An open-data CSV on the city portal accidentally includes extra email columns. An analyst mirroring the portal for OSINT should treat those addresses how?
Select an answer to reveal the explanation.
Short Explanation
A leaked column on the open-data portal is a records spill, not a starter kit. Note it, tell the data owners, and leave the inboxes alone. Publishing a mistake does not turn OSINT into a phishing factory.
Full Explanation
Accidentally published emails in civic open-data remain public artifacts, but the lawful OSINT response is to document the exposure and route it as a records-handling issue. Using the extra column as a phishing kit, marketing list, or password-guessing target exceeds PORP collection and civic ethics. The analyst should capture file name, URL, timestamp, and which fields were extra. Remediation belongs to the open-data steward, not to an exploitation plan.