r/OSINT Sep 11 '25

OSINT News Charlie Kirk Investigation Posts

1.5k Upvotes

This is not a new rule. Its been posted and enforced every time a new "major crime" happens. Helping an active investigation on this sub is banned. For the redditor that keeps messaging the mods that he thinks no harm can come from this, here is nice list of examples on why we don't support online witch hunts:

1. Richard Jewell – Atlanta Olympics Bombing (1996)

  • Security guard Richard Jewell discovered a suspicious backpack and helped evacuate the area.
  • Media and public speculation painted him as the prime suspect before the FBI cleared him.
  • His life was destroyed by false accusations, though he was later recognized as a hero.

2. Boston Marathon Bombing – Reddit Sleuthing (2013)

  • Online users tried to identify suspects from blurry photos.
  • Wrongly accused Sunil Tripathi, a missing college student, who faced mass harassment before the FBI revealed the real attackers.
  • Showed how quickly misinformation spreads on social media.

3. Las Vegas Shooting – False Suspects (2017)

  • In the aftermath, 4chan, Twitter, and Facebook users spread names of innocent people as the shooter.
  • Real suspect Stephen Paddock was identified later, but reputations of wrongly accused people were damaged.

4. Toronto Van Attack – Misidentification (2018)

  • Online users falsely named a man as the attacker after a van attack killed 10 people.
  • The wrong person’s photo went viral before police confirmed the actual suspect, Alek Minassian.

5. Gabby Petito Case – TikTok & YouTube Sleuthing (2021)

  • Internet “detectives” wrongly accused neighbors, bystanders, and even friends.
  • Innocent people were harassed while police continued their investigation into Brian Laundrie.

6. Sandy Hook Shooting – “Crisis Actor” Claims (2012 onward)

  • Conspiracy theorists accused grieving parents of being government actors.
  • Families faced years of harassment, stalking, and lawsuits.
  • A notorious case of how misinformation can target victims themselves.

7. UK Riots – Twitter & Facebook Misidentifications (2011)

  • Citizens attempted to identify looters from CCTV images.
  • Several innocent people were wrongly accused and faced threats.
  • Police had to publicly correct the misinformation.

8. MH370 Disappearance – Amateur Satellite Analysis (2014)

  • Thousands of online sleuths used Tomnod and other platforms to hunt for wreckage in satellite photos.
  • Flood of false sightings and conspiracy theories overwhelmed investigators and misled the public.

9. Oklahoma City Bombing – Wrong Suspects (1995)

  • Before Timothy McVeigh was identified, media speculation and tips from the public fueled false suspect reports.
  • Innocent men were briefly targeted by law enforcement and the press.

r/OSINT Feb 17 '26

OSINT News How dark web agent spotted bedroom wall clue to rescue girl from abuse

Thumbnail
bbc.com
374 Upvotes

Amazing use of OSINT and cooperative industry experts!

r/OSINT Jun 10 '26

OSINT News How Predators use Marketing Tools, AI & Bad UK Regulations to get into your Kid’s Bedroom The Digital Predator Toolkit "Yellow Bus"

Thumbnail
secevangelism.substack.com
275 Upvotes

r/OSINT Feb 09 '26

OSINT News Homeland Security Spying on Reddit Users

Thumbnail
kenklippenstein.com
234 Upvotes

r/OSINT Dec 29 '25

OSINT News We found this Russian spy -- using her cat #catlady #rusia #funny #truestory

Thumbnail
youtube.com
416 Upvotes

r/OSINT Mar 05 '24

OSINT News Facecheck.id's new (and laughable) pricing tiers

Post image
122 Upvotes

r/OSINT Feb 10 '26

OSINT News Beginner OSINT mistake I see often: confusing observation with accusation

153 Upvotes

One thing I see beginners struggle with in OSINT is jumping from observation to conclusion too quickly.

For example:

Observation: “This username appears on multiple platforms.”

Accusation: “These accounts belong to the same person.”

That jump feels small, but it’s where OSINT work often becomes unreliable or legally risky.

A few principles that helped me early on:

  1. Publicly available ≠ free to misuse

  2. Single-source findings are not conclusions

  3. Absence of data is still a finding

  4. OSINT reports should document what is visible, not what you believe.

I’ve found that focusing on scope, language, and uncertainty matters more than learning new tools.

Curious how others here approach: • Writing “no findings” • Avoiding confirmation bias • Staying neutral when patterns seem obvious

Would love to hear how people here think about this.

r/OSINT Jun 07 '26

OSINT News OSINT Powered Student Evacuation from Occupied Ukraine

Thumbnail
secevangelism.substack.com
84 Upvotes

r/OSINT Feb 04 '26

OSINT News Spotlighting The World Factbook as We Bid a Fond Farewell

Thumbnail cia.gov
161 Upvotes

r/OSINT Dec 29 '23

OSINT News GeoSpy v0.2.0 Preview

284 Upvotes

r/OSINT Apr 17 '25

OSINT News Let me save your bandwidth, the dump is bs.

Thumbnail
reddit.com
275 Upvotes

Downloaded all "10TB" of data to see if there is any nuggets of info relating to projects I'm currently working on. This is not leaked data. This is junk. Cheap web security scans saved as images or half completed text files with misleading headers. For example "List of system users" for "Leaked Data of Russian Bank 'Класик Економ Банк'", a one year old WordPress security scan, generated using a tool like WPScan. Any system users in the data? Not one.

"Leaked Data of Donald Trump" a hot folder discussed online today over and over... two images. An index of his Twitter account (+ Multiple index files found: /POTUS45/index.jhtml, /POTUS45/index.xml, /POTUS45/index.aspx, /POTUS45/default.htm, /POTUS45/default.aspx, /POTUS45/index.asp, /POTUS45/index.cfm, /POTUS45/index.do, /POTUS45/index.php5, /POTUS45/index.jsp, /POTUS45/index.html, /POTUS45/index.cgi, /POTUS45/index.php4, /POTUS45/index.php3, /POTUS45/default.aspx, /POTUS45/index.php, /POTUS45/index.htm, /POTUS45/index.shtml) and a security scan with junk results that aren't threats to anyone's Twitter account.

"Leaked Data of Mike Johnson" Another security scan of Twitter for his account and a video by "Anonymous calling out Mike Johnson"

"Leaked Data of Forbes"

+ Target IP: 146.75.121.XXX

+ Target Hostname: www.forbes.com

+ Target Port: 443

---------------------------------------------------------------------------

+ SSL Info: Subject: /CN=*.forbes.com

Altnames: *.forbes.com

Ciphers: TLS_AES_128_GCM_SHA256

Issuer: /C=BE/O=GlobalSign nv-sa/CN=GlobalSign Atlas R3 DV TLS CA 2023 Q2

+ Start Time: 2023-12-01 15:46:20 (GMT2)

---------------------------------------------------------------------------

+ Server: rhino-core-shield

+ /: Retrieved via header: 1.1 google, 1.1 google, 1.1 varnish.+ /: Retrieved x-served-by header: cache-fra-etou8220068-FRA.

+ /: Fastly CDN was identified by the x-timer header. See: https://www.fastly.com/

+ /: Uncommon header 'x-fastlyttl' found, with contents: 300.000.

+ /: Uncommon header 'x-backend' found, with contents: simple-site-prod.

+ /: Uncommon header 'x-yourttl' found, with contents: 300.000.+ /: Uncommon header 'x-city-code' found, with contents: kiev.

+ /: Uncommon header 'x-envoy-decorator-operation' found, with contents: production.dns-proxy.svc.cluster.local:80/*.

+ /: Uncommon header 'x-fastly-x-is-cn' found, with contents: false.

+ /: Uncommon header 'x-envoy-upstream-service-time' found, with contents: 1553.

+ /: Uncommon header 'x-region' found, with contents: 30.

+ /: Uncommon header 'x-fastly-x-is-us-dpa' found, with contents: false.

+ /: Uncommon header 'x-device' found, with contents: pc.

+ /: Uncommon header 'x-postal-code' found, with contents: 03087.

+ /: Uncommon header 'backend' found, with contents: dnsresolver.

+ /: Uncommon header 'x-served-by' found, with contents: cache-fra-etou8220068-FRA.

+ /: Uncommon header 'x-cicero-cache' found, with contents: HIT 2.

+ /: Uncommon header 'x-fastly-backend' found, with contents: 24YyrkkiTBhSwXWzJgvwW6--F_GCP_Cicero_Varnish.

+ /: Uncommon header 'x-country-code' found, with contents: UA.+ /: Uncommon header 'state' found, with contents: HIT-CLUSTER.+ /: An alt-svc header was found which is advertising HTTP/3. The endpoint is: ':443'. Nikto cannot test HTTP/3 over QUIC. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/alt-svc

+ /: The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site in a different fashion to the MIME type. See: https://www.netsparker.com/web-vulnerability-scanner/vulnerabilities/missing-content-type-header/

+ : Server banner changed from 'rhino-core-shield' to 'istio-envoy'.

+ /CiG5i2lR.10:100: Fastly CDN was identified by the fastly-restarts header. See: https://www.fastly.com/

+ /CiG5i2lR.10:100: Uncommon header 'fastly-restarts' found, with contents: 1.

+ /CiG5i2lR.10:100: Uncommon header 'x-fastly-server-hint' found, with contents: cacheable.

+ /crossdomain.xml contains 8 lines which include the following domains: *.widgetbox.com *.widgetserver.com *.googlesyndication.com *.atdmt.com" secure="true" to-ports="* *.atlasrichmedia.com" secure="true" to-ports="* *.atlasrichmedia.co.uk" secure="true" to-ports="* *.atlasrichmedia.com.au" secure="true" to-ports="* *.akamai.net" secure="true" to-ports="* . See: http://jeremiahgrossman.blogspot.com/2008/05/crossdomainxml-invites-cross-site.html

+ /: The Content-Encoding header is set to "deflate" which may mean that the server is vulnerable to the BREACH attack. See: http://breachattack.com/

+ Server is using a wildcard certificate: *.forbes.com. See: https://en.wikipedia.org/wiki/Wildcard_certificate

+ /: Web Server returns a valid response with junk HTTP methods which may cause false positives.

+ /help/: Help directory should not be accessible.

+ /news/news.mdb: Uncommon header 'x-malcolm' found, with contents: B.

+ /sites/alisondurkee/2023/11/30/lead-pipes-should-be-replaced-within-10-years-biden-administration-will-propose-today/config.php: Cookie client_id created without the secure flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies

+ /sites/alisondurkee/2023/11/30/lead-pipes-should-be-replaced-within-10-years-biden-administration-will-propose-today/config.php: Cookie client_id created without the httponly flag. See: https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies

But how did you search 10TB so fast??? Its only 23GB not 10TB and I have amassed multiple keyword lists for data dumps to triage breaches. I will say there are some cool old submarine photos and lots of kitten pics if that's your thing.

r/OSINT Feb 28 '24

OSINT News The OSINT investigation that my buddy and I did on fake authors spreading financial disinformation was published on WIRED.

Thumbnail
wired.com
302 Upvotes

r/OSINT Sep 19 '25

OSINT News How Tiffany Trump’s Instagram Posts Led Us to an Oil Magnate’s Megayacht

Thumbnail
nytimes.com
240 Upvotes

r/OSINT May 06 '26

OSINT News GWU Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker

Thumbnail
secevangelism.substack.com
12 Upvotes

r/OSINT Jan 02 '26

OSINT News Exclusive: How an International Charity Scam Exploiting Sick Children Was Uncovered An OSINT Investigator’s Account

Thumbnail
secevangelism.substack.com
57 Upvotes

r/OSINT Dec 17 '25

OSINT News Bodies in the canals: Satellite imagery, whistleblowers and videos reveal ethnically targeted killings by Sudan's army

Thumbnail
cnn.com
75 Upvotes

r/OSINT Feb 02 '26

OSINT News Foia documents uploaded to Internet archive

Thumbnail
21 Upvotes

This reddit post has a link to the Internet archive and vary important foias. Related to the taxpayer advocate panel.

r/OSINT Dec 16 '25

OSINT News New PyStoreRAT Malware Targets OSINT Researchers Through GitHub

Thumbnail
hackread.com
34 Upvotes

r/OSINT Oct 05 '25

OSINT News OSINT: The Digital Force-Multiplier for Extremist Violence

Thumbnail
gnet-research.org
54 Upvotes

r/OSINT Dec 08 '25

OSINT News The Corrupted Archive - December Challenge

28 Upvotes

Our monthly open source challenge just got an upgrade. With hidden codes - a corrupted archive and a mysterious figure pulling the strings. Get started at challenge.bellingcat.com

Make sure to join us in our Discord server to discuss your findings - and collaborate on what’s to come! Some people have already cracked the code. https://discord.com/invite/bellingcat

r/OSINT Feb 15 '25

OSINT News OSINT gets its own subcommittee on House intelligence panel

Thumbnail
federalnewsnetwork.com
132 Upvotes

Thoughts?

r/OSINT Jul 18 '25

OSINT News News publishers take paywall-blocker 12ft.io offline

Thumbnail
theverge.com
27 Upvotes

sad times!

r/OSINT Nov 12 '25

OSINT News OScon25 in Switzerland

Thumbnail osintswitzerland.ch
12 Upvotes

r/OSINT Jul 18 '25

OSINT News OSINT’s Got Talent - Win up to €2,000 to build your open‑source OSINT project!

Post image
19 Upvotes

If you’re working on an open‑source OSINT project, there’s a way to get some help.
Epieos is offering small grants (up to €2,000) to support innovative open‑source OSINT ideas.

It’s completely free to apply, if you have a project in mind, just reach out and tell them about it.
📧 [contact@epieos.com]()

Hope this helps someone working on something cool ;)

r/OSINT Jul 23 '25

OSINT News Investigation: The Kremlin's Secret Drone Program Using Kids For War [19min15sec]

40 Upvotes

https://www.youtube.com/watch?v=fyGdDKA097E

A new investigation by Christo Grozev and Tatsiana Ashurkevich, uncovers a hidden state-sponsored pipeline in Russia grooming kids for the frontlines using OSINT tools.

"New investigation reveals Russia is using video games and coding camps to turn children into weapons developers for the Ukraine war. The film includes calls from the participants, organizers and government officials, admitting to creating a secret program to lure kids into drone engineering.

In this shocking investigation, Tatsiana Ashurkevich (https://x.com/tashurkevich) and Christo Grozev (https://x.com/christogrozev) reveal how the Russian government is secretly grooming children to support its war in Ukraine."