Attackers rarely start with a technical exploit – they start with research. Through Open Source Intelligence (OSINT), they gather publicly available information about your organization, your employees, and your infrastructure. With this information, they craft tailored phishing attacks that can deceive even trained employees. Our OSINT and phishing simulations uncover exactly these attack surfaces – before a real attacker exploits them.
Open Source Intelligence (OSINT) refers to the systematic collection and analysis of publicly available information. Attackers use OSINT to gather email addresses, organizational structures, technical infrastructure details, and personal information about employees – all without directly attacking a single system. This information serves as the foundation for targeted social engineering attacks and phishing campaigns.
Phishing remains the most common initial attack vector in cyberattacks. Even the best technical defenses can be bypassed by a single employee click. That is why it is crucial to regularly test the human factor and sharpen awareness of social engineering risks.
We search relevant darknet forums, marketplaces, and paste sites for mentions of your organization, leaked data, or credentials being sold.
We check whether your employees' credentials have appeared in known data breaches. We identify compromised accounts and assess the risk of credential-stuffing attacks.
Analysis of the public social media presence of your organization and employees. What information can attackers use for targeted attacks?
Investigation of your domains, subdomains, DNS configurations, and exposed services. We identify forgotten assets, misconfigured entries, and potential attack vectors.
Based on OSINT results, we craft tailored phishing emails targeting specific departments, roles, or individuals – exactly as a real attacker would.
We measure in detail how your employees respond to phishing attempts: open rates, click rates, credential submissions, and reporting rates. This gives you a clear picture of the awareness level across your organization.
At the same time, we test the effectiveness of your technical email security: spam filters, DMARC/SPF/DKIM configurations, URL rewriting, and sandbox solutions.
Systematic collection of publicly available information about your organization, employees, and infrastructure.
Development of realistic phishing scenarios based on the collected OSINT data and your company profile.
Controlled execution of the phishing campaign with real-time tracking of all interactions.
Detailed evaluation of all results with concrete recommendations for improving your security posture.
Anonymized engagement example
A Swiss manufacturing company. 120 employees. 15% hand over their credentials.
MFA activated for all employees, targeted awareness training conducted, public documents cleaned up. Follow-up campaign three months later: click rate reduced from 34% to under 5%.
A Swiss manufacturing company with 120 employees wants to find out how much information about the company and its employees is publicly available — and whether staff would fall for a targeted phishing campaign.
Comprehensive dossier of all publicly discoverable information about your organization – including dark web findings, leaked credentials, exposed infrastructure, and social media risks.
Detailed evaluation of the phishing campaign with open rates, click rates, credential submissions, and timing analysis – broken down by department and scenario.
Measurable metrics on your employees' security awareness: reporting rates, response times, and comparison with industry benchmarks.
Prioritized recommendations for reducing the OSINT attack surface, improving email security, and strengthening employee awareness.