OSINT investigations
Case-based investigations into people, companies, online accounts and networks, from a single identity question to a multi-country inquiry.
Learn more →OSINT services from OSINT-S turn publicly and commercially available information into answers you can act on: who a person really is, who controls a company, where the money went, and what is being said or planned about you online. Every finding comes with its source.
OSINT services are investigations and monitoring built on open-source intelligence: information anyone can lawfully see, buy or request, such as company registries, court records, the media, social networks and leaked-data markets. An OSINT services provider collects that information, verifies it against independent sources and turns it into a report that answers one specific question. At OSINT-S a focused check takes from 10 business days, a comprehensive review up to a month, and urgent work is possible.
OSINT-S offers nine OSINT services. Together they cover most questions an organization asks of open sources, and each one starts with a written scope and ends with a source-referenced report.
Case-based investigations into people, companies, online accounts and networks, from a single identity question to a multi-country inquiry.
Learn more →Identity, career, public-records and online-footprint checks on candidates, executives, partners and counterparties.
Reputational, third-party and investor due diligence: ownership, sanctions, litigation, adverse media and local-language review.
Enhanced customer due diligence when your standard screening returns a hit, a gap or a complex ownership chain.
Tracing property, companies and holdings across jurisdictions to support litigation, enforcement and recovery.
Who really owns and runs a company, who it trades with, and whether its claims hold up.
Leaked credentials, stolen data and mentions of your company, staff and assets on criminal forums, markets and channels.
Learn more →Ongoing alerts on counterparties, portfolios, brands and events, triaged by an analyst before they reach you.
Learn more →Open-source cyber threat intelligence on the actors, campaigns, phishing and vulnerabilities aimed at your organization.
Learn more →Professional open-source intelligence work done for a client: an analyst team collects, verifies and analyzes public and commercial information to answer a defined question, and delivers the answer with its evidence.
Open-source intelligence, or OSINT, is intelligence derived exclusively from publicly or commercially available information that addresses a specific requirement. That is the definition the US intelligence community uses (IC OSINT Strategy 2024–2026). OSINT services apply the same discipline to business questions: a hire, a deal, a dispute, a threat.
A search engine gives you claims. A professional OSINT team gives you findings. The difference is the work in between:
Some providers call the same thing OSINT solutions or OSINT as a service. Whatever the label, you are buying a verified answer rather than a tool.
Questions that turn on facts somebody, somewhere, has recorded in public: identity, ownership, relationships, assets, reputation and intent.
If the answer depends on information that is not lawfully accessible, such as private messages, bank records or phone metadata, OSINT is the wrong tool and we will say so at scoping.
Teams that make decisions about people and counterparties they cannot fully see: security and risk, legal, investment, compliance, HR, insurance and public-interest organizations.
Security teams use open sources to see threats before they arrive: impersonation of executives, leaked credentials, planned protests at a site, actors targeting the sector. Typical services: OSINT monitoring and threat intelligence.
Before you sue or enforce, you need to know where the assets are, who the witnesses are and what the other side has said in public. Typical services: asset tracing and OSINT investigations.
Founders, co-investors and cap tables are rarely as simple as the pitch deck. Typical service: investor due diligence.
When automated screening returns a hit, a gap or an opaque ownership chain, an analyst resolves it with records from the countries involved. Typical service: KYC and AML checks.
Senior hires and board appointments deserve more than a reference call. Typical service: background checks.
Open sources often show whether a claim, a claimant or an incident is what it appears to be. Typical service: OSINT investigations.
Networks behind disinformation, sanctions evasion or supply-chain abuse are often visible in public records. Molfar, which operates OSINT-S, lists organizations from USIP and the Open Society Foundations to Helsing, Ajax Systems and Wikborg Rein among its clients (client list).
Six steps, from a short brief to a debrief on the findings. You see a written scope and a fixed quote before any research starts.
A report you can defend: every material statement is tied to a source, and confirmed facts are kept apart from what remains uncertain.
Reports are written in English and, where the case needs it, draw on local-language records and media. If the report may be used in proceedings, tell us at the brief so the evidence is collected and documented with that in mind.
Molfar's investigations have covered 60+ countries. We are strongest where records are thin or not in English, and we regularly work on UK, EU and US subjects.
| Region | What we do there |
|---|---|
| United Kingdom | Contracts through Molfar Limited (Companies House 13558891); a UK team led by James Westlake; due diligence, background checks and asset tracing for UK funds, manufacturers, fintech and defense companies (UK page). |
| United States | Investigations, due diligence and threat intelligence on US subjects and on foreign counterparties of US clients. For US employment decisions, we flag Fair Credit Reporting Act requirements at scoping. |
| European Union | Company, ownership and sanctions work across EU registries, scoped under the GDPR. |
| Ukraine, Central and Eastern Europe | The team's home ground: local-language registries, courts and media, and Russia-linked networks. |
| Elsewhere | Multi-country cases with offshore structures, scoped country by country. |
Lawfully accessible open sources and licensed data, including criminal forums and leak sites for cyber work, plus agreed local inquiries where they are lawful. No hacking, no pretexting, no access to private accounts.
Our analysts work with 750+ public and restricted registers worldwide, court and corporate records, media archives, social networks and online communities, satellite and street-level imagery, and specialist data on leaks and cybercrime. Where a case needs it and the law allows, we agree local verification or human-source inquiries with you in advance and keep them proportionate to the question.
Public information is still personal data. Under the EU and UK GDPR, investigations rely on a legitimate interest that has to pass a balancing test (EDPB Guidelines 1/2024), and data protection authorities have reminded businesses that publicly accessible personal information remains protected (joint statement, 2023). In the UK, obtaining personal data without the controller's consent can be an offense under section 170 of the Data Protection Act 2018; in the US, pretexting for financial records is banned under the Gramm-Leach-Bliley Act.
Four cases from Molfar's published case studies show the range: sanctions evidence, asset tracing, partner vetting and investor due diligence.
A government client needed evidence packs on individuals linked to a sanctions program. Molfar delivered 34 dossiers in under two weeks; five people were later sanctioned by presidential decree.
Read the case on molfar.com →Molfar mapped Hungarian assets linked to the head of Russia's foreign intelligence service. The dossier was used as a basis for EU-level asset freezes.
Read the case on molfar.com →Before a partnership, Molfar verified a counterparty's disclosures and found three undisclosed European properties worth an estimated €173,000–€312,000.
Read the case on molfar.com →An investor asked for a check on a defense-tech startup. Molfar linked a co-founder to a 2.6 billion UAH gambling enterprise, and the investment was halted.
Read the case on molfar.com →Case studies are published by Molfar Intelligence, which operates OSINT-S. Most are anonymized at the client's request.
Each request is priced after scoping, as a fixed quote. Urgent work carries a 50% surcharge. Public benchmarks run from about $75 an hour for a basic US private investigator to €7,500 a year for a professional OSINT platform license.
The price depends on the number of subjects and countries, how much ownership or network mapping is needed, the languages involved, how thin the records are, and the deadline. A focused check takes from 10 business days and a comprehensive review up to a month (Molfar). If we cannot deliver on the agreed date, we tell you and reduce the fee (FAQ).
| Item | Figure | Source |
|---|---|---|
| US private investigator, basic work | $75–$125 an hour | Talo cost guide |
| UK OSINT contractor day rate (median) | £575 a day | ITJobsWatch |
| Due diligence report on one US subject | $550 (individual), $750 (business) | Global Backgrounds |
| Maltego Professional platform | €7,500 a year | Maltego pricing |
See the full breakdown in our OSINT pricing guide.
Tools give you data, an in-house team gives you control, and a service gives you a verified answer without hiring. Many buyers combine a tool for routine checks with a service for the decisions that matter.
| OSINT-S (service) | OSINT tools and platforms | In-house OSINT team | |
|---|---|---|---|
| Who does the work | Our analysts | Your staff | Your staff |
| Typical cost | Fixed fee per task | From £19 a month to six figures a year | Salaries (UK median £65,579 for OSINT roles, ITJobsWatch) plus tools and training |
| Verification | Built in, with a second check | Up to the user | Depends on the team |
| Languages and regions | Assembled per task | Limited by the tool's coverage | Limited by who you hire |
| Best for | High-stakes, occasional or cross-border questions | High volumes of routine lookups | Constant, sensitive, in-house demand |
| Tool | What it does | Published price |
|---|---|---|
| Maltego | Link analysis and graph investigations | €0 / €3,000 / €7,500 a year (Maltego) |
| OSINT Industries | Lookups on an email, phone number or username | £19–£99 a month (OSINT Industries) |
| Intelligence X | Search across leaks, archives and the dark web | €2,500–€20,000 a year (Intelligence X) |
| Shodan | Internet-connected devices and exposed services | $49 one-off; $69–$1,099 a month (Shodan) |
| Hunchly | Capturing web pages as evidence | €149 a year (Hunchly) |
Tools are only as good as the analyst using them. To compare providers, see our ranking of the best OSINT companies in 2026.
Ask seven questions before you sign: who does the work, which sources they can reach, how they verify, what the report separates, what they refuse to do, who you contract with, and whether the price is fixed.
For a side-by-side view of providers and platforms, see the top OSINT companies compared; if you only need one person for a small task, read how to hire an OSINT investigator.
Seven years of investigative practice, a team assembled around each question, and reports that separate what is proven from what is not.
Want to know more about the team? Read about OSINT-S as an OSINT agency, or about OSINT consulting and training if you need advice rather than a report.
If you need physical surveillance, process serving or a licensed private investigator in a particular US state, forensic imaging of devices, or information that only a court order can unlock, you need a different provider or legal process. If your case requires a provider with no stated position on Russia's war against Ukraine, note that Molfar is Ukraine-born and openly pro-Ukrainian. We will tell you at the first call if one of these applies.
Send a short brief: who or what, the decision it supports, and your deadline. An analyst replies with a scope, a timeline and a fixed quote.
OSINT services are investigations and monitoring based on open-source intelligence: information that is publicly or commercially available, such as registries, court records, media and social networks. A provider collects and verifies it, then reports an answer to a specific question with the sources behind it.
OSINT stands for open-source intelligence. The US intelligence community defines it as intelligence derived exclusively from publicly or commercially available information that addresses specific intelligence priorities, requirements or gaps (IC OSINT Strategy 2024–2026).
OSINT tools are software your own staff use to search and analyze open sources. OSINT services are work done for you: analysts choose the sources, verify the findings and deliver a report. Tools suit high volumes of routine lookups; services suit high-stakes, cross-border or occasional questions.
Yes, when the purpose is legitimate and the methods are lawful. Public information is still personal data under the GDPR, so investigations need a lawful basis and must be proportionate. Hacking, pretexting and access to private accounts are illegal in most countries, and we do not do them.
Each request is priced after scoping as a fixed quote; urgent work carries a 50% surcharge. For context, basic US private investigator work costs about $75–$125 an hour and UK OSINT contractors earn a median of £575 a day. See our pricing guide.
A focused check takes from 10 business days and a comprehensive review up to a month. Some smaller tasks take a business day, and urgent delivery is available for an extra fee.
Corporate security and risk teams, law firms, investors, banks and fintech companies, HR and executive search, insurers, NGOs, media and public bodies. Any organization that makes decisions about people or counterparties it cannot fully see.
They can. Criminal forums, markets, leak sites and messaging channels are open sources in the sense that anyone can observe them, and they matter for cyber and fraud work. We observe and document; we do not buy stolen data to identify people. See dark web monitoring.
OSINT as a service means buying the outcome, verified intelligence, instead of the tools and staff to produce it. You can commission one-off investigations or ongoing monitoring with analyst-reviewed alerts.
Yes. Contracts are with Molfar Limited, a UK company, and we regularly work on UK, EU and US subjects. For US employment decisions, we flag Fair Credit Reporting Act requirements at scoping.
Sometimes, because such details appear in registries, listings or old records. We only look for them when there is a lawful purpose, such as tracing a debtor or a witness, and we do not help anyone locate a person to harass or harm them.
No. We do not log in to other people's accounts, use fake profiles to gain access to private content, or bypass privacy settings. What is private stays out of scope.
Open-source findings are used in litigation and arbitration, but admissibility depends on the court and on how the evidence was collected and documented. If your report may be used in proceedings, tell us at the brief so we preserve and document the evidence accordingly, and involve your lawyers early.
OSINT-S is operated by Molfar Intelligence, a trading name of Molfar Limited (Companies House 13558891). Molfar was founded in Kyiv in 2019 by Artem Starosiek.
Sources checked 6 October 2026. OSINT-S is operated by Molfar Intelligence, a trading name of Molfar Limited (Companies House 13558891). Figures from Molfar are company statements, not independently audited.