Your username is not anonymous. It is a breadcrumb trail you left for yourself.
You think you are being careful. You use a burner handle for the spicy takes, the marketplace sales, the GitHub commits you do at 2am. You tell yourself nobody will connect xX_NeonMax_Xx to the person who pays rent and has a LinkedIn photo in a blazer.
You are wrong. And I mean that with love.
A username is not an identity. It is a pivot point. In OSINT, a pivot is the moment you turn one shitty data point into two better ones, then turn those two into four, then suddenly you are looking at a Zillow listing of someone's actual house because they posted a picture of their cat next to a window.
It does not take 30 hours. It takes 3 clicks if you know where to look. Here is how.
1. The Gravatar Ghost: Your Email Was Never Hidden
This is the oldest trick in the book and it still works because developers are lazy and humans are predictable.
Take your target username. Plug it into a Gravatar lookup. Gravatar hashes emails with MD5, which is basically tissue paper. Tools like Sherlock or WhatsMyName will give you 200 places that username exists, but the real gold is when you find an old WordPress comment, a Git commit, or a forum avatar that calls Gravatar.
You get an MD5 hash. You reverse it in 0.4 seconds on any free MD5 database. Congrats, you now have firstname.lastname@gmail.com.
Why this gets you to a house: Email is the universal foreign key. Paste that email into Google with quotes, then into Dehashed, IntelX, or even just HaveIBeenPwned. You will find breach data, old MySpace dumps, Adobe, Dropbox, LinkedIn 2012. Those breaches often contain real name, second email, location, and sometimes the password they reused for their apartment complex portal.
One email to rule them all.
2. The Git Commit That Doxxed Itself
If your username touches GitHub, GitLab, or any public repo even once, you are probably naked.
Git stores your configured name and email forever in every commit. People think deleting the repo deletes the history. It does not. People think making the repo private later saves them. It does not. The commit is cached, forked, indexed by GH Archive.
Run: git log --all --full-history --source --patch or just throw the username into GitHub search with author:username and look at the raw patches.
You will find John Smith <john.smith.1998@gmail.com> who commits from Johns-MacBook-Pro.local at 11pm from a timezone that is clearly EST.
From there, same as Pivot 1, but better. Because developers also commit .env files, config files with home IPs, and that one time they accidentally committed a screenshot with their house number in VS Code.
I keep my full commit scraping dorks and the automation for this in my OSINT Investigator Pack, along with the Obsidian workflow that turns a single email into a timeline without me losing my mind.
Two clicks so far. You have real name and personal email.
3. The Breach Pivot: Same Password, Same Person, Same House
This is where people get moralistic. I am not hacking. I am reading a text file someone else left on the internet that your target put themselves in by using Fluffy123! for LinkedIn, Adobe, and their HOA account.
You have an email. You check it against breach aggregators. You do not need to log in anywhere. You just need to read.
Breach data is ugly and beautiful. It gives you:
- Old passwords that contain birth year, pet name, city
- Secondary emails like
j.smith@smalltownrealty.com - Physical addresses from e-commerce breaches
- Phone numbers that are still active
The phone number is the cheat code. Take that 10 digit number and paste it into Facebook search, TruePeopleSearch, FastPeopleSearch, or just Google with site:facebook.com "555-123-4567". Old Facebook accounts link phone numbers by default.
That phone number also links to CashApp, Venmo, WhatsApp, Telegram. One number, five platforms that all show friends and profile photos.
You are now at real name, phone, and city. Third click loading.
4. The Marketplace Photo Leak: You Sold Your Location For $40
This is my favorite because it is so avoidable and so common.
Your target sold something on OfferUp, Mercari, Facebook Marketplace, eBay. They took a photo of a PS5 on their carpet. In the background: a mail envelope, a prescription bottle, a unique door handle, the view from their balcony, their kid's school lanyard.
Even if they stripped EXIF, which they did not, the background is EXIF.
How to pivot: Take the username and search it across marketplaces. Most people reuse the same handle for Marketplace and Instagram. Use Google Dorks like:
site:offerup.com "username"
site:mercari.com "username"
site:facebook.com/marketplace "First Last"
Then reverse image search their profile photo. That photo will appear on their marketplace profile, their old Depop, their Etsy reviews.
Once you have one listing, look at all their listings. People are cataloging their entire house for you. One photo has a street number reflected in a TV. One has a moving box with the apartment complex name. One has a very distinctive kitchen backsplash that you can match on Zillow.
I have found home addresses from the reflection in a motorcycle helmet.
5. The Friend Graph Trap: Venmo Will Snitch Every Time
Venmo is the most underrated OSINT source ever built and it is public by default because people love performance art with money.
You have a real name or phone number. You find their Venmo. Venmo is a social network disguised as a payment app. It shows you who they pay, when, why, and who they hang out with.
August 12: Paid Sarah for - U-Haul - moving help!!!
Who is Sarah? Sarah is tagged. Sarah's profile is public. Sarah's Instagram says "So proud of my bestie moving into her new place on Elm Street!"
Or: Paid Mom for - rent
Mom's profile is Linda Smith. Linda has a Facebook that is completely public because she is 62 and does not know what privacy settings are. Linda's Facebook cover photo is her daughter in front of their new house with the house number clearly visible and a caption: "So happy for my baby girl, 1847 Maple Ave!"
You did not even need to hack anything. You just followed the love.
Same trick works with CashApp $cashtags, public wishlists, GoFundMe donations, and wedding registries. People want to be found by the people they love, which means they can be found by everyone.
6. The Fitness and Frustration Leak
Humans are incredibly bad at being boring consistently.
Your target has a username. That username is on Strava, AllTrails, Fitbit, Steam, Reddit, or Letterboxd. One of those apps leaks location by design.
Strava is the classic. People start their run from their front door. They run the same loop every morning. Their heatmap is literally a line from their house to the park. Even if they set a privacy zone, the zone is like 200 meters. That narrows it to 4 houses.
But my favorite is Reddit. Take the username to Reddit. Even if they deleted posts, Pushshift and Reveddit exist. Search for location mentions in their comment history:
I live in...
My apartment...
My landlord...
The traffic on [Highway]...
Humans complain locally. No one complains generically. They say "my landlord at The Peaks on Tryon raised rent again" and suddenly you have an apartment complex and a city.
Once you have a complex, you have a leasing office, you have floor plans, you have Google reviews with photos that match their marketplace photos. It collapses fast.
When I need to run these graphs without burning my own IP or relying on cloud APIs that log everything, I run it all locally on a rig I documented in the Offline AI Cyberdeck Pack. Pi 5 with NVMe, Hailo-8 for local facial recognition on scraped photos, no cloud, no trail. Paranoid? Yes. Effective? Also yes.
7. The Domain and Dork Slip: Your Side Project Is a Home Address
Final pivot, and it is the quiet killer.
Your target is creative. They bought a domain for their portfolio, their Etsy store, their SoundCloud promo site. They bought it in 2018 before GDPR redacted WHOIS.
Historical WHOIS is forever. Search WHOIS history on Whoxy, SecurityTrails, ViewDNS. That 2018 record has full name, address, phone, email. It is still there.
Even if they used privacy, they linked Google Analytics ID or Adsense ID. Search site:*.com "UA-12345678" and you will find every site they own, including the wedding site they made on Wix with their partner's full name and event location.
Then comes the Dork Bible. The real art is Googling what no one thinks to Google:
"First Last" "has moved to"
"First Last" "is survived by"
site:facebook.com "First Last" "Charlotte"
site:linkedin.com/in "First Last" "Open to work" "Charlotte"
site:venmo.com "First Last"
filetype:pdf "First Last" "resume" "address"
Resumes. People upload resumes as PDFs with their full home address, phone, and email and then link them on their personal site that is linked to their GitHub that is linked to their username.
In three clicks: Username to GitHub email to historical WHOIS to home address. Done before your coffee gets cold.
So How Do You Not Become This Case Study?
You cannot delete yourself, but you can make the pivots expensive.
- Never reuse usernames. Use a password manager for usernames too. Seriously.
- Your Git config should be a burner email. Fix it retroactively with
git filter-repo. - Strip EXIF and blur backgrounds. Or better, take marketplace photos on a white sheet.
- Set Venmo to private. Right now. I will wait.
- Privacy zones on Strava should be 1 mile, not 200 meters, and never start from your house.
- Buy domains with privacy and never reuse Analytics IDs.
- Assume every breach is public and your old passwords are a biography.
The point is not to be invisible. The point is to understand that anonymity is not a username, it is a discipline. Most people fail not because they are being hunted, but because they are being helpful to the hunter.
If you want the actual queries, the Obsidian templates that chain these pivots automatically, and the AI workflow that turns a handle into a full report without you opening 40 tabs, I put it all in one place. No fluff, just the tradecraft.
Stay curious. Stay private.
Top comments (0)