Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 

README.md

Yahoo OSINT Investigation and Phishing Risk Analysis

Overview

This project presents an OSINT investigation based on the Yahoo breach. It examines publicly available organizational information, identifies high-value “crown jewels,” and explains how threat actors could use public data for phishing, social engineering, and reconnaissance.

Objectives

  • Identify Yahoo’s crown jewels in a cybersecurity context
  • Analyze public information exposure across multiple categories
  • Explain how attackers could weaponize public data
  • Recommend mitigation strategies

Skills Demonstrated

  • OSINT
  • Threat intelligence
  • Social engineering analysis
  • Phishing risk assessment
  • Security awareness recommendations

Key Findings

  • Public information about leadership, campaigns, partnerships, and financial stress can support targeted phishing
  • Exposed account data and security questions make credential abuse more likely
  • Email security controls such as DMARC, SPF, and DKIM help reduce spoofing risk
  • Clear user communication and anti-impersonation monitoring are important defensive controls

Deliverables

  • OSINT investigation report
  • Phishing exercise analysis

Files

  • osint-investigation-yahoo.pdf – Full project report

Notes

This project highlights how publicly available information can increase organizational attack surface and support social engineering operations.