact names, phone numbers, email addresses and combinations. Verify results. |
| 9-12 | Check username reuse | Google, Bing, DuckDuckGo, Brave Search; Google search operators. There are also specialist tools such as WhatsMyName, Sherlock and Maigret, to help find username exposure | Treat matches as leads. Confirm profile details before deciding an account is yours. |
| 12-16 | Reverse search profile images | Many reverse image search tools provide free tiers, others offer subscriptions at modest rates. Google Lens, Bing Visual Search, TinEye, Yandex Images, Lenso.ai; optional face search: PimEyes | Coverage varies. Use face-search tools only for your own images or with clear permission; verify the surrounding page. |
| 16-20 | Review public social profiles | Perform your checks logged out of any accounts, where relevant select public-view on the platforms you are searching, use privacy tools | Review what a stranger can see: posts, tags, profile fields, friend lists and patterns in locations or routines. |
| 20-23 | Check archived exposure | Wayback Machine allows you to search for any archived websites by url | Check whether old profiles, event pages, biographies, PDFs or directories have been archived. |
| 23-25 | Prioritise and act | Evidence log – creating one will turn a quick 25 minute search into a reliable record of what you found and what you did about it | Choose one high-value action: secure an account, restrict a profile, close an old account or start a removal request. |
| Optional | Check data-broker listings | Examples include: Mozilla Monitor, Incogni, DeleteMe, Optery and Privacy Bee | Coverage, cost and removal methods vary by country. Check the broker list and terms before relying on a service. |
2. Why This Matters Now
Incidents such as the Manchester Airports Group (MAG) data security incident show how ordinary service records can become useful when combined with other public details. MAG reported that data relating to about 8.7 million customers was accessed. Most records related to airport Wi-Fi sign-ups; a smaller set linked email addresses to parking, lounge, and FastTrack booking details, including phone numbers, vehicle registrations, and postcodes. No bank or payment details were reported as accessed.
The broader lesson is aggregation risk. You cannot control every organisation that holds your data, but you can reduce the information you publish, close unused accounts and make exposed credentials less useful.
3. What Is a Digital Footprint?
A digital footprint is the traceable data associated with your use of websites, apps, connected devices and online services. It includes obvious material such as profiles, posts and comments, but also account records, searches, purchases, location signals, identifiers, cookies, app permissions and data inferred from your behaviour.
How a digital footprint is made
| Part | How it is made | Examples |
|---|---|---|
| Active | You deliberately provide or publish it | Posts, reviews, forms, account profiles, uploaded photos |
| Passive | A service or device records it as you use it | IP address, cookies, location, searches, browsing and app telemetry |
| Contributed | Someone else publishes information about you | Tags, event lists, team pages, photographs and comments |
| Derived | A platform or broker combines data and makes an inference | Likely interests, routines, household links and advertising segments |
How a footprint becomes a profile
A single clue may seem harmless. The value comes from linkage: a repeated username, a reused profile photo, an old phone number, an employer page, and a travel post can combine to create a clearer profile than any one item alone. Your check should therefore consider combinations, not just isolated facts.
4. Before You Search: Three Rules of Engagement
Set clear boundaries before you begin. A personal open-source intelligence (OSINT) check should be lawful, proportionate and focused on reducing your own exposure - not investigating or monitoring somebody else.
Search only for yourself, or for another person with their clear permission. Use lawful public sources, record only what you need and treat every result as a lead until you verify it.
First - Act ethically
Do not turn the exercise into a hunt for leaked data. There is an important line between checking your exposure and accessing material without authorisation. You should only use legitimate services that report exposure to breaches, such as https://haveibeenpwned.com/ . Do not download leaked databases, search criminal forums or test whether someone else's information appears in a breach. Aside from legal and ethical issues, leaked data can be incomplete, deliberately manipulated or contain malware.
A personal OSINT check is about understanding what is publicly visible and reducing your own exposure.
Second - Keep a minimal evidence log
Record only enough information to support a decision:
- Date checked
- Source URL or account
- Visible information
- Verification status
- Risk level
- Action and follow-up date
This gives you a baseline for later checks without creating a new store of sensitive personal data. Keep the log secure and delete it when it is no longer useful.
Evidence log
Keep the log short and practical. Its purpose is to help you act, not to create a permanent file of personally identifiable information (PII).
Evidence log – example
| Date | Page or account | Exposed detail | Verified? | Risk | Action |
|---|---|---|---|---|---|
| 9 Sep 2026 | example.com/profile | Old phone number | Yes - personal documentation | Medium | Request removal |
| 9 Sep 2026 | Old forum account | Repeated username | Yes - user history for the following accounts | Low | Close account |
Third - Verify before acting
Treat search results as leads, not facts. Check the source, date and context, then compare the result with any reliable information you already control.
Names, usernames, photographs, and email addresses may belong to several people; copied or outdated content can also be misleading. If you cannot confirm a result belongs to you, mark it unverified and do not report, accuse or request removal on that basis.
Related reading
Learn more about what not to do: OSINT COWBOYS: A BEGINNER'S GUIDE (TO DOING IT WRONG!)
If you have concerns
If you find your own personal information that should not be public, save the relevant link and note what information is exposed without downloading or sharing more than necessary. Review the privacy settings on the account or website involved, remove outdated information where possible and contact the site operator or platform through its official reporting or removal process. Where relevant, change reused passwords, enable multi-factor authentication and check whether the exposed information is connected to other accounts.
If you believe the information creates a risk of fraud, harassment or immediate harm, report it to the relevant platform and contact the appropriate law enforcement or data protection authority.
5. Run the 25 Minute Check
“A matching name, image or username is a lead, not proof.”
Minutes 0-2: Set a safe baseline
Open a private window or separate browser profile so personalisation is less likely to distort results. Start your evidence log and list only the identifiers you plan to test current and old email addresses, name variants, usernames, phone-number formats and two or three profile photographs.
Write one rule at the top of the log: “verify before acting”. A matching name, image or username is a lead, not proof.
Minutes 2-5: Check your email addresses for known breaches
Check your personal and work email addresses on Have I Been Pwned. Use the result to identify accounts that need attention.
If an email address appears in a breach, treat it as a trigger for action rather than a reason to panic. Change reused passwords, enable multi-factor authentication (MFA), review account recovery details and close accounts you no longer need.
Use a password manager to create a different strong password for every account. Options that are already built-in to your own devices, such as Apple Passwords, Google Password Manager and Microsoft Password Manager are suitable for many people.

Minutes 5-9: Search your names and contact details
Search your full name in quotation marks, then try practical combinations: name and town or city, name and employer, name and former employer, name and school or university, name and phone number, and name and email address.
Search phone numbers in several formats, including with and without the country code. Search only your own number. Use quotation marks and compare Google, Bing, DuckDuckGo and Brave Search, as each engine indexes and ranks pages differently.
Search your full name in quotation marks, then try practical combinations: name and town or city, name and employer, name and former employer, name and school or university, name and phone number, and name and email address.
If you are a Google user, they provide guidance on how to refine your searches using advanced search operators, and this technique – often referred to as “dorking” can help you search more precisely and identify relevant data more quickly. The SANS Google Hacking and Defence Cheat Sheet is a useful defensive reference for quickly identifying your own exposed information.
Once you have performed each search, look beyond the first page of results. You may find old event entries, public PDFs, company biographies, archived web pages, directories or social media profiles you had forgotten about. Each result tells you something about how your name is being used and what is associated with it – however, an attacker can see the same information.
Phone numbers can appear in business listings, old advertisements, directories and public documents.
Once verified, prioritise details that create real risk: home address, personal phone number, family links, full date of birth, travel plans, signatures, identity documents or security-answer clues. If the information is on a site you control, remove or restrict it. If it is listed by a third party, use the site's removal process or contact its administrator.
Minutes 9-12: Check your usernames
Most people have reused a username somewhere: an old gaming handle, a forum name, an email prefix, a social account or a work login. Others use predictable variations such as “cityfan2022”, “cityfan2023” or “cityfan_24”.
Search each username in quotation marks and try old spellings, underscores, hyphens and numbers. You can also check WhatsMyName, Sherlock or Maigret. These tools can produce false matches, so confirm profile details before deciding an account is yours.
A repeated username can link accounts you intended to keep separate. If the same handle appears on a professional profile, social account, forum and marketplace listing, the combined history may reveal interests, routines, locations, views and contact details. Verify matches before assuming an account is yours.
If the account is verified, decide whether you still need it. Close unused accounts; where separate parts of your life should not connect, stop reusing the same username, profile photograph and biography.
Minutes 12-16: Reverse search profile photographs
Check current and previous profile photographs across multiple services, because coverage varies: Google Lens, Bing Visual Search, TinEye, Yandex Images and Lenso.ai. For face-focused searching, PimEyes may return additional results; use it only for your own images or with clear permission.
Check the context of every match. If an account is impersonating you, report it through the platform's official process. For an example of how fake recruiters exploit professional networks, see The Art of Connection.
Minutes 16-20: View social profiles as a stranger
Check your public profiles while logged out or via the platform's public-view feature. Ignore how the account looks to friends and focus on what a stranger or an attacker can see.
Look for patterns: regular locations, family links, workplace clues, vehicle details, school identifiers, favourite venues, hobbies, travel timing and posts that reveal when you are away from home.
Restrict posts, remove unnecessary tags, hide friend or follower lists where appropriate, and review profile fields that disclose more than you intended. For example, a photo from an airport, a check-in at a regular venue or a post about a family event can all combine to reveal routine behaviour, and that information is far more useful to a fraudster than any single post.
Platforms change their rules and privacy settings regularly, so information posted years ago may still be searchable, copied or visible to a wider audience than you intended. Check both old and current posts. Remove details that do not need to be public. You do not have to make every account private, but you should decide what each account is meant to reveal.
Minutes 20-23: Check archived or cached exposure
Some old pages remain discoverable after they disappear from the live web. Search for old profile pages, event pages, biographies, PDFs or directories, then check whether important pages appear in the Internet Archive Wayback Machine.
Archived pages cannot always be removed quickly, but knowing they exist helps you judge the risk and avoid relying on simple deletion as a complete fix.
Minutes 23-25: Prioritise and act
Sort your findings by risk and urgency. Do not try to fix everything in the final two minutes. Choose one high-value action and complete it, such as changing a reused password, enabling MFA, removing a public phone number, closing an old account or starting one removal request.
Prioritise findings by risk
| Priority | Examples | Action |
|---|---|---|
| High | Active impersonation, exposed home address, reused breached password, threats, fraud indicators | Secure accounts, preserve evidence and report immediately |
| Medium | Personal phone number, old address, family links, repeated usernames, copied profile photo | Remove, restrict, opt out or separate accounts |
| Low | Outdated biography, old hobby forum, harmless duplicate search result | Review later or monitor |
6. What to Do with Findings
Develop a simple routine: verify, assess, act. Do not report, accuse or request removal until you have checked the surrounding context and confirmed the result really relates to you.
- Verify that the result is yours. Check dates, profile details, photographs, writing style, locations and any associated email address before acting.
- Assess the risk. Prioritise information that can support fraud, impersonation, harassment, account recovery abuse or physical-world targeting.
- Act at the source where possible. Remove or restrict the original page, account, profile field or document before asking search engines to refresh or remove results.
- Record the action taken. Keep the date, URL, request method and any reference number so you can follow up without repeating the whole search.
Search-result removal is not deletion
Removing a search result is not the same as removing the source. Where possible, remove or restrict the information on the original website first, then request removal of the search results if the page still appears.
Data broker and people-search sites
Data broker and people-search sites may publish names, addresses, relatives, phone numbers or other inferred details, depending on your country. If you find a listing, use the site's official opt-out or privacy request process. Removal services can submit requests on your behalf in some regions, but coverage, cost and success rates vary. Check which countries and broker lists a service covers before relying on it.
7. Manage and Protect Your Digital Footprint
Cleanup is reactive. The larger gain comes from being proactive by reducing what is outside your control, limiting how easily separate accounts can be linked, and reviewing what remains public.
Use a pause before publishing
Before posting, uploading or completing a form, ask:
- Does this service need this information to deliver the features I want?
- Who can see it now, and could the audience or platform rules change later?
- Does the image reveal a location, badge, document, registration plate, screen, reflection or routine?
- Could it expose another person, especially a child, who has not agreed to it?
- Would I be comfortable if it were copied, taken out of context or found years from now?
Separate what does not need to connect
Use different email aliases or addresses for high-trust accounts, shopping and public contact. Never rely on separation as a substitute for strong account security.
- Avoid reusing the same username, profile image and biography across professional and private spaces when linkage creates risk.
- Keep recovery information private and current. Do not use public biographical facts as security-question answers.
- For public-facing work, consider a business contact route rather than publishing a personal mobile number or home address.
Manage what other people add
- Where possible, enable tag and mention review. Ask friends, relatives, clubs, schools and employers not to publish sensitive details without checking with you.
- Agree family rules for children's names, school identifiers, uniforms, locations and photographs. A child's footprint can begin before they can consent to it.
- Avoid posting real-time travel or absence. Share later with a limited audience if you want to share at all.
Build safer account habits
Privacy settings help, but screenshots, archives and reposts can outlive the original. Support privacy with habits that reduce both exposure and account risk:
- Use unique passwords and MFA for important accounts, especially email, banking, cloud storage and social media.
- Close accounts you no longer use, particularly old forums, marketplaces, travel accounts and services linked to old email addresses.
- Separate usernames where you do not want different parts of your life connected.
- Think before posting details that reveal regular routines, home area, family relationships, children's schools, vehicles or travel timing.
- Review app permissions, account recovery options and public profile fields every few months.
- Use privacy settings, but do not rely on them as your only protection. Screenshots, archives and reposts can outlive the original post.
8. If You Find Something Concerning
Act calmly and preserve enough evidence to support a report or removal request. Avoid engaging directly with an impersonator, harasser, or suspicious account if doing so could increase the risk.
- Capture minimal evidence: URL, date, platform, account name and a screenshot if needed.
- Secure affected accounts: change passwords, enable MFA, review recovery details and sign out of unknown sessions.
- Use platform reporting tools for impersonation, harassment, doxxing, fake recruiter accounts or unauthorised use of photographs.
- Contact the site owner or use the official removal process for pages exposing personal information.
- If there is fraud, stalking, threats, identity misuse or immediate danger, contact the relevant platform, financial provider, employer security team or local authorities as appropriate.
9. Repeat the Check and Maintain Your Footprint
A digital footprint changes as accounts, tags, permissions, breaches and copies appear. Develop a light maintenance routine and repeat the full check after a major breach or life event that changes your exposure.
A light maintenance schedule
| When | Check | Trigger for action |
|---|---|---|
| Monthly | Security alerts and unfamiliar account activity | Unexpected login, recovery change or MFA prompt |
| Quarterly | Public profiles, app permissions and connected services | Broader visibility, unused access or new data collection |
| Every 6 months | Repeat this 25 minute OSINT check | New listing, copied photo, stale account or breached address |
| Life event | Check after moving, changing jobs, a public dispute or a major breach | Old and new details connect or risk changes materially |
10. Conclusion
A personal OSINT check shows how separate clues can become a useful profile. An old username, a reused photograph, a public email address, or a breached account record may reveal much more when combined with other information.
“The goal is not to erase yourself from the internet.”
Use what you find to remove or restrict unnecessary information, secure exposed accounts and separate identities that do not need to connect. Act at the original source first, then ask search engines to refresh or remove outdated results.
The goal is not to erase yourself from the internet. It is to understand what is visible, verify what is accurate and make deliberate choices about what you leave behind.
Complete one high-value action today, then use the schedule above to decide when to repeat the check.
A simple 25 minute check may show more than you expect. Run it regularly, act on the findings and keep control of what your digital footprint reveals.
Authored by: The Coalition of Cyber Investigators,
Paul Wright (United Kingdom) & Neal Ysart (Philippines).
©2026 The Coalition of Cyber Investigators. All rights reserved.
The Coalition of Cyber Investigators is a collaboration between Paul Wright (United Kingdom) - Experienced Cybercrime, Intelligence (OSINT & HUMINT) and Digital Forensics Investigator; Neal Ysart (Philippines) - Elite Investigator & Strategic Risk Advisor, Ex-Big 4 Forensic Leader; and Lajos Antal (Hungary) - Highly experienced expert in cyberforensics, investigations, and cybercrime.
The Coalition unites leading experts to deliver cutting-edge research, OSINT, Investigations, & Cybercrime Advisory Services worldwide.
Our co-founders, Paul Wright and Neal Ysart, offer over 80 years of combined professional experience. Their careers span law enforcement, cyber investigations, open-source intelligence, risk management, and strategic risk advisory roles across multiple continents.
They have been instrumental in establishing foundational legal precedents and case law in cybercrime investigations and in contributing to the development of globally accepted guidance and standards for handling digital evidence. Their leadership and expertise form the foundation of the Coalition's commitment to excellence and ethical practice.
Alongside them, Lajos Antal, a founding member of our Boiler Room Investment Fraud Practice, brings deep expertise in cybercrime investigations, digital forensics, and cyber response, further strengthening our team's capabilities and reach.
The Coalition of Cyber Investigators, with decades of hands-on experience in cyber investigations and OSINT, is uniquely positioned to support organisations facing complex or high-risk investigations.
Our team's expertise is not just theoretical - it's built on years of real-world investigations, a deep understanding of the dynamic nature of digital intelligence, and a commitment to the highest evidential standards.