US romance scam losses topped $1.14B in a single year (FTC)Total US cybercrime losses hit $16.6B (FBI IC3 2024)Average cost of a data breach: $4.4M (IBM)Roughly 3 in 4 breaches involve the human element (Verizon DBIR)Median romance scam loss: $2,000 per victim (FTC)Business email compromise remains the costliest attack category (FBI IC3)Older adults report the highest total fraud losses (FBI IC3)Most account takeovers start with a reused passwordPhishing is still the number one initial access vectorFeelings meet technology.
../blog
CybersecurityJune 2026·9 min read

Google Yourself Like an Attacker: A 15-Minute OSINT Self-Check

Before someone targets you, they look you up. Here's the exact 15-minute pass I run on myself — and how to shut the obvious doors tonight.

by Pyro Chahua · Cyber Galan

Almost every targeted attack I have looked at starts the same way: someone spent twenty minutes reading about you before they ever contacted you. That is it. No zero-days, no hacking montage. Just open-source intelligence — public information, assembled patiently.

The good news is that you can run the same pass on yourself. Grab a notebook, set a timer, and let's go. Write down everything you find; the list becomes your fix-it plan.

Minutes 1–3: the name sweep

Search your full name in quotes, then your name plus your city, employer, and the last two places you lived. Do it in a private window so your own history doesn't sanitize the results. Then repeat on a different search engine — results diverge more than people expect.

You are looking for three things: pages you forgot existed, pages you never made, and anything that pairs your name with an address, a birthdate, or a family member's name. That last combination is the raw material for account recovery attacks.

Minutes 4–6: breach exposure

Check every email address you use against a reputable breach-notification service, including the old one from high school that still receives your password resets. For each hit, note the site and the year.

  • Any password you reused across those sites is public. Treat it as burned, not risky — burned.
  • Change the email password first, then the financial accounts, then everything else.
  • If an old account is unused, don't just abandon it: log in, remove saved payment methods, and delete it.

Minutes 7–9: data brokers

Search your name alongside words like address, phone, or relatives. You will find people-search sites listing your home, your age, and your family. These feed both scammers and stalkers. Most have an opt-out page buried in the footer. Do three of the largest tonight and put a monthly reminder in your calendar for the rest — they repopulate, so this is maintenance, not a one-time task.

Minutes 10–12: your own images and posts

Reverse image search your main profile photo. Two things can turn up: your picture being used on fake profiles, and other accounts of yours you thought were separate. Then scroll your own public posts as a stranger — log out first — and look for the details that answer security questions: pet's name, first car, mother's maiden name, your street sign in the background of a photo, the badge on the desk in a work selfie.

Also check what your family posts about you. Your own hygiene can be perfect and your exposure still comes through a cousin's public birthday post naming your hometown and your full date of birth.

Minutes 13–15: the perimeter

  • Search your email address and your username — the handle you reuse is a thread that links accounts you consider unrelated.
  • Look at your professional profile as an attacker: your title, your manager's name, and your posting rhythm are everything needed to write a convincing BEC email.
  • Check the recovery options on your primary email. An old phone number you no longer control is an unlocked back door.
  • If you own a domain, look up its public registration record for your home address and personal phone.

What to do with what you found

Rank your list by one question: which of these would help someone impersonate me or reset one of my accounts? Fix those first. Then, in order — turn on a password manager, put app-based 2FA on email and banking, remove security answers that are publicly discoverable, and tighten who can see your old posts.

Do not aim for invisibility. That is not realistic and it is not the point. The point is friction. Attackers work in volume, and volume hates friction. When your exposure takes real effort to assemble, most of them move to the next name on the list.

Run this tonight. It takes less time than an episode of anything. And if what you find worries you — or if you'd rather have someone experienced look with you — request a free assessment and I'll run this pass properly, with my own tooling, and tell you exactly what I'd close first.

Free security assessment

Want me to look at your situation?

I review every request personally and respond within 48 hours — no cost, no pressure.

request_assessment