TL;DR
OSINT earns authority through verifiable method, yet its forensic appearance can be copied selectively to make political advocacy look objective. The structural vulnerability is not that agenda-driven actors use open tools, but that audiences often mistake maps, timestamps, geolocation and technical language for neutrality, while affiliations, funding and selection bias disappear behind the format. Governments cannot prevent that appropriation, but they can prepare for it through targeted public awareness that teaches people to interrogate method and provenance, state-backed methodological platforms with transparent funding and genuine editorial independence, and predictive narrative intelligence that identifies emerging narratives before they gain viral traction.
Executive Summary
Open-source intelligence, the collecting and analysing of publicly available data, entered public vocabulary during the Ukraine war, then intensified through the Israel-Gaza conflict. The global OSINT market is worth $6.3 billion and, by Facts & Factors' reckoning, will reach $28.34 billion by 2026. It runs on an infrastructure whose barrier to entry sits near zero. That openness is the field's biggest strength. It has also become its most serious structural weakness. Across Ukraine-Russia and Israel-Gaza alike, a pattern has hardened: operators reach for the technical kit of OSINT (geolocation, source checking, forensic analysis) to build a forensic look that lends political advocacy the appearance of objectivity. The tools are neutral. The choice of what to verify, what to ignore, and whom to fund are not. This analysis maps that pattern, pulls apart its mechanics, and sets out three specific government responses: targeted public awareness campaigns, state-backed methodological platforms, and predictive narrative intelligence.
OSINT gets its authority from its method. Geolocate a missile strike to within metres, cross-check satellite imagery against social media timestamps, trace a weapon's serial number through open databases: each of these steps produces evidence whose credibility doesn't depend on who the analyst is or who they work for. The forensic method authenticates the finding. That is OSINT's power. It is also the mechanism through which that power gets appropriated.
The term broke into general use during the Russia-Ukraine war, when outfits like Bellingcat (founded by Eliot Higgins) showed that open-source analysts could match, and sometimes beat, the intelligence products of state agencies. The method was out in the open: source data published beside the conclusions, the analytical steps written down so anyone could check them. Credibility was earned through process, not claimed through branding. That model still is the methodological standard.
What has since spread is something structurally different: operators who adopts the aesthetic (the maps, the timestamps, the forensic register) without the method, and deploys it selectively in service of a position settled in advance. The result is not intelligence; it's an agenda-driven narrative wearing the uniform of intelligence work, and it operates at scale.
The Ukraine-Russia War: Telegram as Narrative Infrastructure
During the Russia-Ukraine conflict, Telegram turned into the main vector for narrative warfare. Unlike the other big platforms, Telegram puts almost no limits on content and keeps a light hand on what channels publish, which made it, first, a vector for COVID-19 misinformation, and then for narrative operations tied to the war.
Russian-linked channels set themselves up as prominent OSINT-style outlets. Rybar, run by a former member of the Russian Ministry of Defence's press service and holding more than 1.1 million followers as of mid-2023, turned out detailed analytical content meant to undercut Ukrainian claims on operational detail. The Wagner Group's affiliated channel, The Grayzone, pulled in over 421,000 followers with a format that mimicked investigative journalism (geolocated imagery, source citation, technical analysis) while advancing Russian military narratives and countering Ukrainian accounts.
The mechanism was the format, rather than the content. These channels were not read by their audiences as propaganda, and for a precise reason: the forensic look — the maps, the annotated imagery, the procedural register — signalled rigour no matter what the analysis actually concluded. The format authenticated the operator. And the operator's agenda, once it had that authentication, shaped what the audience took as fact.
The dynamic didn't stay on one side. Platforms that present themselves as objective fact-checkers behaved in a structurally similar way. PolitiFact, the Pulitzer Prize-winning verification outlet, fact-checked Russia-related claims 803 times during the Ukraine war against 486 times for Ukraine, a selection asymmetry that doesn't prove partisan intent but does show editorial selectivity operating under the brand of objectivity.
The Pentagon document leak of April 2023 added another data point. Highly classified documents laying out US assessments of the Ukraine war were leaked by someone working for the Pentagon and then turned up across several social networks, X included. The platform took the documents down the moment they appeared — even though there was no evidence the documents themselves were fake. The platforms were not checking facts; they were manning the gate. Removal rested not on a forensic read of the content but on classification status and, for these documents, on their capacity to disrupt a story already in circulation.
The Israel-Gaza War: The Pattern Intensifies
The war that began on 7 October 2023 didn't bring a new dynamic; it turned up the volume on an old one. By then, OSINT terminology (geolocation, verification, open-source analysis) had worked its way into a much larger public's vocabulary, and the number of operators wearing the aesthetic had grown to match.
The Standard-Bearers and Their Limits
Bellingcat's work on this conflict showed the method doing what it's supposed to do. Its investigation into the killing of Palestinian-American journalist Shireen Abu Akleh used video mapping, acoustic analysis, and spatial reconstruction to single out an IDF shooter as the likely source of the fatal shot. Later work confirmed the geolocations of Hamas militants during the 7 October attacks and, in a separate investigation, confirmed an Israeli strike on the Jabalia refugee camp. The investigations were transparent about method, unhurried in time, and published with the source data. That rigour is what set them apart from operators using the same tools toward different ends.
The limits of Bellingcat's world came into view under stress. GeoConfirmed, one of the platforms in Bellingcat's affiliate network, was among the first to look into the Al Ahli Baptist Hospital explosion on 17 October 2023 and to declare that Palestinian groups, not Israel, had carried out the strike. The post was later taken down for lack of evidence. That early rush to name a culprit, a break from the methodical approach that defines the Bellingcat standard, produced a published finding the evidence could not carry.
The Centre for Information Resilience, another Bellingcat-affiliated platform, runs "Eyes on Russia," a site devoted entirely to documenting Russian conduct in Ukraine, a framing baked into the platform's name and mandate. Its 2022 annual report lists partners, contributors, and donors, mostly non-governmental organisations with no documented government ties. That sits in line with Bellingcat's stated policy of turning down direct government money while accepting funds from international bodies like the United Nations and the European Commission. The funding structure is transparent. The editorial framing is just as transparent. The two don't contradict each other, but neutral they are not.
The Openly Agenda-Driven Operators
Outside the Bellingcat world, OSINT aesthetics get used for explicit political advocacy with fewer methodological constraints.
The X account OSINTdefender, with more than 960,000 followers, calls itself a "Media & News Company" and hangs a Ukrainian flag ribbon around its profile picture. It publishes genuine open-source intelligence (geolocated strike damage, weapons identification, force disposition analysis) right alongside posts calling for the elimination of Hamas supporters. The engagement numbers tell the story: its intelligence reports, framed consistently pro-Israel, pull in roughly 600 to 1,000 reposts, while its openly opinion-based posts pull in about 100. The audience is not engaging with the opinion itself. It is engaging with the opinion once it arrives wrapped in the forensic register.
The counter-example is Eekad, an Arabic-language platform that bills itself as the first "Arab OSINT platform," with 248,000 followers on X. Its content runs mostly pro-Palestinian and anti-Israel, including a well-produced video that disputes Washington Post reporting on Hamas and sexual violence. As of November 2023, Eekad had not debunked a single claim coming out of Hamas, a selection pattern that doesn't prove fabrication but does show asymmetry in which claims get checked. The platform also re-shares its own reports daily to stretch their reach, a distribution tactic built for propagating a message rather than discovering truth.
The Hamas OSINT Apparatus
Non-state use of open-source intelligence is not a hypothetical. Hamas runs a formalised OSINT capability, leaning on open-source information to predict Israeli military movements. Its intelligence broadcasts include segments that run past 29 minutes, one titled "Al-Mashhad Al Israeli" ("The Israeli Scene"), using publicly available data to track Israeli force dispositions and operational patterns. The tools of open-source intelligence don't discriminate. They serve whoever holds them, and they carry the same methodological appearance no matter what the holder wants.
The Structural Vulnerability
The vulnerability is not that actors with agendas use OSINT tools. In an environment where the tools are open to anyone, that is inevitable. The vulnerability is that the public has been trained (by two years of high-profile OSINT wins) to treat the forensic look as the same thing as objectivity. When a post includes a geolocated image, a timestamp, and a technical register, the audience reads it as intelligence rather than advocacy.
The global market figure of $6.3 billion, projected to reach $28.34 billion by 2026, puts a number on the investment pouring into a field whose credibility mechanism has been structurally compromised. The growth is not the problem. What is missing is a credibility infrastructure to match it.
Three Government Responses
Governments can't stop the appropriation of OSINT aesthetics for political advocacy. The tools are too widely spread, the platforms too many, and the incentives (attention, influence, ideological reinforcement) too strong. What governments can do is prepare for the consequences.
-
Targeted Public Awareness
General media literacy campaigns are too diffuse to hit this particular vulnerability; they help minorly, at best. What's called for is a campaign that teaches people to interrogate the forensic look specifically: who funds the platform, which claims it chooses to verify and which it lets pass, whether the operator owns up to their institutional affiliations, and whether the method — as distinct from the format — matches the standard set by outfits like Bellingcat. The aim is not to breed universal scepticism. It is to hand the public a specific diagnostic skill, pointed at a specific kind of content.
-
State-Backed Methodological Platforms
The model already exists and already works. Bellingcat's donor transparency, its habit of publishing source data beside its conclusions, and its refusal of direct government funding all show that methodological rigour can sit with institutional independence. State-backed platforms, built through think tanks and research institutes, could swell the supply of credible open-source intelligence in an environment now crowded with content of unverifiable provenance. Not as rivals to agenda-driven operators, and not as government mouthpieces wearing a different label. Rather, as methodologically disciplined verification bodies whose funding is transparent and whose editorial independence is real. The institutional design would need to keep the analytical function insulated from the funding source, and the Bellingcat evidence suggests that's doable.
-
Predictive Narrative Intelligence
Intelligence agencies already hold the analytical tools (pattern recognition, sentiment analysis, network mapping) to see which narratives are likely to emerge and gain traction before they go viral. The same tools used to track an adversary's force movements can be turned on an adversary's narrative movements. When an agency can identify a narrative as it is forming rather than after it has spread, the response shifts from reactive to anticipatory. Technical infrastructure for this capability exists. What doesn't yet exist, at scale in most agencies, is the institutional allocation to use it for narrative work instead of kinetic intelligence.
The term "OSINT" now carries operational weight in the public domain. It signals rigour, method, and technical competence. That weight needs to be earned through a process people can see, rather than borrowed through an aesthetic someone can imitate. The platforms that borrow the forensic register without the forensic method are already shaping how the public understands active conflicts, and they do it at scale. The institutional response has begun. It has not yet matched the pace of the phenomenon it is answering to. Whether the response can match the pace of the phenomenon — that is the open question, and it is the one the phenomenon itself keeps moving.