Identity and background
Is the person who they claim to be? Names and aliases, education, career, directorships, litigation, media and online footprint.
When a decision depends on facts you cannot see from your desk, our OSINT investigation services find them in the public record, check them against independent sources and show you exactly where each one came from.
An OSINT investigation answers a specific question, such as who is behind an account, who controls a company or where assets sit, using information that is publicly or commercially available. The investigator collects it, verifies it against independent sources and documents it so others can check the work. OSINT-S runs focused investigations from 10 business days and complex, multi-country cases within about a month.
It is a structured inquiry that uses open-source intelligence to answer a defined question for a defined purpose, not an open-ended search for everything about someone.
US law first defined open-source intelligence in 2006 as intelligence produced from publicly available information and delivered "in a timely manner to an appropriate audience for the purpose of addressing a specific intelligence requirement" (Pub. L. 109-163, §931). The intelligence community's current strategy keeps the same idea and adds commercially available data: OSINT is intelligence "derived exclusively from publicly or commercially available information" (IC OSINT Strategy 2024–2026).
The phrase that matters is a specific requirement. A good OSINT investigation starts with a question you can answer with yes, no or a list, and with the decision that depends on it: hire or not, sign or not, sue or not, freeze or not. That keeps the work focused, the cost predictable and the processing of personal data proportionate.
Investigations are the core of the OSINT services we offer, alongside due diligence, monitoring and threat intelligence.
What separates an investigation from a search is verification. Search results are claims. An investigation tests those claims against records that were created independently, keeps a copy of what it relied on, and tells you how confident it is.
Most cases fall into one of eight types. Many combine two or three, for example a company investigation that turns into asset tracing.
Is the person who they claim to be? Names and aliases, education, career, directorships, litigation, media and online footprint.
Beneficial owners, nominee and offshore layers, related companies, trading partners and links to sanctioned or politically exposed persons.
Real estate, company stakes, vehicles and other holdings recorded in registries in several countries, mapped to the people who control them.
Who runs an anonymous account, channel, domain or ad campaign used for fraud, impersonation, harassment or disinformation.
How a scheme worked, who benefited, which companies and accounts were used, and where the money may have gone.
Counterparty and witness research, asset findings, jurisdiction and enforcement notes, and an evidence map for your legal team.
Ownership chains, intermediaries and trade routes used to move goods or money around sanctions and export controls.
Leaked credentials, exposed systems and the actors or infrastructure behind attacks on your organization.
Threat intelligence →Registries and court records first, then media, online and specialist data. Molfar's analysts work with 750+ public and restricted registers worldwide.
| Source type | Examples | What it proves well |
|---|---|---|
| Corporate registries | Company filings, beneficial-ownership registers, gazettes | Who owns and runs a company, and when that changed |
| Court and legal records | Judgments, dockets, insolvency and enforcement records | Disputes, debts, fraud findings and sanctions designations |
| Property and asset records | Land registries, vehicle and vessel records | Holdings and their recorded owners |
| Media and archives | National and local press in local languages, archived web pages | Reputation, events and statements over time |
| Online footprint | Social networks, forums, messaging channels, domains | Relationships, activity and attribution of accounts |
| Imagery and geodata | Satellite and street-level imagery, photo metadata | Where something is, and whether a claim about a place is true |
| Leak and cybercrime data | Breach compilations, criminal forums and markets | Exposure of credentials and data; links between identities |
Where the law allows and you agree in advance, an investigation can add local verification or human-source inquiries, kept proportionate to the question. We do not obtain information by hacking, impersonation or access to private accounts.
In six stages. The method follows the logic of the Berkeley Protocol on digital open-source investigations: collect, preserve, verify, analyze and report.
The Berkeley Protocol was published by the UN Human Rights Office and the University of California, Berkeley (OHCHR). It sets professional, methodological and ethical principles for digital open-source investigations, including verification and preservation.
The answer first, then the evidence: findings with sources, an evidence pack, maps where they help, and a list of what remains open.
We keep three categories apart in every report: confirmed facts, open questions and material risks. That separation is what makes a report safe to rely on, and it is the first thing to look for when you compare providers.
A focused case takes from 10 business days; a comprehensive, multi-jurisdiction case up to a month. Every case gets a fixed quote after scoping, and urgent delivery costs 50% more.
| Case | Typical scope | Typical timeline |
|---|---|---|
| Focused check | One person or company, one or two countries | From 10 business days |
| Standard investigation | A subject and its network, ownership mapping, several sources per finding | Two to three weeks |
| Complex investigation | Several subjects or countries, offshore layers, asset tracing | Up to a month, sometimes phased |
| Urgent work | Any of the above on a shorter deadline | By agreement, 50% surcharge |
Timelines are those published by Molfar (due diligence timelines, FAQ); the middle row is our planning guide. Price is driven by the number of subjects and countries, the depth of mapping, the languages involved and how thin the records are. See OSINT pricing for public benchmarks.
A legitimate purpose, a proportionate scope and lawful methods. Publicly available does not mean free of data-protection law.
This is a summary, not legal advice.
Published Molfar cases show what open sources can establish when they are worked properly.
Molfar mapped Hungarian assets linked to the head of Russia's foreign intelligence service. The dossier was used as a basis for EU-level asset freezes.
Read the case on molfar.com →Before a partnership, Molfar verified a counterparty's disclosures and found three undisclosed European properties worth an estimated €173,000–€312,000.
Read the case on molfar.com →Case studies are published by Molfar Intelligence, which operates OSINT-S. Most are anonymized at the client's request.
When the answer sits in private data. Bank statements, phone records, private messages and device contents need consent, a court order or a different kind of specialist.
We tell you at scoping if your question cannot be answered from lawful open sources. The usual next steps are:
Open-source findings are often what makes these steps possible: they identify the right court, the right asset and the right person to ask.
Describe the subject, the decision and the deadline. We reply with a scope, a timeline and a fixed price, usually within one business day.
An OSINT investigation is a structured inquiry that answers a specific question using publicly or commercially available information, verified against independent sources and documented so others can check it.
Identity and career facts, company ownership and control, litigation and insolvency, assets recorded in registries, media coverage, online accounts and relationships, and exposure in leaked data. It cannot lawfully reach private messages, bank records or phone metadata.
A focused case takes from 10 business days. Complex cases with several countries or offshore structures take up to a month. Urgent delivery is possible for a 50% surcharge.
We quote a fixed price after scoping. The main drivers are the number of subjects and countries, the depth of ownership or network mapping, the languages involved and the deadline. See our pricing guide for public benchmarks.
Yes, if it has a legitimate purpose, a proportionate scope and lawful methods. We do not hack, impersonate people to obtain records, or access private accounts.
We do not contact the subject or alert them through our research. Data-protection law may require notice in some cases; where notice would seriously impair the purpose, for example in a fraud inquiry, an exemption can apply. Your lawyers should confirm your position.
Often, by connecting the account to reused usernames, emails, phone numbers, writing patterns, images or infrastructure. We only take such cases for lawful purposes such as fraud, impersonation, harassment or disinformation, and we report the confidence level honestly.
They are regularly used in litigation and arbitration. Admissibility depends on the court and on how the evidence was collected and preserved, so tell us at the brief if proceedings are likely.
A background check follows a standard set of checks on one person. An investigation follows the evidence wherever the question leads, across people, companies, assets and countries.
Yes. Molfar's investigations have covered 60+ countries, with particular depth in Central and Eastern Europe and Russia-linked networks.
Sources checked 6 October 2026. OSINT-S is operated by Molfar Intelligence, a trading name of Molfar Limited (Companies House 13558891). Figures from Molfar are company statements, not independently audited.