Evidence Poisoning: The OSINT Crisis Nobody Is Ready For
Over the past decade and a half, we have been confronted with chemical warfare, assassination operations involving nerve agents and lethal animal toxins, and accusations of illicit biological research activities, all indicative of serious breaches of the Chemical Weapons Convention (CWC) and the Biological and Toxin Weapons Convention (BTWC).
The incidents were accompanied by information warfare, typically of the type in which one side claimed the allegations were fake and the other side argued their veracity. A characteristic of this information warfare is that the same antagonists – government outlets, organisations and institutions, individual scientists or academics, and motley groups of loosely connected activists – may switch between accusing and defending roles depending on the incident. Yet the same protagonists spread disinformation, while the same challengers counter the disinformation onslaught with facts.
Too often, the context in which the claims are made is poisoned. Conditioning information elements have been planted in advance, not infrequently years before a particular incident, and help make certain arguments plausible. And in international forums, the truth is all too often political, despite the presentation of facts obtained through internationally negotiated investigative protocols and grounded in the most advanced scientific insights and forensic evidence.
In today’s security environment, every individual should ‘know’ instead of ‘believe’ and ‘think’ instead of just ‘being told’ to be able to make informed judgements.
The piece below offers a detailed toolbox for analysts to construct credible arguments with minimal ambiguity and for readers to analyse controversial debates critically. Originally published by Nico Dekens (NL) on his excellent blog covering open-source intelligence (OSINT) analysis in May, we reproduce it here with his permission.
How AI slop, synthetic personas, fake context and algorithmic amplification are contaminating Open-Source Intelligence
There is a problem growing inside OSINT. It is not just deepfakes, fake accounts, bot networks, recycled footage, misleading screenshots, AI-generated articles, fake documents, manipulated images, synthetic voices or coordinated narratives. It is all of them together.
The real problem is that this material is becoming part of the open web. It is being indexed, reposted, screenshotted, summarised, translated, quoted, archived and fed into AI systems. It is being picked up by search engines, social platforms, recommendation systems, large language models, journalists, researchers, investigators, analysts and sometimes even law enforcement.
In other words: polluted information is becoming searchable evidence. That should worry every OSINT practitioner.
Because OSINT used to ask one main question: Can I find the source? That question is no longer enough.
The better question in 2026 is: Was this source manufactured to be found?
It changes how we investigate people, verify events, assess threats, use AI, write reports and teach OSINT. And most importantly, it changes how much confidence we should place in information that appears to be public, repeated, popular or easy to find.
Welcome to the age of evidence poisoning.
What is evidence poisoning?
Evidence poisoning is the contamination of the open information environment with synthetic, manipulated, misleading, recycled or artificially amplified material that later appears useful as investigative evidence.
This is not just misinformation.
Misinformation is usually about misleading a public audience.
Evidence poisoning is about contaminating the material that investigators, analysts and decision-makers may later rely on.
That is a different kind of threat.
A fake claim on social media is bad. A fake claim that later becomes part of an intelligence report, a threat assessment, a media article, a legal case, a corporate security decision or an AI-generated briefing is worse.
That is when polluted information becomes an operational risk.
Why this matters now
For years, OSINT practitioners have warned people not to believe everything they see online.
That advice is still true, but it is too basic now.
The modern problem is not only that individual pieces of content can be false. The modern problem is that entire information environments can be shaped.
A single false post is easy to question.
A network of posts, screenshots, comments, AI-generated articles, recycled videos, fake profiles and search results all pointing in the same direction is much harder to resist.
It creates a feeling of confirmation, illusion of independence and often confidence. And confidence is where many investigations start to go wrong. The more something appears in multiple places, the more tempting it is to treat it as corroborated. But in a polluted web, repetition is not always verification.
Sometimes repetition is the attack.
Sometimes the goal is not to hide the lie.
Sometimes the goal is to make the lie easy to find.
That is the part OSINT needs to take seriously.
The old OSINT assumption is breaking
- Three different accounts may be controlled by the same person.
- Five different posts may be based on the same original screenshot.
- Ten articles may be rewritten from one unverified claim.
- A local-looking website may be AI-generated.
- A realistic profile photo may not belong to a real person.
- A Telegram channel may repost an old video with a new caption.
- An AI search result may summarise a claim without making the source hierarchy clear.
- A viral narrative may look organic while being pushed by coordinated actors.
- A “source” may actually be bait.
This creates a serious problem for analysts. The open web is no longer just a collection of sources. It is also a battlefield of manufactured visibility. And in that battlefield, visibility itself can be manipulated.
Evidence poisoning is not one thing
One reason this problem is difficult to explain is that it does not come from one technique. It is a stack. I think about it in five layers. Each layer can poison an investigation in a different way.
Layer 1: Synthetic content
- an AI-generated photo of a person who does not exist
- a fake screenshot of a conversation
- a realistic-looking PDF that appears to be an internal memo
- a deepfake audio message attributed to an executive
- an AI-generated news article on a low-quality website
- a synthetic image of a protest, explosion, arrest or military movement
- a fake social media post made to look like it came from a real account
- an AI-generated biography for a fake expert
- an altered image where a sign, weapon, logo or person has been added
- a fake leaked document circulated in Telegram groups
By the time it reaches the analyst, it no longer feels like one fake screenshot. It feels like a cluster of evidence. That is how synthetic content becomes evidence poison.
Practical example: the fake protest image
Imagine a picture appears online showing a large group of people outside a government building. The caption says it was taken today in The Hague. The crowd is angry. There are flags, banners and police vehicles in the background.
The image gets shared quickly.
Multiple accounts say the protest is growing.
A few anonymous profiles claim they are there.
A small website publishes a short article about “escalating unrest.”
An analyst monitoring civil unrest sees the image, the reposts and the article.
At first glance, it looks like an emerging incident.
But deeper checks show problems:
- the shadows do not match the claimed time of day
- the police vehicle design is from another country
- one banner contains malformed Dutch
- the building entrance is close to the real location but architecturally wrong
- the earliest version of the image came from an account created two days ago
- the article was published by a site full of AI-generated local news
- no live traffic cameras, local journalists or official updates show the event
The image was not just fake. It was designed to create a quick operational impression. If the analyst only looked at the volume of posts, they might have escalated the wrong threat. That is evidence poisoning.
Layer 2: Synthetic identity
The second layer is synthetic identity. This is where OSINT becomes more complicated.
A fake post can mislead an event investigation.
A fake person can mislead an entire network investigation.
Synthetic identity can include:
- AI-generated profile photos
- stolen profile photos
- realistic but fake biographies
- fake employment histories
- fake education histories
- fake location claims
- manufactured posting histories
- fake friends and followers
- cross-platform sock puppets
- persona farms
- AI-assisted conversation histories
- synthetic experts
- fake victims
- fake witnesses
- fake activists
- fake insiders
For years, investigators have dealt with sock puppets. That is not new.
What is new is scale, realism and automation. A fake persona no longer needs to be an empty account with a random profile picture and a few bad posts.
And once investigators believe the person is real, everything that persona touches may become part of the analytical picture.
Practical example: the fake insider
A better investigation asks:
- Does the person exist outside self-created profiles?
- Is the profile photo synthetic or stolen?
- Does the employment history align with real company timelines?
- Are the technical posts original or copied from public sources?
- Who first amplified the claim?
- Are the amplifying accounts connected?
- Did the blog independently verify anything, or did it just rewrite the original post?
- Does the LinkedIn network look organic?
- Are there archived versions of the profile?
- Is the language consistent with the claimed nationality, profession and career history?
Layer 3: Synthetic consensus
It can include:
- bot comments
- coordinated reposting
- fake reviews
- manipulated likes
- scripted replies
- Telegram amplification loops
- Reddit brigading
- hashtag flooding
- fake “local witness” accounts
- AI-generated comments under news articles
- fake experts agreeing with each other
- multiple blogs rewriting the same claim
Practical example: the false threat narrative
But mapping the spread shows something else:
- the first account has no history before the claim
- the reposting accounts mostly follow each other
- the Telegram channel often amplifies similar narratives
- the news article cites no primary source
- the comments appeared within minutes of publication
- several comments use similar phrasing
- no credible local sources mention the threat
- the activist group’s own channels show no matching indicators
Layer 4: Synthetic context
Not all evidence poisoning involves fake material. Sometimes the content is real, but the context is fake. This is extremely common.
- A real video from 2019 is presented as footage from today.
- A real protest in France is described as a protest in the Netherlands.
- A real photo of a military convoy is attached to the wrong country.
- A real screenshot is cropped to remove important context.
- A real quote is translated badly or deliberately distorted.
- A real username is linked to the wrong person.
- A real crime report is connected to an unrelated group.
- A real image is used to suggest a false timeline.
This is dangerous because real material passes many basic verification checks.
Reverse image search may show the image exists.
The video may not be AI-generated. The account may be real. The location may be real. But the conclusion can still be wrong.
Practical example: the recycled riot video
Further checks reveal:
- the same video appeared three years earlier
- the original upload was from another country
- the police vehicle markings do not match Dutch police
- the street furniture is inconsistent with Amsterdam
- the weather does not match the claimed date
- no local emergency services or news outlets reported the incident
Layer 5: Synthetic discovery
Synthetic discovery is when polluted information becomes easier to find because search engines, platform algorithms or AI systems surface it.
This can happen because material is:
- recent
- highly shared
- keyword optimised
- repeatedly cited
- structured like an article
- posted across platforms
- embedded in automated content
- amplified by engagement
- summarised by AI tools
- translated into multiple languages
- presented as “what people are saying”
This is where SEO and OSINT collide.
And now GEO (Generative Engine Optimisation) adds another layer. We are moving into a world where people do not only search Google.
They ask ChatGPT.
They ask Perplexity.
They read AI Overviews.
They use summarisation tools.
They query dashboards.
They ask automated intelligence systems to brief them.
That means investigators may encounter information not as raw sources, but as AI-shaped answers. The danger is that AI systems can make polluted information look cleaner than it is. They remove the mess, compress uncertainty and summarise conflict. They may place a weak claim next to a strong source in a way that makes both look equally useful. They can turn a polluted cluster into a neat paragraph. And neat paragraphs are dangerous when the underlying source chain is dirty.
Practical example: the AI summary trap
Imagine an analyst asks an AI search tool: “What is known about Group X and threats against Event Y?” The AI returns a confident summary: “Several online sources have linked Group X to planned disruptions around Event Y, including social media posts, forum discussions and local reporting.”
That sounds useful. But what are “several online sources”?
Did the “local reporting” verify the claim or just repeat it?
Was the forum discussion organic or coordinated?
Did the AI understand the difference?
The analyst must not treat the AI answer as evidence. The AI answer is a lead. Nothing more. The source chain still needs to be reconstructed manually. In modern OSINT, the question is not only “what did the AI say?”
The question is: What source path produced this answer?
Why multiple sources can still be wrong
1. The repost chain
2. The screenshot chain
3. The article laundering chain
4. The translation chain
5. The AI summary chain
An AI tool summarises multiple weak sources into a clean answer. Another person quotes the AI answer. The summary becomes a new source.
6. The influencer chain
7. The archive chain
This is why analysts must map source relationships, not just collect source counts.
The analyst’s biggest enemy: fluency
AI-generated content is often fluent. That is part of the problem. Bad information used to have more obvious signals.
Broken formatting.
Strange phrasing.
Low-quality images.
Obvious spam behaviour.
Those signals still exist, but they are less reliable.
The future of OSINT will punish analysts who confuse fluency with reliability.
Practical examples of evidence poisoning in different OSINT fields
Evidence poisoning does not only affect disinformation researchers. It affects almost every OSINT discipline.
Corporate security
A company monitors threats against executives.
An anonymous account claims that an executive is involved in corruption.
A few accounts repost the claim.
A fake whistleblower profile appears.
A low-quality article is published.
A YouTube video summarises the allegation.
An AI tool now says there are “online allegations” involving the executive.
The risk team must assess whether the allegation is credible.
The danger is that reputational risk and evidence quality get mixed.
Yes, the allegation may create reputational risk because people are discussing it.
But that does not mean the allegation is true.
The report should separate:
- existence of the narrative
- spread of the narrative
- credibility of the claim
- credibility of the origin
- potential impact on the company
- unknowns and confidence level
Do not let narrative visibility become factual confidence.
Law enforcement
Investigators monitor online threats around a public event.
Several accounts claim that a group is planning violence.
Some posts include screenshots of private chats.
Other accounts claim to know the suspects.
A few profiles share images of weapons.
The situation looks urgent.
But practical verification questions matter:
- Are the screenshots authentic?
- Are the weapon images original?
- Are the accounts linked to real people?
- Are the threat claims specific and actionable?
- Are the same accounts involved in prior hoaxes?
- Are the accounts amplifying each other?
- Is there offline corroboration?
- Is there a plausible capability and intent?
Online threats should never be ignored.
But neither should they be accepted at face value.
Evidence poisoning can create false positives.
False positives waste resources and can damage innocent people.
False negatives are dangerous too.
This is why structured confidence matters.
Journalism
A journalist sees a viral video claiming to show a massacre, police abuse, military movement or public disorder.
The video is emotionally powerful.
Many accounts share it.
The pressure to publish is high.
But emotional urgency is exactly when verification discipline matters most.
The journalist should ask:
- What is the earliest upload?
- Who filmed it?
- Where exactly was it filmed?
- When was it filmed?
- What is outside the frame?
- Is there matching local reporting?
- Are there satellite, weather, traffic, acoustic or visual clues?
- Are there signs of reuse?
- Who benefits from this framing?
Being wrong can make you part of the poisoning.
Cyber threat intelligence
A threat actor claims to have breached a company.
They post a sample file.
Other channels repost it.
A few security blogs mention the alleged breach.
The company name starts trending in threat-intel circles.
But the sample file may be old.
It may come from a previous leak.
It may be scraped data.
It may be fabricated.
It may be mixed with real data to appear credible.
It may be used for extortion.
CTI analysts should separate:
- actor claim
- actor reputation
- data authenticity
- data freshness
- source of the sample
- uniqueness of the records
- evidence of access
- victim confirmation
- operational impact
A threat actor’s claim is not evidence by itself. It is a lead. Sometimes criminals poison the information environment to increase pressure on victims.
Geolocation
A photo is claimed to show a suspect near a sensitive location.
The image includes recognisable buildings.
The geolocation appears correct.
But there are still questions:
- Was the person actually there?
- Was the image manipulated?
- Is the person in the image the claimed person?
- Is the image recent?
- Was the background inserted?
- Was the photo taken from a real estate listing, travel blog or stock image?
- Does the lighting match the claimed time?
- Does clothing match the season?
- Is there EXIF data, and can it be trusted?
- Does the image appear elsewhere?
Geolocation proves where an image appears to have been taken.
It does not automatically prove who took it, when it was taken, why it was taken or whether the claimed person was present.
Extremism and radicalisation monitoring
A network of accounts posts increasingly violent rhetoric.
Some accounts appear to encourage others.
A few profiles claim they are ready to act.
Screenshots circulate in monitoring communities.
This area is sensitive because online rhetoric can become real-world harm. But evidence poisoning can happen here too.
False extremist personas can be used to:
- provoke real users
- discredit a movement
- create panic
- lure individuals into conversations
- make a group appear larger than it is
- frame opponents
- generate media attention
- manipulate law enforcement attention
Analysts need to be careful with attribution.
They should distinguish:
- genuine ideological commitment
- trolling
- roleplay
- provocation
- infiltration
- satire
- mental health crisis indicators
- coordinated influence behavior
- actual capability and intent
The SOURCE framework for detecting evidence poisoning
We need practical methods, not just warnings. Here is a simple framework analysts can use. I call it SOURCE.
S – Source origin
Find the earliest trace.
Do not start with the version that went viral.
Start with the first known appearance.
Ask:
- Where did this claim first appear?
- Who posted it first?
- Was it text, image, video, screenshot, document or audio?
- Is the original still available?
- Has it been edited?
- Are there archived versions?
- Did it appear first in one language and later in another?
- Was the first source credible, anonymous, new or suspicious?
The earliest source is not always the true source. But it is the best starting point.
O – Ownership and operator signals
Investigate who controls the source.
For accounts:
- creation date
- username history
- profile photo history
- posting rhythm
- language use
- network connections
- follower quality
- previous topics
- behavioral consistency
- signs of automation
For websites:
- domain registration clues
- hosting patterns
- archive history
- author identity
- contact details
- content quality
- reused templates
- outbound links
- ad networks
- related domains
For channels and groups:
- admin signals
- posting schedule
- amplification patterns
- cross-posting behaviour
- linked communities
- recurring narratives
You are not only verifying content. You are verifying the container that delivered the content.
U – Upload and reuse history
Check whether the material has appeared before.
For images and videos:
- reverse image search
- video keyframes
- thumbnails
- filenames
- watermarks
- captions
- compression artifacts
- platform reposts
- earlier language version
For text:
- exact phrase search
- unique sentence search
- quote search
- translation search
- AI-like repetition patterns
- copied paragraphs
For documents:
- metadata
- formatting consistency
- fonts
- author fields
- template reuse
- file creation clues
- previous public versions
A lot of fake context is exposed by reuse. Old material with a new caption is one of the oldest tricks online.
R – Relationship mapping
Map how the sources relate to each other. Do not just collect them. Draw the chain.
Ask:
- Which account posted first?
- Who amplified it?
- Which accounts cite each other?
- Which websites repeat the same wording?
- Are the same images used across profiles?
- Do the accounts share followers?
- Do they post in synchronised bursts?
- Are there common links, domains or hashtags?
- Are the comments organic or coordinated?
The goal is to determine whether you have independent sources or one source echoing through a network.
Corroboration requires independence. Without independence, you have repetition.
C – Context integrity
Check whether the context holds.
For event claims:
- date
- time
- weather
- shadows
- clothing
- language
- signs
- architecture
- vehicles
- road markings
- local holidays
- public transport disruptions
- local media
- official statements
- live cameras where available
For identity claims:
- age consistency
- career timeline
- location history
- language ability
- social graph
- platform behavior
- profile evolution
- cross-platform consistency
For documents:
- terminology
- formatting
- dates
- signatures
- logos
- version history
- internal consistency
- whether the organisation would produce such a document in that form
Context is where many false claims collapse.
The content may look real. The context may not.
E – Evidence confidence
For example:
- High confidence
- Moderate confidence
- Low confidence
- Unverified
- Disputed
- Likely false
- Insufficient information
Explain why.
A good confidence statement might look like this:
“Moderate confidence that the video was filmed at the claimed location, based on matching architecture, road layout and signage. Low confidence that it was filmed on the claimed date, because no earliest upload has been established and the weather does not match local records.”
That is much better than:
“Video verified.”
Verification is rarely binary. Confidence is the language of honest analysis.
The evidence poisoning checklist
Use this before placing online material into a report.
Origin
- Did I find the earliest known appearance?
- Did I preserve the original URL?
- Did I archive the source where appropriate?
- Did I separate original material from reposts?
- Did I check whether the source has changed over time?
Independence
- Are my sources genuinely independent?
- Are they citing each other?
- Do they trace back to the same origin?
- Are they part of the same network?
- Am I counting repetition as corroboration?
Identity
- Is the account/person real?
- Is the profile photo authentic?
- Does the biography make sense?
- Is the posting history consistent?
- Does the claimed location match behaviour?
- Are there signs of persona farming?
Media
- Has the image or video appeared before?
- Is the media cropped or edited?
- Do visual details match the claim?
- Do weather, shadows and environment match?
- Is the audio consistent with the scene?
- Could the media be AI-generated or manipulated?
Context
- Is the date verified?
- Is the location verified?
- Is the translation accurate?
- Is there missing surrounding conversation?
- Has the material been reframed?
- Does the claim depend on an emotional caption?
AI and search
- Did an AI tool summarise this claim?
- Did I inspect the sources behind the AI answer?
- Are AI systems citing derivative sources?
- Is the claim appearing because it is true or because it is and amplified?
- Did I treat the AI answer as a lead instead of evidence?
Reporting
- Did I state confidence clearly?
- Did I document uncertainty?
- Did I separate facts from assessment?
- Did I explain source limitations?
- Did I avoid overstating what the evidence proves?
- Did I include what would change my assessment?
The language problem: how words inflate weak evidence
Evidence poisoning is not only a source problem. It is also a writing problem. Analysts sometimes poison their own reports by using language that is too strong.
Words matter.
Compare these phrases:
“Multiple sources confirm…”
versus
“Multiple accounts repeat…”
Those are not the same.
“Online evidence shows…”
versus
“Online material suggests…”
Not the same.
“Linked to…”
versus
“Mentioned alongside…”
Not the same.
“Verified video…”
versus
“Video geolocated to…”
Not the same.
“Known associate…”
versus
“Account frequently interacts with…”
Not the same.
“Threat actor breached…”
versus
“Threat actor claims to have breached…”
Not the same.
Bad wording turns uncertainty into fact.
This is especially dangerous when reports are read by executives, investigators, journalists or decision-makers who do not see the underlying source mess.
A polished report can hide weak evidence. So can an AI-generated summary.
Good OSINT writing should preserve uncertainty, not erase it.
The screenshot problem
Screenshots are useful. But screenshots are also dangerous. A screenshot without context is not enough.
Screenshots can be:
- fabricated
- edited
- cropped
- translated incorrectly
- taken from another date
- taken from a fake account
- missing the URL
- missing the surrounding thread
- missing the platform context
- missing replies that change the meaning
- impossible to verify later
This does not mean screenshots are worthless.
It means screenshots should be treated as captures, not conclusions.
A proper source trail should include:
- original URL
- capture date and time
- platform
- account identifier
- surrounding context
- archive link where possible
- notes on access limitations
- whether the content was deleted or edited
- whether the screenshot was made by you or obtained from someone else
If all you have is a screenshot, say so.
Do not pretend it is stronger than it is.
A screenshot can:
- be a lead.
- support documentation.
- preserve volatile content.
But a screenshot alone should rarely be the end of verification.
The AI problem: useful assistant, dangerous witness
AI is useful in OSINT. I use it. Many analysts use it.
It can help with translation, summarisation, entity extraction, brainstorming, coding, clustering, report drafting and identifying investigative angles.
But AI should not be treated as a witness.
AI did not see the event.
AI did not collect the source.
AI did not verify the identity.
AI did not understand the operational consequences unless you force it to reason with evidence.
AI can help you think.
It can also help you become lazy. That is the danger.
In evidence-poisoned environments, AI can make things worse because it is very good at turning messy, uncertain information into clean language. Clean language feels safe. But the source chain may still be dirty.
Safe ways to use AI in polluted investigations
Use AI to:
- generate alternative hypotheses
- list verification steps
- extract entities from long texts
- compare conflicting narratives
- identify missing information
- translate content carefully
- summarise only after source quality is assessed
- draft confidence language
- create structured timelines from verified inputs
Do not use AI to:
- decide whether a person is guilty
- confirm identity without evidence
- summarise unknown sources as fact
- replace source verification
- rank threats without context
- infer intent from weak signals
- treat popularity as credibility
- generate final conclusions from unverified material
A simple rule:
AI can help process evidence. It should not become the evidence.
The GEO problem: when AI engines choose what becomes visible
Traditional SEO (Search Engine Optimisation) was about being found by search engines.
GEO (Generative Engine Optimisation) is about being found, cited or summarised by AI answer engines.
This matters for OSINT because polluted information can be designed not only for humans, but also for machines.
A bad actor may not need to convince every analyst directly.
They may only need to place enough structured, repeated, keyword-rich material online so that search engines and AI systems start surfacing it.
This could affect:
- reputation attacks
- smear campaigns
- fake allegations
- synthetic expert commentary
- false company histories
- fake local news
- manipulated crisis narratives
- political influence operations
- scam legitimacy
- threat actor branding
If AI systems start summarising polluted material, the pollution gets a second life. It becomes discoverable through questions. This is why analysts must inspect not only the answer, but the retrieval path.
Ask:
- Why did this source surface?
- Is it primary or derivative?
- Is it recent because it is new, or because it was republished?
- Is it cited because it is credible, or because it is structured well?
- Are multiple AI tools repeating the same weak source?
- Are search results dominated by content farms?
- Are exact phrases appearing across many low-quality domains?
In the future, adversaries will not only manipulate people. They will manipulate the information systems people rely on. That includes AI.
How to report evidence poisoning properly
Do not overstate. Do not accuse without evidence. Use structured language.
Example wording:
“Several online sources repeat the claim, but the available material appears to trace back to a single anonymous account. No independent primary source was identified during this review.”
“Confidence in the claimed date is low. The video appears authentic as media, but current evidence does not support the caption’s timeline.”
“The account presents as a local witness, but its creation date, posting pattern and amplification behaviour suggest it may not be an organic observer.”
“The article should be treated as derivative reporting. It appears to summarise social media claims without independent verification.”
“AI-generated summaries identified during the review repeated the claim but did not provide additional primary evidence.”
“This assessment distinguishes between the spread of the allegation and the credibility of the allegation.”
That last sentence is especially important. Good OSINT keeps those lines clear.
Practical mini-cases
Below are short hypothetical cases that show how evidence poisoning can work. These are not about one platform or one country. They are patterns.
Case 1: The fake witness swarm
A breaking incident occurs near a train station.
Within minutes, several accounts claim they are nearby.
They describe the same suspect.
They mention the same detail: a red backpack.
A few accounts post blurry images.
One image is widely shared.
The phrase “red backpack” starts appearing in posts.
A local rumour account posts: “Multiple witnesses report suspect with red backpack.”
But analysis shows:
- the earliest “witness” account was created that day
- several accounts used similar wording
- the blurry image came from an unrelated event
- no verified local witnesses mention a red backpack
- official updates describe no suspect matching that detail
The red backpack became a false anchor.
Once people repeated it, others began looking for it.
This can distort public reporting and investigative attention.
Case 2: The synthetic expert
A polished LinkedIn profile appears for a “geopolitical risk consultant.”
The person posts daily analysis about a conflict.
Their posts are well written.
They cite public sources.
They slowly build an audience.
After months, they start promoting a specific narrative about who caused an attack.
Journalists quote them.
AI search tools summarise them.
But checks reveal:
- no employment records outside self-published profiles
- profile image shows signs of AI generation
- posts are mostly rewritten from public analysis
- the account’s early followers are suspicious
- the same writing pattern appears on other personas
- the domain linked in the bio was recently created
The issue is not only that the expert is fake. The issue is that the fake expert became part of the public evidence environment.
Case 3: The old video, new outrage
Case 4: The breach that may not be a breach
- the actor made a claim
- the data sample contains real-looking records
- the data may be old
- no evidence currently proves fresh access
- reputational impact exists regardless of breach confirmation
Case 5: The fake local news loop
What OSINT teams should change
This problem is not solved by one tool. It requires better habits.
1. Teach source-chain reconstruction
Every OSINT course should teach people how to map where a claim came from and how it moved.
Not just how to find things.
How to understand the life of a claim.
2. Separate discovery from verification
AI is useful for discovery.
Search engines are useful for discovery.
Social platforms are useful for discovery.
But discovery is step one.
Verification is a different discipline.
3. Use confidence language
4. Track source independence
Do not count sources until you understand their relationships.
Five reposts are not five confirmations.
5. Preserve source trails
6. Train against emotional manipulation
7. Audit AI outputs
A simple evidence grading model
For practical reporting, teams can use a basic grading model.
Source reliability
A — Known reliable primary source
B — Usually reliable source with some limitations
C — Unknown or mixed reliability
D — Low reliability or anonymous source
E — Known unreliable or deceptive source
Information credibility
1 — Confirmed by independent primary evidence
2 — Probably true, supported by several indicators
3 — Possibly true, limited support
4 — Doubtful, major gaps or contradictions
5 — Likely false or misleading
Example
A video from a known journalist at the scene might be B2 or A2 depending on context.
A screenshot from an anonymous Telegram account might be D3 or D4.
A claim repeated by multiple anonymous accounts tracing back to one origin might still be D3 or D4, even if it appears widely.
This kind of grading forces analysts to separate source quality from claim visibility.
The truth
But access is not the same as truth. The next phase of OSINT will not be defined by who can collect the most data. Everyone can collect data.
Tools can collect data.
AI can summarise data.
Dashboards can visualise data.
The scarce skill will be judgment.
Can you tell the difference between a source and an echo?
Between a witness and a persona?
Between an event and a reframing?
Between corroboration and repetition?
Between visibility and credibility?
Between a useful AI summary and a poisoned one?
That is where professional OSINT lives, in the reasoning.
Final thought
The future OSINT analyst will not be the person who finds the most information.
That phase is over. Information is everywhere.
The future OSINT analyst will be the person who can move through polluted information without becoming part of the pollution. And they will understand one of the most important OSINT lessons for the next decade:
The question is no longer only whether information can be found.
The question is whether it was placed there to be found.
FAQ
Written by Nico Dekens
9 May 2026
Reproduced with permission

