What Hackers Know About You
Internet Risks
Many people underestimate how much they reveal about themselves through seemingly harmless posts, photos, or comments. But to hackers, it’s an open book. This campaign shows how your digital footprints can become a trap and how you can protect yourself from it.
What do you reveal about yourself online? More than you’d like. Photos, comments, or likes often reveal where you live, your employer, or who you’re in touch with. Hackers exploit this information in a targeted way—completely legally—using so-called OSINT methods. This leads to personal attacks, such as through fake emails or social media. This campaign shows you how hackers think, what they look for, and how you can protect yourself. Sharing less means greater security.
What is the problem?
Many people carelessly share information online without realizing the risks. Hackers use exactly this information for attacks such as identity theft, fraud, or phishing. They combine publicly available information to carry out targeted attacks through social manipulation.
How can I recognize the danger?
If you’re surprised by how much strangers know about you, then you’ve shared too much.
What information makes you vulnerable?
Date of birth, location, occupation, friend lists—we often reveal more than we realize. This data can be specifically targeted against you.
«You can’t not communicate, but you can choose wisely.”»
How can I protect myself?
Before every post, ask yourself if you’d tell this information to a stranger. Share thoughtfully, adjust your privacy settings, and restrict access to personal information.
How to Protect Yourself Against OSINT and Social Engineering
Check your privacy settings
Limit the visibility of your content to “Friends Only” or “Only Me.”
Disable location data
Avoid letting photos or posts reveal where you are.
Don’t share your date of birth publicly
The date of birth is a common starting point for identity theft.
Hide friend lists
Protect your network—your contacts are valuable to attackers.
Be sparing with professional information
Sharing fewer details on platforms like LinkedIn makes targeted attacks more difficult.
Don’t announce your vacation plans
When you’re away, you’re vulnerable both digitally and physically.
Check screenshots and documents
Be careful not to reveal any sensitive information.
Check photos for clues
Watch out for house numbers, IDs, children, or place name signs in the background.
Remove image metadata
Remove GPS coordinates and other metadata before uploading.
Google your personal information
Search for your name regularly and see what others can find.
What is OSINT?
Open Source Intelligence refers to the collection of publicly available information. Anything you post online that’s freely accessible can be analyzed, combined, and misused by third parties.
Social Engineering Explained
Attackers use psychological tricks to obtain information or gain access. The more they know about you, the more credible they appear—and the more dangerous it becomes.
Additional information
A practical introduction to common deception methods—from love scams to CEO fraud. Highlights the role of information.
Social Engineering: How Cybercriminals Manipulate UsTips on how to maintain control over your information on social media.
Data Privacy on Social MediaShows how attackers use everyday technology like QR codes for social manipulation.
Be Careful with QR CodesA technical introduction to OSINT and the risks posed by freely available data.
Imperva: Open Source Intelligence (OSINT)Practical guide to conducting your own digital research and minimizing risks.
OSINTGuide.com: Protect Yourself from OSINTFor individuals: shows how to identify and reduce personal data.
EFF: Den eigenen digitalen Fussabdruck kontrollierenOverview of OSINT tools and their everyday applications.
OSINT-Framework
Social Engineering
Social engineering is a common method of manipulating people so they give up confidential information. Attack target is always the human.
Criminals use social engineering tactics because it is usually easier to exploit your natural inclination to trust than it is to discover ways to hack your software. For example, it is much easier to fool someone into giving you their password than it is for you to try hacking their password (unless the password is really weak).
In order to obtain confidential information, it is very often the good faith and the helpfulness but also the uncertainty of a person exploited. From fake phone calls, to people pretending to be someone else, to phishing attacks, anything is possible.
Social networking sites have made social engineering attacks easier to conduct. Today's attackers can go to sites like LinkedIn and find all of the users that work at a company and gather plenty of detailed information that can be used to further an attack.
CEO Fraud
CEO fraud is a sophisticated email scam that cybercriminals use to trick employees into transferring them money or providing them with confidential company information.
Cybercriminals send savvy emails impersonating the company CEO or other company executives and ask employees, typically in HR or accounting to help them out by sending a wire transfer. Often referred to as Business Email Compromise (BEC), this cybercrime uses spoofed or compromised email accounts to trick email recipients into acting.
CEO fraud is a social engineering technique that relies on winning the trust of the email recipient. The cybercriminals behind CEO fraud know that most people don’t look at email addresses very closely or notice minor differences in spelling.
These emails use familiar yet urgent language and make it clear that the recipient is doing the sender a big favor by helping them out. Cybercriminals prey on the human instinct to trust one another and on the desire to want to help others.
Open Source Intelligence (OSINT)
Open Source Intelligence refers to the collection of publicly available information. Anything you put on the web can be analyzed, combined and abused by third parties.


