I Tested 7 AI OSINT Agents on My Digital Footprint - What They Found in 4 Min

I tested 7 AI OSINT agents on my own digital footprint. In 4 minutes they found my address, photos, breaches. Learn how to protect yourself.

martes, 28 de julio de 2026 • 4 min read • Q2BSTUDIO Team

Lo que 7 agentes OSINT con IA revelaron sobre mí

In today's world, where personal information is the most valuable currency, cybersecurity is no longer an optional luxury but a strategic necessity. As a software development professional and partner at Q2BSTUDIO, I decided to run a controlled experiment: test seven AI-powered OSINT (Open Source Intelligence) agents against my own digital footprint. The goal was not morbid curiosity but to understand how modern tools can expose vulnerabilities we didn't even know existed. And the results, believe me, were eye-opening.

The premise was simple: give each tool my real name, primary email, and one profile photo—exactly the same data I leave on social media, forums, and online services. No aliases, no temporary accounts. Then measure how much information they could gather in just four minutes. It's not a rigorous scientific study, but it's a practical demonstration of what any attacker could achieve with accessible tools and a bit of patience.

Before diving into details, a necessary warning: this is self-OSINT, performed with my explicit consent. I'm not sharing these techniques to encourage harassment or doxxing. On the contrary, my goal is to show how we can audit our own attack surface and, with the help of AI solutions and good security practices, reduce the risk of exposure.

The selected tools represent the most popular categories in 2025: from email trackers to facial recognition engines, OSINT automation frameworks with AI layers. Specifically, I used Epieos to trace my email presence, IntelX.io to search for dark web leaks, OSINT Industries to correlate personal data, username searchers like Social Searcher, PimEyes for reverse facial recognition, SpiderFoot with a GPT wrapper for automated analysis, and Maltego with an OpenAI plugin to visualize relationships.

Within sixty seconds, results started pouring in. My current address appeared with 87% confidence, sourced from a data broker opt-out page I thought I had removed myself from. My old MySpace username resurfaced from digital ashes. I discovered three data breaches I didn't know about, including one with plaintext passwords I reused in 2018. My LinkedIn, GitHub, Medium, Instagram, and a forgotten Flickr account with photos of my dog were also identified.

By minute two, things got more intense. PimEyes located twelve photos of me, including one from a conference talk in 2022, another from a local newspaper article about a charity run, and a cropped version of my Venmo profile picture shared by someone else. IntelX linked my email to a breach containing my old phone number, which OSINT Industries used to pull carrier info and a list of 'possible associates.' Among them were my mother and a stranger I bought a couch from on Facebook Marketplace in 2020. The algorithm considered us close.

At four minutes, the picture was complete. Full name, date of birth, current and two previous addresses, phone number, six personal emails, employment history, university, 47 photos, 12 social profiles, breached passwords, my Amazon wishlist (why is it public?), and my political donation record. All this without my active help. The cost to an attacker: between $0 and $47, depending on the tools. The effort: less than ordering a burrito.

This experiment confirms something we at Q2BSTUDIO know well: the problem isn't having a single isolated breach, but the ability to correlate multiple seemingly harmless data sources. A leaked password from 2018, combined with a public Strava profile and a LinkedIn account, can reveal your exact address and when you're not home. Artificial intelligence supercharges this correlation by automating what used to require days of manual work.

What can we do about it? First, accept that deleting your information from the internet is a mirage. Instead, focus on reducing exposure: delete old accounts with services like JustDeleteMe, opt out of data brokers using tools like DeleteMe or Optery, and disable public lists on Venmo or Amazon. Each small step raises the attack cost for a potential intruder.

Second, audit your own digital footprint periodically. I recommend setting a quarterly reminder to run tools like Epieos on your email, PimEyes on your photo, and Have I Been Pwned to check for breaches. If you find something you dislike, fix it immediately. This process should be part of any personal or corporate cybersecurity strategy.

From a technical perspective, this experiment also highlights the importance of investing in custom software development that integrates security by design. At Q2BSTUDIO, we help companies build software with protective layers that minimize the attack surface, whether through cloud infrastructure on AWS or Azure, Business Intelligence solutions with Power BI to monitor threats, or AI agents that automate vulnerability detection.

Cybersecurity is not a destination but a continuous process. What this experiment taught me is that our digital footprint is no longer a simple footprint in the sand; it's a high-definition documentary with timestamps, geolocation, and searchable transcripts. And it only takes four minutes to play it. If you work in security, development, or simply care about your privacy, I invite you to reflect on what you're leaving exposed. At Q2BSTUDIO, we're ready to help you build a more secure digital ecosystem, from code to cloud.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.