Reverse OSINT: What Does the Internet Know About YOU?
Most people use OSINT to gather intel on others. But the most powerful application for your personal security is Reverse OSINT (also known as Self-Doxing). By investigating yourself, you can patch security flaws before cybercriminals exploit them.
The 3-Step Guide to De-Doxing
Step 1: Think Like an Attacker
Search for yourself using incognito mode and multiple search engines.
Google Dorking your own name: Search for
"Firstname Lastname" + "City"or"Firstname Lastname" + filetype:pdfto uncover forgotten documents, like old club rosters or school PDFs.Trace your usernames: Plug your common online handles into tools like WhatsMyName.app. You might be surprised by the ancient forum accounts you forgot existed.
Step 2: Check Images and Leak Databases
Audit profile pictures: Upload your current profile photos into Google Lens or TinEye. Where else are they hosted?
Scan breach databases: Run your email addresses and phone numbers through HaveIBeenPwned.com. If your data was leaked, bad actors can easily find your passwords and info.
Step 3: Remove the Data (De-Doxing)
Delete legacy accounts: Use justdelete.me to find direct deletion links for obscure websites you no longer use.
Google Removal Requests: You can officially request Google to remove highly sensitive personal information (like explicit images, phone numbers, or home addresses) from search results.
Opt-out of Data Brokers: Data harvesters constantly buy and sell your background information. Services like Incogni or DeleteMe automate the process of forcing these brokers to delete your profiles.