What Iran and Ukraine Reveal About OSINT in War

A tricky reality of the U.S.-Iran war and Russia’s war on Ukraine will plague American policymakers in future conflicts, including in any potential future conflict with China. That reality is just how little control the U.S. government may have over how foreign adversaries access and exploit open-source intelligence (OSINT), sometimes with devastating consequences.

In the past several months, Chinese private companies (some with military ties) have marketed what they describe as open-source data combined with AI analysis on U.S. equipment, aircraft, and force movements in the Middle East. An adversarial nation-state, ostensibly Iran, has accessed commercial geolocation data on U.S. troops to track and target them in theater. Over in Europe, researchers and civil society groups have kept leveraging access to social media, open-source and freely available satellite imagery, and other public data sources to track Russia-Ukraine war developments. Bellingcat alone has used social media and other data to track and publicly identify Russian military units, the names and faces of their members, and even their places of work in Russia. Nation-states commonly use AI models these days to research targets as well.

One of the simplest and most important takeaways from these developments is that OSINT will be an important point of exposure in any future conflict involving the United States. Policymakers and planners must accept that they cannot entirely control how adversaries obtain open-source data, process OSINT, and exploit that intelligence against American interests. But what they can and should do is twofold. First, the U.S. government should limit the availability of the open-source information it can reasonably and responsibly control, focusing on curtailing the sale of commercial data on Americans, enhancing operational security training for the average military service member, and studying the promises and risks of U.S. government control over commercial satellite images. Second, policymakers and planners should obfuscate the rest, taking care to understand adversaries’ limits in processing the ocean of open-source data available and leveraging new technologies, including privacy-enhancing capabilities, to hide in plain sight.

OSINT: It’s Complicated

The U.S. government recently defined OSINT as “intelligence exclusively derived from publicly or commercially available information that addresses specific intelligence priorities, requirements, or gaps.” In other words, it generally (though not exclusively) refers to the kind of information you can look up on the internet or purchase from a commercial vendor and turn into intelligence. That processing is necessary to take what is purely open-source information—perhaps not vetted, perhaps not put into context yet—and make it a finished intelligence product.

Despite repeated warnings and studies of the problem, the Iran war has underscored how little the U.S. government can effectively control the amount of open-source information about its forces and activities. Foreign adversaries can use American platforms and companies to acquire open-source information on U.S. government personnel, facilities, assets, movements, and operations. A foreign military organization can scrape American social media platforms such as Facebook, Instagram, LinkedIn, Reddit, and X to collect data and snapshot the moment a service member or senior government official posts too much about their work travel on their personal account. Information is made available to the adversary, and it is largely not something the U.S. government can (or should be able to) compel social media companies to monitor for and remove. Similarly, foreign intelligence services could set up front companies and purchase highly sensitive data from legally operating U.S. data brokers eager to sell it—easier to lock down in theory, but not without stronger privacy laws. They can also query U.S. AI models for information, leveraging vast amounts of scraped data about the United States for their own ends.

Foreign governments can also pull up freely available U.S. commercial satellite imagery websites to look at the Middle East, Kyiv, or Moscow to inform their analysis and operations. American satellite companies might have decided to delay or pause releases of their imagery from Iran (some reportedly of their own volition), and National Oceanic and Atmospheric Administration (NOAA) regulations for more sensitive commercial remote sensing systems also empower the government to require as much via “limited-operations directives” (also known as “shutter control”). These directives require companies to temporarily limit collection or dissemination for national security or foreign policy reasons. But if a company suddenly ceases to publicly publish imagery on a region of the world, that could prompt an adversary to scrutinize the zone more closely—just one illustration of the complexity of governmental efforts to control space activities in the name of national security.

And equally significantly, including in the satellite case, foreign adversaries can use their own platforms and capabilities to collect open-source information on the United States and its activities. Chinese commercial satellite vendors already operating in a region can keep making their satellite imagery available to the world; it doesn’t matter what NOAA back in the United States might think. Or Chinese companies could do so proactively, choosing as a conflict ramps up to park their own satellites above a country or region, collect and make available imagery from what they see on the ground, and in doing so intentionally showcase the movements, equipment, vehicles, and stations of U.S. forces. Russian, Iranian, and other governments can use their own AI models to scrape U.S. social media websites and identify signs of an imminent force deployment, such as posts in small towns or from service members’ children.

There is an enormous volume of open-source information available in the world, particularly regarding the United States. It is not a theoretical exercise to consider how adversaries could likewise use OSINT in war: the conflicts in Iran and Ukraine show it must be a part of any future planning.

Focus Where You Can Control; Obfuscate Elsewhere

The U.S. government should try its best to limit some of the OSINT available about its activities in the context of competition or conflict, where the availability of the underlying information poses a substantial enough risk to safety, security, or critical outcomes. But doing so is not about chasing an illusion of total control over open-source data. Instead, U.S. policymakers and practitioners should control what they can and invest greatly in obfuscation everywhere else the data exists.

First, the U.S. government should focus on controlling what it can. This largely means considering what kinds of responsible, constitutional controls over commercial vendors (including those subject to federal acquisition regulations) might limit the availability of OSINT or commercial data in some contexts. For example, many U.S. commercial satellite vendors have proactively taken steps to limit what imagery they disseminate on Iran, ostensibly to protect U.S. forces. A study examining what these restrictions have accomplished for U.S. security, what harm they may have caused to the ability of the U.S. public and U.S. congressional overseers to understand the war, and what effects they may have had on U.S. companies’ economic competitiveness, among other questions, could illuminate future areas for strategic or regulatory updates to protect U.S. personnel in an era of ubiquitous data. Again, the considerations are numerous and complex, meriting expert input and deep review.

In the case of purchasable data, long overdue consumer privacy laws could heavily limit data brokers’ sale of U.S. citizens’ data; curtailing sales of such data would shore up those vulnerabilities ahead of any conflict or intensive competition (as the United States is in now with multiple adversaries). Responsible, mandatory controls for AI chatbots could help limit the extent to which they can dox individuals. Better, more widespread OSINT operational security training for the average military service member could likewise help increase the security of their online behavior, while still respecting First Amendment rights. None of these measures are a silver bullet, but they could help to reduce the amount of sensitive open-source data available and raise the costs for adversaries to collect and exploit it.

Second, the U.S. government should focus outside of this zone on obfuscating open-source data, in a focused and responsible fashion, where it presents considerable national security risks. Recent events in—and more accurately, in the sky above—Iran have underscored that the U.S. government has little control over whether Chinese AI-OSINT companies move their satellites to generate commercial imagery on U.S. activities overseas. Laws and regulations passed in the United States are not going to affect that capability, at least directly. (Export controls, sanctions, and other indirect measures are a different question and outside the scope of this article.) Similarly, the U.S. government would be wasting its time and likely running into a whole host of constitutional issues if it tried to remove every single dark web leak, publicly available database, and other information source potentially providing an adversary with an advantage.

U.S. policymakers should navigate this open-source data reality by focusing on obscurity. This can mean hiding in plain sight. This can mean not resorting to simplistic solutions that expose U.S. personnel and activities, but instead opting for combinations of privacy-enhancing technologies, more secure communications systems, and technologies and practices that recognize that the mere availability of data does not necessarily equal the ability to process and act on it. In other words, adversaries may grapple with the sheer volume of open-source data, too, and understanding their limits in that regard will become even more important to navigating conflict and competition in the coming years.

One can call it a more “transparent battlefield,” the data conditions of modern warfare, or an operating reality of the intelligence environment. In any case, social media, public satellite imagery, and other open-source data sources will continue to challenge and potentially expose the United States in future conflicts. Identifying both the lessons to date and the levers of U.S. control is the first step to planning for the next time OSINT puts U.S. personnel and security at risk.

Justin Sherman is a senior associate (non-resident) with the Intelligence, National Security, and Technology Program at the Center for Strategic & International Studies in Washington, D.C.

Image
Justin Sherman
Senior Associate (Non-resident), Intelligence, National Security, and Technology Program