This project presents an OSINT investigation based on the Yahoo breach. It examines publicly available organizational information, identifies high-value “crown jewels,” and explains how threat actors could use public data for phishing, social engineering, and reconnaissance.
- Identify Yahoo’s crown jewels in a cybersecurity context
- Analyze public information exposure across multiple categories
- Explain how attackers could weaponize public data
- Recommend mitigation strategies
- OSINT
- Threat intelligence
- Social engineering analysis
- Phishing risk assessment
- Security awareness recommendations
- Public information about leadership, campaigns, partnerships, and financial stress can support targeted phishing
- Exposed account data and security questions make credential abuse more likely
- Email security controls such as DMARC, SPF, and DKIM help reduce spoofing risk
- Clear user communication and anti-impersonation monitoring are important defensive controls
- OSINT investigation report
- Phishing exercise analysis
osint-investigation-yahoo.pdf– Full project report
This project highlights how publicly available information can increase organizational attack surface and support social engineering operations.