IN a world where every service requires you to sign up online and hand over your email address or phone number, we’ve all become accustomed to giving away our personal data. We all know there are risks associated with our details being in the hands of numerous companies and websites, but frankly, it’s just easier to give in and use their services. Cybersecurity expert Scott McGready (R) built a comprehensive map of The Sun’s Ricky Freelove in just 45 minutes Credit: The Sun I consider myself to be a relatively private person, but after 25 years of online activity, I questioned just how much personal information I had inadvertently released to the digital Wild West. So I employed the services of a professional hacker to find everything he could about me using only publicly available information. Sign up for the Tech newsletter Thank you! Within 45 minutes, he had worked out where I used to live, knew the names of my immediate family and housemates, and had tracked my movements abroad. He identified which online services I had paid for, he had unearthed compromised passwords, and ominously asked me: “How’s your Italian coming along?” Armed with just my name, email address and phone number, cybersecurity expert Scott McGready spent two hours piecing together my digital footprint. By the end, I was presented with a sobering graphic which mapped out everywhere I had left personal information which was visible to anyone online … and the results were absolutely terrifying. Before we began, I nervously asked Scott how much he could find out about me during this investigation. “Potentially quite a lot,” he said. “And it might shock you.” Most read in Tech The Glaswegian cybersecurity expert, who carries out these sorts of investigations to help individuals and businesses stay safe, explained that each confirmed datapoint would lead to another. He started by combing the internet for ‘open source intelligence’ or OSINT as the cyber professionals call it. “Some of the tools we use make it a little quicker to find that data, but it’s all public, it’s all open, and it’s everywhere online already.” He began by searching for accounts which were connected to my email address and phone number. Scott McGready is a respected ethical hacker who helps individuals and businesses stay safe Credit: Scott McGready The hacker found Ricky’s profile on the language learning app Duolingo, which revealed he was learning Italian and so it was likely he had, or was going to, Italy Credit: Getty Images Within minutes he had mapped out my Facebook, X, Snapchat, LinkedIn, and Pinterest accounts, which wasn’t exactly surprising given they are all public-facing and likely featured my full name. But I was surprised to learn that, using a legal online tool which searches public data sets linked to my email address, he also knew I had accounts with paid-for services including Apple, ESPN, Spotify, Duolingo and Disney+. Nevertheless, everything he had found within the first few minutes seemed quite innocuous to me. What could anyone really do with that information? But Scott explained that it wasn’t necessarily any individual piece of information which could be a threat or danger, but rather what could be discovered by piecing several together like a jigsaw. After finding my Italian course on the language learning app Duolingo, Scott suggested I may have travelled to Italy around 2018. Based on this initial piece of information, he explained he would then look for social media posts or online reviews confirming my movements. McGready later followed that up by asking me ‘how was watching the World Cup at the A’Riccione Terrazza bar in Milan?’ It was a remarkably accurate response because I had unknowingly put the information out there myself. He informed me that back in July 2018 I’d left a positive Google review of the bar and even mentioned I’d been there to watch the international football tournament. This was a textbook example of how one piece of data – and a good hunch – leads to another. But I still didn’t understand what could be achieved by knowing tiny, seemingly worthless pieces of information. After finding one seemingly ‘meaningless’ piece of information, the hacker was able to locate his movements Credit: Getty Images By combing through Ricky’s Google reviews, McGready was able to confirm the reporter travelled to Italy in 2018 Credit: Google McGready clarified that by piecing these snippets of information together, someone online could try and use the information to claim we had met before in an attempt to defraud or catfish me. He claimed a scammer might say: “Hey, do you remember me? We met at a bar in Milan, we were watching the World Cup together.” The hypothetical scenario was unnerving, but it was a mere warning of what was to come. As our investigation passed the 45-minute mark, Scott brought the potential threat quite literally to my doorstep after he unearthed my old home address. He had discovered it by finding a run I had unintentionally published on Strava in 2017, and then worked out the house number by where I had started and finished. “That is absolutely terrifying,” I responded as he pinpointed my old property in South London. The hacker explained how fitness apps inadvertently offer up people’s home addresses often because a jogger wants to know exactly how far they have run from the moment they left their house. More worryingly, McGready went on to explain that people are creatures of habit and tend to set off for exercise around the same time of day and also take fairly similar routes. If a fitness app user uploads enough information online, a pattern emerges which could be used to predict when and where they might be at a certain point of their run. Similarly, the same information could be used to determine whether the user is likely to be away from their home too. Scott continued that after locating my home address, he would hypothetically then go on to Zoopla and look at property prices, recent house sales and estimate my salary and possible savings. If I were to be a high-net-worth individual, this could potentially be very valuable information to a criminal. A run which Ricky inadvertently published online in 2017 using the fitness app Strava, revealed his old home address Credit: Getty Images Ricky said it was “absolutely terrifying” how the hacker managed pinpoint his former address Credit: The Sun Having mapped out my physical vulnerabilities, Scott pivoted to my digital security and pulled up a list of passwords which had been compromised during a series of data breaches. He said that, if this were a real attack, the next step would be to attempt to log in to my social media accounts in the hope that I used the same password across accounts. Thankfully, I hadn’t, so thought I was in the clear. Instead, McGready started to examine the passwords looking for similarities or information concealed within them. He speculated whether the numbers in the compromised passwords could include my date of birth, a phone number, or a house number. With the password analysis providing little to work with, Scott returned back to the data breach and quickly unearthed an IP address buried amongst the information which suggested I likely attended the University of Exeter. After exhausting that line of inquiry, the cybersecurity expert then found another account linked to my email address and combed through my review history on Google. “Looks like you had a very, very good time at a bar in Newcastle. You left a 10/10 review… and you were definitely under the influence at that point.” I confessed I had been on a stag do and was encouraged to leave a positive review by a barmaid who saw an opportunity. Scott explained that a fraudster could exploit these details to build a fake rapport and claim: “Remember me from the stag do? We had that really drunken night out together in Newcastle!” He added I would drunkenly have no way to verify the claim, leaving me vulnerable to being befriended by the scammer or potentially even being coerced into handing over money. He continued combing through the reviews I’d left online: “I know you went hiking in Australia.” A data breach revealing a username and password also exposed an IP address Ricky had used, which was linked to the University of Exeter Credit: Alamy A drunken Google review left The Sun’s Ricky Freelove exposed to potential scammers or catfishers Credit: Google Each of these locations — with an additional level of detail — was of course correct because I had left the Google reviews, stamped with a date and time and in various states of merriment. But I had no appreciation that by using my historic travels and states of inebriation could also be used against me. Combining my email address, phone number and Google reviews, McGready claimed he could use the information to ‘social engineer’ me on the phone. He claimed that he could call me pretending to be my bank and ask if I had made transactions from a list of locations where had I left online reviews, say, during a pub crawl. Knowing I had likely made transactions at each of them, he could use this intelligence to convincingly persuade me to hand over sensitive information. Similarly, by simply checking he could send me an iMessage – as opposed to an SMS text – he knew I had an iPhone which he claimed he could also take advantage of. “I could phone you up or send you an email and say ‘Hey, your iPhone is due for a warranty upgrade.’ People like free stuff.” He had discovered all of this about me within just 45 minutes using only publicly available online information. If I wasn’t terrified enough at this point, I thought it wise to give Scott another hour to deep dive into anything else I had put online or that had been published unbeknownst to me. When he returned, he found a series of images of me which had been published online where I hadn’t been named or tagged. Using my profile picture on social media, he managed to find more photos of me by searching for ‘exact image searches’ or someone with my ‘exact likeness’. From there he knew I’d been to the Ukrainian border after being photographed in a news article in 2022. Reverse image searches revealed the reporter, who wasn’t named in the news article, had been to the Ukrainian border in 2022 Credit: Ricky Freelove Another positive image match revealed Ricky on the London Underground in 2016 where, again, he wasn’t named or tagged in the blog Credit: Amy Lakin/Commute Blog He then asked me: “When you were seven, did you want to be a dancer?” Taken by surprise at the stark contrast of the question, I acknowledged that I had. McGready then pulled up a blog he found from 2016 where I had spoken to an aspiring journalist about my upbringing while on my commute home. I wasn’t named or linked in the article, but a photo of me in the blog post from 10 years ago had returned a positive result. From the image and context of the blog, he knew I was a commuter using the London Underground in October 2016. He even found a photo from an old university newspaper feature in which I had been asked to describe what my ideal blind date looked like. I responded simply with the name “Rachel Riley.” Again it sounds harmless, but if someone wanted to catfish me (where they pretend to be someone else online), she’d be an obvious contender. After Scott had finished finding embarrassing nuggets of information which I had no recollection of giving, he moved on to census data and the electoral register. Using this publicly available information, he was also able to determine my previous postcode areas and rattle off the names of my immediate family and former housemates. He was also able to estimate when I likely moved from the family home and again found more evidence of my time in Exeter. Combining all of this together, he warned that somebody could say to me: “Hey Ricky, we haven’t spoken in ages. I remember you used to want to be a dancer when we grew up together in Cheadle.” REFLECTING ON HAVING MY DIGITAL LIFE EXPOSED AFTER having my digital life unpicked before my eyes, I rushed over to my laptop and quickly deactivated my Strava account and deleted those embarrassing restaurant reviews. I’ll never write another one — even if a waiter asks me to — knowing now that someone online could be monitoring them and potentially utilise that information against me. I’m lucky that this was just a controlled investigation, carried out by an ethical hacker who had exposed my digital vulnerabilities because I’d asked him to. But the idea that somebody could have done this to me, and likely gone much further by attempting to hack my accounts, targeting my friends and family, or even coercing me into handing over sensitive information, has genuinely scared me. I have since carried out a review of my online profiles and ensured that the information which is publicly available is information which I’m comfortable with and doesn’t compromise my physical or digital security. For the purpose of this exercise, none of my friends or family were included in the investigation. But if online criminals wanted to do this seriously, it would not take much to connect the dots and build an exceptionally comprehensive profile for anybody online. And the terrifying thing is, all of this information was already publicly available online whether I thought I was in control of it or not. Had I given McGready two days to carry out this investigation, I’m positive the end result would have only been more intrusive and even more embarrassing. We finished our two-hour investigation together by reviewing a spider’s web-like graphic which he had updated as he found more pieces of my digital jigsaw. In the centre was my name, phone number and email address, and from that information were sprawling lines pointing to: my home addresses, names of my family members and housemates, lists of domestic and foreign locations I’d visited, my education history, social media profiles, and compromised usernames and passwords. My main takeaways from this experiment are to ensure fitness apps are set to private and to hold back on writing online reviews – particularly if you’ve had a sherbet or two. But after watching Scott piece together my life, the most unsettling discovery was just how much personal information I had unknowingly put online and forgotten about. A Strava spokesperson said: “Strava takes the safety and privacy of its global community very seriously and has significantly updated its privacy controls since 2017. Relevant to this example, we changed our privacy-zone defaults: new accounts now automatically hide the start and end points of activities. “We’ve also expanded our privacy controls so users can hide a specific address across both past and future activities, hide start and end points wherever they occur, or hide activity maps entirely. Nearly ten years on, a new account created on Strava today would have those start and end points hidden automatically.” SCOTT McGREADY’S TOP TIPS FOR SUN READERS Here's what you can do to keep yourself safer online: “Passwords are one of the Achilles heels when it comes to online accounts. Services will be breached, that’s a given now. I’d recommend signing up to the free service HaveIBeenPwned.com. It will let you know if there’s been a data breach and whether your email address is contained within it — it’s a nice early warning system. “Also, I would absolutely recommend using a password manager. They’re very simple to use. It’s easy copy and paste stuff and they auto-fill too. “Turn on two-factor authentication where you can. I know it adds some friction and time before you can log into the service. But getting a text message or even the authenticator prompt on your phone is way better [than being hacked]. “It also means that, let’s say I were to use an old password and your email address to try and log into, for example, your Snapchat account, you would get a ping on your phone saying, ‘Is this you? Here’s the six-digit code, do you want to allow this?’ It would give you an early warning that someone’s up to no good. “Don’t be afraid to search for yourself online. Do reverse image searches of your face or your profile pictures. A lot of these services are freely available. Doing a quick search isn’t being vain, it’s knowing what’s out there. “There is no difference between locking your front door at night and being aware that you have a breached password online “Your social media account is open to the world and anyone can read it. If you’re comfortable with that, that’s great. But it’s all about consent and knowing that anybody can find it if they so choose.” 1 comment1
I got professional hacker to find out everything they could about me online in just 45mins – the results are terrifying
Full Article
Original Source
Read the full article at Thesun →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.