Explainer · Philippines
By Cybercode.ph Editorial Team
Open-source intelligence, or OSINT, is how investigators, journalists, security teams and ordinary Filipinos check whether a seller, a job offer, a link or a viral photo is what it claims to be. This guide explains what OSINT is, what it can and cannot do, which tools matter, how accurate it is, where Philippine law draws the line, and how to use it at work through a problem-to-solution method you can apply today.
Direct answer
OSINT is intelligence produced by collecting and analysing information that anyone can lawfully access: websites, social media, public registries, news, satellite imagery, domain records and leaked-data notifications. The U.S. intelligence community defines it as intelligence “derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements, or gaps.” ODNI, IC OSINT Strategy 2024–2026
Two points matter most. First, OSINT is a method, not a tool: raw search results only become intelligence after verification and analysis. Second, “public” does not mean “free to use any way you like.” In the Philippines, personal information you find online is still personal information, and collecting, compiling or sharing it must satisfy the Data Privacy Act’s principles of transparency, legitimate purpose and proportionality. RA 10173, Section 11
- What it is: a disciplined way to answer a specific question using open information
- What it can do: verify identities, businesses, images, domains and claims; map your own exposure; support fraud and security investigations
- Accuracy: as good as its corroboration. A single source is a lead, not a finding
- Legal line: no hacking, no pretexting into private accounts, no doxxing, and a defensible purpose for any personal data you keep
1. What OSINT is, and what it is not
OSINT sits alongside other intelligence disciplines such as human intelligence (people) and signals intelligence (intercepted communications). What makes it “open source” is the access route: the information is available to the public, by request, by purchase or by observation, without breaking into anything.
A useful working definition has three parts:
- A question. “Is this online seller a real registered business?” is an OSINT question. “Find everything about this person” is not; it is a fishing expedition, and in most work settings it is also a privacy problem.
- Open sources. Search engines, social platforms, government registries, court decisions, corporate filings, domain and certificate records, maps, archived web pages and media metadata.
- Analysis. Cross-checking, dating, geolocating, attributing and assigning confidence. Without this step, you have a pile of screenshots, not intelligence.
OSINT is not guessing passwords, logging into someone else’s account, buying stolen databases, creating fake profiles to get inside private groups, or tricking a telco or bank agent into revealing records. Those activities move from research into potential offences. See Philippine legal lines below.
2. Why OSINT matters in the Philippines
Filipinos transact, hire, date, invest and get their news online, and fraud follows that activity. The same open information scammers use to target victims can be used to check them first. Cybercode’s scam guides repeatedly show the same pattern: a few minutes of verification before payment would have exposed the problem. See our coverage of job and task scams, romance scams and investment and crypto scams.
OSINT also matters for organisations. Under the Data Privacy Act, companies must protect personal data they hold. Knowing what your staff, systems and brand expose publicly is part of understanding your risk. Cybersecurity in the Philippines: legal duties and practical baseline
3. What OSINT can do
| Capability | Typical question | Main sources |
|---|---|---|
| Identity and business verification | Is this seller, agency or “investment company” real and registered? | SEC, DTI business name registry, BSP institution lists, official websites |
| Image and video verification | Is this viral photo recent, real and from where it claims? | Reverse image search, metadata, maps, weather and shadow analysis |
| Domain and link analysis | Is this link a phishing clone of a bank or e-wallet? | Domain registration (RDAP/WHOIS), certificate logs, web archives |
| Exposure mapping | What can an attacker learn about our company or my family? | Search engines, social profiles, breach-notification services, internet-device search |
| Due diligence | Should we sign with this vendor, partner or hire? | Corporate filings, court decisions, news archives, regulator advisories |
| Disinformation tracking | Who first posted this claim and how did it spread? | Platform search, archived posts, account creation patterns |
What OSINT cannot do: see private messages, read bank or telco records, confirm who controls an anonymous account to a legal standard, or replace a police, NBI or court process. When the answer sits behind a private wall, the lawful route is a report to the platform, the regulator or law enforcement.
4. Problem-to-solution guide: six real situations
Most OSINT guides list tools. The better approach is to start from the problem. Each situation below follows the same four moves: define the question, check the official source first, corroborate with two independent signals, then act or escalate.
Problem 1: An online seller wants full payment before delivery
- Question: Is this a real, traceable business?
- Official source first: Search the business name in the DTI business name registry (sole proprietors) or SEC records (corporations). A registered name does not prove honesty, but a fake or mismatched name is a red flag.
- Corroborate: Reverse-search the product photos. If they appear on overseas stores or older listings, they were copied. Check how old the page is and whether its name changed recently.
- Act: Use platform checkout or cash-on-delivery. If you already paid, preserve evidence and follow our help directory for banks, wallets and shopping apps.
Problem 2: A job offer arrives by text or Telegram
- Question: Does this employer and recruiter actually exist?
- Official source first: Find the company’s own website independently (do not click the link sent to you) and check whether the role is posted there. For overseas jobs, check the government’s licensed-agency listings.
- Corroborate: Search the recruiter’s phone number and name in quotation marks. Check whether the “HR” profile picture is a stock or stolen photo.
- Act: Any request to pay a fee or complete “tasks” for commission matches known scam patterns. See how to report a job or task scam.
Problem 3: A link claims to be from your bank or e-wallet
- Question: Is this domain controlled by the institution?
- Official source first: Compare the domain exactly with the one printed on your card or the official app. Look for added words, hyphens or swapped letters.
- Corroborate: Run an RDAP/WHOIS lookup. A domain registered days ago is a strong warning sign. Check the web archive for whether the page existed before.
- Act: Do not enter credentials. If you did, contact the institution through its official hotline immediately. See our GCash and Maya guides.
Problem 4: A dramatic photo or video is going viral
- Question: Is it authentic, current and from the stated place?
- Official source first: Check whether PAGASA, an LGU, PNA or the agency involved has said anything.
- Corroborate: Reverse-search key frames. Match landmarks, signage language, road markings and shadows to maps. Look for the earliest upload.
- Act: Do not share until verified. If the content may be an AI fake involving a real person, see how to prove a deepfake is fake.
Problem 5: You think you are being targeted or stalked online
- Question: What can a stranger learn about me, and from where?
- Official source first: Search your full name, mobile number and email in quotation marks. Check breach-notification services for your email addresses.
- Corroborate: Review old posts showing your address, school, workplace, routine or children. Check tagged photos and public friend lists.
- Act: Lock down or remove exposed details, change reused passwords and enable two-factor authentication. If someone is harassing you, preserve evidence first. Electronic evidence checklist
Problem 6: Your company is about to sign a new vendor
- Question: Is the vendor real, solvent, legitimately operating and free of red flags relevant to the deal?
- Official source first: SEC registration and filings, regulator advisories, and Supreme Court e-Library decisions involving the company.
- Corroborate: News archives, the vendor’s domain age and security posture, and whether named officers match public records.
- Act: Record findings in the vendor file. For AI and data vendors, pair OSINT with contractual safeguards. AI vendor due diligence checklist
5. OSINT tools by job
Tools change quickly. Organise them by the job they do, and always prefer the official source when one exists. Inclusion here is not an endorsement; check each tool’s terms and your organisation’s data policies before use.
| Job | Examples | Use with care because |
|---|---|---|
| Philippine official records | SEC company records and advisories, DTI business name search, BSP lists of supervised institutions, IPOPHL trademark search, Supreme Court e-Library, Official Gazette | Registration proves existence, not legitimacy of every activity |
| Search | Advanced search operators (site:, filetype:, quotation marks, minus), multiple search engines | Results are personalised and incomplete |
| Images and video | Google Lens, TinEye, Bing Visual Search, InVID-WeVerify plugin, ExifTool for metadata | Most platforms strip metadata; missing EXIF proves nothing |
| Domains and infrastructure | ICANN RDAP lookup, certificate-transparency search (crt.sh), Wayback Machine, Shodan | Privacy-protected registrations hide owners; Shodan shows exposure, not permission to touch |
| Breach exposure | Have I Been Pwned | Use to check your own or your organisation’s accounts, not to obtain others’ leaked data |
| Maps and geolocation | Google Earth and Street View, OpenStreetMap, Sentinel Hub satellite imagery | Imagery dates vary; confirm the capture date |
| Link analysis and automation | Maltego, SpiderFoot, theHarvester, the OSINT Framework directory | Automated collection can over-collect personal data. Scope it tightly |
| Preservation | Full-page capture with URL and timestamp, web archive submissions, hash values for files | Screenshots alone are weaker evidence; see authenticating electronic evidence |
6. How accurate is OSINT
OSINT can be highly accurate, and it can be confidently wrong. Accuracy depends on method, not on the tool. The most common failure is treating a single result as proof: a reverse image match, a name in a search result, or a profile with the same photo.
Professional practice rates two things separately:
- Source reliability: Is the source official, established and consistent, or anonymous and new?
- Information credibility: Is the specific claim confirmed by other independent sources, or does it stand alone?
A practical confidence scale for workplace use:
| Confidence | Meaning | What you may do with it |
|---|---|---|
| Confirmed | An official record plus at least one independent corroboration | Base decisions on it; cite the record |
| Probable | Two or more independent open sources agree; no official record | Use for internal risk decisions; state the limits |
| Possible | One source or circumstantial match | Treat as a lead; do not accuse, publish or act against a person |
| Unverified | Cannot be checked, or sources conflict | Do not rely on it |
The biggest accuracy risks are name collisions (many Filipinos share common names), recycled images, edited or AI-generated media, outdated records, and confirmation bias: finding what you expected to find. Name a person only when you can explain the evidence chain, and say what you could not verify.
7. Philippine legal lines
There is no Philippine statute named “OSINT law.” The rules come from existing laws that apply depending on what you collect and what you do with it.
The Data Privacy Act still applies to public information
Personal information does not lose protection simply because it is posted publicly. If you collect, organise, store or share it, you are processing personal information. The processing must follow transparency, legitimate purpose and proportionality, and must have a lawful basis such as consent, a legal obligation or a legitimate interest that is not overridden by the data subject’s fundamental rights. RA 10173, Sections 11 and 12
The NPC has issued guidance on legitimate-interest processing under NPC Circular No. 2023-07, and on processing for legal claims, which requires that data be “adequate, relevant, suitable, and not excessive” for the purpose. NPC Advisory No. 2024-02
Some processing falls outside the Act’s scope, including personal information processed for journalistic, artistic, literary or research purposes, and processing by public authorities performing constitutional or statutory functions, subject to conditions. These exclusions are not a blanket licence. RA 10173, Section 4 For background, see What is RA 10173? and Data Privacy Act penalties.
Where research becomes cybercrime
Accessing “the whole or any part of a computer system without right” is illegal access. Using or acquiring another person’s identifying information “without right” can be computer-related identity theft. RA 10175, Sections 4(a)(1) and 4(b)(3) Guessing passwords, using leaked credentials, or creating accounts impersonating real people falls on the wrong side of this line. See what RA 10175 covers and does not cover.
Doxxing and harassment
Compiling and posting someone’s information to shame, threaten or expose them can create liability under several laws, depending on the facts. The Safe Spaces Act, for example, covers gender-based online sexual harassment including “unauthorized recording and sharing of any of the victim’s photos, videos, or any information online” and “impersonating identities of victims online.” RA 11313, Section 12
| Generally acceptable OSINT | Crosses the line |
|---|---|
| Checking a seller’s business registration | Logging into a seller’s account with a leaked password |
| Reverse-searching a suspicious profile photo | Creating a fake profile to join a private group and harvest members’ data |
| Verifying a viral video’s location | Publishing a private person’s home address to “expose” them |
| Auditing your company’s public exposure | Scanning or probing systems you do not own or have permission to test |
| Documenting a scammer’s public posts for a report | Calling a telco pretending to be the subscriber to obtain records |
8. How to use OSINT at work
OSINT pays off in HR verification, procurement, fraud and claims review, brand protection, security, compliance, journalism and legal support. The difference between useful workplace OSINT and a privacy incident is process. Use this five-step workflow.
- Write the requirement. One sentence: what decision this supports and what question must be answered. Record who asked and why.
- Check purpose and proportionality. Identify the lawful basis. For people, collect only what the decision needs. Your organisation’s DPO should approve recurring OSINT activities and include them in privacy notices where applicable. Data privacy compliance checklist for SMEs
- Collect from official sources first, then open sources. Use a separate work browser profile, do not interact with targets, and do not log in to personal accounts.
- Verify and grade. Apply the confidence scale above. Note conflicts and gaps.
- Report, preserve and dispose. Report findings with sources, timestamps and confidence. Preserve evidence properly if a complaint or case is likely. Electronic evidence preservation Delete personal data you no longer need under your retention policy.
Role-based uses:
- HR: verify claimed employers, licences and public professional records with the candidate’s knowledge. Do not trawl personal social media for unrelated traits.
- Procurement and finance: confirm vendor registration, check regulator advisories, and verify bank-detail change requests through a known contact, not the email that requested the change.
- Security and IT: map exposed staff emails, subdomains and leaked-credential notifications for your own domain; use findings to train staff against phishing.
- Brand and marketing: find fake pages, counterfeit listings and impersonating accounts, then use platform reporting and trademark remedies.
- Legal and compliance: document public evidence for complaints and claims, observing NPC guidance on processing for legal claims.
9. How OSINT makes the world a better place
Used responsibly, OSINT shifts power toward ordinary people. A buyer can check a seller before paying. A parent can see what strangers can learn about a child’s public account. A reporter can verify a disaster video before it misleads thousands. Researchers worldwide have used satellite imagery, public posts and shipping data to document illegal fishing, environmental damage and human rights abuses that would otherwise stay hidden. Security teams use it to find and fix their own exposure before criminals exploit it.
The same techniques can harm when used for stalking, harassment or targeting. The defence is not to avoid OSINT, but to practise it with a clear purpose, minimum necessary data, verification before accusation and respect for the law.
10. Questions people always ask about OSINT
What does OSINT stand for?
OSINT stands for open-source intelligence: intelligence derived from publicly or commercially available information to answer a specific question. “Open source” refers to how the information is accessed, not to open-source software. ODNI, IC OSINT Strategy 2024–2026
What is an example of OSINT?
Checking whether an online seller’s business name is registered with the DTI or SEC, then reverse-searching its product photos to see if they were copied from another store, is a simple OSINT check. So is looking up when a suspicious bank-lookalike domain was registered.
Is OSINT accurate?
It can be, if findings are corroborated. Treat a single source as a lead, not a fact. A finding is strongest when an official record is confirmed by at least one independent source. Name collisions, recycled images, AI-generated media and outdated records are the most common causes of error.
Who uses OSINT?
Law enforcement, journalists and fact-checkers, cybersecurity and threat-intelligence teams, fraud and compliance investigators, HR and procurement teams, lawyers, researchers and ordinary consumers checking sellers, links and job offers before acting.
What are the best free OSINT tools?
For most Philippine users: the SEC, DTI and BSP registries, advanced search operators, Google Lens or TinEye for reverse image search, an RDAP/WHOIS lookup, the Wayback Machine and Have I Been Pwned for your own accounts. The right tool depends on the question; see OSINT tools by job.
Can employers use OSINT on job applicants?
Employers can verify job-relevant facts, such as claimed employment, licences and professional records, but this is processing of personal information under the Data Privacy Act. It needs a lawful basis, must be proportionate to the hiring decision and should be disclosed to applicants, for example in the recruitment privacy notice. Trawling personal social media for unrelated traits is hard to justify. RA 10173, Sections 11 and 12
Is OSINT legal in the Philippines?
Collecting and analysing lawfully accessible information is generally legal. Liability arises from how you obtain it (for example, illegal access) and what you do with personal information (for example, processing without a lawful basis, or using it to harass). RA 10173; RA 10175
If information is public, can I use it freely?
No. Personal information remains protected under the Data Privacy Act when you process it. You still need a legitimate purpose and must not collect more than the purpose requires. RA 10173, Section 11
Is OSINT the same as hacking?
No. OSINT uses information that is open to the public. Hacking involves accessing systems or accounts without right, which can be illegal access under RA 10175. RA 10175, Section 4(a)(1)
Can OSINT find who is behind a dummy or anonymous account?
Sometimes it produces strong leads, such as reused photos, usernames or writing patterns. It rarely proves identity to a legal standard. Report the account to the platform and, if a crime is involved, to the PNP Anti-Cybercrime Group, NBI or CICC, which can seek records through legal process. What the CICC handles
Can I use OSINT findings in a complaint or court case?
Often, yes, if properly preserved and authenticated. Capture full pages with URLs and dates, keep originals, and record how you obtained them. Are screenshots, emails and chats admissible?
Do I need paid tools to do OSINT?
No. Most everyday verification uses free official registries, search operators, reverse image search, domain lookups and web archives. Paid platforms add automation and scale, which increases the duty to scope collection tightly.
How do I protect myself from someone using OSINT against me?
Run the Problem 5 checklist on yourself: search your name, number and email; remove addresses, routines and children’s details from public posts; use unique passwords with two-factor authentication; and review who can see your friend list and tagged photos.
Is OSINT a good career skill?
Yes. It is used in cybersecurity, threat intelligence, fraud investigation, compliance, journalism, risk consulting and legal support. Employers value verification discipline, clear reporting and privacy awareness as much as tool knowledge.
Bottom line
OSINT is the habit of asking a precise question, checking the official source first, corroborating before believing, and acting within the law. Use it to protect yourself, your money and your organisation, not to expose people.
Related CyberCode coverage
Sources checked as of: October 5, 2026
This article provides general Philippine legal information, not advice on a particular case.

