Friday, September 11, 2026
Solar
Home Latest India’s Open Digital Flank: When OSINT Becomes a Weapon

India’s Open Digital Flank: When OSINT Becomes a Weapon

0
Open Source Intelligence

Editor’s Note

Open-source intelligence (OSINT) has moved from the margins of intelligence work to the frontline of modern warfare. AI lets adversaries fuse OSINT, cyber intrusions, and social media data into actionable intelligence at extraordinary speed. For India, it is becoming a new security vulnerability. The piece argues that India must respond not by restricting openness, but by building stronger OSINT, cyber, OPSEC and AI-verification capabilities.

Open-source intelligence began as a supporting discipline: news clippings, monitored broadcasts, published statistics, filed at the margins of state intelligence work. It has since moved to the front line. OSINT today draws on anything a member of the public can access — media reports, government filings, academic research, and commercial satellite imagery sold by firms such as Maxar and Planet Labs. What has changed is not the definition of “open,” but how quickly open data becomes usable intelligence, and its fusion with cyber tools and artificial intelligence has multiplied both its power and its risks.

A Timeline Compressed to Minutes

That compression was visible within hours of Russia’s 2022 invasion of Ukraine. Commercial satellite operators had tracked the Russian build-up for months. Britain’s then Chief of Defence Intelligence, Lieutenant General Sir Jim Hockenhull, later told the Royal United Services Institute that open-source material let classified assessments be shared far more widely than intelligence agencies alone could manage.

Analysts using Sentinel-1 radar imagery and geolocated social media posts identified Russian brigades near Hostomel airport within hours of the invasion, feeding directly into Ukrainian defensive planning. Real-time satellite passes, flight- and ship-tracking feeds, and geolocated posts have compressed a process that once took analysts days into one that now takes minutes, for anyone with the right tools and the patience to look.

What Adversaries Have Always Looked For

Long before AI entered the picture, OSINT’s standout use was inference: reading force posture, intent and capacity from what states and militaries chose, or were forced, to make public. Published movement, state media and diplomatic signalling let analysts estimate order of battle without a single classified source. The instinct is old — open-press and broadcast monitoring were Cold War staples — but its modern form is visual, continuous and crowd-verified.

The Dutch project Oryx has visually confirmed more than 23,000 pieces of Russian military equipment lost in Ukraine since 2022, each entry backed by a photograph or video rather than an official claim. Crowd-sourced trackers are in a way new battle-damage assessors. At a price, they give visibility to both sides.

AI and the Democratisation of Espionage

Artificial intelligence has changed what a small team, or a single analyst, can do with this material. Machine translation, automated geolocation and satellite-image change detection let AI search, cross-reference and interpret open data faster than any human analyst could.

During the joint US-Israeli campaign against Iran in early 2026, AI assistance fused drone footage, satellite passes and telemetry to help enable more than 1,000 discrete strikes within the campaign’s opening 24 hours. Within days, an independent technologist had built a minute-by-minute reconstruction of the same campaign using AI agents to scrape open-source signals before they could be purged from digital caches, entirely from public data.

This is genuine democratisation of technique. It is not, however, a democratisation of advantage: the edge still tilts toward whoever commands the most computing power, an asymmetry that matters as much for India as for any state actor.

India’s Exposed Flank

India’s vulnerability to this capability is less a design flaw than a by-product of what India is: a large, competitive, always-on media environment; a democratic population whose digital footprint has grown faster than the systems meant to secure it. During Operation Sindoor in May 2025, cyberattacks on Indian critical infrastructure rose by roughly 500 per cent, with seven advanced persistent threat groups linked to Pakistan-aligned operations targeting power grids, government portals and defence websites.

Pakistan simultaneously ran a disinformation campaign falsely claiming the destruction of Indian S-400 air defence systems and BrahMos missile bases. That same competitive information space —fast-moving but difficult to fully verify in real time — is what such campaigns are exploiting now. It is this space India cannot simply switch off without undermining its own democratic character.

India’s scale of digitisation is akin to a crown of thorns. A 2018 investigation found that unauthorised agents had built a WhatsApp-based gateway into the Aadhaar identity database. Query of a citizen’s name, address, photograph and phone number could be had for a price. In 2023, many Indian records — names, Aadhaar and passport numbers, addresses — were up for sale on the dark web, which a security firm later confirmed as genuine after sampling the data. Government has begun to recognise the exposure: like amendments narrowing what personal information must be disclosed under the Right to Information Act, even as critics warn the same amendments weaken public accountability.

The armed forces have made a narrower, parallel adjustment, permitting personnel passive-only access to platforms like Instagram while continuing to bar posting or commenting.

Where AI-Enabled OSINT Has Found Its Mark

AI has not created new Indian vulnerabilities so much as exploited existing ones. During Operation Sindoor, the adversary circulated false, misleading and communally sensitive AI-generated video. This forced authorities to block around 8,000 accounts and over 1,400 URLs. An ORF brief estimates that in 2024 alone, China- and Pakistan-linked sources generated roughly 12,000 fake articles and 3,500 deepfakes, and 8,000 articles and 5,000 deepfakes respectively, aimed at Indian elections, military credibility and Kashmir narratives — a volume achievable only with AI-assisted generation.

The same brief highlights a structural collusion: Chinese training of Pakistani hacking groups, joint cyber intrusions, and satellite-positioning support through China’s BeiDou system for Pakistani drone operations. Previously leaked Aadhaar-linked data allows AI-assisted profiling of Indian citizens, officials and institutions- a start adversary never had earlier.

India’s own uniformed and official community adds to this exposure. Postings, professional profiles, and family social media accounts create a large, searchable footprint that AI-assisted scraping can aggregate and geolocate at a speed no earlier generation of analysts could match, without ever touching a single classified source.

Domestic commentary argues India’s cyber-response architecture remains largely reactive, built to investigate after an incident rather than anticipate one. The gap is of awareness and tempo: the adversary is proactive, while India’s verification and takedown processes are reactive. Closing this gap is easier said than done.

Plugging the Loopholes

Openness cannot be curbed; it can best be managed. The most consistent recommendation is attribution as deterrence: naming actors behind cyber and disinformation operations with technical evidence, rather than treating intrusions as anonymous.

A second is posture: shifting agencies like CERT-In from post-incident investigation toward AI-assisted anticipatory threat simulation.

A third is capacity. National Cyber Reserve Force, a hybrid civilian-military model drawing partly on the American National Guard template, built to mobilise technical talent quickly during a crisis such as the 2025 India-Pakistan standoff.

Build tools to reduce dependence on foreign AI vendors for threat detection and OSINT verification would address the compute asymmetry. Have standing, quality-controlled OSINT cells practising the human-machine teaming and verification discipline that separates a useful assessment from a convincing fake.

Another measure is coordination between government agencies, private operators of critical infrastructure and platform companies, so a warning surfacing in one sector reaches the others before an adversary can exploit the lag.

The armed forces’ passive-social-media model is a reasonable template for wider OPSEC discipline across government and defence institutions; digital hygiene, if required, has to be enforced. Transparency and exposure need not be traded off wholesale, either. Disciplined classification and publication review for genuinely sensitive categories can coexist with the Right to Information Act’s core purpose, rather than the blanket narrowing now under debate. Finally, public digital literacy — training citizens to recognise deepfakes, manipulated imagery and phishing attempts — blunts the multiplier effect of synthetic content even where it is not caught at the source.

No single measure closes the gap on its own. Together, they describe an India that treats its own openness as an asset to be defended deliberately, rather than a vulnerability left for its neighbours to discover first.

AVM Prashant Mohan

+ posts

Air Vice Marshal Prashant Mohan, a fighter pilot superannuated from IAF on 31 Mar 25. A Qualified Flying Instructor commanded a frontline fighter squadron and two front line fighter bases. The Air Officer was India’s Defence and Air Attaché to UK from May 19 to Oct 22.

Previous articlePutin Visit Puts Russian Su-57E Pitch Back in Focus