30 October 2026 – 09:00 – Volkshaus, Zurich
OScon ’26
OScon is back – and this year, we’re going bigger!
After an amazing first edition last year, we’re thrilled to announce OScon 2026, the second edition of the OSINT Conference in Switzerland.
This year, we’re going full-day, bringing the OSINT community together again for a day of learning, discovery, and connection.
📍 Friday, 30 October 2026
🏛️ Volkshaus Zürich
🕘 09:00–17:00, followed by networking
🎟️ Tickets are available now!
Get yours here: https://eventfrog.ch/oscon26
We’re incredibly proud to bring internationally recognised OSINT experts to Zürich!
It’s a unique opportunity to learn directly from leading practitioners and connect with them in person. Here are the speakers and talks we’re excited to announce:
▸Sofia Santos
Hiding in Plain Sight – Tiny Details, Big Conclusions
“In this digital age saturated with fast paced data, the ability to pause and notice details is often overlooked. The need to be the first to uncover or report something, coupled with the availability of OSINT tools that promise to solve all of our problems, has the potential of leading people to miss what is right in front of them.
This session aims to explore how attention to detail and critical thinking are crucial skills in open source investigations.
Through expert advice, real examples, and a few engaging exercises along the way,
attendees will learn practical techniques to improve their analytical process, avoid common pitfalls, and approach data with greater confidence and curiosity.
The session is designed to be accessible to beginners whilst still offering useful reminders and techniques for experienced investigators.”
▸Skip Schiphorst
Beyond Translation: Analytical Techniques for Chinese, Russian and Arabic Sources
“AI has transformed how analysts collect and translate information from foreign sources, but it cannot replace human judgment. Understanding context, assessing credibility, identifying bias, and producing actionable intelligence remain fundamentally human skills.”
▸Yoni
The Untapped Intelligence of Infostealer Logs: Reverse Searching for Advanced OSINT
“Infostealer logs have rapidly become one of the richest sources of publicly circulating digital intelligence, yet they remain underused within the OSINT community. This presentation explores how infostealer data can be transformed into a powerful investigative resource by approaching it from the opposite direction: instead of searching for a compromised victim, investigators can pivot from known identifiers to uncover hidden relationships, accounts, infrastructure, and digital footprints. Through practical demonstrations, attendees will learn how reverse searches can be performed using IP addresses, email addresses, usernames, passwords, domains, and websites to identify additional accounts, recover forgotten online identities, map infrastructure, attribute digital assets, and build stronger intelligence profiles. Whether supporting cyber investigations, fraud cases, or traditional OSINT enquiries, infostealer datasets provide a unique perspective that complements conventional intelligence sources and often reveals information unavailable anywhere else.”
▸ Jonas Rey
How to Launder USD 800 Million (and Steal USD 150 Million in the Process)
“Using a real investigation that we have concluded over multiple years, this presentation will explore how OSINT allowed us to help financial institutions detect a large financial crime before it unravelled. The investigation will show how the criminals wanted to set up fraudulent trading companies to circulate funds and launder USD 800 million that were initially embezzled from a large bank in India. The proceeds of that theft have, partially, been laundered in European / US Banks. The criminals were even successful of being listed on the Nasdaq, being their fraud was exposed to the larger public. In the meantime, our investigation had detected that fraud 4 years earlier already.”
▸ Liliia Korostelova and Antonina Mozzhukhina
Digital Evidence in Open Sources: The Role of OSINT and Digital Forensics in Missing Persons Cases in Ukraine
“This presentation explores modern approaches to the search and identification of persons missing under special circumstances in Ukraine. It focuses on the integration of OSINT, digital forensics, facial recognition, geolocation analysis, social media monitoring, photo and video verification, and DNA-based identification. Special attention is given to the role of open-source digital evidence in establishing possible circumstances of disappearance, captivity, death, or repatriation. The presentation also highlights the importance of verification, ethical handling of sensitive data, interagency cooperation, and the transformation of digital findings into analytical materials for humanitarian, investigative, and identification purposes.”
▸ Alexandre Herzog
2.6 Million Domains and Endless Pivots: OSINT from the .CH DNS Zone File
“What can 2.6 million .CH domain registrations tell you about cybercrime, scams, and internet oddities? Quite a lot, it turns out. Join us as we turn the .CH DNS zone file into an OSINT playground, combining daily registration changes with RDAP and DNS data to uncover phishing campaigns, suspicious infrastructure, brand impersonation, and unexpected connections between seemingly unrelated domains.”
▸ Pavel Liber and Lina Shpakouskaya
How Coordinated Propaganda Crosses Borders: Three Cases and a Practical OSINT Workflow
“Coordinated propaganda rarely stays inside one national information space: narratives, distribution infrastructure and amplifying accounts move between countries and regions, languages and platforms. This case-based talk walks through three investigations from 2025/2026 monitoring infrastructure – built and run by our team as a non-profit, public-interest project. Ahead of Armenia’s parliamentary election, about 5% of monitored commenters – 475 suspicious accounts – produced roughly 40% of comments matched to flagged narratives, reusing hundreds of message templates. During Moldova’s electoral campaign, 124 coordinated bursts hit three or more channels within 45-minute windows. And in Poland, with no election taking place, the same methods amplified two very different flashpoints: the Volhynia historical-memory dispute, where 461 suspicious accounts produced almost a quarter of the monitored discussion, and the September 2025 drone incursions into Polish airspace.
The talk follows the investigation workflow from signal to evidence: spotting anomalies, testing alternative explanations, tracing synchronisation and copy-paste chains, and documenting findings that other investigators can independently review. No black-box scores – only observable indicators, stated limitations and reproducible steps. Participants will get knowledge of how a disinformation coordinated campaign works and an indicator checklist they can apply to their own investigations, inside or outside elections.”
We can’t wait to welcome you to Zürich for a full day of OSINT, knowledge sharing, inspiring talks, and great conversations.
See you at OScon 2026!

