Skip to main content

Wireless OSINT: Verifying Places and Premises via Wi-Fi and Bluetooth (2025)

Business networks broadcast identifiers that community projects have mapped for years. Learn how SSID and BSSID records help verify where a business operates, check supplier claims and audit your own sites.

· By UserSearch Team · 10 min read

Disclaimer: This article is for education and for lawful, authorised professional research. Use these methods only where you have a legitimate purpose and a lawful basis, and follow the laws and platform terms that apply to you, including data protection law such as the UK GDPR and EU GDPR. See our Terms of Service.

Every office, shop, warehouse, hotel and factory runs wireless networks, and most of them announce themselves by name. Routers, access points and connected equipment broadcast identifiers that community mapping projects have recorded for years. For researchers working on behalf of organisations, those public records can answer a practical question: does a place, a photo or a claim about a business match the wireless evidence?

TL;DR

  • The Public Record: Business networks broadcast identifiers (SSIDs and BSSIDs) that community projects such as WiGLE have mapped and archived.
  • Global Search: You do not need to drive anywhere. The UserSearch Wireless Device Search type queries WiGLE data so you can check network names and BSSIDs from your desk.
  • The Pivot: We show how a network name visible in a company photo or video can help verify where a business really operates, and how organisations can audit their own sites.

For the advanced OSINT analyst, these public wireless records are useful context. They create a map of where business networks have been seen and when. A company network that appears at a new industrial unit tells a story. An unknown access point appearing inside your own secure facility tells another.

This guide explores Wireless OSINT: the analysis of publicly broadcast IEEE 802.11 (Wi-Fi Standard) and 802.15.1 (Bluetooth) identifiers. We cover how the data is collected, the manual tools used for authorised site surveys, and how to use UserSearch to query global wireless datasets without leaving your desk.


What Is Wireless OSINT?

Wireless OSINT involves searching databases of geographic data derived from wireless access points (BSSIDs) and network names (SSIDs). It relies on the fact that wireless access points, like the domain WHOIS infrastructure behind a website, are distinctive and (mostly) stay in one place.

To understand this, you need to distinguish between three identifiers:

  1. SSID (Service Set Identifier): The human-readable name of a network (for example "Starbucks_WiFi" or "Harbourside_Hotel_Guest"). Not unique.
  2. BSSID (Basic Service Set Identifier): The machine-readable MAC address of the wireless access point (for example 00:14:22:01:23:45). Globally unique.
  3. Client MAC: The hardware address of a phone or laptop. Usually randomised by modern operating systems and, when it relates to a person, personal data. We leave client devices out of this guide.

When Google Street View cars drove around the world, they did not just take photos; they also recorded the BSSIDs of access points they passed. Community projects such as WiGLE and companies like Skyhook have built similar maps. Wireless OSINT is simply querying these maps.


Why It Matters: The Place Anchor

Wireless data gives you a place anchor for claims about organisations that does not depend on what the organisation says about itself.

  • Verifying Business Claims: If a supplier says its factory is in Leeds, but the network names visible in its own promotional video map to a unit in another country, the claim needs a closer look.
  • Establishing Where a Business Operates: Businesses move, but they often take their access points with them. When a company's distinctive network reappears in a new city, the business has probably moved there too.
  • Recovering Company Assets: High-value company equipment (construction plant, vessels, vehicles) often has embedded connectivity that broadcasts via Bluetooth or Wi-Fi, and community scans may have recorded where it was seen.

A well-known example of how aggregated signals reveal more than intended is the Strava heatmap story reported by the BBC, where a fitness app's public activity map showed the layout of military bases. Wireless OSINT works on the same principle with finer detail. For an organisation, that cuts both ways: an unknown access point inside your own premises, or your own network names appearing somewhere they should not be, are early signs that something needs checking.

The same data raises real privacy questions. The ICO's guidance on personal data is a good reminder that identifiers linked to a person are personal data. That is why we keep the focus on business networks and organisations, and why teams in law enforcement and the private sector need a clear lawful basis for this work.


The Manual Method: Mapping Data and Site Surveys

To understand the data, it helps to know how it is collected. "Wardriving" is the practice of moving through an area and logging the wireless networks your device can see. Volunteers upload these logs to community databases.

1. Using WiGLE

WiGLE (Wireless Geographic Logging Engine) is the best-known public database. It crowdsources data from volunteers who run scanning apps on their phones.

The Manual Search:

  • Create a free account.
  • Go to "Web Maps".
  • Enter an SSID (for example "Harbourside_Hotel_Guest").
  • The map shows each place that SSID has been recorded.

Limitation: SSIDs are not unique. Searching for "iPhone" returns an unusable number of results. You need the BSSID (MAC address) for precision.

2. Surveying Your Own Site (Android/Linux)

Organisations can survey their own premises, with authorisation, to see which networks are visible.

  • Android: The WiGLE WiFi Wardriving app passively logs every network your phone sees and can upload the results to the public database (you can keep them local instead).
  • Linux: Use airodump-ng to list nearby access points during an authorised site survey.
# Put the wireless adapter wlan0 into passive capture mode
sudo airmon-ng start wlan0
# List nearby access points, their BSSIDs, channels and encryption
sudo airodump-ng wlan0mon

This displays the BSSID, channel and encryption type of nearby access points. On your own site, compare the list with your asset register: an access point broadcasting your corporate network name that is not on the register is worth investigating with your IT team.

Site Audits with Kismet

While basic scanners show you what networks are here, Kismet gives a fuller picture of the wireless environment on premises you are responsible for. It is a passive tool: it listens rather than transmits.

In an authorised audit of your own site, this lets you see:

  • Unlisted Networks: Networks configured not to broadcast a name still transmit data, so they still show up in an audit.
  • Unexpected Access Points: Devices using your corporate SSID from an unknown BSSID, a common sign of a misconfigured or unauthorised access point.
  • Channel and Encryption Issues: Access points using outdated encryption or crowded channels, which you can export to Wireshark for detailed analysis of your own traffic.

For a security team, Kismet turns a laptop into a wireless audit station for the premises it covers.

3. Bluetooth Checks

Bluetooth Low Energy (BLE) devices (sensors, beacons, headsets) broadcast frequently. Apps such as nRF Connect let you read the advertised data from devices in your own building. In some cases, poorly configured IoT equipment broadcasts serial numbers or descriptive names in clear text, which is a finding worth fixing.

4. Choosing Survey Hardware

Survey teams often use external network adapters, for example from Alfa Network (such as the AWUS036ACS), which support passive capture mode. These adapters with higher-gain antennas can see networks much further away than a standard smartphone, which helps on large sites such as warehouses and campuses. Survey results can also show the chipset and manufacturer of each access point, which helps you match equipment to your asset register.

5. Analysing Beacon Intervals

Every access point sends a "beacon frame" (usually every 100ms) to announce its presence. The exact interval can vary slightly because of clock drift or configuration. By measuring this interval precisely, analysts can tell apart access points of the same model on the same site. This technique, known as clock skew fingerprinting, can help identify a device even when its MAC address has been changed.


The Pivot: Scaling with UserSearch

You cannot drive every street in the world. The UserSearch Wireless Device Search type uses WiGLE data so you can check network names and BSSIDs remotely, alongside 17 other Search types and 100+ third-party data sources available through one account.

Note: Wireless searches cover very large datasets, so these queries can take up to 60 seconds. Patience is required.

Scenario 1: The Supplier's "Local" Factory

The Context: A procurement team at a fictional retailer, Millbrook Home, is running due diligence on a new textile supplier that says it manufactures in Portugal. Its promotional video shows the production floor.

The Data Point: In one frame, a laptop screen shows its list of available Wi-Fi networks. The strongest is Tecelagem_Norte_Prod; a weaker one is Unit7_Logistics_5G.

The UserSearch Workflow:

  1. Wireless Lookup: The analyst runs Tecelagem_Norte_Prod through the Wireless Device Search type (SSID search).
  2. The Hit: The data returns a cluster of records near Porto, consistent with the supplier's claim.
  3. Corroboration: Unit7_Logistics_5G maps to the same industrial estate, and the Corporate Intelligence Search type shows a logistics company registered at that estate.
  4. Analysis: Two independent network names place the video at the claimed site. Together with company records, this supports the supplier's account.

The Outcome: The claim is corroborated and the evidence is saved to a Case. Had the networks mapped elsewhere, the team would have asked the supplier for an explanation before signing.

Scenario 2: Establishing Where a Business Moved

The Context: A fictional insurer, Wexcombe Mutual, is reviewing a claim network linked to a call centre that closed its registered office and moved. The business no longer publishes an address. The insurer's file holds the BSSID of the call centre's main access point from an earlier authorised site visit (00:14:22:88:99:AA).

The UserSearch Workflow:

  1. BSSID Search: The analyst enters 00:14:22:88:99:AA into the Wireless Device Search type.
  2. The History: The historical data shows it at Address A (the old office) until June.
  3. The New Record: A record from September places the same BSSID at an industrial park five miles away.
  4. Confirmation: Satellite imagery and the Corporate Intelligence Search type show a unit at that park registered to a company with the same directors.

The Outcome: The insurer establishes where the organisation now operates and passes the findings to its legal team. The business reused its old equipment, and the public wireless record showed it.

Scenario 3: A Missing Company Vessel

The Context: A fictional charter company, Solent Blue Charters, reports one of its vessels missing from a marina. The vessel carries a maritime Wi-Fi router (for example a Peplink or Cradlepoint unit) for guest internet, and the company knows its BSSID.

The Workflow: The company's analyst runs a one-off search for the router's BSSID in the Wireless Device Search type and finds a recent community record from a marina along the coast.

The Result: The company now has a dated record for its own vessel and passes it to the police and port officials, who take it from there.


Advanced Strategies: Reading the Spectrum

Going deeper requires understanding how organisations name and equip their networks.

1. Network Naming Patterns

Organisations often use consistent naming conventions. If a company uses Brackwater_Staff at its head office, it will often use Brackwater_Guest and Brackwater_Depot at other sites. Searching for the string pattern "Brackwater" can show a map of the company's sites: head office, depots and warehouses. This is useful for due diligence on a company's claimed footprint of premises.

2. MAC Address OUI Lookups

The first six characters of a MAC address (for example 00:14:22) are the OUI (Organisationally Unique Identifier). They tell you the manufacturer. You can use free lookups such as MAC Lookup.

  • Audit Tip: If a survey of your own offices shows a device with an OUI belonging to "Raspberry Pi" or "Espressif" (ESP32 chips), it may be a hobby device or unapproved IoT equipment that your IT team should review. If you see "Axis Communications", it is probably a professional security camera, and "Ring" or "Nest" suggests consumer-grade equipment. This hardware view helps you check your own estate against your asset register.

3. Spotting Mobile Hotspots on Your Premises

Mobile hotspots often have predictable names (for example "iPhone" followed by a first name). On your own premises, a surge of hotspots can mean staff are working around a slow or restricted corporate network, which is a policy and security issue worth raising. Keep this to counts and patterns; there is no need to record who owns each hotspot.

4. Triangulation Logic

A single BSSID record gives you an area of probability (often around 50 to 100 metres). To narrow it down, look for the intersection of several BSSIDs recorded at the same time. If Access Point A (range 100m) and Access Point B (range 100m) are both visible, the recording was made in the overlap. WiGLE data often provides this estimated coordinate rather than the raw signal positions.

5. Checking Where Your Own Network Names Appear

Search the Wireless Device Search type for your organisation's own SSIDs. If your corporate network name appears at an address where you have no office, someone may have set up a lookalike network, a common setup for collecting staff logins. That is a finding for your security team and, where needed, the authorities.


6. The IoMT (Internet of Moving Things)

It is not just offices. Modern vehicles, logistics units and high-end machinery often have embedded LTE-to-Wi-Fi bridges. A fleet of delivery vans might all broadcast Delivery_Fleet_WiFi.

For the company that owns them, those broadcasts can help establish where missing equipment was last recorded. If a construction company's generator has a built-in diagnostic Wi-Fi network, a volunteer scanning near a yard might log that BSSID and upload it to the public map. The owner can then pass a dated record to the police.

Scenario 4: A Defensive Sweep of a Boardroom

Wireless OSINT is also a defensive tool for organisations.

The Context: Before a sensitive board meeting, a fictional engineering firm, Kellan Ridge Ltd, asks its security team to check the boardroom for unexpected wireless devices.

The Analysis: An authorised sweep with Kismet and a BLE scanner shows a persistent Bluetooth Low Energy beacon in the room that is not on the asset register. Its MAC address does not resolve to a known manufacturer in standard OUI lookups.

The Pivot: Searching the identifier in historical wireless datasets shows it was first recorded three months earlier, around the time a new AV contractor installed equipment. The team physically inspects the AV rack, finds an unapproved diagnostic module, and raises it with the contractor and legal counsel.

The Future: 5G and Satellite Connectivity

As 5G and Low Earth Orbit (LEO) satellite internet (such as Starlink) spread, the wireless spectrum is becoming busier and more precise. 5G "beamforming" focuses signals directly at devices, which could produce very local data that goes beyond current Wi-Fi precision. Satellite terminals also broadcast identifiable signals, a topic that has come up in reporting on recent conflicts. The principle of Wireless OSINT stays the same: if it transmits, it can be mapped. Analysts in 2026 will look beyond routers to satellite uplinks and 5G small cells.

Important: Laws on wireless data are complex.

  • Passive Only: Passive scanning (listening to what is broadcast) is generally lawful in the UK and US, and it is the only kind of work this guide covers. Connecting to networks you do not own, attempting to get around their security or disrupting a signal is an offence under laws such as the Computer Misuse Act and the CFAA.
  • MAC Addresses and GDPR: In the UK and EU, MAC addresses can be personal data if they can be linked to an individual. Keep your work to business networks and your own premises, and record your lawful basis.
  • Purpose and Proportionality: Use wireless data for organisations, premises and company assets. When a record points to a private individual rather than a business, stop and check whether your purpose really needs it.

The Airwaves Have a Memory

We think of radio waves as fleeting: they go out and vanish. But thanks to global mapping projects, the radio spectrum has a memory. Many business networks have been logged, mapped and archived in public databases.

For the analyst, that is a useful extra source. It helps you verify where a business operates, check a supplier's claims and audit your own sites, with evidence you can save to a Case and put in a report.

Ready to tune into the signal?
Stop guessing. Start researching with UserSearch today.

About the author

UserSearch Team
Updated on Sep 26, 2026