How to remove information about yourself from the Internet

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
838
Deposit
0$
Intelligence on MITRE ATT&CK: why attack your data
Before you delete something, it is worth to understand what the enemy is looking for. Attackers work on specific techniques from MITRE ATT&CK matrix, Reconnaissance tactics: Read more in our the Osint Review for Information Security Specialist.

Search Open Websites/Domains (T1593) - Search for open resources. Subtechnics: Social Media (T1593.001) - parsing of VC profiles, Telegram channels, Odnoklassniki; Search Engines (T1593.002) - Google Dorking by your name and nicknames.
Gather Victim Identity Information (T1589) - collection of victim IDs. Email Addresses (T1589.002): email from leakage becomes the entry point for credential stuffing and targeted phishing.
Gather Victim Org Information (T1591) - position, colleagues, internal structures of the company. Vector for social engineering against you or your employer.
WHOIS (T1596.002) is a domain without privatization, and WHOIS issues the name, phone number and physical address of the registrar. Just a gift for the attacker.
IP Addresses (T1590.005) - collection of IP for geolocation and correlation of activity.

Business logic is simple: the more identifiers collected at the exploration stage, the more accurate social engineering and the higher the chance of a successful attack. For the attacker, this investment of minutes is viewing open profiles, punching email on leaks, WHOIS request. For the victim, the consequences are stretched for months: from doxing and fraud to theft of records and financial losses.
The task of self-stretching is to minimize the number of available identifiers so that the cost of exploration for the attacker becomes economically inexpedient. Simply put - to make you more expensive to punch than a neighbor.
Self-Sisting Analysis of Self: A Complete Digital Footprint Audit

Systemic deanonymization of itself is built on the same tools that the attacker uses - only directed to its own digital trace. Below is the methodology I use in professional audits.
Google Dorking and search by search engines
The usual request "Ivan Petrov" is useless - too much noise. Use search operators for point search:


Check not only Google, but also Yandex (indexes differ - a page invisible in Google, quietly lies in the Yandex cache), Bing and DuckDuckGo. Namechk checks the employment of the nickname on 90+ platforms - helps to unearth forgotten registrations. Web Cleaner is looking for you through dozens of search engines in parallel - what is not found in Google can pop up in Yahoo or Bing.

Separate stage - archive.org (Wayback Machine). A remote VKontakte page or an old profile on the forum can be stored in snapshots for years. To remove snapsots, send a request to [email protected] with specific URLs and justification - personal data are posted without consent. Describe the situation in as much detail as possible: the indication of safety risk speeds up processing.
Interesting Fact: In September 2024, the Internet Archive itself was hacked. According to HIBP, 31 081 179 records - email, passwords, nicknames. If you have ever registered for archive.org, your data may also be compromised. Irony - the repository of foreign traces itself left a trace.
How do you know what's in the leak databases
Have I Been Pwned (haveibeenpwned.com) - basic and free tool for checking your privacy on the network. Enter the email - get a complete list of leaks in which it appears. Verified HIBP data on the largest leaks:

Service Year of Leak Records Types of leaked data
Facebook 2019 509 458 528 Email, dates of birth, employers, gender, geolocation
LinkedIn 2012 164 611 595 Email, passwords
mail.ru 2014 16 630 988 Email, passwords
START 2021 7 455 386 Email, names, passwords, geolocation
Twitter 2022 6 682 453 Email, phones, biographies, geolocation
Instagram 2026 6 215 150 Email, phones, nicknames, geolocation

For Russian users, mail.ru (16.6 million) and START (7.4 million - Russian online cinema) are particularly relevant. If the email appears in at least one database - the password should be considered compromised wherever it was used again. No options.
Configure notifications: HIBP allows you to subscribe to email alerts. If your address appears in a new leak, the notification will arrive within a day.
Audit of social networks and shadow profiles
In addition to the obvious VKontakte, Telegram and Odnoklassniki - look at the browser password manager and the mail archive. Search by keywords "registration," "confirmation," "welcome," "your account" in the mailbox identifies dozens of forgotten services. Go through the saved passwords in Chrome or in the password manager - there are often accounts that you will not remember without a hint.

A separate story - shadow profiles. According to researchers (Kaspersky and others), social networks form profiles even for people who have never registered on the platform. The source is the address books of other users who gave the application access to contacts. It is impossible to completely prevent the creation of such profiles, but to minimize the damage is real: withdraw permissions from applications for access to contacts, camera and geolocation. If your Google, Apple or social network account is connected to a third-party service that you do not use, untie it. Now.

Keep an audit table - without it in a week you will not remember where you sent requests. Structure (adapted from ESET methodology):

URL Source Type Open data Action Status Verification date
vk.com/id123 Social network Name, photo, city Delete account In the process -
forum.example.ru Forum Nick, email, posts Request to the administrator Sent -
sbis.ru Aggregator INN, OGRN, NAME PD removal request Waiting for a response -
Remove data from search engines: de-indexation and cash update
The moment that most Russian-speaking guides miss: removal from the search engine does not remove data from the original site. This is a decrease in visibility, not destruction. Always prioritize source removal, de-indexation use as an add-on.
Google: Results About You and Deletion Forms
Google provides several mechanisms. The most powerful of them is almost not described in Russian-language sources.

About You - dashboard in the Google app (profile icon -> Results About You). Finds search results containing your address, phone or email and allows you to request their removal massively. The main thing - after setting up Google automatically monitors the issue and notifies about new results with your contact details. In fact, automating one of the most time-consuming steps.

Form of deletion of personal data - for the removal of bank details, passport data, medical records, explicit images without consent. According to the official documentation of Google, a request for deletion is allowed: addresses, phone, email, numbers of state documents, bank data, signature photos or identity cards. You will need URLs of problem pages and screenshots.

Cache Update - if the page is changed or deleted, but Google shows the old version. Request through the update form of obsolete content.

Google Maps and Street View - if your home is visible on the panoramas, request a blur through the Street View interface and save the request confirmation.
Google may reject the appeal if the information is of public interest. Solutions are of two types: complete removal (URL does not appear for any query) and partial (URL does not appear when searching for your name, but can appear on other queries).
Yandex, Mail.ru and the right to forget
Yandex has a special form for hiding pages from the issue and a separate form for frank content placed without consent. To update the cache - Yandex.Webmaster or form in Help.

In Russia, there is a "right to forget" - search engines are required to process the request within 10 days and remove references if the information is obsolete or distributed illegally. The forms are at Yandex, Google and Mail.ru. According to the statistics of Yandex itself, more than half of the appeals are rejected - the justification should be specific and supported by facts. The general wording "I want to remove" will not pass. You need specific URLs, a description of the problem, and a reference to the legal basis.
For Bing - Microsoft Report a Concern form, the category "Exposed personal information" with a search query and URL.
Removing accounts and traces in the network: step-by-step self-cleaning

Just Delete Me and Anonymization of Unremoved Accounts
The Just Delete Me service contains direct links to the removal of accounts of hundreds of platforms and ranks for the complexity: Easy, Medium, Hard, Impossible. Extensions for Chrome and Firefox speed up the process - when you visit the site, you can immediately see how difficult it is to delete the account.


Data broker opt-out
Data brokers aggregate and resell data about people - on behalf and age to frequency orders and geolocation. For users with international activity, opt-out is mandatory. Algorithm (adapted from ESET methodology):

Find your profile on the broker’s website
Select opt-out or do-not-sell (not delete - otherwise the record of your refusal will also be deleted and the data is highly likely to return). The subtle moment many stumble.
Submit a request from a dedicated email, not from the main one
Pass verification by email or SMS
Fix the date of sending and reference ID
Check after 7, 30 and 90 days - the data tends to return

On GitHub-repository The-Osint-Toolbox/Privacy-Opt-Out collected links to the opt-out forms of dozens of services: Acxiom, Fast People Search, Intelius, PeekYou, Truecaller and others. There - Just Whats The Data (which data is collected by each service) and Just Get My Data (how to get your data back).
Personal data protection: FZ-152 and legal instruments


For Russian users the main legal leverage - Federal Law No. 152-FZ "On Personal Data".

What is considered personal data (art. 3 FZ-152): Name, date of birth, address, telephone, email, passport data, INN - any information that allows you to directly or indirectly determine an individual.

Rights of the subject of the PD:

Revocation of consent to processing at any time (art. 9). Consent must be specific, informed and conscious - if you have not given it explicitly, the processing may be illegal.
Confidentiality (art. 7) - the operator is not entitled to disclose the PD without your consent, except in cases provided by law.
Processing is permitted only for specific purposes (art. 5). The goal has been achieved or has disappeared - the data are to be destroyed.

Practical steps:

Send a written request to remove the PD with a formal withdrawal of consent to the processing. Provide specific data that you request to delete.
If the operator does not react within a reasonable time - a complaint to Roskomnadzor.
The extreme measure is the court.

For international services: GDPR Article 17 (Right to Erasure) for European companies, CCPA for California. In the request, quote a specific article of the law - by experience, it speeds up processing. A formal reference to the law turns your letter from "please delete" to a legal requirement. If there are no contacts on the site, the service who.is will show who is registered the domain.
Digital hygiene checklist: monitoring and prevention
Removal is a one-time action. Without system monitoring, the data is returned. Minimum set for permanent control:

Monitoring:

HIBP subscription to all your email addresses - new leak notices
Google Alerts - alerts on the name and key identifiers
Results About You - Google automatic monitoring by contact details
Re-audit once a quarter: Google Dorking + Yandex + HIBP + social network check

Prevention:

WHOIS Privacy when registering domains - without privatization your name, phone and address fall into the public register and are indexed by search engines. Direct operation of the WHOIS (T1596.002) equipment from the attacker's arsenal.
Masked email alias for new registrations: iCloud Hide My Email, SimpleLogin, Firefox Relay. Each service receives a unique address - only it will be compromised when leaking.
Disabling the synchronization of contacts in mobile applications is the main channel for the formation of shadow profiles.
Minimization of data during registration - do not fill in the optional fields (date of birth, city, employer). The less data in the profile, the less will leak when the service is hacked.

Emergency protocol for doxing or stalking (adapted from ESET recommendations):

Record evidence: screenshots, URLs, time tags. Save in a separate table.
Change passwords on email and financial accounts, enable two-factor authentication, delete recovery options that you do not control.
Remove high-risk identifiers first: phone, home address, place of work. Start with Google Results About You.
Close the profiles of social networks, disable indexing by search engines.
Run opt-out at the data brokers immediately - people-search sites are often the main amplifier when doxing.
In the case of a real threat to security, contacting law enforcement agencies.

Regular checking of their privacy in the network is not paranoia, but basic hygiene. The attacker spends on exploration by technology T1593 and T1589 minutes. Your audit takes a couple of hours a quarter. The difference is that you find the problem before you find it for you.
 
Last edited:
Top Bottom