Our weekly Briefing is free, but you should upgrade to access all of our reporting, resources, and a monthly workshop.
This week on Indicator
Craig published a guide to building your own no-code tools for OSINT. It offers advice on the easiest ways to get started, how to scale up, cautions about security and privacy, and firsthand accounts of how people are building.
Alexios and Ben Shultz uncovered an affiliate link spamming operation on Facebook and Instagram. The network of accounts racked more than 107 million views using Reels of AI-generated employees at Aldi, Costco, Target and other retail chains. The fake retail workers claimed to be “spilling the beans” about their employer but actually pitched a mythical gift card worth hundreds of dollars. Meta deleted the accounts after Indicator reached out.
Deception in the News
📍 Antonio Rotondo, who is on trial in Brisbane over the alleged creation and distribution of sexualized deepfakes of women and girls, allegedly told police that what he did was "funny." Rotondo has pleaded not guilty. In a depressingly lucid display of what AI nudifiers are actually about — degrading women, not exploring sexual fantasies — he also allegedly said “every woman on earth should live in fear of a camera.” — Alexios
📍 In an open letter, a group of 100 companies warned that advances in AI will make cybersecurity attacks far riskier and more prevalent. Signatories include many of the companies that got us to this point, including Anthropic, Google, Microsoft, and OpenAI.
📍 Inquirer.net reported that the Marcos administration sees “no immediate need to ban Facebook in the Philippines after the social media giant showed willingness to respond to government requests to remove fake news and violent content.” The possibility was floated over misinformation and child safety concerns, including a recent school shooting that the gunman live streamed on Facebook.
📍 Also in Meta news: earlier this month 19 members of the US House of Representatives wrote to Mark Zuckerberg expressing concern about the rollback of interventions against misinformation as we approach the 2026 midterms. From the letter: “By replacing dedicated fact-checking and robust enforcement of your own content-moderation policies with Community Notes, Meta has effectively shifted the burden of fact-checking onto its users, who may not have the resources, the time, or the expertise to scrutinize the news they are receiving on Meta’s platforms.”
📍 A Google senior director for trust and safety outlined expectations for Play Store developers when it comes to the use of generative AI. The goal is to prevent features that can be used to generate non-consensual intimate imagery, including synthetic nudes. Recommendations include keeping documentation of adversarial testing and not relying only on the safety filters of off-the-shelf models.
📍 X announced that it identified a “suspected Chinese” bot farm of roughly 200,000 accounts that posted anti-data center content. “Within this farm, we found 200 accounts posting in a manner that could manipulate a legitimate debate about American AI and energy policy,” said a tweet from the company’s Global Government Affairs account.
📍 Music charts in Australia will no longer feature AI-generated songs, following a kerfuffle over a synthetic cover of Madonna’s “Like a Prayer” hitting no. 4 in ARIA charts in July. Tracks that use generative AI in a supporting role remain eligible.
Tools & Tips

Image created with Gemini
Nicole Hurey runs The OSINT Vault, a free collection of tools and resources for investigators. She just released OMERTÀ, a free tool “built to connect names, usernames, phone numbers, emails, domains, and other digital identifiers across open-source data.” I’ve tested it with usernames and found that it goes a few steps beyond a traditional username enumeration tool. It’s worth trying.
Hurey has been releasing tools at an impressive pace, so I reached out to ask her a few questions. — Craig
What does OMERTÀ do?
OMERTÀ is an OSINT search engine. The basic idea is that you give it one identifier and it helps you find where that identifier connects. You can start with a name, username, phone number, email, or domain. OMERTÀ searches 698 platforms and 30 data sources and is designed to return results it can verify.
The verification part was one of the things that mattered most to me. I didn’t want another tool that throws 500 possible matches at an investigator and leaves them to figure out what’s real. Results include the underlying evidence, including the HTTP response, the signature that matched, and the source that produced it. If OMERTÀ returns a profile as a result, the investigator can look at what produced that result and make that determination for themselves.
You can also keep going from there. A username, email, phone number, or linked profile can become the next pivot, and OMERTÀ maps those relationships into a connection graph. So, if you find something in the first search that leads you somewhere else, you can use it to start another search.
The point for me was never just finding more results. I wanted those results to be useful, traceable, and something an investigator could actually work with instead of manually chasing every possible lead from the beginning.
What motivated you to build it and what use case(s) did you have in mind?
If I’m being honest, which I tend to be brutally honest, I started building OMERTÀ because I was so tired of getting false positives from existing username-search tools.
What I am about to say is going to sound completely minuscule; however, what really aggravated me, literally to my core, was how often everything seemed to come back positive for Chess.com. It bothered me so much that I started running completely random names through it, including names I had literally made up, just to see what would happen. I didn’t even know if these people existed, and somehow, they would still come back with a Chess.com hit.
I am by no means downplaying the intelligence behind the build of these tools. I’m sure they were the Golden Girls of OSINT in their era. But at some point, even Dorothy, Blanche, Rose, and Sophia had to call it a series finale.
However, I kept coming back to the same question: how are we still treating these results like they’re reliable when I can type in a completely made-up person and somehow get a profile back? Not only is that counterproductive, but that’s also not what I consider intelligence. It’s merely a questionable lead, a subpar one at best, and there’s a significant difference between the two.
That’s what led me toward attribution. If an investigator starts with something as simple as a username, email address, phone number, or name, I wanted them to be able to follow what they find, look at the connections around it, and start determining whether those pieces point back to the same person. That becomes especially important when you’re dealing with common names, reused usernames, burner accounts, old information, or identifiers that may have changed hands.
The idea was never just, “Here’s an account that exists.” It was more, “Okay, you found something. What else can you establish from it?” I wanted OMERTÀ to help an investigator move from that initial lead into something they could investigate and evaluate.
That’s where I kept coming back to the question: “Okay, you found it. Now prove it.”
There are lots of tools for username, email, phone searches, etc. Where do you see this tool fitting in compared to other free options?
I genuinely don’t see OMERTÀ as fitting into a specific place compared to other tools because I never built it by comparing it to anything else. I don’t look at another tool and think, “Okay, this is what they’re doing, so this is what I should build.” That’s just not how I build things.
I build around what I personally need, what I see as missing in my eyes, and what I think is needed. I’ll sit with an idea for months, figure out exactly what I want it to do, change things, test the output, and keep working on it until I’m happy with where it is. Lately, that has been taking me a lot longer than expected. I apparently have a hard time meeting my own standards.
Then I release it to the public for free with the idea that it would be beneficial to others. I’m aware there are paid tools that aggregate significantly more information, but the concept behind every tool I build is that it is and will always be 100% completely free.
You've released a lot of tools over the last year or so. Can you share any advice for investigators who want to build their own tools?
My advice would be to take your time and learn how to build things from the ground up. I didn’t have any formal training when it came to coding or software development. I’ve always just had a need to know why things work, and more importantly, why they don’t work.
I’m the person who will take apart my dishwasher just to figure out how it works and then convince myself that the handful of screws left over were definitely extra. Or start messing around with the motherboard in my laptop just to see if I could reconfigure something and make it work differently.
I like starting from the ground up because that’s the only way I retain what I’m learning. If I’m relying on something I don’t understand, I’m never going to be as comfortable with it as I am when I actually figure out how it works myself.
For investigators who want to build their own tools, I’d say don’t be afraid of not knowing how to do something. Start learning it. Take it apart. Break it. Figure out why you broke it. Fix it and do it again. You don’t need to know everything before you start building. You just need to be willing to keep figuring it out.

Satellite Eye
📍 Satellite Eye is a free tool that enables you to enter a location and see how many times it was photographed by imaging satellites over the past 24 hours. It’s a cool way to understand satellite imagery and to get a sense of which companies or organizations may have recent images for a location interest. (via Ben Heubl)
📍 Nitter, a tool that allowed you to view content on X without having to access the service or be logged in, has gone offline. X sent it a cease and desist notice on Aug. 24. “I'm seeking legal advice and won't be commenting further on the specifics for now,” read a message on the site’s homepage. TechCrunch got a hold of the letter. It said Nitter engaged in “unlawful use and circumvention of X’s Application Programming Interface (API) and associated data.”
📍 Jeremy Caplan of Wonder Tools published “Your AI Privacy Toolkit: Easy ways to protect your documents, data, and chats.”
📍 Deutsche Welle published “How DW uses Artificial Intelligence in journalism.”
📍 Bellingcat published, “Tracking a Sanctioned Russian Vessel’s West African Odyssey.”
📍 The Global Investigative Journalism Network published “How Many Tobacco Shops Are Near Your Town’s Schools? Using Georeferenced Data Analysis for Location-Based Investigations.” It also shared a collection of five short(ish) videos with tips from top investigators on How to Expose Corruption, How to Investigate Online Scams, Tips and Tools for Investigating Leaks, and more. Here’s the video about scams:
Reports & Research
📍 Amnesty submitted 15 mock ads to Facebook — 14 containing election disinformation, plus one neutral control — to test the company's ad moderation filters ahead of Brazil's October 4 presidential election. Eight of the disinformation ads were approved (Amnesty scheduled them for a future date so it could cancel them before publication). The other seven were rejected because the account hadn't completed identity verification, not for their content.
📍 An investment scam targeting victims in Norway and elsewhere by impersonating financial influencers on TikTok was traced to web hosting infrastructure run by a Nigerian IT company, according to an investigation by NRK, Premium Times, and Ben Television. The giveaway was some leftover source code on one of the fraudulent websites.
📍 The Anti-Corruption Data Collective found 556 Polymarket wallets it calls "Orcas" — accounts that place large, highly successful longshot bets in a handful of niche markets. Of those, 152 concentrated on military and defense markets, collectively winning $8 million at an average win rate of 97.2%. The researchers said these are “most likely potential insiders.”
📍 A Code for Africa and Graphika report found “44 inauthentic personas” pushing pro-Russian talking points in African media outlets, including on “legitimate media sites.”
One More Thing
Researchers at Stanford and Revelio Labs documented how professionals quietly edit their work experience on LinkedIn to adapt to trends. They dubbed the practice “time traveling” to describe how people go back and edit their jobs to make them more attractive in the present.
“As they polish their resumés, their job descriptions become less like the job they had and more like the job they're looking for,” wrote Gideon Moore, a coauthor of the working paper that was published by National Bureau of Economic Research.
For example, this chart tracks how workers started padding their past job descriptions with references to AI right after ChatGPT's release triggered the current tech boom:

This chart shows how people removed references to DEI after Trump came back into power in 2025:

Another reason to not trust everything you see on a Linkedin Profile…
Indicator is a reader-funded publication.
Please upgrade to access all of our content, including our how-to guides and Academic Library, and to our live monthly workshops.


