Security1 distinct publisher2 min readPublished
ESET says AI tooling removes the reconnaissance bottleneck that once kept OSINT for high-value targets. The post carries no actor, no dates and one number, so treat it as an argument about program design rather than a campaign report.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Per-target labor was the gate. Before the tooling, someone had to locate a target's public accounts, interests, colleagues and family, then correlate the pieces, work out who was related to whom, and decide what was usable in an attack [3]. That was the reason open-source intelligence gathering was aimed at high-profile and potentially high-value people and nobody else [2].
What the post does not carry is telemetry. No threat actor is named, no campaign is dated, no before-and-after reconnaissance cost is measured [9]. Exactly one figure in it is quantified: hundreds of UK under-18s reporting sextortion victimization this year, and "hundreds" is an order of magnitude rather than a count [6][10]. That makes this a capability argument about what is now cheap to attempt, not evidence that target selection has already moved down the org chart. A capability argument is grounds for changing a process; campaign data is what justifies unplanned spend.
Tiered awareness programs encode a scarcity assumption. The personalized pretext is expensive, so you rehearse it with the twenty people worth an attacker's afternoon and give everyone else generic guidance about odd phrasing and urgency. Both halves erode against what ESET describes. The model drafts the script, including for operators who do not write the target's language well, which is the tell most generic training still teaches [5]. The personalization inputs are already public: a child's school, a posted holiday, the workplace itself, gathered at scale [11].
The asymmetry is directional. Reconnaissance cost per target falls with tooling, while protective coverage is bought per person, so a program that stops at senior staff gets relatively more expensive to extend at the moment the attacker's shortlist stops being short.
For a corporate defender the operative paragraph in the post is the least dramatic one. Hybrid work has fused the two identities, with personal devices and home addresses used for corporate activity, and joining personal social accounts to professional ones is trivial for a model, so personal detail becomes the raw material for harvesting work credentials [7]. The deepfaked ransom calls and the sextortion cases are real harm to real people and they change no control a security team owns [6]. What changes controls is that the call reaching your helpdesk now arrives with accurate personal detail attached, which means verification has to hold when the caller's story checks out. ESET also puts vulnerability exploitation and basic malware generation on the same cost curve [8].
Ranked by verification strength, evidence, and original report placement.
The post states that open-source intelligence gathering (OSINT) was once used only on high-profile and potentially high-value targets because it took skill and time to carry out.
Before AI tooling, the post says, an adversary had to spend time finding a target's public-facing accounts, interests, friends, family and colleagues, using dedicated tools or trawling websites and posts, correlating and cross-checking information, working out relationships between individuals, and deciding what to use in an attack.
The post says the boundary between work and home has blurred under hybrid working, with personal devices and home addresses used for corporate activity, that linking professional and personal social media accounts is a simple task for AI, and that fraudsters could use personal information to craft attacks designed to harvest work credentials.
The post gives as an example a phishing email made more convincing by personal details such as the recipient's workplace, a child's school, a recent event attended, or posted news such as a birthday or holiday, and says all of it may be in the public domain and easy to gather at scale.
The source material names no threat actor, no campaign, and no dated incident, and reports no measured reconnaissance cost before or after AI tooling.
Exactly one quantified figure appears across the source's assertions: the hundreds of UK under-18s reported as sextortion victims this year.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
The bottleneck moved: 622 CVEs in July, and no one left to write up the fixes1 distinct publisher
science
Feeds are triaging patients by engagement, and the proposed defence is literacy, not moderation1 distinct publisher
security
Hugging Face breach ran 69 days: a containment failure, not a rogue-agent flash1 distinct publisher
build
Two design mindsets, one LLM policy, and the reason the new rules cancel each other1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor essay, no measurements
ESET argues its case rather than documenting it: no actor, no campaign, no dated incident, and — most tellingly for a piece built on cost collapse — no measurement of reconnaissance effort before or after AI tooling. The single number, hundreds of UK under-18s reporting sextortion this year, arrives without saying who counted them. What keeps this above the floor is that the mechanics described are internally coherent and match how public-source collection actually works; what holds it down is that every load-carrying sentence is an assertion.
Nothing deployed, nothing observed
There is no uptake to measure. ESET names no tool, releases no telemetry and points to no instance of an attacker doing this on a date we could check — the piece is about what is now possible, and possibility leaves no adoption trail.
Direction plausible, magnitude asserted
'End-to-end fraud pipeline' and 'everyone could be a target' are carrying far more weight than the material underneath them. The underlying direction is credible and cheap to believe — collection genuinely does get faster when a model does the correlating — but ESET converts a plausible trend into a settled state of the world with one unattributed statistic in support. Overstated on magnitude, not on premise.
Security vendor arguing threat expansion
ESET sells security software, and this post's thesis — the cheap-target pool just widened to include everyone — is exactly the thesis that grows its market. Worth naming, since nothing in the piece names it. Two things temper the reading: the remedies offered are unbranded and free (private profiles, share less, multi-factor authentication), and no ESET product appears anywhere in the argument.
Single voice, unchecked
We are confident about what ESET said and what it left out — that part is on the page. We are much less confident that the shift is as complete as described, because there is no second publisher to cross-check, and the assertions most useful to a defender are precisely the ones with no numbers attached.