<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Project OSINT : OSINT Papers]]></title><description><![CDATA[In-depth research, methodologies, case studies, and analytical reports on open source intelligence and digital investigations.]]></description><link>https://projectosint.substack.com/s/osint-papers</link><image><url>https://substackcdn.com/image/fetch/$s_!eWzR!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6db31ae7-7c3a-4d08-91f3-f30694efb817_1024x1024.png</url><title>Project OSINT : OSINT Papers</title><link>https://projectosint.substack.com/s/osint-papers</link></image><generator>Substack</generator><lastBuildDate>Fri, 21 Aug 2026 02:50:21 GMT</lastBuildDate><atom:link href="https://projectosint.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Project OSINT]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[projectosint@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[projectosint@substack.com]]></itunes:email><itunes:name><![CDATA[Project OSINT]]></itunes:name></itunes:owner><itunes:author><![CDATA[Project OSINT]]></itunes:author><googleplay:owner><![CDATA[projectosint@substack.com]]></googleplay:owner><googleplay:email><![CDATA[projectosint@substack.com]]></googleplay:email><googleplay:author><![CDATA[Project OSINT]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Cyber Command suicide cluster: how to verify a defense story before you repost it]]></title><description><![CDATA[How to trace the US Cyber Command suicide cluster story back to primary sources, and which widely shared details do not survive the check.]]></description><link>https://projectosint.substack.com/p/the-cyber-command-suicide-cluster</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-cyber-command-suicide-cluster</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Fri, 14 Aug 2026 13:47:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9g-C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9g-C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9g-C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!9g-C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!9g-C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!9g-C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9g-C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2327688,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/211071194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9g-C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!9g-C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!9g-C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!9g-C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e7951a9-4475-4b49-a029-1359dcec08d3_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A short post lands in your feed. Five people at U.S. Cyber Command died by suicide in a single month. A four-star general is named. A dollar figure is attached to an unfunded mental-health request. The command, the post says, has linked the deaths together.</p><p>It reads like reporting. It has dates, names, numbers. And two of those details are wrong.</p><p>The general&#8217;s name is misspelled in a way that would send you to an empty search result. And the claim that the command &#8220;linked&#8221; the deaths misstates the single most important fact in the story: officials have not established that the deaths are connected. That distinction is the difference between a workforce tragedy and a conspiracy.</p><p>This is what most disinformation looks like in 2026. Not fabrication, but a real story that loses precision every time it is summarized, translated and reposted. The underlying reporting here is solid. What reaches you is a degraded copy. Learning to <strong>verify a defense story</strong> against primary sources is not an academic exercise &#8212; it is the difference between amplifying journalism and amplifying noise.</p><h2>What does &#8220;suicide cluster&#8221; actually mean?</h2><p>Start with the term itself, because it is doing the heaviest lifting and it is the term most often misread.</p><p>A suicide cluster is an administrative and epidemiological designation, not a causal one. It means deaths have occurred closer together in time than statistical expectation, in a defined population, at a rate that triggers a specific institutional response. Declaring a cluster does not assert that the deaths share a cause, that the people knew each other, or that anything links them beyond timing. It is a threshold for intervention.</p><p>Bloomberg reported on 6 August 2026 that as many as five people who worked for or closely with U.S. Cyber Command died by suicide between early June and early July, based on internal military communications, public records and officials. The command applied the cluster designation because of the compressed timeframe. Coverage consistently notes that officials have not determined the deaths are connected.</p><p>Note the hedge in the original: <strong>as many as five</strong>. Not &#8220;five.&#8221; The number in the summary post has hardened into a fact it was never reported as.</p><h2>How do you trace a claim back to its primary source?</h2><p>The following process took under an hour and requires nothing but a browser. It works on almost any defense or intelligence story.</p><p><strong>1. Identify the originating outlet, not the outlet you read.</strong> The post in your feed cites &#8220;sources of the broadcaster&#8221; or nothing at all. Search a distinctive phrase from it. In this case every downstream version &#8212; Japanese, Azerbaijani, Iranian, Russian &#8212; traces to one Bloomberg article. Everything else is aggregation. If you cannot find an originating outlet, that is your finding.</p><p><strong>2. Correct the proper nouns first.</strong> Names are the cheapest thing to check and the most revealing when wrong. The commander of U.S. Cyber Command is General Joshua M. Rudd, confirmed by the Senate on 10 March 2026 by a vote of 71-29, serving simultaneously as Director of the National Security Agency. He is not &#8220;Joshua Rad.&#8221; A misspelled principal is a reliable signal that the text has passed through several hands, at least one of which was working from audio or a machine translation.</p><p><strong>3. Go to the institution&#8217;s own publications.</strong> Cybercom.mil hosts Rudd&#8217;s full posture statement to the Senate Armed Services Committee, dated 28 April 2026. It confirms that the command supports U.S. Central Command and U.S. Special Operations Command &#8220;in their campaigns to counter Iranian aggression,&#8221; and that it participated in Operation Absolute Resolve in Venezuela. Primary documents also tell you what is absent: the posture statement makes no mention of the suicides or the mental-health funding request, which is consistent with a document written months earlier.</p><p><strong>4. Check the congressional record separately from the reporting about it.</strong> Senator Roger Wicker&#8217;s own site publishes his opening statement from that hearing verbatim. The relevant passage: &#8220;Our cyber operators are working overtime, and we are not ready to generate new forces to replace them. I am troubled that this effort is not moving fast enough. Current operations will always be priority number one, but we must ensure this pace is sustainable.&#8221; The summary post paraphrased this accurately. That is worth confirming rather than assuming.</p><p><strong>5. Separate what you verified from what you could not.</strong> The same post attributes a statement about the Iran war to Senator Jack Reed at that hearing. I could not locate a primary source for it. Cyber Command&#8217;s involvement in operations against Iran is independently documented &#8212; DefenseScoop reported in March 2026 that Rudd took command while Cybercom was supporting Operation Epic Fury &#8212; but the specific attribution to Reed remains unconfirmed. Say so, in those words. An honest gap is stronger than a smoothed-over one.</p><p><strong>6. Find the institutional record that predates the news.</strong> This is the step most people skip, and it is the one that changes the story. U.S. Cyber Command published its own account, through DVIDS, of embedding licensed mental-health providers inside its Fort Meade spaces. The open house was 11 May 2026; clinical care began 12 May. In it, Major CJ McAulay, the command psychologist, drew the comparison to special operations directly: both communities are &#8220;always in the fight,&#8221; but where SOF personnel rotate between training, deployment and recovery, cyber personnel are &#8220;almost never out of the fight.&#8221; He named the cost &#8212; &#8220;the personnel price of persistent engagement is real&#8221; &#8212; and its shape: disrupted sleep, exercise, nutrition and social interaction.</p><p>That statement was published by the command itself, weeks before the deaths, and it is the strongest available evidence for the workload interpretation. It is also the piece the viral summary rendered most vaguely.</p><p><strong>Common errors along the way.</strong> Treating an aggregator as a source. Trusting a number that arrives without its hedge. Reading &#8220;cluster&#8221; as &#8220;connected.&#8221; Accepting a paraphrased quote when the verbatim text is one search away. And the subtler one: stopping once the story is confirmed, instead of continuing until you understand what it means.</p><p><strong>Expected result.</strong> A version of the story you can defend line by line, with a short, explicit list of what you could not confirm.</p><h2>Why this matters beyond one story</h2><p>For newsrooms and independent publishers, the practical takeaway is that the verification cost of a story like this is roughly an hour, and skipping it produces text that is confidently wrong about the only thing that matters.</p><p>For anyone tracking defense and intelligence topics, the structural lesson is different. High-demand, low-density military communities &#8212; special operations, drone crews, now cyber operators &#8212; have produced comparable episodes before. The public record here does not require inference. A committee chairman said the pace was unsustainable in April. The command&#8217;s own psychologist described the mechanism in May. The commander placed mental-health sustainment second on his unfunded priorities list, at roughly $11 million, warning of burnout and force degradation without it. The deaths followed.</p><p>None of that establishes causation, and no responsible reading claims it does. What it establishes is that the warnings were on the record, in public, in the institution&#8217;s own words, before anyone needed them to explain anything.</p><p>The practical criterion to carry forward: when a summary tells you an institution has &#8220;linked&#8221; a set of events, go and read whether it actually said so. That single check catches most of what goes wrong between the original reporting and your feed.</p><p><em>If you or someone you know is struggling, help is available. In the United States, call or text 988, or chat at 988lifeline.org.</em></p><div><hr></div><p><strong>Sources:</strong> <a href="https://www.bloomberg.com/news/articles/2026-08-06/us-military-s-cyber-command-unit-grapples-with-cluster-of-deaths-by-suicide">Bloomberg</a> &#183; <a href="https://www.nsa.gov/About/Leadership/Leadership-View/Article/4439868/general-joshua-m-rudd-usa/">NSA &#8211; Gen. Rudd bio</a> &#183; <a href="https://defensescoop.com/2026/03/10/gen-rudd-cyber-command-commander-nsa-director/">DefenseScoop</a> &#183; <a href="https://www.dvidshub.net/news/568656/uscybercom-and-kimbrough-team-up-site-mental-health-care-cyber-force">DVIDS &#8211; USCYBERCOM/Kimbrough</a> &#183; <a href="https://www.armed-services.senate.gov/hearings/to-receive-testimony-on-the-posture-of-united-states-special-operations-command-and-united-states-cyber-command-in-review-of-the-defense-authorization-request-for-fiscal-year-2027-and-the-future-years-defense-program">SASC hearing 28/04/2026</a> &#183; <a href="https://breakingdefense.com/2026/01/venezuela-150-aircraft-cyber-effects-maduro-operation-how-it-happened-caine/">Breaking Defense</a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Definitive List of MCP Servers for OSINT (2026 Edition)]]></title><description><![CDATA[How Model Context Protocol Is Transforming Open Source Intelligence]]></description><link>https://projectosint.substack.com/p/the-definitive-list-of-mcp-servers</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-definitive-list-of-mcp-servers</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Thu, 06 Aug 2026 13:08:22 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cbc08664-5ddf-4a19-a4e3-7a1ee4b9725d_1200x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>The rise of Large Language Models has changed how analysts perform Open Source Intelligence (OSINT). Until recently, analysts manually queried dozens of tools&#8212;Shodan, VirusTotal, WHOIS databases, social media search engines, company registries&#8212;and correlated the findings themselves.</h4><p>Today, <strong>Model Context Protocol (MCP)</strong> allows an AI assistant to interact directly with these tools, orchestrating complete investigative workflows instead of simply answering questions.</p><p>As highlighted in recent research, the revolution is not about new OSINT tools, but about existing tools becoming autonomous through standardized AI connectors.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>What is an MCP Server?</h2><p>An MCP (Model Context Protocol) server exposes an application or data source through a standardized interface that any LLM can use.</p><p>Instead of building custom integrations for every AI model and every OSINT platform:</p><pre><code><code>LLM
 &#9474;
 &#9500;&#9472;&#9472; MCP &#8594; Shodan
 &#9500;&#9472;&#9472; MCP &#8594; VirusTotal
 &#9500;&#9472;&#9472; MCP &#8594; Maigret
 &#9500;&#9472;&#9472; MCP &#8594; WHOIS
 &#9500;&#9472;&#9472; MCP &#8594; Company Registry
 &#9500;&#9472;&#9472; MCP &#8594; DNS
 &#9500;&#9472;&#9472; MCP &#8594; BrightData
 &#9492;&#9472;&#9472; MCP &#8594; Internal Database
</code></code></pre><p>The AI becomes an <strong>orchestrator</strong>:</p><ul><li><p>decides which tool to use</p></li><li><p>executes the query</p></li><li><p>interprets the result</p></li><li><p>determines the next investigative step</p></li><li><p>writes the report</p></li></ul><p>This evolution aligns with the broader shift from manual intelligence collection to AI-assisted orchestration described in recent OSINT literature.</p><h2>Why MCP Matters for OSINT</h2><p>Traditional workflow:</p><pre><code><code>Investigator
    &#8595;
Shodan
    &#8595;
VirusTotal
    &#8595;
WHOIS
    &#8595;
DNS
    &#8595;
LinkedIn
    &#8595;
Company Registry
    &#8595;
Excel
    &#8595;
Report
</code></code></pre><p>MCP workflow:</p><pre><code><code>Investigator
      &#8595;
Prompt

"Investigate ACME Ltd"

      &#8595;

LLM

      &#8595;

MCP Servers

      &#8595;

Automatic Investigation

      &#8595;

Structured Intelligence Report
</code></code></pre><p>The analyst moves from executing searches to validating intelligence.</p><h1>Best MCP Servers for OSINT</h1><h2>1. Maigret MCP</h2><p>Purpose:</p><p>Username investigation</p><p>Capabilities:</p><ul><li><p>username enumeration</p></li><li><p>account discovery</p></li><li><p>social profile correlation</p></li><li><p>forgotten accounts</p></li><li><p>historical usernames</p></li></ul><p>Ideal for:</p><ul><li><p>SOCMINT</p></li><li><p>Threat Hunting</p></li><li><p>Insider investigations</p></li></ul><h4>Real Case</h4><p>A ransomware negotiator publishes under the username:</p><pre><code><code>darkphoenix</code></code></pre><p>Prompt:</p><blockquote><p><em>Find every public account associated with &#8220;darkphoenix&#8221;.</em></p></blockquote><p>The AI:</p><ul><li><p>launches Maigret</p></li><li><p>queries thousands of platforms</p></li><li><p>discovers:</p></li><li><p>GitHub</p></li><li><p>Reddit</p></li><li><p>Mastodon</p></li><li><p>old forum profile</p></li><li><p>Steam account</p></li><li><p>archived blogs</p></li></ul><p>The AI automatically correlates:</p><ul><li><p>reused avatar</p></li><li><p>reused email</p></li><li><p>reused bio</p></li><li><p>timezone</p></li></ul><p>instead of forcing the analyst to pivot manually.</p><h2>2. Shodan MCP</h2><p>Purpose</p><p>Infrastructure Intelligence</p><p>Capabilities</p><ul><li><p>exposed services</p></li><li><p>banners</p></li><li><p>CVEs</p></li><li><p>SSL certificates</p></li><li><p>open ports</p></li><li><p>technologies</p></li><li><p>vulnerabilities</p></li></ul><h4>Real Case</h4><p>Investigating a phishing domain.</p><p>Prompt:</p><blockquote><p><em>Analyze infrastructure related to phishing-example.com</em></p></blockquote><p>The AI:</p><ul><li><p>queries Shodan</p></li><li><p>discovers</p></li></ul><pre><code><code>IP
ASN
Hosting
Apache version
Open RDP
VPN
Exposed Jenkins
</code></code></pre><p>Then automatically pivots to:</p><ul><li><p>VirusTotal</p></li><li><p>WHOIS</p></li><li><p>DNS</p></li><li><p>SSL history</p></li></ul><h2>3. VirusTotal MCP</h2><p>Purpose</p><p>Threat Intelligence</p><p>Capabilities</p><ul><li><p>URL analysis</p></li><li><p>malware reports</p></li><li><p>domain reputation</p></li><li><p>IP reputation</p></li><li><p>passive DNS</p></li><li><p>relationships</p></li></ul><h4>Real Case</h4><p>Investigating malware.</p><p>Prompt:</p><blockquote><p><em>Investigate hash XXXXX.</em></p></blockquote><p>The AI retrieves:</p><ul><li><p>sandbox execution</p></li><li><p>contacted IPs</p></li><li><p>associated domains</p></li><li><p>malware family</p></li><li><p>previous campaigns</p></li></ul><p>Then automatically investigates every discovered IOC.</p><h2>4. OpenRegistry MCP</h2><p>Purpose</p><p>Corporate Intelligence</p><p>Capabilities</p><ul><li><p>shareholders</p></li><li><p>directors</p></li><li><p>subsidiaries</p></li><li><p>filings</p></li><li><p>addresses</p></li></ul><p>The recent MCP ecosystem includes connectors capable of querying company registries across dozens of jurisdictions, making corporate investigations significantly faster.</p><h4>Real Case</h4><p>A procurement fraud investigation.</p><p>Prompt:</p><blockquote><p><em>Investigate Alpha Consulting Ltd.</em></p></blockquote><p>The AI finds:</p><ul><li><p>directors</p></li><li><p>dissolved companies</p></li><li><p>beneficial owners</p></li><li><p>registered addresses</p></li><li><p>linked entities</p></li></ul><p>It automatically pivots into:</p><ul><li><p>LinkedIn</p></li><li><p>leaked documents</p></li><li><p>social media</p></li><li><p>procurement databases</p></li></ul><h2>5. Bright Data MCP</h2><p>Purpose</p><p>Web Collection</p><p>Capabilities</p><ul><li><p>scraping</p></li><li><p>structured extraction</p></li><li><p>JavaScript rendering</p></li><li><p>anti-bot browsing</p></li></ul><h4>Real Case</h4><p>Threat actor marketplace monitoring.</p><p>Prompt:</p><blockquote><p><em>Collect all vendor profiles mentioning &#8220;RedLine Stealer&#8221;.</em></p></blockquote><p>The AI extracts:</p><ul><li><p>usernames</p></li><li><p>prices</p></li><li><p>Telegram handles</p></li><li><p>Bitcoin wallets</p></li><li><p>PGP keys</p></li></ul><p>into a structured dataset.</p><h2>6. DNS Twist MCP</h2><p>Purpose</p><p>Typosquatting Detection</p><p>Capabilities</p><ul><li><p>homoglyph domains</p></li><li><p>phishing domains</p></li><li><p>certificate monitoring</p></li></ul><h4>Real Case</h4><p>Monitoring Microsoft.</p><p>Prompt:</p><blockquote><p><em>Detect suspicious Microsoft typosquatting domains.</em></p></blockquote><p>The AI:</p><ul><li><p>generates thousands of permutations</p></li><li><p>checks DNS</p></li><li><p>checks SSL</p></li><li><p>checks WHOIS</p></li><li><p>checks hosting</p></li></ul><p>and ranks suspicious domains automatically.</p><h2>7. ZoomEye MCP</h2><p>Purpose</p><p>Internet-wide reconnaissance</p><p>Ideal for:</p><ul><li><p>exposed services</p></li><li><p>ICS</p></li><li><p>IoT</p></li><li><p>infrastructure hunting</p></li></ul><p>Useful alternative to Shodan.</p><h2>8. WHOIS MCP</h2><p>Purpose</p><p>Registration Intelligence</p><p>Automatically retrieves:</p><ul><li><p>registrant</p></li><li><p>registrar</p></li><li><p>dates</p></li><li><p>abuse contacts</p></li><li><p>expiration</p></li><li><p>ownership history</p></li></ul><h2>9. DNS MCP</h2><p>Capabilities</p><ul><li><p>A</p></li><li><p>AAAA</p></li><li><p>MX</p></li><li><p>TXT</p></li><li><p>NS</p></li><li><p>SPF</p></li><li><p>DMARC</p></li><li><p>DKIM</p></li></ul><p>Useful during phishing investigations.</p><h2>10. Passive DNS MCP</h2><p>Allows automatic pivoting across</p><ul><li><p>historical IPs</p></li><li><p>historical domains</p></li><li><p>infrastructure reuse</p></li></ul><p style="text-align: center;"><code>Example Investigation</code></p><p>Suppose a security team discovers:</p><pre><code><code>invoice-update[.]com</code></code></pre><p>Instead of opening fifteen browser tabs, an analyst could prompt:</p><blockquote><p><em>Investigate invoice-update.com and identify related infrastructure, phishing indicators, historical ownership, malware associations, exposed services, and connected social profiles.</em></p></blockquote><p>The AI could automatically execute:</p><pre><code><code>WHOIS
&#8595;
DNS
&#8595;
Passive DNS
&#8595;
VirusTotal
&#8595;
Shodan
&#8595;
Certificate Transparency
&#8595;
ASN
&#8595;
GitHub
&#8595;
Maigret
&#8595;
Report generation
</code></code></pre><p>The output is a fully structured intelligence report requiring analyst validation rather than manual data collection.</p><h2>Current Limitations</h2><p>Despite their capabilities, MCP-powered agents are not replacements for analysts.</p><p>Recent research emphasizes an important methodological principle:</p><blockquote><p><strong>The agent must execute real tools and consume their outputs&#8212;not invent information.</strong> A WHOIS record retrieved from a registry is evidence; a WHOIS value &#8220;remembered&#8221; by an LLM is not.</p></blockquote><p>Human expertise remains essential for:</p><ul><li><p>evaluating source reliability</p></li><li><p>resolving conflicting evidence</p></li><li><p>assessing deception</p></li><li><p>applying legal and ethical constraints</p></li><li><p>making analytical judgments</p></li></ul><p>This mirrors established OSINT methodologies, where collection, processing, analysis, and reporting remain distinct phases requiring critical thinking rather than blind automation.</p><h2>The Future of AI-Assisted OSINT</h2><p>MCP is not replacing the traditional OSINT toolbox described by practitioners such as Michael Bazzell or Rae Baker; rather, it is providing a standardized orchestration layer on top of it. The same foundational resources&#8212;search engines, social networks, infrastructure intelligence, corporate records, and threat intelligence&#8212;are now accessible through AI-driven workflows instead of isolated manual searches.</p><p>The next generation of analysts will likely spend less time copying data between browser tabs and more time validating hypotheses, identifying patterns, and producing high-confidence intelligence. In that sense, MCP servers represent one of the most significant shifts in OSINT since the emergence of automated reconnaissance tools: not because they introduce entirely new sources, but because they enable AI to chain trusted tools together into repeatable investigative workflows while keeping the analyst in control of the final judgment.</p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A Login Page Still Beats a Zero-Day: Inside the Zimbra Phishing Campaign]]></title><description><![CDATA[An email arrives from your own mail platform.]]></description><link>https://projectosint.substack.com/p/a-login-page-still-beats-a-zero-day</link><guid isPermaLink="false">https://projectosint.substack.com/p/a-login-page-still-beats-a-zero-day</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 03 Aug 2026 13:03:46 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e391d83b-cbef-4108-9d84-a3677c5de64e_1448x1086.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>An email arrives from your own mail platform. It says your session is expiring and asks you to confirm your credentials before access is suspended. The layout matches what you have seen a hundred times. The link goes to a domain that looks close enough not to trigger a second thought. Nothing about the message demands anything unusual &#8212; just the same login you perform every morning.</p><p>That ordinariness is the entire mechanism behind one of 2026&#8217;s more consequential state-linked campaigns. On July 23, CISA and a group of international partner agencies published a joint advisory describing a phishing operation run by Russian state-supported actors against organizations running Zimbra Collaboration Suite (ZCS), a mail and collaboration platform used by government bodies, universities, and companies across the West. The activity has been tracked since at least July 2025 under several industry names, most prominently LAUNDRY BEAR, and also referenced as Void Blizzard, CL-STA-1114, or TA488, depending on which security vendor is doing the labeling.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>The technique is old. The target selection is not.</h2><p>There is no exotic tradecraft here. The actors send messages that imitate account or system notifications, direct recipients to a spoofed login page, and harvest whatever credentials get typed in. What makes the campaign worth an editorial pause is not the method &#8212; it is the contrast between how the intrusion is discussed and how it is actually carried out. Public conversation in 2026 tends to center on autonomous agents and AI-assisted intrusion tooling. This campaign shows a well-resourced state actor still getting results from a fake login form, because a fake login form still works.</p><p>The advisory notes the group is very likely to keep targeting ZCS and other mail systems used by Western organizations, combining known vulnerabilities with social engineering when a technical shortcut is not available. Mail platforms are attractive precisely because compromising one account rarely means compromising just that account. A mailbox holds contact lists, calendars, internal threads, and enough context to write the next phishing message with far more credibility than the first one had.</p><h2>Why &#8220;check the sender&#8221; is no longer sufficient advice</h2><p>Once an account is taken over, the attacker does not need to impersonate anyone. The next message in the chain can be sent from a real, previously trusted address &#8212; one the recipient has exchanged messages with for years. This is the detail that breaks the standard advice given to non-technical users. Checking who sent an email tells you nothing when the sender&#8217;s account has already been compromised. The email is, technically, legitimate. The judgment has to move from &#8220;who sent this&#8221; to &#8220;how did I get to this login page.&#8221;</p><p>That shift &#8212; from recognizing a suspicious sender to verifying a suspicious path &#8212; is the actual operational takeaway of this advisory, and it is something any reader can apply regardless of which mail platform they use.</p><h2>How to verify a login request instead of a sender</h2><p>The following sequence works for Zimbra, for any corporate webmail, and for most SaaS login flows. It does not require technical background, only a change in habit.</p><ol><li><p><strong>Do not open the login portal through the link in the email.</strong> Close the message. This removes the attacker&#8217;s ability to control where you land, which is the entire point of the exercise.</p></li><li><p><strong>Reach the service through a bookmark or an address you already know.</strong> Type it, or use a saved link created before the email arrived. If the platform is asking you to re-authenticate, it will ask again once you get there through your own route &#8212; a genuine prompt does not disappear because you arrived independently.</p></li><li><p><strong>Read the full domain, not just the part that looks familiar.</strong> A convincing brand name at the start of a URL means nothing if the actual domain that follows it belongs to someone else. This is the single most common point where verification fails, because attention naturally goes to the first recognizable word rather than the domain as a whole.</p></li><li><p><strong>Use authentication that is resistant to phishing where it is available.</strong> The advisory specifically recommends passkey-based authentication through a third-party identity provider for platforms &#8212; Zimbra included &#8212; that do not support passkeys natively. Passwords and even one-time codes can be relayed by an attacker in real time; a passkey tied to a specific domain cannot be reused on a fake one.</p></li><li><p><strong>Check active sessions and mail forwarding rules periodically</strong>, not only after suspicion arises. A forwarding rule quietly added to a compromised mailbox can leak every future message without the account owner noticing anything different in their own inbox.</p></li><li><p><strong>Report anomalous access immediately</strong>, even if the outcome turns out to be nothing. The advisory&#8217;s own framing &#8212; that this group is likely to keep operating against the same category of targets &#8212; makes early reporting a defense that helps the next recipient, not just the current one.</p></li></ol><p>The common mistake is stopping at step three and treating a plausible-looking domain as proof of safety. A domain can be plausible and still be wrong; verification means confirming the exact string, not judging whether it feels right.</p><h2>What this means beyond the security team</h2><p>For an ordinary employee, the practical change is habit, not tooling: stop clicking into login prompts from email, and start reaching services through known paths. For journalists and communicators who handle sensitive sources, a compromised mailbox is a much bigger loss than a single leaked message &#8212; it exposes the full pattern of who they talk to and when. For small organizations without dedicated security staff, the advisory&#8217;s emphasis on passkey-capable identity providers is a rare piece of guidance that is both concrete and affordable, since it does not require replacing the underlying mail platform.</p><p>There is also a research angle worth naming without turning it into a how-to. A phishing page is, itself, an artifact that can be studied &#8212; its domain registration, certificate, hosting provider, favicon, and source code can sometimes connect it to other campaigns run by the same infrastructure. That kind of analysis belongs strictly to passive, documentary observation: looking at what is publicly exposed about a page, never interacting with systems one is not authorized to test.</p><h2>The one thing worth carrying forward</h2><p>The lesson from this advisory is not &#8220;watch out for Russia&#8221; or &#8220;update your software,&#8221; even though both are true. It is that credential theft still travels through the most familiar gesture in anyone&#8217;s workday &#8212; logging in &#8212; and that the only reliable defense left is verifying the path you took to get there, not the message that suggested you take it. <a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p><em>CISA advisory AA26-204A, &#8220;Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite,&#8221; July 23, 2026 (cisa.gov)</em></p></div></div>]]></content:encoded></item><item><title><![CDATA[Ad Auctions as a Weapon: How Iran Allegedly Used Tracking Data to Locate U.S. Troops]]></title><description><![CDATA[A soldier doesn&#8217;t need to post his location online for an adversary to find him.]]></description><link>https://projectosint.substack.com/p/ad-auctions-as-a-weapon-how-iran</link><guid isPermaLink="false">https://projectosint.substack.com/p/ad-auctions-as-a-weapon-how-iran</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Fri, 24 Jul 2026 12:54:51 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/7d4594a6-d089-496f-a7e9-96fba7e1c1e4_330x330.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A soldier doesn&#8217;t need to post his location online for an adversary to find him. He just needs a phone with an ad-supported app running in the background &#8212; and someone on the other end willing to buy the bid stream.</p><p>That is the scenario now under scrutiny after a Financial Times investigation, reported on by Matthew Petti for Reason, into how Iran may have used commercial advertising data during its recent conflict with the United States to track American military personnel who had been moved out of their bases and into hotels and civilian offices in the region.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>The Case</h2><p>When U.S. forces evacuated several bases during the war, personnel were redistributed into hotels and civilian buildings across the Middle East, including in Iraqi Kurdistan and Bahrain. According to the Financial Times report, investigators suspect that in at least one instance in Iraqi Kurdistan, Iranian-aligned forces used advertising-tracking data to identify which hotels were housing U.S. troops. Iran-backed militias then struck several hotels in the region with drones, and Iranian forces bombed the Crowne Plaza in Bahrain directly, wounding two Pentagon employees. It remains unconfirmed which specific strikes, if any, were guided by ad-data targeting rather than other intelligence methods.</p><p>Byron Tau, the journalist whose reporting first exposed U.S. government use of commercial ad data to sidestep Fourth Amendment protections, told Reason in 2024 that any government running a competent cyber-intelligence program participates in this data trade, calling it an extraordinarily valuable source. The mechanism he described &#8212; governments buying access to advertising data that was never meant for intelligence use &#8212; is the same one now allegedly being turned against the personnel it once helped track.</p><p>The ad-tracking angle was not the only intelligence vector identified. The Financial Times report also documented use of Signaling System No. 7 (SS7), the protocol telecom carriers use to locate roaming phones internationally. An Iranian telecom operator reportedly sent a series of SS7 &#8220;pings&#8221; toward Arab countries, and Senator Ron Wyden told the Times that the Department of Homeland Security was aware Iran was using this method to locate American phones.</p><h2>The OSINT Workflow: How Ad-Data Targeting Actually Works</h2><p>The mechanism described in the reporting maps onto a replicable technical chain &#8212; the same chain any analyst studying ad-tech exposure would need to trace.</p><ol><li><p><strong>App-level data leakage.</strong> A phone runs an ordinary app &#8212; a fitness tracker, a prayer app, a game &#8212; that requests location and device-identifier permissions for advertising purposes. Precision here matters: the app doesn&#8217;t need to be built for surveillance, only to be ad-supported.</p></li><li><p><strong>Real-time bidding (RTB) exposure.</strong> When the app serves an ad, it broadcasts a bid request onto an RTB exchange &#8212; the auction system that lets advertisers compete for that specific ad slot. That request bundles location, device ID, and behavioral attributes into a single package visible to every bidder on the exchange, not just the winner.</p></li><li><p><strong>Demand-side platform (DSP) aggregation.</strong> Buyers use DSP software to place automated bids on these requests. Data brokers can sit inside this layer, harvesting the bid stream itself rather than actually buying ads &#8212; a use most RTB exchanges explicitly prohibit in their terms of service, but one the FTC&#8217;s own enforcement record shows is not reliably policed.</p></li><li><p><strong>Aggregation into a location pattern.</strong> A single bid request reveals one moment. Repeated requests, tied to a persistent device identifier, reveal a pattern &#8212; which hotel a phone returns to every night, for instance. This is the step that converts ad exhaust into targetable intelligence.</p></li><li><p><strong>Cross-validation against other signals.</strong> The Financial Times reporting notes that SS7 telecom pings and, more mundanely, social-media posts and human sources were also in play. In several Middle Eastern countries, which hotels housed U.S. troops was described as widely known locally. This matters methodologically: ad-data targeting, if it occurred, likely functioned as one corroborating layer among several, not a standalone targeting system.</p></li></ol><h2>Operational Takeaways</h2><ul><li><p><strong>Ad-supported apps are a location-disclosure risk independent of intent.</strong> Strava&#8217;s 2017 heat map and the flashcard-app exposure of U.S. nuclear personnel, later mapped by Bellingcat, show this isn&#8217;t hypothetical &#8212; it has already happened through completely unrelated apps.</p></li><li><p><strong>RTB bid streams are a data source, not just an ad mechanism.</strong> Anyone conducting OSINT work involving device or location data should treat the ad-bidding layer as its own leak vector, separate from the app&#8217;s stated function.</p></li><li><p><strong>Broker-level terms-of-service violations are hard to detect from outside.</strong> The FTC&#8217;s action against Mobilewalla for scraping RTB auctions in violation of exchange rules shows enforcement is reactive, not preventive &#8212; and that same settlement carved out an exception for geolocation data collected outside the U.S. for national-security purposes, which is worth flagging in any analysis of this ecosystem.</p></li><li><p><strong>User-facing controls are emerging but narrow.</strong> Google&#8217;s new RTB Control setting, introduced after a user lawsuit, lets individuals limit what reaches ad auctions &#8212; a mitigation, not a fix, since it depends on adoption by the same population least likely to know the risk exists.</p></li><li><p><strong>Attribution in this case remains unconfirmed.</strong> The Financial Times report raises the ad-tracking hypothesis; it does not establish which specific attacks, if any, were guided by it. Any downstream reporting or analysis should preserve that distinction rather than treat suspicion as confirmation.</p></li></ul><h2>Further Reading</h2><ul><li><p>Matthew Petti, &#8220;Iran Allegedly Used Ad Tracking to Hunt U.S. Soldiers,&#8221; <em>Reason</em></p></li><li><p>Financial Times investigation into ad-data use during the Iran conflict (as cited in the Reason report)</p></li><li><p>Byron Tau&#8217;s reporting on U.S. government use of commercial ad data</p></li><li><p>Bellingcat&#8217;s 2021 investigation into flashcard-app data and U.S. nuclear-weapons locations</p></li><li><p>FTC settlement with Mobilewalla on unauthorized RTB data collection</p></li></ul><h2>A Closing Note</h2><p>The version of this story that should concern analysts isn&#8217;t the sophistication of the tradecraft &#8212; buying access to an ad exchange is not exotic. It&#8217;s that the infrastructure was never built for this, was adopted by militaries anyway, and is now available to whoever else decides to buy in. Anyone tracking similar cases, or with documentation on other ad-data targeting incidents, is welcome to send it in for the next installment of this series.</p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[ The Drone That Follows a Thread]]></title><description><![CDATA[What fibre-optic FPV strikes in Ukraine teach us about verifying tactical videos from social media]]></description><link>https://projectosint.substack.com/p/the-drone-that-follows-a-thread</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-drone-that-follows-a-thread</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 20 Jul 2026 13:01:05 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/37f6f9cb-fbe2-49a5-bd3c-54c79427437e_518x316.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;fff8c17f-0a88-4ff6-8a94-ce6c21953903&quot;,&quot;duration&quot;:null}"></div><p>A strike video is not evidence by itself.</p><p>It is a claim with images attached.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>This distinction matters every time a military video appears on Telegram, X, YouTube, Facebook or a mirrored channel. A camera can show impact. It can show smoke, fire, damage, speed, direction and sometimes a target. But the useful OSINT question is not simply:</p><blockquote><p>Does the video look real?</p></blockquote><p>The better question is:</p><blockquote><p>What can this video prove, what does it only suggest, and what must be verified somewhere else?</p></blockquote><p>The latest example comes from Ukraine&#8217;s energy war.</p><p>According to Reuters, Russia has been using small FPV drones controlled through fibre-optic cables to damage high-voltage electricity substations in Ukraine&#8217;s Sumy region. The footage of the strikes was posted on Russian social media channels, then verified by the Centre for Information Resilience and confirmed by Reuters.</p><p>That is the fact pattern worth studying.</p><p>Not because the weapon is visually dramatic. Not because every tactical claim around it should be accepted. But because it shows how modern OSINT often works: public video, platform context, infrastructure analysis, battlefield mapping, expert verification and careful limits.</p><h3>The claim</h3><p>The reported tactic is simple in concept and difficult in practice.</p><p>Ukraine has protected important electrical substations with concrete structures and anti-drone netting. These defences are designed to protect expensive and critical transformer equipment from missiles and larger attack drones.</p><p>The Russian workaround, as described in Reuters&#8217; reporting, is to use fibre-optic FPV drones.</p><p>Unlike many radio-controlled drones, these systems are guided through a physical fibre-optic cable. That makes them harder to stop with electronic warfare as long as the cable remains intact. Instead of relying on a radio link that can be jammed, the drone follows a physical thread back to the operator.</p><p>The reported strike sequence is also important.</p><p>In the Reuters account, CIR investigator Joshua Scriven describes a pattern in which a first drone damages or opens the protective netting. A second drone then flies through the new gap and strikes the autotransformer.</p><p>This is not just a story about drones.</p><p>It is a story about adaptation.</p><p>One defence changes the target environment. The attacker studies the defence. The weapon changes. The video becomes a public signal that the tactic is being tested, repeated or advertised.</p><p>For an OSINT analyst, the video is only one layer.</p><h3>The OSINT problem</h3><p>When a strike video appears on a Russian social channel, there are at least five separate questions.</p><h4>1. Is the video from the claimed event?</h4><p>A real video can still be miscaptioned.</p><p>It may show a different date, a different location, a different target or a previous strike reposted as new. The first task is not to admire the footage. It is to detach the visual evidence from the caption.</p><p>Useful checks include:</p><p>- visual landmarks;</p><p>- infrastructure layout;</p><p>- road and field patterns;</p><p>- shadows and weather;</p><p>- visible defensive structures;</p><p>- upload history;</p><p>- earliest findable version;</p><p>- repost chains;</p><p>- whether the same clip appears with different claims.</p><p>The caption is a lead, not a conclusion.</p><h4>2. Can the target be geolocated?</h4><p>Energy infrastructure has a recognizable geometry.</p><p>Substations often have open yards, transformer bays, access roads, perimeter fencing, gantries and repeated structural patterns. Protective concrete structures and anti-drone netting may create additional visual signatures.</p><p>But a recognizable category is not a geolocation.</p><p>The analyst still needs to match the video to a specific site. That requires comparing visible features in the footage with satellite imagery, maps, prior imagery, local reporting or other public records.</p><p>In this case, Reuters reports that CIR verified multiple strikes, including attacks on large 330 kV substations and smaller 110 kV substations. The locations of the larger strikes were reported to be between 16 and 26 kilometres from the frontline, according to DeepState battlefield mapping cited in the Reuters report.</p><p>That distance matters because it helps evaluate a second claim: range.</p><p>If verified, the videos do not only show damage. They suggest that small fibre-optic FPV drones are being used at distances that matter operationally.</p><h4>3. Does the video show the method, or only the result?</h4><p>This is where many social media interpretations overreach.</p><p>A clip of a strike may prove that something hit something. It may not prove the full method.</p><p>To support the fibre-optic claim, an investigator has to look for additional indicators:</p><p>- visible cable or launch evidence;</p><p>- repeated strike behaviour;</p><p>- known characteristics of similar drones;</p><p>- technical assessment from specialists;</p><p>- corroboration from recovered components;</p><p>- consistency with battlefield reports;</p><p>- credible expert review.</p><p>Reuters&#8217; reporting relies on CIR verification and additional confirmation. That gives the public reader a stronger basis than an anonymous Telegram caption.</p><p>Still, the method should be described carefully:</p><blockquote><p>Public reporting indicates that fibre-optic FPV drones are being used.</p></blockquote><p>That is stronger than:</p><blockquote><p>This specific video alone proves the entire system.</p></blockquote><h4>4. What does the strike change?</h4><p>OSINT is not only about location.</p><p>A verified strike can answer a narrow question: where did this happen?</p><p>A better investigation asks what the event means within a system.</p><p>In this case, the target is not a random object. A high-voltage substation is part of a regional electrical network. Reuters cites Ukrainian energy expert Oleksandr Kharchenko saying that disabling the autotransformer in a 330 kV substation can bring down the entire transformer unit and that such a component is worth roughly $3.5 million.</p><p>The public-interest question becomes:</p><blockquote><p>Is this a tactical strike, or part of an effort to isolate a region from the national grid?</p></blockquote><p>Reuters reports that CIR interprets the strikes as part of a wider strategy to reduce the ability of a region to receive electricity from outside and then degrade local generation.</p><p>That is an analytical assessment, not a video fact.</p><p>It should be labelled as such.</p><h3>A practical verification frame</h3><p>For ProjectOSINT, this case is useful because it gives us a compact workflow for strike videos.</p><h4>Step 1: Preserve before judging</h4><p>Save the post, the video, the caption, the account name, the timestamp, the URL and any visible engagement/context.</p><p>If the platform is Telegram, preserve the channel post link when possible. If the clip is reposted elsewhere, keep the repost chain but do not treat the loudest post as the earliest source.</p><p>The first question is:</p><blockquote><p>What did the public record look like when we found it?</p></blockquote><h4>Step 2: Separate claims into units</h4><p>Do not verify the whole caption at once.</p><p>Break it down.</p><p>- This is a fibre-optic FPV drone.</p><p>- The target is a Ukrainian substation.</p><p>- The substation is in Sumy region.</p><p>- The strike happened recently.</p><p>- The drone bypassed protective netting.</p><p>- The target was an autotransformer.</p><p>- The tactic is being used repeatedly.</p><p>- The attacks are part of a regional blackout strategy.</p><p>Each claim needs a different kind of evidence.</p><p>Some may be visible in the video. Some may require maps. Some may require expert analysis. Some may remain hypotheses.</p><h4>Step 3: Geolocate the target, not the explosion</h4><p>Explosions are visually noisy.</p><p>Infrastructure is usually more useful.</p><p>Look for the stable features around the strike:</p><p>- transformer yard layout;</p><p>- access roads;</p><p>- fence lines;</p><p>- nearby tree lines;</p><p>- pylons and power lines;</p><p>- concrete protective structures;</p><p>- netting frames;</p><p>- rail or road access;</p><p>- building shadows;</p><p>- distinctive roof or ground patterns.</p><p>The goal is not to identify a general type of place. It is to connect the footage to a specific physical site.</p><h4>Step 4: Confirm timing with external context</h4><p>A video can be geolocated and still be old.</p><p>Chronolocation may use:</p><p>- first upload time;</p><p>- weather;</p><p>- vegetation;</p><p>- shadow direction;</p><p>- visible damage before and after;</p><p>- local outage reports;</p><p>- official statements;</p><p>- satellite imagery;</p><p>- other videos from the same incident.</p><p>If the timing cannot be confirmed, say so.</p><h4>Step 5: Explain the limit</h4><p>Every strong OSINT piece should contain a limit statement.</p><p>For this case:</p><p>- A public video may support the fact of a strike.</p><p>- Geolocation may support the target location.</p><p>- Repeated verified videos may support a pattern.</p><p>- Expert analysis may support the fibre-optic method.</p><p>- But strategic intent requires more caution.</p><p>The sentence should be boring and useful:</p><blockquote><p>The available public evidence supports the existence of a repeated strike pattern against substations, but it does not by itself prove the full command intent behind the campaign.</p></blockquote><p>That kind of sentence protects the investigation from becoming propaganda.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;13a4d1f9-f7e8-4f99-b0b8-bd34d976d53f&quot;,&quot;duration&quot;:null}"></div><h3>Why this case matters</h3><p>The visible story is about drones.</p><p>The OSINT story is about evidence discipline.</p><p>Fibre-optic FPV drones are important because they show how quickly battlefield methods adapt to defensive measures. Concrete protection, anti-drone nets and electronic warfare do not end the problem. They change the attack surface.</p><p>But the public information environment adapts too.</p><p>Military actors publish videos because videos persuade. They compress a complex event into a few seconds of apparent certainty. The viewer sees a drone approach, a gap, a target, an impact. The brain wants to complete the story.</p><p>OSINT has to slow that process down.</p><p>Not because the footage is useless.</p><p>Because the footage is only the beginning.</p><p>The method is:</p><blockquote><p>preserve, separate, geolocate, corroborate, classify, limit.</p></blockquote><p>If a strike video survives that process, it becomes evidence.</p><p>If it does not, it remains a claim with images attached.</p><p>That difference is the work.</p><div><hr></div><div class="callout-block" data-callout="true"><p><strong>Russia&#8217;s unstoppable fiber-optic drones shutting down Ukraine&#8217;s power grid piece by piece</strong></p><p>NATO-aligned media is sounding the alarm about the capabilities of Russia&#8217;s unjammable small, cheap drone fleets, reporting eight separate, successful attacks on 110 and 330 kV substations (four of each type) in Sumy, Ukraine, 16-26 km from the frontlines.</p><p>&#127759; Reuters describes the drones&#8217; complex, tandem-charge and follow-on strike tactics, involving one UAV breaking through anti-drone netting before a second flies through.</p><p>&#127759; The second drone then maneuvers around concrete sarcophagi structures Ukraine has built to try to protect its grid, straight into ventilation holes, to knock out substations that cost up to $3.5M apiece.</p><p>&#127759;The price of the drones? $2k. Immune to Ukraine&#8217;s NATO-provided electronic warfare systems, the small fiber optic FPV strike drones make short work of on-site defenses.</p><p>&#127759; The news agency did not go into details on the types of drones involved, but we know Russia&#8217;s FPV fiber-optic drone fleet includes:</p><p>&#9830;&#65039; <em>Knyaz Vandal Novgorodsky</em> &#8211; 30km range, 3 kg payload. Among the most widely available and used UAVs of this kind in Russia&#8217;s arsenal.</p><p>&#9830;&#65039; <em>Molniya-2: </em>Ultra-cheap, fixed-wing drone made of plywood, polystyrene and aluminium tubing. 6-10kg payload, 40-50km range, production cost as low as $500.</p><p>&#9830;&#65039; <em>Skvorets</em>: another FPV fiber-optic-ready platform. 3.5 kg payload, 8km range. 150km/h top speed.</p><p>&#9830;&#65039;<em> Veterok:</em> 7 kg payload, 30 km range. Designed for minelaying and targeting of armored vehicles.</p><p><em>The Knyaz Vandal Novgorodsky</em> pioneered FPV fiber-optic drone warfare, debuting in August 2024 during the campaign to expel Ukrainian forces from Kursk region. It was developed by SPC Ushkuynik, a civilian-volunteer-backed tech group based in Veliky Novgorod.</p><p>Created to counter the proliferation of vehicle-mounted and stationary radio jammers which degrade FPV signals, the ingenious concept is a nod to the 20th century wire-guided tech used in anti-tank guided missiles.</p></div><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Turning a Notes App Into an Intelligence Multiplier: The Obsidian Method]]></title><description><![CDATA[Uncommon OSINT: Obsidian, Semantic Meaning and NLP]]></description><link>https://projectosint.substack.com/p/turning-a-notes-app-into-an-intelligence</link><guid isPermaLink="false">https://projectosint.substack.com/p/turning-a-notes-app-into-an-intelligence</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Fri, 17 Jul 2026 13:00:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jGIG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jGIG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jGIG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 424w, https://substackcdn.com/image/fetch/$s_!jGIG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 848w, https://substackcdn.com/image/fetch/$s_!jGIG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 1272w, https://substackcdn.com/image/fetch/$s_!jGIG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jGIG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp" width="1400" height="908" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:908,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68266,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/207026335?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jGIG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 424w, https://substackcdn.com/image/fetch/$s_!jGIG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 848w, https://substackcdn.com/image/fetch/$s_!jGIG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 1272w, https://substackcdn.com/image/fetch/$s_!jGIG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13fa97c4-2ecd-4a81-9f26-f7334bcf5c49_1400x908.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A husband and wife working as Russian intelligence assets in two different countries, never once connected through their cover identities. The unknown locations of Ukrainian children transported to Russia, anticipated before official confirmation. A corporate structure untangled, a money-laundering chain traced. None of this came from a commercial intelligence platform. It came from Obsidian &#8212; a free note-taking application that Claudia Tietze, founder of the boutique OSINT shop Farallon, LLC, deliberately broke and rebuilt into a semantic analysis engine. She documents the method in her Medium piece, &#8220;Uncommon OSINT: Obsidian, Semantic Meaning and NLP&#8221; (April 2024).</p><h2>The Gap the Method Fills</h2><p>Most OSINT tooling is built for one job: collection. Scrapers, aggregators, people-search engines. What happens after collection &#8212; organizing fragments into relationships, testing whether two data points are actually connected, communicating the result &#8212; is left to spreadsheets, corkboards, or memory. Tietze&#8217;s argument is that a tool built for something else entirely, a digital garden for linked notes, already contains the primitives an analyst needs: bidirectional links, a graph view, and a plugin ecosystem that can pull in external ontologies. The question her workflow answers is whether note-taking software can be pushed to reveal relationships that were never typed in directly.</p><h2>System Map: What Lives Where</h2><p>The setup rests on four layers. The <strong>vault</strong> is the case file &#8212; a self-contained folder of notes, one vault per investigation. Each <strong>note</strong> carries a body of free text plus <strong>YAML front matter</strong>, a metadata block that functions like a note&#8217;s ID card. <strong>Wikidata</strong>, a free structured database with more than 100 million entries across 300-plus languages, supplies the semantic layer: imported into the YAML, it tags a concept with relationships such as &#8220;subclass of,&#8221; &#8220;used by,&#8221; or &#8220;field of work.&#8221; The <strong>graph view</strong> then renders every note as a node and every YAML relationship or in-text mention as an edge, native to the app and extendable through community plugins.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!D4jf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!D4jf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 424w, https://substackcdn.com/image/fetch/$s_!D4jf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 848w, https://substackcdn.com/image/fetch/$s_!D4jf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 1272w, https://substackcdn.com/image/fetch/$s_!D4jf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!D4jf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp" width="1400" height="835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:835,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:34406,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/207026335?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!D4jf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 424w, https://substackcdn.com/image/fetch/$s_!D4jf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 848w, https://substackcdn.com/image/fetch/$s_!D4jf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 1272w, https://substackcdn.com/image/fetch/$s_!D4jf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F02b6e433-3aa6-4947-ac3c-c5b4c11612bf_1400x835.webp 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Operational Method</h2><ol><li><p><strong>Create a dedicated vault per case.</strong> Reason: isolates one investigation&#8217;s links from another&#8217;s, and lets a vault be locked down or shared independently. What to look for: whether restricted mode needs to stay on while sensitive files are added.</p></li><li><p><strong>Import a term through the Wikidata Importer plugin (by Sam Rose).</strong> Action: search the term, review the list of candidate senses &#8212; a search for &#8220;spy&#8221; returns the profession alongside a 2015 film, a Belgian village, and a Team Fortress 2 class &#8212; and select the one matching the case. What it proves: only that the correct Wikidata entity was chosen, not that the imported relationships are complete; Wikidata is a generalist source, so intelligence-specific facets sometimes need to be added by hand.</p></li><li><p><strong>Add a Wikipedia extract to the note body via the Wikipedia plugin (by Jonathan Miller).</strong> This pulls the article&#8217;s first section into the note, giving later NLP and link-detection steps actual prose to work against instead of bare YAML fields.</p></li><li><p><strong>Review unlinked mentions before confirming links.</strong> Obsidian surfaces two categories: linked mentions (already-confirmed connections) and unlinked mentions (terms that appear in a note&#8217;s text or YAML but haven&#8217;t been formally linked yet). Each unlinked mention requires a human decision &#8212; link it with double brackets, or leave it. This step is where analyst judgment, not the plugin, does the verification work.</p></li><li><p><strong>Run the Graph Analysis algorithms (SkepticMystic and Emile) once the NLP plugin has indexed the vault.</strong> HITS scores which notes function as hubs versus authorities; Jaccard scores how much two specific notes have in common. What each result can prove: HITS flags structurally central concepts, useful for prioritizing which notes deserve deeper review; Jaccard flags candidate overlaps between two named entities. What it cannot prove: causation or intent &#8212; a high Jaccard score between two companies indicates shared vocabulary in the vault, not confirmed common ownership. It is a lead to check against source documents, not a finding on its own.</p></li><li><p><strong>Visualize with Graph Link Types (natefrisch01) and Juggl (Emile van Krieken).</strong> These add labeled, color-coded edges and interactive re-centering on a selected node &#8212; useful for tracing a specific relationship pathway (e.g., spy &#8594; intelligence agency &#8594; counterintelligence) rather than reading raw YAML.</p></li><li><p><strong>Build a working canvas with Link Exploder (Ben Hughes) and Semantic Canvas (Aaron Gillespie).</strong> Link Exploder auto-populates a canvas with a note&#8217;s incoming and outgoing links as cards; Semantic Canvas renders the underlying triples and shows empty cards for entities referenced in YAML but not yet created as notes &#8212; a direct prompt for what still needs collecting.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IXNA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IXNA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 424w, https://substackcdn.com/image/fetch/$s_!IXNA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 848w, https://substackcdn.com/image/fetch/$s_!IXNA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 1272w, https://substackcdn.com/image/fetch/$s_!IXNA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IXNA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp" width="1392" height="1088" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1088,&quot;width&quot;:1392,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:46424,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/207026335?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IXNA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 424w, https://substackcdn.com/image/fetch/$s_!IXNA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 848w, https://substackcdn.com/image/fetch/$s_!IXNA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 1272w, https://substackcdn.com/image/fetch/$s_!IXNA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b283f96-a9d2-4bcb-8ae9-bb3aa77d0975_1392x1088.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h6><em>Intelligence Playground Vault Wikidata Importer plugin interface. This allows you to see and select the concept that you want to import. If you don&#8217;t see a good option, you can alter your search term or import the definition closest to your subject matter and fine-tune it with your own YAML pruning and cultivation.</em></h6><h2>Critical Issues</h2><p>The method depends on custom YAML the analyst designs, which means the schema for one case (say, tracking espionage cells by arrest location, handler, and cover legend) has to be built by hand each time &#8212; there&#8217;s no default template for intelligence work. Obsidian also rejects certain characters in note titles, so any Wikidata entry containing a colon fails to import silently, and that gap needs a separate workaround. On the security side, several plugins call third-party services, meaning vault data can leave the machine; Tietze&#8217;s own advice is to populate Wikidata terms first, then lock the vault before adding sensitive case files. Finally, algorithmic outputs like HITS or Jaccard scores can be skewed simply because some notes have Wikipedia text added and others don&#8217;t &#8212; an artifact of uneven enrichment, not of the underlying relationships.</p><h2>Analytical Layer</h2><p>The structural pattern worth flagging is the deliberate separation between <em>linked</em> and <em>unlinked</em> mentions. Most graph tools show only confirmed edges; Obsidian&#8217;s unlinked-mentions pane keeps candidate connections visible without forcing a premature decision, which is closer to how an analyst actually works through ambiguous evidence. A second pattern: pairing a generalist ontology (Wikidata) with a bespoke, case-specific YAML schema lets one vault serve dual purposes &#8212; it inherits broad semantic coverage while still answering the narrow question a specific investigation needs answered, such as who shares a handler or a cover business across an espionage network.</p><h2>Closing</h2><p>The tools that matter most in an investigation aren&#8217;t always the ones built for it. Obsidian was never designed for espionage tracking or corporate structure mapping &#8212; the fact that it can be repurposed for both, using nothing more than free plugins and a well-designed YAML schema, is the actual takeaway: an analyst&#8217;s leverage often comes from bending general-purpose software into a shape the vendor never intended, not from waiting for a purpose-built product.</p><div><hr></div><p><strong>Further reading:</strong> Claudia Tietze, <em>&#8220;Uncommon OSINT: Obsidian, Semantic Meaning and NLP,&#8221;</em> Medium, April 12, 2024 &#8212; first article in her Uncommon OSINT series. Tools referenced: Obsidian, Wikidata Importer (Sam Rose), Wikipedia plugin (Jonathan Miller), NLP and Graph Analysis (SkepticMystic, Emile van Krieken), Graph Link Types (natefrisch01), Juggl (Emile van Krieken), Link Exploder (Ben Hughes), Semantic Canvas (Aaron Gillespie), Charts View (Caronchen).</p><p><em>Have you repurposed a mainstream tool for OSINT work? ProjectOsint wants to hear about it &#8212; reply with your case.</em></p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[Preserve the Source Before It Disappears]]></title><description><![CDATA[The first version of a source is often the one you need most.]]></description><link>https://projectosint.substack.com/p/preserve-the-source-before-it-disappears</link><guid isPermaLink="false">https://projectosint.substack.com/p/preserve-the-source-before-it-disappears</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 13 Jul 2026 01:00:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!CLWz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CLWz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CLWz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CLWz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CLWz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CLWz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CLWz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:99109,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/206707419?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CLWz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!CLWz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!CLWz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!CLWz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1d832708-6bdb-4e06-a02d-9461e3b71dc5_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The first version of a source is often the one you need most.</p><p>It is also the easiest one to lose.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>A post can be deleted. A company page can be edited. A profile can be renamed. A file can be replaced at the same URL. A search result can disappear. An AI answer can cite a page that later changes, moves, or no longer says what it seemed to say.</p><p>For OSINT work, the problem is practical:</p><div class="callout-block" data-callout="true"><p>If the source changes before you document it, your investigation may lose the evidence it was built on.</p></div><p>That does not mean every edit is suspicious.</p><p>Web pages change. Platforms moderate content. Accounts evolve. Organizations update their sites. Mistakes get corrected.</p><p>But if you cannot reconstruct what you saw, where you saw it, when you saw it, and what part of the claim it supported, the evidence chain becomes weaker.</p><p>Preservation should happen before interpretation.</p><h3>A source is not automatically proof</h3><p>This is the mistake worth avoiding.</p><p>Someone captures a screenshot, saves an archive link, or copies a quote, and then treats the source as if it proves the whole claim.</p><p>It usually does not.</p><p>A source may show that a name appeared on a page.</p><p>It may not prove why the name appeared there.</p><p>An archive may show that text was visible at a URL on a certain date.</p><p>It may not prove that the text was accurate.</p><p>A screenshot may preserve a post.</p><p>It may not prove that the event described in the post happened as claimed.</p><p>Good OSINT keeps the claim narrow.</p><p>The question is not:</p><div class="callout-block" data-callout="true"><p>Does this source prove the story?</p></div><p>The better question is:</p><div class="callout-block" data-callout="true"><p>Which specific claim component does this source support, and what does it not prove?</p></div><h3>The five-minute preservation habit</h3><p>When a source may matter, capture enough context before it changes:</p><div class="callout-block" data-callout="true"><p>1. Record the exact URL.</p><p>2. Record the date, time and time zone checked.</p><p>3. Take a contextual screenshot.</p><p>4. Archive the page when legal and technically possible.</p><p>5. Copy the exact claim text.</p><p>6. Record basic source metadata.</p><p>7. Connect the source to one claim component.</p><p>8. Write the limitation.</p></div><p>The limitation is not a minor note.</p><p>It is what prevents one captured source from becoming a false conclusion.</p><p>For example:</p><div class="callout-block" data-callout="true"><p>The archived page shows that this profile listed the person as an advisor on 10 July 2026.</p><p>It does not independently confirm that the person accepted the role, still held it, or approved the wording.</p></div><p>That kind of narrow statement is less dramatic.</p><p>It is also more useful.</p><h3>Context matters more than a cropped capture</h3><p>A screenshot of one sentence is weak.</p><p>A contextual screenshot is stronger.</p><p>It should preserve the surrounding evidence: page title, visible source name, URL when possible, timestamp or publication date if visible, the relevant claim, and enough page structure to identify the source later.</p><p>For a social post, capture the post in context.</p><p>For a website, capture the section that contains the claim and enough header or page structure to identify the page.</p><p>For a document, capture the title, date, page number if available, and the specific passage.</p><p>The screenshot should answer:</p><div class="callout-block" data-callout="true"><p>What did I see, where did I see it, and what was around it?</p></div><h3>Deletion is a signal, not a conclusion</h3><p>A disappearing source may matter.</p><p>But disappearance alone does not prove intent.</p><p>A page can change for ordinary reasons. A post can be removed because it was wrong, because it was sensitive, because it violated platform rules, because it attracted attention, or because the author changed strategy.</p><p>The job is not to turn disappearance into a story too quickly.</p><p>The job is to preserve the earlier state, document the change, and separate what is known from what is inferred.</p><p>That is the discipline behind source-chain work.</p><p>Preserve first.</p><p>Interpret later.</p><p>I wrote the full ProjectOSINT workflow here:</p><p><a href="https://projectosint.com/source-disappearing-preserve-osint-evidence/">https://projectosint.com/source-disappearing-preserve-osint-evidence/</a></p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The AI Coding Agent May Not Use a Bot Account]]></title><description><![CDATA[The easiest way to look for AI coding agents in open source is to search for the bot account.]]></description><link>https://projectosint.substack.com/p/the-ai-coding-agent-may-not-use-a</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-ai-coding-agent-may-not-use-a</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Wed, 08 Jul 2026 12:18:59 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9vCE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9vCE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9vCE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9vCE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9vCE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9vCE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9vCE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68592,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/205494793?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9vCE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9vCE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9vCE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9vCE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff9a15900-5cca-4c69-b77d-abca47149b23_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The easiest way to look for AI coding agents in open source is to search for the bot account.</p><p>That is also the first mistake.</p><p>A visible bot is useful. It gives you a name, a timestamp, a pull request, a public identity. It feels like clean evidence.</p><p>But AI coding agents do not always work that way.</p><p>Sometimes they open pull requests under an automated account.</p><p>Sometimes they leave traces in commit messages.</p><p>Sometimes they appear through configuration files.</p><p>Sometimes they generate code locally and a human commits the final change.</p><p>Sometimes the only public clue is a pattern across repository files, pull request metadata, commit history and timeline.</p><p>So the better OSINT question is not:</p><pre><code><code>Was this written by AI?</code></code></pre><p>The better question is:</p><pre><code><code>Which public signals support agent involvement, and how strong is each one?</code></code></pre><p>That change matters because AI coding agents are no longer just private developer tools. They are entering the open-source supply chain: writing code, modifying tests, touching configuration files, preparing pull requests, updating dependencies and sometimes operating close to credentials, local context and release workflows.</p><p>If we want to understand that ecosystem, we need better evidence discipline.</p><h2>One Signal Is Not Enough</h2><p>A recent paper by Arsham Khosravani and Audris Mockus looked at AI coding agent traces across more than 180 million Git repositories.</p><p>The most useful finding, for OSINT work, is not only the scale.</p><p>It is the method.</p><p>The authors did not rely on one signal. They combined configuration-file scanning, commit-message analysis, author-identity matching and bot-signature lookup.</p><p>That matters because bot-account lookup alone misses too much.</p><p>In one snapshot, their multi-method approach identified 850,157 Claude Code commits. Bot-account lookup recovered only 28,154 of them.</p><p>The exact numbers will change.</p><p>The lesson is more stable:</p><pre><code><code>If you only count the obvious bots, you are not measuring agent activity.
You are measuring the part of agent activity that chose to identify itself.</code></code></pre><p>For open-source OSINT, this is the key shift.</p><p>The repository has to be read as a system.</p><h2>Adoption, Assistance and Authorship Are Different Claims</h2><p>This is where weak analysis can become misleading.</p><p>A repository can show signs of AI-agent adoption without proving that a specific commit was generated by an agent.</p><p>A commit can be agent-assisted without being fully agent-authored.</p><p>A pull request can be opened by an agent and then rewritten by a human.</p><p>A human can use an agent privately and leave no bot identity in the public record.</p><p>Those are different findings.</p><p>They need different language.</p><p>Useful labels are:</p><pre><code><code>Agent-capable workflow
Agent-assisted contribution
Agent-attributed contribution</code></code></pre><p>An agent configuration file may support the first label.</p><p>A commit message or co-author line may support the second.</p><p>A bot account or direct tool attribution may support the third.</p><p>Collapsing them into one sentence is how a clue becomes an overclaim.</p><h2>What to Look For</h2><p>A practical repository review should start with four layers:</p><ul><li><p>identity signals;</p></li><li><p>commit-message and co-author patterns;</p></li><li><p>configuration files and tool artifacts;</p></li><li><p>pull request behavior.</p></li></ul><p>None of these is perfect.</p><p>A bot account can miss local agent use.</p><p>A commit message can be edited.</p><p>A configuration file can show capability, not authorship.</p><p>A pull request can show automation without proving that every line survived without human review.</p><p>The useful work is not finding one impressive trace.</p><p>It is asking whether the traces converge.</p><pre><code><code>identity + metadata + configuration + timeline + code change + review trail + limits</code></code></pre><p>That is the evidence chain.</p><h2>Why This Is a Supply-Chain Question</h2><p>Agent adoption is not automatically a security problem.</p><p>But it changes the attack surface.</p><p>A coding agent can read instructions, follow documentation, run setup commands, edit files, generate tests, call package managers or prepare code for review. If it works inside a developer environment, it may be close to secrets, private repositories, browser sessions or deployment tools.</p><p>This does not mean every AI-assisted repository is unsafe.</p><p>It means agent activity should become part of the repository risk model.</p><p>When did agent traces first appear?</p><p>Were security-sensitive files touched?</p><p>Did the review process change?</p><p>Were dependency, CI or release workflows affected?</p><p>Is the evidence about adoption, assistance or attribution?</p><p>Those questions are less dramatic than saying &#8220;AI wrote the code.&#8221;</p><p>They are also more useful.</p><h2>The Full Workflow</h2><p>I published the full ProjectOSINT workflow here:</p><p><a href="https://projectosint.com/detect-ai-coding-agents-open-source-repositories/">https://projectosint.com/detect-ai-coding-agents-open-source-repositories/</a></p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[When AI Agents Become Insider Threats]]></title><description><![CDATA[The most useful way to investigate an AI agent is not to ask whether it is intelligent.]]></description><link>https://projectosint.substack.com/p/when-ai-agents-become-insider-threats</link><guid isPermaLink="false">https://projectosint.substack.com/p/when-ai-agents-become-insider-threats</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 06 Jul 2026 12:13:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Lj8u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Lj8u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Lj8u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lj8u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lj8u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lj8u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Lj8u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70913,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/204612556?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Lj8u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Lj8u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Lj8u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Lj8u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7242ab3-c3a6-45eb-a77c-b8dac8ddaa04_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The most useful way to investigate an AI agent is not to ask whether it is intelligent.</p><p>Ask what it can touch.</p><p>An agent that writes a document is one kind of system. An agent that can edit files, call APIs, query internal data, open tickets, deploy code, change permissions, send messages or trigger workflows is another.</p><p>The risk changes when the model stops being only a generator and becomes an actor inside a system.</p><p>That is why <a href="https://deepmind.google/blog/securing-the-future-of-ai-agents/">Google DeepMind&#8217;s recent AI Control Roadmap</a> is worth reading as an OSINT and security document, not only as an AI safety document. The company describes a framework for securing internal systems against increasingly capable AI agents and explicitly borrows from cybersecurity. Its core planning assumption is simple and uncomfortable: treat powerful internal agents as if they could be imperfectly aligned and capable of unexpected behavior.</p><p>In cybersecurity terms, the agent starts to look less like a tool and more like a potential insider.</p><p>Not because today&#8217;s agents are all malicious. Not because every automation is dangerous. But because a system with access, goals, tools and partial autonomy creates an evidence problem.</p><p>If something goes wrong, you need to know what happened.</p><p>And you need to know before the damage is irreversible.</p><h2>The OSINT Question Is About Access</h2><p>Public discussion about AI agents often focuses on capability.</p><p>Can the agent code?<br>Can it browse?<br>Can it reason?<br>Can it complete a task?<br>Can it use tools?</p><p>Those questions matter. But for investigative and defensive work, the first question is more operational:</p><pre><code><code>What permissions does the agent have?</code></code></pre><p>An AI agent with no external access can still produce bad information. That is a quality and verification problem.</p><p>An AI agent with external access can create a security problem:</p><ul><li><p>it can read information it should not use;</p></li><li><p>it can combine data from separate contexts;</p></li><li><p>it can trigger actions faster than a human reviewer can follow;</p></li><li><p>it can misunderstand an instruction and over-execute;</p></li><li><p>it can delete, overwrite, expose or transmit data;</p></li><li><p>it can be influenced by malicious inputs from the environment;</p></li><li><p>it can make an action look intentional even when it came from a flawed task interpretation.</p></li></ul><p>This is why the unit of analysis should not be &#8220;the model&#8221; alone.</p><p>The unit of analysis is the agentic system:</p><pre><code><code>model + tools + permissions + memory + instructions + environment + logs + human oversight</code></code></pre><p>If one of these elements is missing from your notes, your picture is incomplete.</p><h2>Why DeepMind Uses an Insider-Threat Lens</h2><p>Google DeepMind says its roadmap treats untrusted AI agents as potential insider threats, similar to a rogue employee who already has access inside an organization.</p><p>That comparison is useful because it moves the conversation away from vague fear.</p><p>An insider-threat model does not start with the assumption that every insider is hostile. It starts with the fact that insiders have privileges. They can already reach systems, documents, credentials, channels, databases or workflows that outsiders cannot reach.</p><p>An AI agent with internal tool access creates a similar planning problem.</p><p>The question is not only:</p><pre><code><code>Will the model refuse harmful requests?</code></code></pre><p>The better questions are:</p><pre><code><code>Which actions can it take?
Which systems can it reach?
Which actions require approval?
Which actions are logged?
Which actions can be reversed?
Which actions are blocked in real time?
Which actions are only reviewed after the fact?</code></code></pre><p>This is the OSINT value of the roadmap: it gives analysts a way to translate AI safety language into observable system behavior.</p><h2>Detection Is Not the Same as Control</h2><p>One of the most important distinctions in the DeepMind post is between detection, prevention and response.</p><p>Detection means the system can notice a concerning action, plan or pattern.</p><p>Prevention means it can block the action before it happens.</p><p>Response means it can contain, reverse, investigate or escalate after something has happened.</p><p>These should not be collapsed.</p><p>A company saying &#8220;we monitor agents&#8221; is not the same as saying &#8220;we can stop high-risk actions in real time.&#8221;</p><p>For OSINT work, this distinction gives you a simple claim-checking method.</p><p>When an organization describes agent safeguards, break the claim into three columns:</p><p>The point is not to demand perfect control. That does not exist.</p><p>The point is to avoid treating a monitoring claim as if it were a containment claim.</p><h2>The Evidence Log for an AI Agent</h2><p>If an AI agent is involved in a mistake, leak, unexpected action or security incident, the investigation needs an evidence log.</p><p>Not a transcript dump.</p><p>A structured log.</p><p>Use this template.</p><pre><code><code>Agent:
Name, version, provider, deployment context.

Task:
What was the agent asked to do?

User instruction:
Original instruction, relevant constraints, approval requirements.

System instruction:
Known policy, guardrails, tool-use rules, role boundaries.

Tools:
Which tools were available?

Permissions:
Read, write, execute, send, delete, deploy, invite, export, query.

Data access:
Which files, systems, channels, repositories or records could the agent access?

Action sequence:
What did the agent do, in order?

Human checkpoints:
Where did a human approve, reject, edit or miss an action?

External inputs:
Which web pages, documents, emails, tickets, prompts or data sources influenced the agent?

Observed failure:
Misinterpretation, over-execution, policy bypass, data exposure, deletion, unauthorized action, hallucinated evidence.

Evidence level:
Direct log, screenshot, audit event, vendor statement, third-party report, user claim.

Reversibility:
Can the action be undone? How quickly?

Open questions:
What cannot be verified from the available evidence?</code></code></pre><p>This template is deliberately boring.</p><p>That is the point.</p><p>Agent incidents will be difficult to analyze if every discussion begins with abstract terms: autonomy, alignment, intelligence, safety, trust.</p><p>A good evidence log forces the investigation back to observable events.</p><h2>Watch the Difference Between Error and Adversarial Behavior</h2><p>DeepMind notes that many flagged events in its analysis did not appear to come from adversarial intent. They often came from agent misinterpretation or over-eagerness to achieve a user&#8217;s goal.</p><p>This distinction matters.</p><p>If an agent deletes data because it misunderstood a task, that is different from an agent trying to hide a harmful action.</p><p>But the operational impact can still be serious.</p><p>For investigators and defenders, intent should not be guessed too early. Start with behavior.</p><p>Ask:</p><ul><li><p>What instruction did the agent receive?</p></li><li><p>What goal did it appear to optimize?</p></li><li><p>Which constraints did it ignore?</p></li><li><p>Did it ask for confirmation?</p></li><li><p>Did it operate inside its expected scope?</p></li><li><p>Did it use a tool in a way the user could reasonably anticipate?</p></li><li><p>Did the system warn, block or log the action?</p></li></ul><p>Only after that should you move toward interpretation.</p><p>The mistake is to turn every failure into a drama about rogue AI, or every failure into a harmless bug. Both shortcuts hide the evidence.</p><h2>A Practical Risk Matrix</h2><p>For a quick assessment, map agent actions across two dimensions:</p><pre><code><code>Impact if wrong
Reversibility after execution</code></code></pre><p>Low impact and reversible:</p><ul><li><p>drafting text;</p></li><li><p>summarizing public material;</p></li><li><p>creating a local note;</p></li><li><p>suggesting a query;</p></li><li><p>preparing a non-sent message.</p></li></ul><p>Medium impact or partially reversible:</p><ul><li><p>editing shared documents;</p></li><li><p>moving files;</p></li><li><p>opening tickets;</p></li><li><p>updating metadata;</p></li><li><p>querying internal knowledge bases;</p></li><li><p>drafting messages in a live workspace.</p></li></ul><p>High impact or hard to reverse:</p><ul><li><p>deleting data;</p></li><li><p>changing permissions;</p></li><li><p>sending messages externally;</p></li><li><p>deploying code;</p></li><li><p>modifying production systems;</p></li><li><p>exporting sensitive information;</p></li><li><p>connecting new integrations;</p></li><li><p>approving transactions or access requests.</p></li></ul><p>This matrix should shape the control level.</p><p>Low-risk actions can be reviewed asynchronously.</p><p>High-risk actions need real-time approval, sandboxing, or hard blocks.</p><p>If an agent can perform high-impact, hard-to-reverse actions with only delayed review, the problem is not the agent&#8217;s personality. The problem is system design.</p><h2>What to Check Before Trusting an Agentic Workflow</h2><p>Before relying on an AI agent in a research, journalism, OSINT or security workflow, ask these questions:</p><ol><li><p><strong>Scope</strong><br>What is the agent allowed to do?</p></li><li><p><strong>Tool access</strong><br>Which tools can it call without asking?</p></li><li><p><strong>Data boundaries</strong><br>Can it access private, sensitive, unpublished or cross-client data?</p></li><li><p><strong>Action boundaries</strong><br>Can it write, delete, send, publish, deploy or invite?</p></li><li><p><strong>Approval</strong><br>Which actions require human confirmation?</p></li><li><p><strong>Logging</strong><br>Can you reconstruct the full action sequence?</p></li><li><p><strong>External influence</strong><br>Can web pages, emails, documents or tickets inject instructions into the workflow?</p></li><li><p><strong>Rollback</strong><br>What can be undone, and how fast?</p></li><li><p><strong>Monitoring</strong><br>Are you looking only at outputs, or also at actions and tool calls?</p></li><li><p><strong>Evidence retention</strong><br>How long are logs, transcripts and tool events preserved?</p></li></ol><p>This is not only an enterprise checklist.</p><p>It applies to smaller workflows too: a research assistant connected to documents, a coding agent inside a repository, a browser agent that can submit forms, or a content agent that can publish drafts.</p><p>The moment an AI system can act, the evidence trail becomes part of the safety model.</p><h2>The Takeaway</h2><p>AI agents make verification harder because they sit between instruction and action.</p><p>They can read, decide, call tools, interpret context and produce outputs that look coherent even when the path was flawed.</p><p>For OSINT, that means we need to stop treating agent output as the only artifact worth checking.</p><p>The important artifacts are:</p><ul><li><p>the instruction;</p></li><li><p>the available tools;</p></li><li><p>the permissions;</p></li><li><p>the data accessed;</p></li><li><p>the action sequence;</p></li><li><p>the human checkpoints;</p></li><li><p>the logs;</p></li><li><p>the blocked actions;</p></li><li><p>the failed actions;</p></li><li><p>the rollback path.</p></li></ul><p>An AI agent should not be trusted because it sounds reliable.</p><p>It should be trusted only to the degree that its actions are bounded, logged, reviewable and reversible.</p><p>That is the real investigative shift.</p><p>The question is no longer only:</p><pre><code><code>What did the AI say?</code></code></pre><p>It is:</p><pre><code><code>What did the AI do, what could it have done, and how do we know?</code></code></pre><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><div><hr></div>]]></content:encoded></item><item><title><![CDATA[Fable 5 Is Back. The Real Story Is the Jailbreak Severity Problem]]></title><description><![CDATA[Anthropic&#8217;s Fable 5 is back. That is the simple version of the story.]]></description><link>https://projectosint.substack.com/p/fable-5-is-back-the-real-story-is</link><guid isPermaLink="false">https://projectosint.substack.com/p/fable-5-is-back-the-real-story-is</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Thu, 02 Jul 2026 09:23:44 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/477efcce-0a64-4ecf-a10a-430b3d9d02f1_640x360.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The more useful version is different: a frontier AI model was released, restricted, reviewed, updated, and redeployed in less than a month. The public explanation now contains a timeline, a safeguard update, a description of classifier-based defenses, and a proposed framework for rating AI jailbreaks.</p><p>For OSINT work, that is the part worth studying.</p><p>Not because every reader needs to follow the model release cycle. Not because the public post answers every question. But because it shows what investigators, journalists, researchers, and security teams should ask when a powerful AI system is paused and then returned to service.</p><p>The question is not only:</p><pre><code><code>Is the model available again?</code></code></pre><p>The better question is:</p><pre><code><code>What changed between restriction and redeployment?</code></code></pre><h2>The Timeline Matters</h2><p>According to Anthropic, Fable 5 and Mythos 5 were released on June 9, 2026.</p><p>On June 12, the U.S. government applied export controls to both models. Anthropic says the order required it to restrict access to foreign nationals, whether inside or outside the United States. Because the company said it could not verify nationality in real time, it suspended access to both models for all users.</p><p>On June 30, Anthropic said those export controls had been lifted. Fable 5 would become available globally on July 1 across the Claude Platform, Claude.ai, Claude Code, and Claude Cowork, with cloud partner access to follow as quickly as possible.</p><p>That timeline gives us the first OSINT lesson: do not treat &#8220;model removed&#8221; and &#8220;model restored&#8221; as isolated events.</p><p>Write the sequence.</p><pre><code><code>June 9: model release
June 12: export controls and access suspension
June 26: partial government approval for Mythos 5 access
June 30: announcement that export controls were lifted
July 1: Fable 5 availability expected to resume</code></code></pre><p>Once the sequence is visible, the investigation becomes clearer. You can separate access decisions, safety claims, government action, technical mitigation, and business availability.</p><p>Without a timeline, everything becomes noise.</p><h2>Fable 5 and Mythos 5 Are Not the Same Operational Object</h2><p>Anthropic says Fable 5 and Mythos 5 share the same underlying model, but were released under different access and safeguard conditions.</p><p>Fable 5 was released for general use with strong safeguards. Mythos 5, according to Anthropic, has fewer safeguards and was released only to a small number of trusted Project Glasswing partners for defensive cybersecurity work.</p><p>That distinction matters.</p><p>When a public discussion says &#8220;the model was restricted&#8221; or &#8220;the model is back,&#8221; it can hide important differences:</p><ul><li><p>which model is being discussed;</p></li><li><p>who can access it;</p></li><li><p>what safeguards are attached;</p></li><li><p>what use case is allowed;</p></li><li><p>what partner program is involved;</p></li><li><p>whether access is public, commercial, cloud-based, domestic, international, or restricted.</p></li></ul><p>In OSINT, naming is not a cosmetic detail. It is part of the evidence chain.</p><p>If two systems share an underlying model but differ in safeguards and access conditions, they should not be collapsed into one object in your notes.</p><h2>The Reported Issue Was About a Bypass, Not a Public Exploit Chain</h2><p>Anthropic says the June 12 directive followed a report in which Amazon researchers found a method of bypassing Fable 5&#8217;s safeguards. The company describes the reported behavior as involving identification of software vulnerabilities and, in one case, code demonstrating how a relevant vulnerability could be exploited.</p><p>That sentence needs careful handling.</p><p>For a security reader, it is tempting to jump straight to the operational question: what was the bypass?</p><p>For responsible OSINT, the better question is different:</p><pre><code><code>What is the claim, and what level of detail is publicly supported?</code></code></pre><p>From the public post, we can say:</p><ul><li><p>Anthropic says Amazon researchers reported a safeguard bypass.</p></li><li><p>Anthropic says it reviewed the report with government and industry partners.</p></li><li><p>Anthropic says the issue did not expose unique Mythos-level cyber capabilities.</p></li><li><p>Anthropic says the behavior reflected a borderline case for Fable 5 safeguards.</p></li><li><p>Anthropic says it trained an improved safety classifier to block the behavior described in the report.</p></li></ul><p>What we cannot responsibly do from this public post is reconstruct the bypass technique, infer the exact vulnerability, or describe how the exploit demonstration worked.</p><p>That is the second OSINT lesson: when the public evidence is high-level, keep your own conclusion high-level.</p><p>Do not fill the gap with technical imagination.</p><h2>The New Safeguard Is a Classifier Update</h2><p>Anthropic says it trained an improved safety classifier targeting the behavior described in the Amazon report. If a Fable 5 request is blocked, the request is routed to Opus 4.8 instead.</p><p>The company also says the new classifier blocks the specific technique described in the Amazon report in more than 99% of cases. It acknowledges a tradeoff: the classifier may flag benign requests more often during routine coding and debugging.</p><p>This is a useful detail because it shows the shape of the mitigation.</p><p>It was not described as:</p><ul><li><p>a complete redesign of the model;</p></li><li><p>a guarantee that all jailbreaks are impossible;</p></li><li><p>proof that no cyber risk remains;</p></li><li><p>a universal solution for misuse.</p></li></ul><p>It was described as a targeted classifier improvement, inside a broader &#8220;defense in depth&#8221; approach.</p><p>That distinction matters for anyone tracking AI safety claims. A mitigation can be meaningful without being absolute. A classifier can reduce a specific behavior while increasing false positives. A model can be safer than before without being immune to future jailbreaks.</p><p>The right question is not &#8220;is it fixed?&#8221;</p><p>The better question is:</p><pre><code><code>Which behavior was mitigated, how was it mitigated, and what tradeoff did the mitigation introduce?</code></code></pre><h2>The Most Important Part Is the Severity Framework</h2><p>The most interesting section of Anthropic&#8217;s post is not the redeployment announcement.</p><p>It is the proposed framework for assessing AI jailbreak severity.</p><p>Anthropic argues that the industry lacks a common way to describe the severity of a jailbreak. That creates uncertainty for model developers, governments, researchers, and users. A minor bypass, a narrow harmful jailbreak, and a broad universal jailbreak should not be treated as the same kind of event.</p><p>The company proposes four criteria:</p><ol><li><p><strong>Capability gain</strong><br>How much capability does the jailbreak provide beyond existing tools?</p></li><li><p><strong>Breadth of capability gain</strong><br>Does the jailbreak unlock one narrow behavior, or many offensive tasks?</p></li><li><p><strong>Ease of weaponization</strong><br>How much effort is needed to turn the jailbreak into a real attack?</p></li><li><p><strong>Discoverability</strong><br>How easy is it for others to obtain or reproduce the technique?</p></li></ol><p>For OSINT, this is a strong analytical template.</p><p>It helps move the discussion away from vague labels like &#8220;dangerous,&#8221; &#8220;safe,&#8221; &#8220;broken,&#8221; or &#8220;jailbroken,&#8221; and toward structured questions.</p><p>If a jailbreak only unlocks a low-risk behavior that existing tools can already perform, its severity is different from a prompt that reliably enables a broad class of harmful tasks on the first try.</p><p>The word &#8220;jailbreak&#8221; is not enough.</p><p>You need the severity profile.</p><h2>A Practical OSINT Note Template</h2><p>When a model safety incident appears in public, use a simple note structure.</p><pre><code><code>Event:
What happened?

Timeline:
When was the model released, restricted, updated, restored?

Actors:
Which company, government body, researchers, cloud partners, or programs are named?

Model distinction:
Which model? Which version? Which safeguard level? Which access tier?

Reported issue:
What behavior is publicly described?

Evidence level:
Official statement, researcher report, government statement, third-party reporting, rumor?

Mitigation:
Classifier update, access restriction, policy change, monitoring, red-team program, other?

Severity questions:
Capability gain?
Breadth?
Weaponization effort?
Discoverability?

Limits:
What is not publicly known?</code></code></pre><p>This template prevents a common mistake: treating every model safety story as either a public relations statement or a technical exploit story.</p><p>It may be neither.</p><p>It may be a governance event, an access-control event, a safety-classifier event, a cloud-availability event, or all of those at once.</p><h2>What This Means for Cyber Defenders</h2><p>For defenders, the Fable 5 redeployment story points to a future where model access, cyber capability, jailbreak reporting, government review, and cloud availability are all connected.</p><p>This creates practical problems.</p><p>Security teams may need to know:</p><ul><li><p>which models are available to their organization;</p></li><li><p>whether access differs across consumer, platform, enterprise, and cloud channels;</p></li><li><p>what happens when a request is blocked;</p></li><li><p>whether blocked requests are rerouted to another model;</p></li><li><p>what logging and audit trails exist;</p></li><li><p>how model updates affect coding, debugging, vulnerability research, and defensive workflows;</p></li><li><p>whether a safety change increases false positives in legitimate work.</p></li></ul><p>For OSINT researchers, the public question is broader:</p><pre><code><code>Can we track frontier model changes with the same discipline we use for software vulnerabilities?</code></code></pre><p>That means version names, release dates, access conditions, mitigation notes, public claims, partner statements, and unresolved gaps.</p><h2>The Key Takeaway</h2><p>Fable 5 being redeployed is news.</p><p>But the deeper signal is that frontier AI incidents now need structured public analysis.</p><p>A model may be restricted for policy reasons. Access may depend on nationality, partner status, cloud provider, subscription tier, or government approval. A safeguard bypass may be minor, narrow, harmful, or broad. A mitigation may block a specific behavior while creating false positives elsewhere.</p><p>If we collapse all of that into &#8220;the model was banned&#8221; or &#8220;the model is safe again,&#8221; we lose the useful part.</p><p>The useful part is the chain:</p><pre><code><code>release -&gt; report -&gt; restriction -&gt; review -&gt; mitigation -&gt; redeployment -&gt; monitoring</code></code></pre><p>That chain is now part of AI OSINT.</p><h2>Sources</h2><ul><li><p>Anthropic, &#8220;Redeploying Fable 5,&#8221; June 30, 2026, <a href="https://www.anthropic.com/news/redeploying-fable-5">https://www.anthropic.com/news/redeploying-fable-5</a></p><div><hr></div></li></ul><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[Before You Trust the Image, Build the Chain]]></title><description><![CDATA[Reverse image search used to feel like the first serious move in visual verification.]]></description><link>https://projectosint.substack.com/p/before-you-trust-the-image-build-f5a</link><guid isPermaLink="false">https://projectosint.substack.com/p/before-you-trust-the-image-build-f5a</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 29 Jun 2026 17:17:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!a7aO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Reverse image search used to feel like the first serious move in visual verification.</p><p>Upload the image. Look for earlier appearances. Find the old context. Check whether the current caption is false.</p><p>That habit still matters.</p><p>But it is no longer enough.</p><p>An image can have no useful reverse search results for many reasons. It may be new. It may be cropped. It may be synthetic. It may have been edited. It may have circulated first in a closed channel. It may not be indexed yet. It may be a screenshot of another image. It may be real and still attached to the wrong claim.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a7aO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a7aO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!a7aO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!a7aO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!a7aO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a7aO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94654,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/204149291?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a7aO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!a7aO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!a7aO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!a7aO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F354773e9-8e8a-4a0b-b99f-ad4db63ca656_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So the better question is not only:</p><pre><code><code>Where else does this image appear?</code></code></pre><p>The better question is:</p><pre><code><code>What chain of evidence supports the image, the source, the location, the time and the claim?</code></code></pre><p>That is the shift.</p><p>Visual verification is moving from single-tool confidence to evidence-chain discipline.</p><h2>The image is not the claim</h2><p>This is the mistake I see most often.</p><p>Someone verifies that an image exists, or that it has not appeared before, and then treats the caption as if it has been verified too.</p><p>But an image and its caption are different evidence objects.</p><p>The image may be real. The location may be correct. The date may still be wrong. The actor may be unconfirmed. The consequence may be exaggerated. The visible scene may support part of the claim, but not all of it.</p><p>Good OSINT does not ask an image to prove more than it can prove.</p><h2>A lighter workflow</h2><p>Before using a visual claim, run a short chain check:</p><pre><code><code>1. What exact claim does the image support?
2. What is the earliest source you can find?
3. Did reverse search find older uses or variants?
4. Are there provenance signals or labels?
5. What visual clues support the location?
6. What evidence supports the time?
7. Who confirmed the event independently?
8. What remains unverified?</code></code></pre><p>The last question is not a formality.</p><p>It is often the most important part of the analysis.</p><h2>Provenance helps, but it does not replace verification</h2><p>Content Credentials, C2PA data, platform labels and tools like Google&#8217;s &#8220;About this image&#8221; can help.</p><p>They can provide useful context about origin, edits, earlier indexing or appearances elsewhere online.</p><p>But they do not automatically prove that the current claim is true.</p><p>Metadata can be missing. Labels can be incomplete. Context tools can show where an image appeared without proving why it appeared there. A file can carry useful provenance and still be attached to a misleading caption.</p><p>Treat provenance as one signal in the chain.</p><p>Not the chain itself.</p><h2>The takeaway</h2><p>Reverse image search is still useful.</p><p>It is just not the whole workflow anymore.</p><p>Visual verification now needs a wider frame:</p><ul><li><p>preserve the original post;</p></li><li><p>isolate the claim;</p></li><li><p>search for earlier appearances;</p></li><li><p>check provenance signals;</p></li><li><p>geolocate visible features;</p></li><li><p>test the timeline;</p></li><li><p>map the source chain;</p></li><li><p>state the conclusion narrowly.</p></li></ul><p>The important question is no longer whether one tool gives an answer.</p><p>It is whether each part of the claim survives being checked separately.</p><p>I wrote the full ProjectOSINT workflow here:</p><p><a href="https://projectosint.com/visual-verification-reverse-image-search-not-enough">https://projectosint.com/visual-verification-reverse-image-search-not-enough</a></p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[Break the Claim Before You Search]]></title><description><![CDATA[A weak OSINT workflow often starts with movement.]]></description><link>https://projectosint.substack.com/p/break-the-claim-before-you-search</link><guid isPermaLink="false">https://projectosint.substack.com/p/break-the-claim-before-you-search</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 22 Jun 2026 12:35:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lXt3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lXt3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lXt3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lXt3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lXt3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lXt3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lXt3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66161,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/203076206?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lXt3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lXt3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lXt3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lXt3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f17395b-0383-41c6-94af-bb905ba2f256_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A weak OSINT workflow often starts with movement.</p><p>Someone sees a claim, opens a search engine, checks a social platform, runs a reverse image search, asks an AI tool for suggestions, opens a map, saves a few links, and starts building a conclusion before the actual object of verification has been defined.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The problem is not curiosity.</p><p>The problem is speed without structure.</p><p>Before you search, break the claim.</p><p>Take a sentence like this:</p><blockquote><p>This video shows police using tear gas during a protest in Madrid on 10 June 2026.</p></blockquote><p>It looks like one claim. It is not.</p><p>It contains several smaller claims:</p><ul><li><p>the content is a video;</p></li><li><p>the actor is police;</p></li><li><p>the action is the use of tear gas;</p></li><li><p>the event is a protest;</p></li><li><p>the location is Madrid;</p></li><li><p>the date is 10 June 2026;</p></li><li><p>the video is connected to that specific event.</p></li></ul><p>Each part needs a different kind of evidence.</p><p>A timestamp can help with publication time. It may not prove recording time.</p><p>A street sign can support location. It does not prove the date.</p><p>A local news report can confirm that a protest happened. It may not prove that this specific video shows that protest.</p><p>A uniform can be a useful visual indicator. It is not, by itself, a complete actor verification.</p><p>This is where many investigations become fragile. One part of the claim starts to look plausible, and the whole sentence quietly inherits that plausibility.</p><p>Location looks right, so the date feels right.</p><p>The event happened, so the video feels connected.</p><p>The account looks relevant, so the source feels original.</p><p>That is not verification. That is momentum.</p><h2>The First Question Is Not &#8220;Is This True?&#8221;</h2><p>The first question should be:</p><pre><code><code>What is this claim made of?</code></code></pre><p>Only after that can you ask:</p><ul><li><p>Which part can be checked first?</p></li><li><p>Which part requires a primary source?</p></li><li><p>Which part needs visual verification?</p></li><li><p>Which part depends on timing?</p></li><li><p>Which part is only context?</p></li><li><p>Which part may remain unknown?</p></li></ul><p>This matters because the search path changes depending on the component.</p><p>If you are checking location, you may need maps, street-level imagery, signage, architecture, transport routes, local landmarks, satellite imagery, or posts from the same area.</p><p>If you are checking time, you may need upload timestamps, archive timestamps, weather records, light, shadows, event schedules, livestreams, or earlier versions of the same media.</p><p>If you are checking source origin, you may need platform search, repost chains, archives, unique captions, usernames, watermarks, or metadata if it is available and reliable.</p><p>If you are checking identity, you need to move much more carefully. A username match, a profile photo, or a repeated phrase may create a lead. It does not automatically prove that two accounts belong to the same person.</p><p>Breaking the claim first protects the investigation from using the wrong source for the wrong question.</p><h2>AI Can Help Here, But Only in One Role</h2><p>AI can be useful before the search begins.</p><p>Not as a source.</p><p>Not as a judge.</p><p>Not as the thing that tells you whether the claim is true.</p><p>Its useful role is to slow the claim down.</p><p>You can ask:</p><pre><code><code>Break this claim into separate verifiable components.
For each component, identify the type of evidence that would support it, what would not be enough, and what source types should be checked first.

Claim:
[paste claim]</code></code></pre><p>The output is not evidence. It is a planning layer.</p><p>You still have to edit it. AI may miss local sources, misunderstand context, suggest weak categories, or treat one component as more checkable than it really is.</p><p>But as a first pass, it can help expose the hidden structure of the claim.</p><p>That is useful because many false conclusions are not caused by a lack of tools. They are caused by unclear questions.</p><h2>Look for the Evidence Gap</h2><p>Once the claim is broken apart, the most important part of the workflow is not the evidence you already have.</p><p>It is the gap.</p><p>For each component, ask:</p><ul><li><p>What would support this?</p></li><li><p>What would weaken this?</p></li><li><p>What would not be enough?</p></li><li><p>What have I not checked yet?</p></li><li><p>What alternative explanation remains possible?</p></li></ul><p>The evidence gap is where cautious language comes from.</p><p>If the location is supported but the date is not, the conclusion should say that.</p><p>If the event is confirmed but the media origin is unknown, the conclusion should say that.</p><p>If two usernames look connected but there is no independent source linking them, the conclusion should not turn that into identity.</p><p>Good OSINT protects the distance between evidence and conclusion.</p><p>That distance is not a stylistic detail. It is the method.</p><h2>The Evidence Log</h2><p>After you break the claim, the next step is to log the evidence.</p><p>Not in a long report. Not necessarily in a complex database.</p><p>A simple table is enough if it keeps the reasoning visible.</p><p>Use columns like:</p><ul><li><p>claim component;</p></li><li><p>verification question;</p></li><li><p>source checked;</p></li><li><p>what the source shows;</p></li><li><p>limitation;</p></li><li><p>confidence;</p></li><li><p>next step.</p></li></ul><p>This structure forces a useful discipline.</p><p>You cannot simply write &#8220;confirmed&#8221; because a source looked convincing. You have to write what the source actually shows.</p><p>You cannot hide uncertainty inside a polished paragraph. You have to name the limitation.</p><p>You cannot move from a weak indicator to a strong conclusion without leaving a trace.</p><p>The evidence log makes the investigation harder to overstate.</p><h2>A Better Conclusion</h2><p>A careful conclusion may sound less dramatic than a confident one.</p><p>It may say:</p><pre><code><code>The available evidence supports the location claim with medium confidence and confirms that a related protest occurred in Madrid on the stated date. However, the current sources do not establish the original uploader or prove that the footage was recorded during that specific event. The claim should be treated as partially supported, not fully verified.</code></code></pre><p>That is not a weak conclusion.</p><p>It is a more accurate one.</p><p>It tells the reader what is supported, what is still open, and where the boundary is.</p><p>This is especially important when AI is part of the workflow. A model can make weak evidence sound clean. It can turn messy notes into a fluent paragraph. It can make uncertainty disappear simply because fluent writing has no visible gaps.</p><p>The evidence log does the opposite.</p><p>It keeps the gaps visible.</p><h2>The Full Template</h2><p>I published a practical ProjectOSINT guide with a copyable evidence log template for claim verification.</p><p>It includes:</p><ul><li><p>a basic evidence log table;</p></li><li><p>a more detailed template for sensitive claims;</p></li><li><p>examples of source limitations;</p></li><li><p>confidence levels;</p></li><li><p>common mistakes;</p></li><li><p>prompts for using AI without treating it as a source.</p></li></ul><p>Read it here:</p><p><a href="https://projectosint.com/evidence-log-template-claim-verification/">Evidence Log Template for Claim Verification</a></p><p>The core idea is simple:</p><p>Break the claim before you search.</p><p>Log the source before you conclude.</p><p>Name the limitation before you assign confidence.</p><p>That is where verification becomes visible.</p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Google’s Fight Against AI Scams May Be Too Late]]></title><description><![CDATA[Google is suing a cybercrime network accused of using Gemini to scale SMS phishing. The case shows a deeper problem: AI abuse may be detected only after the scam infrastructure is already large.]]></description><link>https://projectosint.substack.com/p/googles-fight-against-ai-scams-may</link><guid isPermaLink="false">https://projectosint.substack.com/p/googles-fight-against-ai-scams-may</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 22 Jun 2026 11:40:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!eDxp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!eDxp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!eDxp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!eDxp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!eDxp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!eDxp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!eDxp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108869,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/202119351?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!eDxp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!eDxp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!eDxp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!eDxp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F07ec99c1-d435-4916-8db5-d94da32f47ea_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A scam message used to be easy to distrust.</p><p>The spelling was strange. The layout was wrong. The link looked suspicious. The fake delivery notice felt slightly off. The bank warning had the wrong tone. The website copied a brand, but not quite well enough.</p><p>That margin is shrinking.</p><p>Generative AI has given scammers a new production layer: better text, faster variations, more convincing templates, translated messages, cloned branding, realistic fake websites and the ability to test many versions of the same deception at scale.</p><p>Google is now trying to fight back.</p><p>But the difficult question is not whether Google is doing something.</p><p>The question is whether the response can ever be fast enough once AI-assisted scams become industrial infrastructure.</p><h2><strong>The Outsider case</strong></h2><p>According to Google&#8217;s lawsuit and reporting by The Wall Street Journal and other outlets, the company has sued a China-linked cybercrime network known as Outsider.</p><p>Google says the group used Gemini and other AI tools to support large-scale SMS phishing campaigns. The operation allegedly relied on fake websites impersonating telecom companies, government services and commercial brands. Victims received familiar messages: package alerts, urgent account warnings, reward notices, bank-related panic messages or other prompts designed to push them toward a fraudulent link.</p><p>From there, the workflow was simple.</p><p>The message created urgency. The website created trust. The form collected payment card details, credentials or personal information.</p><p>The numbers reported are significant. Google and law enforcement-linked reporting describe thousands of fake websites, millions of scam messages and large numbers of affected users. The Wall Street Journal reported that Outsider used more than 8,000 phishing websites and that the broader operation was connected to millions of stolen credit card numbers and very large estimated losses. Other reports cite more than 9,000 fake websites and millions of fraudulent URLs or messages.</p><p>The exact figures vary by source and by how the operation is defined.</p><p>The pattern is clearer than the number:</p><p><code>AI did not create phishing.<br>AI helped phishing scale better.</code></p><p>That distinction matters.</p><p>Phishing is old. SMS scams are old. Fake delivery alerts are old. Fake bank warnings are old. What changes with AI is the speed, volume and adaptability of the operation.</p><p>Scammers no longer need one perfect message. They can generate thousands of decent ones.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>Why this is an OSINT problem</strong></h2><p>At first glance, this may look like a cybersecurity story.</p><p>It is also an OSINT story.</p><p>Every phishing campaign leaves public traces:</p><ul><li><p>domains;</p></li><li><p>URLs;</p></li><li><p>landing pages;</p></li><li><p>logos;</p></li><li><p>brand impersonation patterns;</p></li><li><p>phone numbers;</p></li><li><p>text-message templates;</p></li><li><p>hosting infrastructure;</p></li><li><p>certificates;</p></li><li><p>payment flows;</p></li><li><p>reused wording;</p></li><li><p>archived pages;</p></li><li><p>screenshots shared by victims;</p></li><li><p>reports from telecom providers, platforms and security teams.</p></li></ul><p>The problem is that AI changes how those traces behave.</p><p>A traditional scam campaign may reuse the same text, same layout, same domain pattern or same translation mistakes. Those repetitions help investigators connect cases.</p><p>AI-generated campaigns can mutate more easily.</p><p>The message can change. The landing page can change. The brand copy can become more natural. The fake website can be rebuilt quickly. A scammer can ask a model to adapt the same lure to another carrier, another bank, another country or another language.</p><p>This does not make the campaign invisible.</p><p>It makes the evidence more distributed.</p><p>Instead of looking only for identical text, investigators need to look for systems:</p><ul><li><p>repeated infrastructure;</p></li><li><p>domain registration patterns;</p></li><li><p>shared hosting;</p></li><li><p>common form behavior;</p></li><li><p>similar data collection flows;</p></li><li><p>reused templates behind different surface designs;</p></li><li><p>timing of campaigns;</p></li><li><p>overlap between SMS lures and landing pages;</p></li><li><p>payment card collection logic;</p></li><li><p>brand impersonation clusters.</p></li></ul><p>The surface becomes more flexible.</p><p>The workflow remains traceable.</p><h2><strong>Google&#8217;s response is serious</strong></h2><p>Google is not treating this as a small abuse case.</p><p>The company is using litigation, platform monitoring, user reports, partnerships with telecom providers and cooperation with law enforcement. It is also supporting legislation aimed at reducing scam harm, including measures focused on seniors and public education around AI-enabled fraud.</p><p>This matters.</p><p>Legal action can help disrupt infrastructure. Telecom partnerships can block messages before they reach users. Android protections can reduce exposure. Public reporting can help users recognize patterns. Lawsuits can reveal how scam ecosystems operate and put pressure on repeat actors.</p><p>Google has also rolled out fake call detection in the Phone by Google app, designed to warn users when a call appears to be impersonating one of their contacts. That responds to another AI-enabled risk: voice impersonation and spoofed calls.</p><p>These are not cosmetic steps.</p><p>They show that scam defense is moving from individual user advice toward platform-level intervention.</p><p>But they also reveal the timing problem.</p><p>The response arrives after the scale is already visible.</p><h2><strong>The timing problem</strong></h2><p>AI abuse is often detected after harm has already happened.</p><p>That is not unique to Google. It is a structural problem in AI safety and platform security.</p><p>Platforms usually see abuse through signals:</p><ul><li><p>user reports;</p></li><li><p>unusual traffic;</p></li><li><p>repeated prompt patterns;</p></li><li><p>suspicious account behavior;</p></li><li><p>takedown requests;</p></li><li><p>law enforcement referrals;</p></li><li><p>infrastructure overlap;</p></li><li><p>brand impersonation complaints;</p></li><li><p>payment fraud indicators.</p></li></ul><p>But by the time those signals become strong enough to justify action, the campaign may already be large.</p><p>This is the central weakness of reactive defense.</p><p>It can reduce ongoing harm. It can remove domains. It can block messages. It can sue operators. It can warn users.</p><p>But it often cannot prevent the first wave.</p><p>AI makes this worse because it lowers the cost of producing the first wave. A bad actor does not need to build every fake page by hand. They can generate code, copy, translations and variations. Even if filters block some requests, ordinary-looking prompts can still support abuse when placed inside a larger criminal workflow.</p><p>That is the hard part.</p><p>A request to generate website code is not automatically malicious.</p><p>A request to rewrite a message is not automatically malicious.</p><p>A request to translate text is not automatically malicious.</p><p>The abuse emerges from the context, the scale, the destination and the operational chain.</p><p>Current AI systems are still much better at detecting isolated dangerous content than at understanding how many harmless-looking steps become a fraud machine.</p><h2><strong>The Pandora&#8217;s box question</strong></h2><p>This is where the uncomfortable question appears.</p><p>Should models with this kind of production power be available so widely, so easily and with so little friction?</p><p>There is no simple answer.</p><p>If access is too restricted, legitimate researchers, journalists, small businesses, developers and civil society groups lose useful tools. AI can help defenders too: writing detection rules, translating scam reports, clustering phishing patterns, summarizing victim complaints, analyzing suspicious domains and explaining threats to non-technical users.</p><p>If access is too open, attackers get the same productivity boost.</p><p>The issue is not that AI &#8220;causes&#8221; scams.</p><p>The issue is that AI changes the economics of scams.</p><p>It makes low-quality deception cheaper to improve. It makes internationalization easier. It makes brand imitation faster. It lets criminals test more lures, more languages and more page designs. It helps small teams behave like larger operations.</p><p>That is why legal action after the fact may never be enough.</p><p>The industry needs stronger abuse modeling before deployment, not only better takedowns afterward.</p><h2><strong>What proactive defense would look like</strong></h2><p>Proactive defense does not mean banning every risky capability.</p><p>It means treating scam production as a system, not as a single prompt.</p><p>For AI companies, that could include:</p><ul><li><p>stronger monitoring for repeated generation of phishing-like templates;</p></li><li><p>risk scoring based on account behavior over time;</p></li><li><p>friction for bulk generation of brand-impersonation material;</p></li><li><p>better detection of multi-step scam workflows;</p></li><li><p>partnerships with telecom providers, browsers, registrars and payment processors;</p></li><li><p>faster sharing of abuse indicators with trusted security teams;</p></li><li><p>red-team testing focused on fraud operations, not only prohibited content;</p></li><li><p>transparency reports on AI-assisted abuse categories.</p></li></ul><p>For investigators, it means adapting the workflow.</p><p>Do not only ask:</p><p><code>Was this message generated by AI?</code></p><p>Ask:</p><p><code>What system produced, distributed and monetized this scam?</code></p><p>That system includes the message, the phone number, the URL, the domain, the landing page, the form, the payment flow, the hosting, the copied brand assets, the delivery channel and the resale or use of stolen data.</p><p>AI is one layer of that system.</p><p>Not the whole story.</p><h2><strong>The defender&#8217;s dilemma</strong></h2><p>The same models that help scammers also help defenders.</p><p>An analyst can use AI to cluster scam reports, summarize victim messages, identify repeated wording, translate foreign-language lures, generate regex patterns, draft user warnings or compare suspicious pages.</p><p>A telecom provider can use machine learning to block spam before delivery.</p><p>A browser can warn users before they submit data to a known malicious page.</p><p>A phone app can detect impersonation signals.</p><p>But this creates a strange race.</p><p>Attackers use AI to generate more variants.</p><p>Defenders use AI to detect more variants.</p><p>Attackers adapt.</p><p>Defenders update.</p><p>The user still receives the message.</p><p>That is why public education remains necessary, even when platforms improve. Not because users should carry the whole burden, but because the last step of many scams is still psychological: urgency, fear, reward, authority, scarcity, panic.</p><p>AI improves the surface.</p><p>The old emotional triggers remain.</p><h2><strong>The warning from the AI safety debate</strong></h2><p>The broader AI safety debate often sounds abstract: frontier models, dangerous capabilities, alignment, export controls, catastrophic misuse.</p><p>Scams make the problem concrete.</p><p>You do not need a science-fiction scenario to see how AI changes risk. A fake carrier website, a convincing SMS, a cloned voice, a realistic brand page and a payment form are enough.</p><p>Companies such as Anthropic have warned that powerful AI systems can create new categories of misuse if deployment moves faster than safeguards. Whether one agrees with every warning or not, the Google case shows the practical version of the same concern:</p><p>once a capability is widely available, abuse may scale before the control layer is mature.</p><p>The question is no longer whether criminals will use AI.</p><p>They already are.</p><p>The question is whether AI companies can detect system-level abuse before it reaches millions of people.</p><h2><strong>What to watch next</strong></h2><p>For OSINT researchers and digital safety teams, the Google case is worth following for several reasons.</p><p>First, the lawsuit may reveal how AI-generated scam infrastructure is organized: templates, domains, delivery channels, brand impersonation, accounts and monetization.</p><p>Second, telecom partnerships may show whether SMS fraud can be blocked earlier in the chain or only after large-scale reporting.</p><p>Third, user-facing defenses such as fake call detection may show how much protection can be moved onto the device.</p><p>Fourth, legislation may expand the responsibilities of platforms, carriers and AI providers.</p><p>Finally, the case may become a test of accountability. If an AI model is used to produce part of a scam workflow, what responsibility does the model provider have? What responsibility belongs to telecom carriers? What belongs to registrars, hosting providers, payment processors and app platforms?</p><p>No single actor owns the whole chain.</p><p>That is exactly why the chain matters.</p><h2><strong>The practical takeaway</strong></h2><p>For users, the basic rule remains simple:</p><p>do not trust urgency delivered by a message.</p><p>If a package, bank, carrier, government office or platform account appears to require immediate action, do not use the link in the message. Go through the official app or website. Check the domain. Slow down the decision.</p><p>For investigators, the rule is different:</p><p>do not focus only on whether AI wrote the text.</p><p>Map the operation.</p><p>Look for repeated infrastructure, domain clusters, brand impersonation patterns, landing page behavior, data collection flows, telecom signals and payment paths.</p><p>AI-generated scams are not magic.</p><p>They are systems.</p><p>Google&#8217;s lawsuit may disrupt one of them.</p><p>But the larger lesson is harder: if AI turns scam production into an industrial process, then takedowns after the fact will always feel late.</p><p>The next phase of AI safety will not only be about preventing spectacular misuse.</p><p>It will be about stopping ordinary fraud from becoming faster, cheaper and more convincing than our defenses.</p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[Before You Verify a Claim, Break It Apart]]></title><description><![CDATA[A weak OSINT workflow often starts too fast.]]></description><link>https://projectosint.substack.com/p/before-you-verify-a-claim-break-it</link><guid isPermaLink="false">https://projectosint.substack.com/p/before-you-verify-a-claim-break-it</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 15 Jun 2026 13:03:28 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d3a6b52e-bafc-460d-aa92-5e2c5c518071_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A weak OSINT workflow often starts too fast.</p><p>Someone sees a claim, opens a search engine, checks a social platform, runs a reverse image search, asks an AI tool for help, and begins collecting fragments before the real question has been defined.</p><p>That is how noise enters the investigation.</p><p>The first step should be slower.</p><p>Before asking whether a claim is true, ask what the claim is made of.</p><p>Take a sentence like this:</p><blockquote><p><em>This video shows police using tear gas during a protest in Madrid on 10 June 2026.</em></p></blockquote><p>It looks like one claim. It is not.</p><p>It contains several smaller claims:</p><ul><li><p>the content is a video;</p></li><li><p>the actor is police;</p></li><li><p>the action is the use of tear gas;</p></li><li><p>the event is a protest;</p></li><li><p>the place is Madrid;</p></li><li><p>the date is 10 June 2026.</p></li></ul><p>Each part needs a different kind of evidence.</p><p>A timestamp may help with publication timing, but not necessarily with recording time. A street sign may help with location, but not with the date. A local news report may confirm that a protest happened, but not that this specific video shows that protest.</p><p>This is where AI can be useful in OSINT.</p><p>Not as a truth machine. Not as a source. Not as a shortcut around verification.</p><p>AI is useful when it helps you slow down the claim.</p><p>You can ask it to separate entities, actions, time, and place. You can ask it to turn each part into verification questions. You can ask it to suggest source types: maps, archives, official pages, local media, social platforms, weather records, earlier uploads, or public documents.</p><p>Then the actual work begins.</p><p>You still have to search manually. You still have to check primary sources. You still have to decide whether a screenshot is enough, whether a report supports the specific claim, whether two sources are independent, and whether your conclusion deserves high confidence or only cautious wording.</p><p>The useful role of AI is not to close the investigation.</p><p>It is to expose the gaps before you pretend they are closed.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>A simple prompt to use before you start</strong></h2><p><code>Break this claim into separate verifiable components. For each component, explain what type of evidence would support it, what would not be enough, and what source types should be checked first.<br><br>Claim: [paste the claim]</code></p><p>Then edit the result.</p><p>Remove weak suggestions. Add local sources. Add language variations. Add the source types that AI may have missed. Treat the output as a planning layer, not as evidence.</p><p>The difference matters.</p><p>An AI-generated investigation plan can help you ask better questions. It cannot tell you what happened.</p><h2><strong>The language of uncertainty</strong></h2><p>A good OSINT conclusion does not force certainty where the evidence does not support it.</p><p>Useful wording includes:</p><ul><li><p>verified;</p></li><li><p>likely;</p></li><li><p>consistent with;</p></li><li><p>unverified;</p></li><li><p>false or misleading.</p></li></ul><p>Those are not stylistic choices. They are analytical boundaries.</p><p>If a video matches a location but the date is still unclear, the finding is not fully verified. If a username appears across two platforms, that may be an indicator, not an identity confirmation. If a source has not been found, that does not automatically make the claim false.</p><p>Good OSINT protects the distance between evidence and conclusion.</p><p>AI can help maintain that distance if you use it as a reviewer:</p><p><code>Review this evidence log. Identify weak assumptions, missing source types, possible false positives, and claims that are not yet supported. Do not decide whether the original claim is true.</code></p><p>That last sentence matters.</p><p>Do not let the tool become the judge.</p><h2><strong>The full workflow</strong></h2><p>I published a practical guide on ProjectOSINT that turns this idea into a step-by-step workflow:</p><ol><li><p>write the claim as one sentence;</p></li><li><p>separate entities, actions, time, and place;</p></li><li><p>turn each part into verification questions;</p></li><li><p>build a source map;</p></li><li><p>generate search queries;</p></li><li><p>test them manually;</p></li><li><p>keep an evidence log;</p></li><li><p>use AI to identify gaps;</p></li><li><p>assign confidence levels;</p></li></ol><ol start="10"><li><p>write the conclusion with limits.</p></li></ol><p>Read the full guide here:</p><p><strong><a href="https://projectosint.com/ai-osint-workflow-news-claim-verification/">How to Turn a News Claim Into an OSINT Workflow With AI</a></strong></p><p>The main point is simple: AI should not make OSINT faster at the cost of evidence.</p><p>It should make the workflow more explicit.</p><p>Break the claim. Map the sources. Log the evidence. Name the uncertainty.</p><p>That is where verification starts.</p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[How to Investigate an NFT Scam Without Getting Lost in the Blockchain]]></title><description><![CDATA[A victim sends you three screenshots, a dead project website, and a long Ethereum address that starts with 0x.]]></description><link>https://projectosint.substack.com/p/how-to-investigate-an-nft-scam-without</link><guid isPermaLink="false">https://projectosint.substack.com/p/how-to-investigate-an-nft-scam-without</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 08 Jun 2026 12:50:29 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!csm3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!csm3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!csm3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!csm3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!csm3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!csm3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!csm3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg" width="1200" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74050,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/200649903?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!csm3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 424w, https://substackcdn.com/image/fetch/$s_!csm3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 848w, https://substackcdn.com/image/fetch/$s_!csm3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!csm3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d2919e0-2f8e-41ff-8cbc-e7e68721306c_1200x800.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A victim sends you three screenshots, a dead project website, and a long Ethereum address that starts with 0x.</p><p>They say they lost money in an NFT collection. The Discord server is gone. The social accounts have disappeared. The project page no longer loads. The only thing that still exists is the blockchain trace.</p><p>That is usually enough to start.</p><p>NFT fraud can look technical from the outside, but many investigations do not begin with code. They begin with a simple evidence problem: what existed, who controlled it, where the money moved, and which parts can be documented before they disappear.</p><p>The mistake is to treat &#8220;crypto&#8221; as the investigation.</p><p>The better approach is to treat the NFT case as a normal OSINT workflow with a few specific objects: wallets, contracts, transactions, marketplaces, archived pages, social profiles, and public scam reports.</p><p>The blockchain gives you part of the trail. It does not give you the whole story.</p><h2><strong>What an NFT Scam Investigation Is Really About</strong></h2><p>An NFT is often described as a unique digital certificate linked to an asset: an image, collectible, audio file, video, or other digital object. In many scams, the fraud is not in the image itself. It is in the promise connected to it: future value, community access, exclusive benefits, a roadmap, a game, a token, a metaverse, a limited collection, or the credibility of the team.</p><p>For investigation purposes, the key point is simpler:</p><p><code>An NFT project creates public traces before, during, and after the sale.</code></p><p>Those traces can include:</p><ul><li><p>the project website;</p></li><li><p>the smart contract;</p></li><li><p>the creator wallet;</p></li><li><p>the wallet receiving payments;</p></li><li><p>marketplace activity;</p></li><li><p>Discord announcements;</p></li><li><p>social media posts;</p></li><li><p>usernames used by the team;</p></li><li><p>transaction flows after the sale;</p></li><li><p>previous scam reports involving the same wallet, domain, or username.</p></li></ul><p>An NFT scam case is rarely solved by one screenshot or one transaction. It is built by connecting those traces carefully, without turning every clue into an accusation.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>The System Map: Where the Evidence Lives</strong></h2><p>The first layer is the web layer.</p><p>This includes the project site, roadmap, team page, mint page, whitepaper, social accounts, Discord announcements, and promotional material. This layer often disappears quickly after a rug pull or fraudulent launch.</p><p>The second layer is the blockchain layer.</p><p>This includes the contract address, creator wallet, payment wallet, transaction history, transfers, secondary wallets, exchange deposits, and possible use of mixers. This layer is harder to erase because the transaction history remains public.</p><p>The third layer is the social layer.</p><p>This includes usernames, avatars, developer handles, reused bios, interviews, GitHub accounts, Reddit posts, Telegram handles, LinkedIn profiles, and any public identity signals connected to the project team.</p><p>The fourth layer is the reporting layer.</p><p>This includes public scam databases, wallet abuse reports, victim complaints, marketplace warnings, and previous cases involving the same infrastructure.</p><p>Each layer answers a different question. The web layer shows what was promised. The blockchain layer shows where funds moved. The social layer may show who was publicly associated with the project. The reporting layer shows whether the same traces appear in other complaints.</p><p>Do not collapse these layers into one conclusion.</p><h2><strong>A Defensive Workflow for Investigating an NFT Scam</strong></h2><h3><strong>1. Preserve the web evidence before it disappears</strong></h3><p>Start with preservation, not analysis.</p><p>If the project is fraudulent, the website, social posts, Discord channels, roadmap, team page, and mint page may vanish quickly. Screenshots can help you remember what you saw, but they are weak if they are not documented properly.</p><p>What to collect:</p><ul><li><p>live project pages;</p></li><li><p>team descriptions;</p></li><li><p>roadmap claims;</p></li><li><p>Discord announcements;</p></li><li><p>social media posts;</p></li><li><p>marketplace pages;</p></li><li><p>whitepaper or project files;</p></li><li><p>terms, disclaimers, and promotional claims.</p></li></ul><p>What to record:</p><ul><li><p>URL;</p></li><li><p>date and time;</p></li><li><p>platform;</p></li><li><p>account name;</p></li><li><p>screenshot or archive link;</p></li><li><p>what specific claim the page supports.</p></li></ul><p>What it can prove:</p><ul><li><p>that a public claim existed at a specific time;</p></li><li><p>that a project presented itself in a certain way;</p></li><li><p>that specific usernames, wallets, domains, or promises were publicly connected.</p></li></ul><p>What it cannot prove:</p><ul><li><p>who personally controlled the project;</p></li><li><p>whether a promise was knowingly fraudulent;</p></li><li><p>whether a screenshot alone is suitable for legal use.</p></li></ul><p>For serious cases, preservation needs a stronger chain of custody than casual screenshots. The operational rule is simple: if the evidence may be used in a legal context, capture it in a way that can be defended later.</p><h3><strong>2. Identify the contract and the project wallets</strong></h3><p>The contract address is often the best starting point.</p><p>It may appear in the marketplace listing, the victim&#8217;s wallet history, the mint page, or the transaction receipt. Once you have the contract address, a block explorer can show the contract page, creator address, token activity, and related transactions.</p><p>Look for two addresses:</p><p><code>Creator wallet:<br>Payment wallet:</code></p><p>Sometimes they are the same. Sometimes one wallet created the contract and another received the funds. That difference matters because it may show how the project separated technical deployment from revenue collection.</p><p>What to look for:</p><ul><li><p>when the creator wallet was created;</p></li><li><p>whether it was newly created before the launch;</p></li><li><p>which wallet received mint payments;</p></li><li><p>whether funds accumulated through many small payments;</p></li><li><p>whether the wallet later moved most funds in one transaction.</p></li></ul><p>What it can prove:</p><ul><li><p>which public addresses were involved in deployment or payment flow;</p></li><li><p>how funds moved from buyers to project-controlled wallets;</p></li><li><p>whether the wallet behavior matches known scam patterns.</p></li></ul><p>What it cannot prove:</p><ul><li><p>the real-world identity of the person controlling the wallet;</p></li><li><p>intent;</p></li><li><p>full responsibility for the fraud.</p></li></ul><p>On-chain attribution is not personal attribution. Keep that distinction visible.</p><h3><strong>3. Follow the money, but document each hop separately</strong></h3><p>In many rug pull cases, the pattern is not subtle.</p><p>A project wallet receives many small payments during the sale. Later, the funds move to another wallet. That wallet may split the amount into several smaller wallets. Some of those wallets may send funds to a centralized exchange. Others may send funds to a mixer or another obscuring service.</p><p>Do not write &#8220;the scammer sent the money to X&#8221; too early.</p><p>Write what the chain shows:</p><p><code>Wallet A received buyer payments.<br>Wallet A sent most of the balance to Wallet B.<br>Wallet B split the funds across six wallets.<br>Four wallets later sent funds to centralized exchanges.<br>Two wallets sent funds toward mixing infrastructure.</code></p><p>This wording matters.</p><p>It keeps the evidence factual and avoids unsupported personal attribution.</p><p>What to look for:</p><ul><li><p>concentration of funds after the sale;</p></li><li><p>large outbound transfers after the project stops communicating;</p></li><li><p>splitting into multiple new wallets;</p></li><li><p>deposits to centralized exchanges;</p></li><li><p>interaction with mixers;</p></li><li><p>repeated patterns across other projects.</p></li></ul><p>What it can prove:</p><ul><li><p>movement of funds;</p></li><li><p>timing;</p></li><li><p>destination categories;</p></li><li><p>possible legal points of inquiry if centralized exchanges are involved.</p></li></ul><p>What it cannot prove:</p><ul><li><p>who controlled the destination account;</p></li><li><p>whether exchange KYC identifies a suspect without legal process;</p></li><li><p>whether a mixer breaks all investigative value.</p></li></ul><p>If funds reach a centralized exchange, the investigator does not &#8220;identify&#8221; the user directly. That requires legal authority. The OSINT task is to document the route clearly enough that the next legal step is possible.</p><h3><strong>4. Check whether the wallet, domain, or username appears in public scam reports</strong></h3><p>Before going deeper, check whether the same wallet, domain, marketplace account, or username appears in public abuse reports.</p><p>This can help in two ways.</p><p>First, it may show that the case is not isolated. A wallet involved in one NFT project may also appear in previous complaints. A domain may be connected to multiple phishing pages. A username may have been reported by other victims.</p><p>Second, public reports may contain leads you would not find from the victim&#8217;s material alone: alternative usernames, related domains, transaction hashes, project names, or victim timelines.</p><p>What to look for:</p><ul><li><p>wallet address reports;</p></li><li><p>domain reports;</p></li><li><p>repeated usernames;</p></li><li><p>similar project names;</p></li><li><p>transaction hashes;</p></li><li><p>descriptions of the same pattern.</p></li></ul><p>What it can prove:</p><ul><li><p>that other people publicly reported similar activity;</p></li><li><p>that the same technical traces appear across complaints;</p></li><li><p>that a pattern may be broader than one victim.</p></li></ul><p>What it cannot prove:</p><ul><li><p>that every report is accurate;</p></li><li><p>that all reported cases involve the same operator;</p></li><li><p>that public reporting alone is enough for legal attribution.</p></li></ul><p>Treat public reports as leads, not final proof.</p><h3><strong>5. Investigate the public social layer of the project team</strong></h3><p>The blockchain shows transactions. The social layer may show how the project was presented and who publicly associated themselves with it.</p><p>NFT projects often have team handles, developer names, artist names, founder personas, Discord moderators, Twitter accounts, or promotional interviews. Some are real. Some are pseudonymous. Some are borrowed. Some are generated. Some are reused across platforms.</p><p>The OSINT task is not to dox private people. It is to document public associations relevant to the case.</p><p>What to look for:</p><ul><li><p>reused usernames across platforms;</p></li><li><p>public GitHub accounts connected to project code or websites;</p></li><li><p>interviews, podcasts, or launch announcements;</p></li><li><p>profile images that appear elsewhere;</p></li><li><p>domain registration traces, when available;</p></li><li><p>old archived pages that listed team details before deletion.</p></li></ul><p>What it can prove:</p><ul><li><p>that a public account was associated with the project;</p></li><li><p>that the same username appears across platforms;</p></li><li><p>that an avatar or profile may be copied, synthetic, or misleading;</p></li><li><p>that project claims about the team may be inconsistent.</p></li></ul><p>What it cannot prove:</p><ul><li><p>real identity without stronger corroboration;</p></li><li><p>criminal responsibility;</p></li><li><p>ownership of a wallet unless additional evidence connects the account to the address.</p></li></ul><p>This step is where many investigations become risky. Do not publish a real person&#8217;s identity simply because a username appears connected. Preserve the finding, assess confidence, and route sensitive attribution through legal or organizational channels.</p><h2><strong>Red Flags Before the Scam Happens</strong></h2><p>Many NFT scams show warning signs before victims buy.</p><p>No single signal is enough. Several together should change the risk assessment.</p><p>Useful warning signs include:</p><ul><li><p>anonymous team with no verifiable history;</p></li><li><p>unrealistic roadmap promising a game, token, marketplace, community benefits, and future utility in a short period;</p></li><li><p>large community numbers with little real conversation;</p></li><li><p>sudden sales volume from newly created wallets;</p></li><li><p>paid promotion presented as personal recommendation;</p></li><li><p>unverified contract;</p></li><li><p>creator-controlled minting functions that may allow excessive token creation;</p></li><li><p>copied artwork or near-duplicate collection names;</p></li><li><p>domain and social accounts created shortly before launch.</p></li></ul><p>The analytical value of these signs is not that they &#8220;prove&#8221; fraud. They help decide where to look next.</p><p>If the team is anonymous, focus on social OSINT and archived pages. If the sales volume looks artificial, examine wallet relationships. If the contract is unverified, document that limitation. If the art appears copied, use reverse image search and marketplace history.</p><p>Red flags guide the workflow. They do not replace it.</p><h2><strong>A Fictional Mini-Case</strong></h2><p>Assume a victim lost 9 ETH in a collection called &#8220;Lunar Orchard Pass.&#8221;</p><p>The website is offline. The social account is deleted. The victim still has the NFT contract address and one screenshot from the mint page.</p><p>The investigator starts with the contract.</p><p>The contract page shows that Wallet A created the collection two weeks before launch. Wallet B received the mint payments. Over 36 hours, Wallet B received many small buyer transactions. Four days later, almost the entire balance moved to Wallet C.</p><p>Wallet C split the funds across five new addresses.</p><p>Three of those addresses later sent funds to centralized exchanges. Two interacted with a mixing service.</p><p>At this point, the investigator has not identified a person. But the case is no longer vague. There is a transaction path, a timeline, and several points that legal authorities may be able to query.</p><p>The investigator then checks public reports. Wallet B appears in two previous complaints involving smaller NFT drops with similar disappearance patterns.</p><p>The social layer adds context. An archived version of the project page lists three team handles. One handle appears on a public code repository connected to an older crypto project. Another profile image appears to be reused from an unrelated account. A third handle appears only in the deleted project environment.</p><p>The result is not a public accusation.</p><p>The result is a structured dossier:</p><ul><li><p>archived project claims;</p></li><li><p>contract and wallet map;</p></li><li><p>transaction path;</p></li><li><p>public report matches;</p></li><li><p>social OSINT leads;</p></li><li><p>confidence levels;</p></li><li><p>open questions;</p></li><li><p>legal handoff points.</p></li></ul><p>That is the difference between &#8220;someone scammed my client&#8221; and an evidence chain.</p><h2><strong>Critical Mistakes</strong></h2><p>The first mistake is starting with identity.</p><p>Start with traces. Identity may come later, and often only through legal process.</p><p>The second mistake is treating the blockchain as complete truth.</p><p>The blockchain can show transactions. It cannot explain intent, ownership, coercion, authorization, or whether a wallet was controlled by one person or a group.</p><p>The third mistake is failing to preserve disappearing material.</p><p>If the project page, Discord messages, and team claims vanish before capture, the investigation becomes weaker even if the blockchain remains intact.</p><p>The fourth mistake is overvaluing public reports.</p><p>Reports are useful leads. They need corroboration.</p><p>The fifth mistake is publishing personal attribution too early.</p><p>OSINT can support a case. It should not become harassment, doxxing, or trial by thread.</p><h2><strong>The Transferable Method</strong></h2><p>NFT scams are not special because they are mysterious.</p><p>They are special because they combine unstable web evidence with durable transaction evidence.</p><p>The web layer disappears. The blockchain layer remains. The social layer fragments. The legal layer decides what can be turned into formal identification.</p><p>The investigator&#8217;s job is to keep those layers separate long enough to build a defensible chain:</p><p><code>Preserve what existed.<br>Identify the contract and wallets.<br>Trace the funds.<br>Check public abuse reports.<br>Map the social layer.<br>Mark what is proven, inferred, and still unknown.</code></p><p>You do not need to be a crypto specialist to start this kind of investigation.</p><p>You need to avoid the two traps: being intimidated by the blockchain, and being overconfident because the blockchain is public.</p><p>The useful question is not &#8220;Who is behind this wallet?&#8221;.</p><p>The useful first question is:</p><p><code>What can this wallet, this contract, this page, and this username each prove on their own?</code></p><p>Once you answer that, the case becomes less about crypto.</p><p>It becomes OSINT again.</p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[The New OSINT Question: What Can the AI Agent Change? ]]></title><description><![CDATA[When an AI Support Bot Can Change an Account]]></description><link>https://projectosint.substack.com/p/the-new-osint-question-what-can-the</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-new-osint-question-what-can-the</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Wed, 03 Jun 2026 13:01:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GCx3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GCx3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GCx3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GCx3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GCx3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GCx3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GCx3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:274144,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/200436709?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GCx3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 424w, https://substackcdn.com/image/fetch/$s_!GCx3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 848w, https://substackcdn.com/image/fetch/$s_!GCx3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!GCx3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F542dafc2-25cb-45b5-96be-ffa459936c6f_1920x1280.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The dangerous part of an AI support system is not the chatbot interface.</p><p>It is what the chatbot is allowed to do.</p><p>An account support bot that can answer questions is one thing. An account support bot that can change account details, trigger recovery flows, connect a new email address, or act inside a platform&#8217;s identity system is something else. At that point, the bot is no longer only a communication layer. It becomes an operator.</p><p>That distinction matters for OSINT, account security, platform investigations, and digital risk analysis.</p><p>If a human support agent makes a mistake, the error may still be serious. But there are familiar controls around human support: training, escalation, logs, supervision, internal policy, and sometimes personal accountability. With AI support, the weak point can move. The question is no longer only whether the system gives a correct answer. The question is whether it has been connected to functions that can change reality.</p><p>In account security, &#8220;reality&#8221; can mean a recovery email, a password reset path, a login credential, a verification step, or access to a private profile.</p><p>That is where the problem begins.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>The case is not only about Instagram</strong></h2><p>The reported incident involved attackers persuading an AI support system to help with account access. The public material around the case describes screenshots and videos shared in researcher and hacking communities, with the AI system apparently accepting requests that should have required stronger identity verification.</p><p>The specific platform matters, but the larger lesson is not platform-specific.</p><p>This is a pattern.</p><p>Companies are moving AI systems closer to operational workflows: support, moderation, account recovery, customer service, business tools, internal assistance, content review, and eventually agentic actions. These systems are not just reading text. They are being placed near buttons, permissions, databases, and workflows that can produce real effects.</p><p>For an investigator, this creates a new kind of object to examine: not just the account, not just the platform, not just the attacker, but the automated decision layer between a user request and a privileged action.</p><p>That layer can fail in ways that look different from traditional security failures.</p><p>There may be no stolen password. No malware. No phishing page. No exposed database. The weak point may be an automated assistant that accepts a request, interprets it as legitimate, and routes it into an account-change process.</p><h2><strong>System map: where the evidence lives</strong></h2><p>To investigate this kind of incident, do not start with the chatbot as a personality. Start with the system around it.</p><p>The information is usually distributed across several layers:</p><ul><li><p>public reports describing the incident;</p></li><li><p>platform statements or posts confirming whether a fix was applied;</p></li><li><p>screenshots or videos showing the claimed flow;</p></li><li><p>support documentation explaining legitimate account recovery;</p></li><li><p>user reports from affected accounts;</p></li><li><p>researcher discussion in public or semi-public communities;</p></li><li><p>platform policy on account changes, recovery, verification, and support automation.</p></li></ul><p>Each layer has a different evidentiary value.</p><p>A screenshot can show what someone claims happened, but it may not prove the full sequence. A video can show a flow, but it may not prove how broadly the flow worked. A company statement can confirm that an issue was addressed, but it may not explain the technical cause. A researcher discussion can point to a pattern, but it may also include exaggeration, incomplete testing, or copied claims.</p><p>The OSINT task is not to treat one layer as enough. It is to reconstruct what each layer can support.</p><h2><strong>A defensive workflow for investigating AI support failures</strong></h2><h3><strong>1. Separate the claim from the mechanism</strong></h3><p>Start by writing the claim in one sentence.</p><p>Example:</p><p><code>An AI support system was reportedly persuaded to assist with account access changes.</code></p><p>Then separate it from the possible mechanism:</p><p><code>Possible mechanism: the AI system accepted a request related to account recovery or account detail changes without sufficient verification.</code></p><p>This prevents the first common mistake: turning a reported outcome into a confirmed technical explanation. The outcome may be visible. The mechanism may still be uncertain.</p><p>What to look for:</p><ul><li><p>wording that describes what happened;</p></li><li><p>wording that describes how it supposedly happened;</p></li><li><p>whether the two are supported by the same evidence.</p></li></ul><p>What it can prove:</p><ul><li><p>the scope of the allegation;</p></li><li><p>the distinction between observed behavior and inferred cause.</p></li></ul><p>What it cannot prove:</p><ul><li><p>whether the exploit worked for all accounts;</p></li><li><p>whether the same pathway is still available;</p></li><li><p>whether the system failed because of the model, the workflow, permissions, or surrounding controls.</p></li></ul><h3><strong>2. Map the AI system&#8217;s authority</strong></h3><p>The central question is not &#8220;Was the bot smart enough?&#8221;.</p><p>The central question is:</p><p><code>What was the bot allowed to do?</code></p><p>In a support environment, an AI assistant may have several possible roles. It may answer questions. It may collect information. It may summarize a case for a human agent. It may initiate a support ticket. It may trigger an account flow. It may call internal tools.</p><p>These roles should not be treated as the same.</p><p>What to look for:</p><ul><li><p>whether the bot only responded with information;</p></li><li><p>whether it initiated or requested account changes;</p></li><li><p>whether it accessed account-specific data;</p></li><li><p>whether a human review step appeared to exist;</p></li><li><p>whether verification happened before any sensitive action.</p></li></ul><p>What it can prove:</p><ul><li><p>the level of operational privilege exposed to the AI layer.</p></li></ul><p>What it cannot prove:</p><ul><li><p>the exact internal architecture unless internal documentation, logs, or verified technical analysis are available.</p></li></ul><h3><strong>3. Build an evidence chain from public material</strong></h3><p>For public investigation, create a simple evidence table.</p><p>Use four columns:</p><p><code>Source type:<br>Claim supported:<br>Confidence:<br>Open question:</code></p><p>For example, a public article may support the fact that the incident was reported and that the company said it had fixed the issue. A screenshot may support that a certain interaction was shown. A company post may support that the issue was acknowledged or addressed. None of these alone necessarily proves the full exploitability of the system.</p><p>This is where OSINT discipline matters.</p><p>Do not collapse all evidence into one conclusion. Keep the chain visible.</p><h3><strong>4. Identify the missing controls</strong></h3><p>In account access incidents, useful analysis often comes from asking which control should have stopped the flow.</p><p>Possible controls include:</p><ul><li><p>identity verification before account changes;</p></li><li><p>limits on what an AI assistant can modify;</p></li><li><p>mandatory human approval for sensitive actions;</p></li><li><p>rate limits on repeated attempts;</p></li><li><p>anomaly detection for unusual recovery requests;</p></li><li><p>separation between conversational output and account operations;</p></li><li><p>audit logs that show who or what initiated the change.</p></li></ul><p>The goal is not to guess the internal failure. The goal is to define the control questions.</p><p>For OSINT readers, this is useful because it moves the discussion away from vague &#8220;AI failed&#8221; language and toward a concrete audit frame.</p><h3><strong>5. Preserve what remains uncertain</strong></h3><p>An AI support incident can be easy to overstate.</p><p>Public material may not show:</p><ul><li><p>how many accounts were affected;</p></li><li><p>whether the same method worked consistently;</p></li><li><p>whether the weakness was in the model, the support workflow, the permissions layer, or the account recovery policy;</p></li><li><p>whether attackers needed prior information about the target;</p></li><li><p>whether all steps were fully automated;</p></li><li><p>whether a patch fixed the root cause or only blocked one path.</p></li></ul><p>These gaps are not a weakness in your analysis. They are part of the analysis.</p><p>Good OSINT does not fill unknowns with confidence. It marks them.</p><h2><strong>Critical issues and false positives</strong></h2><p>There are three common mistakes in this type of investigation.</p><p>The first is treating the AI as the attacker. The attacker is still the human operator. The AI system is the manipulated interface or the vulnerable operational layer.</p><p>The second is treating every chatbot as equally dangerous. A chatbot that only answers general questions is not the same as an agent connected to account tools. Risk depends on authority.</p><p>The third is assuming that a company statement closes the investigation. A fix may close one pathway, but it does not automatically answer broader questions about design, privilege boundaries, escalation, auditability, and future agentic workflows.</p><p>For platform investigators, the real question is not whether this single path has been closed.</p><p>The real question is how many similar paths are being created as AI systems are given more operational power.</p><h2><strong>The analytical layer: AI support as an access surface</strong></h2><p>Traditional account security focuses on credentials, recovery emails, SIM swaps, phishing pages, malware, leaked databases, and social engineering against human support.</p><p>AI support introduces a hybrid surface.</p><p>It can be conversational like social engineering, automated like a workflow, and privileged like internal support. That combination is what makes it important.</p><p>An attacker does not always need to break encryption, steal a password, or compromise a device if a support system can be convinced to modify the account path. The practical risk is not &#8220;AI is insecure&#8221; as a slogan. The practical risk is that AI can become a trusted intermediary between an untrusted request and a sensitive action.</p><p>That is the pattern investigators should watch.</p><p>Not every AI support feature is dangerous. Not every incident proves systemic failure. But any AI system connected to identity, account recovery, permissions, payments, personal data, moderation, or platform enforcement should be treated as a high-risk operational layer.</p><p>The question for researchers is simple:</p><p><code>Where does the AI stop talking and start acting?</code></p><p>That boundary is now part of the evidence.</p><h2><strong>Operational takeaway</strong></h2><p>When investigating AI support incidents, do not focus only on the prompt, the chatbot, or the screenshot.</p><p>Map the authority.</p><p>Ask what the system could access, what it could change, what verification was required, what logs might exist, what human review was bypassed or preserved, and what remains unknown from public material.</p><p>The future of account security will not only depend on stronger passwords or better recovery flows. It will also depend on whether platforms can prevent AI agents from becoming shortcuts around their own controls.</p><p>For OSINT, this creates a new habit: every time an AI system is placed inside a support workflow, investigate it as both an interface and a permission boundary.</p><p>That is where the next class of platform failures may become visible first.</p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[The Source Is Disappearing]]></title><description><![CDATA[Google AI Mode and the OSINT Problem of the Disappearing Source]]></description><link>https://projectosint.substack.com/p/the-source-is-disappearing</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-source-is-disappearing</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 01 Jun 2026 15:01:49 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/469b5d56-233b-491e-94a2-64ff1da198d7_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Search used to begin with a list of sources.</p><p>Now, increasingly, it begins with an answer.</p><p>That shift looks convenient on the surface. Google AI Mode and AI Overviews are designed to compress the web into a conversational response: a user asks, the system reads across pages, summarizes what it finds, and offers a few links for context. For everyday browsing, this may feel faster. For OSINT, journalism, and digital investigation, it changes something more fundamental.</p><p>It changes the analyst&#8217;s first contact with evidence.</p><p>The problem is not only that AI-generated answers can be wrong. The deeper issue is that they can make the original source chain harder to see. A claim may arrive already cleaned, compressed, paraphrased, and detached from the messy context that gives it meaning: who published it, when it appeared, what wording was used, what other sources contradicted it, and whether the page has changed since.</p><p>For OSINT work, that context is not decoration. It is the work.</p><p>An AI answer can be useful as a lead. It can surface entities, suggest possible angles, and help map a topic quickly. But a lead is not a source. A generated paragraph is not an evidence trail. And a link attached to an AI summary is not automatically proof that the claim is supported by that page.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>This is where AI-mediated search becomes risky: it can make weak evidence look tidy.</p><p>One of the key shifts is interface behavior. Traditional search pushed the investigator outward: open a result, compare pages, inspect timestamps, save URLs, look for primary material. AI Mode can keep the user inside the conversation. Follow-up questions become easier than source checking. The answer improves in fluency, but the research path may become less reproducible.</p><p>That matters especially in investigations involving breaking news, cyber incidents, disinformation, corporate ownership, conflict footage, public records, sanctions, online identities, or any topic where timing and provenance affect interpretation.</p><p>A generated answer may merge three very different source types into one smooth paragraph: an official statement, a media report, and a social media claim. To a casual reader, the result may look coherent. To an investigator, that coherence can be a warning sign.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gtMi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gtMi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gtMi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gtMi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gtMi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gtMi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg" width="1200" height="1200" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:70484,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/199987920?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gtMi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gtMi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gtMi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gtMi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b15601f-a2d8-4a3e-a53a-970656b3290c_1200x1200.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The missing question is: what exactly supports what?</p><p>This is the discipline OSINT needs to preserve. AI Mode should not be treated as the end point of research, but as a starting layer that must be reopened. The analyst has to separate the AI answer from the linked sources, then separate the linked sources from independently verified evidence.</p><p>That means recording the query, capturing the generated answer, opening every visible source, checking whether each source actually supports the claim, and searching outside the AI interface. It also means preserving dates, URLs, screenshots, archive links, and the conditions under which the result appeared.</p><p>The workflow is not complicated, but it is easy to skip because the interface is built to reduce friction.</p><p>OSINT often requires putting friction back.</p><p>There is also a personalization problem. AI search can vary based on account state, location, language, subscriptions, previous activity, and interface changes. Two analysts may not see the same answer or the same source set. That does not make AI search unusable. It makes documentation more important.</p><p>The central rule is simple: never cite the answer when you can cite the evidence.</p><p>The full piece breaks down the practical workflow for reopening the source chain behind AI-generated search results, including what to capture, what to verify, and how to avoid treating summaries as findings.</p><p>Read the full analysis on Project OSINT: </p><p><a href="https://projectosint.com/google-ai-mode-osint-disappearing-source">https://projectosint.com/</a><strong><a href="https://projectosint.com/google-ai-mode-osint-disappearing-source">google-ai-mode-osint-disappearing-source</a></strong></p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[Merkel’s “Ten Years” and the Architecture of European Rearmament]]></title><description><![CDATA[What a single sentence from a Berlin podcast reveals &#8212; and what the documents behind it actually say]]></description><link>https://projectosint.substack.com/p/merkels-ten-years-and-the-architecture</link><guid isPermaLink="false">https://projectosint.substack.com/p/merkels-ten-years-and-the-architecture</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Thu, 28 May 2026 13:18:55 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cd4d7c9a-eb38-40ad-8220-8766fbaef47a_816x428.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;fee16e97-6dba-4605-97a3-1b25b1787fc6&quot;,&quot;duration&quot;:null}"></div><p>On May 18, during a podcast recorded in Berlin, former German Chancellor Angela Merkel said: <em>&#8220;In ten years, we hope the war in Ukraine will be over.&#8221;</em> The sentence circulated widely, interpreted by some as a slip, by others as a deliberate signal. Neither reading engages with the more verifiable question: what does the institutional timeline around that statement actually look like?</p><p>Merkel is not a serving official. She holds no formal position in the EU or the German government. Her statements carry no operational authority. What they do carry is context &#8212; and that context is documented.</p><h2>The Minsk Baseline</h2><p>Any reading of Merkel&#8217;s current statements requires anchoring to a previous one. On December 7, 2022, in an interview with <em>Die Zeit</em>, Merkel stated that the Minsk agreements signed in 2014 and 2015 had functioned, in her assessment, as time for Ukraine to build military capacity. Her precise framing: the agreements gave Ukraine &#8220;valuable time&#8221; to develop its defenses.</p><p>That interview is publicly available and has been widely reported. It generated significant diplomatic friction at the time, particularly from Russian officials who cited it as retroactive admission of bad faith in the negotiations. The German government did not issue a formal correction.</p><p>This is the evidentiary baseline: a documented statement by a former head of government, on record, regarding the functional use of a diplomatic process. Whether that represents candor, revisionism, or something else is a question the record leaves open. What the record does not leave open is that the statement was made.</p><h2>The German Military Doctrine: April 2025</h2><p>In April 2025, the German government published a new military doctrine &#8212; the <em>Bundeswehrplanung 2025</em> &#8212; outlining a structural expansion of the armed forces across three defined phases:</p><ul><li><p><strong>By 2029:</strong> Rapid rearmament. Active personnel increases from approximately 185,000 to 260,000. Combat-ready strength, including reserves, reaches 460,000.</p></li><li><p><strong>By 2035:</strong> Full-spectrum expansion across all branches.</p></li><li><p><strong>By 2039:</strong> Technology-led superiority as the doctrinal objective.</p></li></ul><p>The doctrine also revises the conscription framework, introducing a mechanism that allows mandatory service if voluntary recruitment falls short of targets. Russia is formally designated as the primary threat to European security.</p><p>These figures come from the published doctrine itself, not from interpretive sources. The 2039 endpoint is the document&#8217;s own language.</p><h2>The EU Defense Union Proposal</h2><p>In the same month, European Commissioner for Defence Andrius Kubilius publicly presented a proposal for a formal European Defence Union. The core elements of the proposal, as presented:</p><ul><li><p>A new treaty structure integrating the EU, the United Kingdom, Norway, and Ukraine under a shared security framework.</p></li><li><p>A permanent EU Security Council.</p></li><li><p>A standing EU rapid-reaction force of 100,000 personnel with centralized command.</p></li><li><p>EU-level weapons stockpiling.</p></li></ul><p>The proposal is framed as an extension of European Commission President Ursula von der Leyen&#8217;s &#8364;930 billion defense and armaments program, which targets 2030 as its primary delivery horizon. Von der Leyen&#8217;s program focuses on expanding European weapons production capacity and military readiness across member states.</p><p>The Kubilius proposal is a Commission-level document. It has not been adopted as binding policy. Its timeline, budget architecture, and institutional form remain subject to member state negotiation.</p><h2>What the Timelines Show</h2><p>Laid side by side, three timelines emerge from the source material:</p><p>Document Origin Key Horizon Von der Leyen defense program European Commission 2030 German military doctrine (<em>Bundeswehrplanung 2025</em>) German Federal Government 2029 / 2035 / 2039 Kubilius EU Defence Union proposal European Commission 2030+ Merkel podcast statement Personal, non-official &#8220;ten years&#8221; (~2035)</p><p>The German doctrine&#8217;s full-spectrum expansion target is 2035. Merkel&#8217;s informal horizon is &#8220;ten years&#8221; from May 2025 &#8212; which lands at approximately 2035. That alignment is a documented fact. What it means &#8212; coordination, coincidence, or shared institutional understanding &#8212; is not established by the documents alone.</p><h2>Verification Methodology</h2><p>For a reader who wants to verify this material independently, the chain is accessible:</p><p><strong>Step 1 &#8212; Merkel podcast (May 18, 2025).</strong> Search German-language media archives using the terms <em>&#8220;Merkel Podcast Berlin Mai 2025&#8221;</em> and <em>&#8220;zehn Jahre Ukraine.&#8221;</em> Multiple outlets covered the appearance; transcripts or clips are available through ARD, ZDF, and <em>Der Spiegel</em> archives.</p><p><strong>Step 2 &#8212; </strong><em><strong>Die Zeit</strong></em><strong> interview (December 7, 2022).</strong> The interview is indexed in <em>Die Zeit</em>&#8216;s public archive. Search <em>&#8220;Merkel Minsk Zeit Interview Dezember 2022.&#8221;</em> The original German text is the primary source; translated summaries in English-language outlets vary in precision.</p><p><strong>Step 3 &#8212; German military doctrine.</strong> The <em>Bundeswehrplanung</em> and associated documents are published by the Federal Ministry of Defence (<em>Bundesministerium der Verteidigung</em>). The April 2025 version is accessible via the ministry&#8217;s official portal. Personnel figures, phase timelines, and conscription provisions are directly verifiable in the original.</p><p><strong>Step 4 &#8212; Kubilius proposal.</strong> European Commission communications are published in the Official Journal and the Commission&#8217;s newsroom. Search <em>&#8220;Kubilius European Defence Union proposal 2025&#8221;</em> in the Commission&#8217;s document database. Cross-reference with von der Leyen&#8217;s &#8364;930 billion figure in her State of the Union address archives.</p><p><strong>Step 5 &#8212; Cross-reference and gap analysis.</strong> Note what the documents do not say: none of them reference Ukraine&#8217;s conflict in terms of a fixed endpoint. The German doctrine&#8217;s threat designation is categorical, not duration-dependent. Merkel&#8217;s &#8220;ten years&#8221; is a hope expressed in a non-official setting, not a planning document.</p><h2>What Remains Unverified</h2><p>The source material establishes the documents and statements listed above. It does not establish:</p><ul><li><p>Any coordination between Merkel&#8217;s statement and current German or EU planning cycles.</p></li><li><p>That the Minsk admission reflects the official position of the German government, then or now.</p></li><li><p>That the timelines in military doctrine and the Kubilius proposal are linked to a single strategic intent.</p></li><li><p>That any of the above constitutes a policy to prolong the conflict rather than prepare for post-conflict security architecture.</p></li></ul><p>These are analytical questions that the documents raise without answering. A rigorous reading distinguishes between what is documented, what is plausible given the documents, and what requires additional sourcing.</p><h2>The Structural Pattern</h2><p>What the documents collectively show is a European institutional architecture that is building toward mid-2030s military capacity as a planning horizon &#8212; regardless of how the Ukraine conflict resolves. The German doctrine explicitly extends to 2039. The EU defence proposal is framed around permanent structural integration, not crisis response.</p><p>Whether Merkel&#8217;s informal remark reflects awareness of that institutional timeline, or simply a realistic read of conflict dynamics, the documents do not decide. What they do show is that the timeline she named is not arbitrary relative to the planning documents that exist in the public record.</p><p>Readers who want to assess alignment between political statements and institutional timelines have the primary sources to do it. The gap between a politician&#8217;s words and a government&#8217;s documents is often where the most verifiable &#8212; and most consequential &#8212; information lives.</p><div><hr></div><div class="callout-block" data-callout="true"><p><em>All claims in this piece are sourced to publicly available primary documents or on-record statements. No inference has been presented as established fact. Readers are encouraged to consult the original sources listed in the verification section.</em></p></div><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[The Leak Wasn’t the Real Story]]></title><description><![CDATA[The OnlyFans Mega Leak Shows How Data Correlation Becomes an OSINT Problem]]></description><link>https://projectosint.substack.com/p/the-leak-wasnt-the-real-story</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-leak-wasnt-the-real-story</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 25 May 2026 12:39:56 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZWsW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZWsW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZWsW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZWsW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZWsW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZWsW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZWsW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68540,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/199182162?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZWsW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZWsW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZWsW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZWsW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37ff4142-9c42-4036-806a-f31540f5b58b_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The alleged OnlyFans mega leak quickly became another giant number in the breach economy: hundreds of millions of records, leaked accounts, exposed identities.</p><p>But the operational problem starts elsewhere.</p><p>Not with passwords.<br>Not with direct platform compromise.<br>With correlation.</p><p>Researchers reviewing the reported sample noted something that changes the entire investigative angle: parts of the dataset may have originated from older leaks, public sources, and unrelated breach collections rather than one fresh intrusion.</p><p>That distinction matters more than most headlines suggest.</p><p>Because modern identity exposure rarely comes from a single dataset anymore. It comes from accumulation.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>An email reused across:</p><ul><li><p>streaming accounts,</p></li><li><p>newsletters,</p></li><li><p>creator platforms,</p></li><li><p>ecommerce profiles,</p></li><li><p>gaming services,</p></li><li><p>archived breaches</p></li></ul><p>can quietly bridge identities that users assumed were separated.</p><p>A pseudonymous profile stops being pseudonymous once one repeated identifier connects the dots.</p><p>That is where OSINT becomes relevant.</p><p>The article breaks down how analysts actually evaluate breach claims:</p><ul><li><p>why samples matter more than headlines;</p></li><li><p>how investigators separate public data from breach-exclusive data;</p></li><li><p>why old datasets still create operational risk;</p></li><li><p>how attackers inflate credibility by merging recycled leaks together;</p></li><li><p>why phishing campaigns increasingly rely on emotional pressure instead of technical sophistication.</p></li></ul><p>One section is particularly revealing: investigators often spend less time asking &#8220;Was the platform hacked?&#8221; and more time asking:</p><ul><li><p>Which identifiers overlap?</p></li><li><p>Which timestamps do not match?</p></li><li><p>Which records look recycled?</p></li><li><p>Which accounts remain active?</p></li><li><p>Which identities can realistically be correlated?</p></li></ul><p>That verification layer is usually missing from public discussions.</p><p>The deeper issue extends far beyond one platform.</p><p>Dating apps, creator ecosystems, forums, gaming communities, subscription services, and pseudonymous online spaces all rely on the same fragile assumption: that fragmented identities remain disconnected.</p><p>Data correlation breaks that assumption surprisingly fast.</p><p>The full breakdown analyzes:</p><ul><li><p>the OSINT workflow used to validate breach claims;</p></li><li><p>the difference between aggregation and intrusion;</p></li><li><p>common mistakes analysts make when evaluating leaked datasets;</p></li><li><p>how identity reconstruction happens through overlap rather than direct exposure.</p></li></ul><p>Read the full article here:</p><p>&#128073; <a href="https://projectosint.com/onlyfans-mega-leak-osint-risk/">https://projectosint.com/onlyfans-mega-leak-osint-risk/</a></p><div><hr></div><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p>]]></content:encoded></item><item><title><![CDATA[The Ledger Is Public. The Identity Is Not.]]></title><description><![CDATA[A crypto wallet can show everything and still reveal nothing.]]></description><link>https://projectosint.substack.com/p/the-ledger-is-public-the-identity</link><guid isPermaLink="false">https://projectosint.substack.com/p/the-ledger-is-public-the-identity</guid><dc:creator><![CDATA[Project OSINT]]></dc:creator><pubDate>Mon, 18 May 2026 14:35:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZdeP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZdeP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZdeP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZdeP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZdeP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZdeP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZdeP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg" width="1200" height="675" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:675,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:65534,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/198269856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZdeP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ZdeP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ZdeP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ZdeP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe688f66e-62b8-4658-84e1-9142cc49c913_1200x675.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>That is the first trap in blockchain OSINT. A Bitcoin address, an Ethereum address, a transaction hash: they look precise, technical, almost definitive. You paste them into an explorer and the trail appears &#8212; timestamps, amounts, fees, counterparties, confirmations, token movements. The data is there. The mistake is believing the person is there too.</p><p>The full guide on Project OSINT starts from a realistic investigative entry point: a lawyer sends two wallet addresses and asks where the money went. One Ethereum. One Bitcoin. No names. No background. No case file. Just two strings and a question that sounds simple until the first methodological decision appears. Which explorer do you open? Which tab matters? Which output is the recipient, and which one is only change returning to the sender?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>That decision matters because blockchain explorers are not interchangeable. Ethereum and Bitcoin are separate infrastructures. A wallet beginning with <code>0x</code> belongs in an Ethereum explorer such as Etherscan. A Bitcoin address beginning with <code>1</code>, <code>3</code>, or <code>bc1</code> belongs in a Bitcoin explorer such as Blockchain.com or mempool.space. Use the wrong interface and the investigation starts with noise, not evidence.</p><p>The useful part of a blockchain explorer is not that it &#8220;finds the criminal.&#8221; It does not. Its value is narrower, and that is exactly why it is powerful.</p><p>It can show whether funds moved.<br>It can show when they moved.<br>It can show whether the destination was a normal address, a smart contract, a token transfer, or possibly a centralized exchange.<br>It can show patterns: consolidation, dispersal, urgency, failed attempts, stablecoin conversion, repeated counterparties.</p><p>What it cannot show, by itself, is who controls the address. The guide is very clear on this point: blockchain addresses are pseudonymous. The explorer records the address, not the person. Attribution requires external convergence &#8212; legal process, exchange records, open-source correlation, court material, leaks, or behavioral links that can be independently checked.</p><p>That gap is where weak crypto investigations collapse.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cL_Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cL_Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cL_Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cL_Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cL_Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cL_Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg" width="1200" height="670" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:670,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://projectosint.substack.com/i/198269856?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cL_Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cL_Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cL_Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cL_Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2403fc1f-6ddc-4c53-9736-4b11362c703d_1200x670.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One common error is treating a wallet label as proof. On Etherscan, labels can point to exchanges, protocols, mixers, or flagged addresses. But labels are not verdicts. They are leads. A tag can help structure the next question; it cannot close the case.</p><p>Another error is more technical but equally damaging: misreading Bitcoin outputs. Bitcoin does not behave like a simple bank transfer. A transaction may have multiple inputs and multiple outputs, and one of those outputs may be the sender&#8217;s own change address. Follow the wrong output, and the report sends the reader down a false path. The guide flags this as one of the most predictable mistakes in Bitcoin tracing.</p><p>The full piece also shows why Ethereum needs a different reading habit. The visible transfer is only the surface. Internal transactions, ERC-20 token movements, smart contract interactions, transaction fees, failed transactions, and decoded input data can all change the interpretation of what happened. A direct transfer, a token swap, and a contract interaction are not the same investigative event.</p><p>The real value of the method is not drama. It is discipline.</p><p>You do not start by naming a suspect.<br>You start by identifying the chain.<br>Then the explorer.<br>Then the wallet summary.<br>Then outgoing flows.<br>Then transaction-level fields.<br>Then the limits of what the data can prove.</p><p>The missing layer &#8212; and the reason the full guide is worth reading &#8212; is the workflow: how to move from a raw address to a structured analytical trail without overstating attribution, misreading outputs, or confusing public ledger data with identity evidence.</p><p>Read the full guide here:<br>&#128073; <a href="https://projectosint.com/blockchain-explorer-osint-crypto-tracing/">How to Read a Blockchain Explorer: OSINT Guide to Tracing Crypto Transactions</a></p><p style="text-align: right;">If this is useful, share it.</p><p style="text-align: right;">This is the weekly selection. But it&#8217;s not the only one.</p><p style="text-align: right;">If you&#8217;d like to read more: &#8594; full articles on the website </p><p style="text-align: right;">&#128073; <a href="https://projectosint.com">https://projectosint.com</a></p><p style="text-align: right;">If you&#8217;d like to get the latest updates first: &#8594; Telegram </p><p style="text-align: right;">&#128073; <a href="https://t.me/osintprojectgroup">https://t.me/osintprojectgroup</a></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://projectosint.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Project OSINT ! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>