OSINT Investigation Services

When a decision depends on facts you cannot see from your desk, our OSINT investigation services find them in the public record, check them against independent sources and show you exactly where each one came from.

  • People, companies, assets, accounts
  • Local-language research
  • Confirmed facts kept apart from open questions
  • Focused cases from 10 business days
Short answer

An OSINT investigation answers a specific question, such as who is behind an account, who controls a company or where assets sit, using information that is publicly or commercially available. The investigator collects it, verifies it against independent sources and documents it so others can check the work. OSINT-S runs focused investigations from 10 business days and complex, multi-country cases within about a month.

What Is an OSINT Investigation?

It is a structured inquiry that uses open-source intelligence to answer a defined question for a defined purpose, not an open-ended search for everything about someone.

US law first defined open-source intelligence in 2006 as intelligence produced from publicly available information and delivered "in a timely manner to an appropriate audience for the purpose of addressing a specific intelligence requirement" (Pub. L. 109-163, §931). The intelligence community's current strategy keeps the same idea and adds commercially available data: OSINT is intelligence "derived exclusively from publicly or commercially available information" (IC OSINT Strategy 2024–2026).

The phrase that matters is a specific requirement. A good OSINT investigation starts with a question you can answer with yes, no or a list, and with the decision that depends on it: hire or not, sign or not, sue or not, freeze or not. That keeps the work focused, the cost predictable and the processing of personal data proportionate.

Investigations are the core of the OSINT services we offer, alongside due diligence, monitoring and threat intelligence.

What separates an investigation from a search is verification. Search results are claims. An investigation tests those claims against records that were created independently, keeps a copy of what it relied on, and tells you how confident it is.

Types of OSINT Investigations We Run

Most cases fall into one of eight types. Many combine two or three, for example a company investigation that turns into asset tracing.

People

Identity and background

Is the person who they claim to be? Names and aliases, education, career, directorships, litigation, media and online footprint.

Companies

Ownership and control

Beneficial owners, nominee and offshore layers, related companies, trading partners and links to sanctioned or politically exposed persons.

Assets

Asset tracing

Real estate, company stakes, vehicles and other holdings recorded in registries in several countries, mapped to the people who control them.

Online

Account and website attribution

Who runs an anonymous account, channel, domain or ad campaign used for fraud, impersonation, harassment or disinformation.

Fraud

Fraud and financial investigations

How a scheme worked, who benefited, which companies and accounts were used, and where the money may have gone.

Legal

Litigation support

Counterparty and witness research, asset findings, jurisdiction and enforcement notes, and an evidence map for your legal team.

Sanctions

Sanctions and evasion networks

Ownership chains, intermediaries and trade routes used to move goods or money around sanctions and export controls.

Cyber

Exposure and threat actors

Leaked credentials, exposed systems and the actors or infrastructure behind attacks on your organization.

Threat intelligence →

Which Sources Does an OSINT Investigation Use?

Registries and court records first, then media, online and specialist data. Molfar's analysts work with 750+ public and restricted registers worldwide.

Source typeExamplesWhat it proves well
Corporate registriesCompany filings, beneficial-ownership registers, gazettesWho owns and runs a company, and when that changed
Court and legal recordsJudgments, dockets, insolvency and enforcement recordsDisputes, debts, fraud findings and sanctions designations
Property and asset recordsLand registries, vehicle and vessel recordsHoldings and their recorded owners
Media and archivesNational and local press in local languages, archived web pagesReputation, events and statements over time
Online footprintSocial networks, forums, messaging channels, domainsRelationships, activity and attribution of accounts
Imagery and geodataSatellite and street-level imagery, photo metadataWhere something is, and whether a claim about a place is true
Leak and cybercrime dataBreach compilations, criminal forums and marketsExposure of credentials and data; links between identities

Where the law allows and you agree in advance, an investigation can add local verification or human-source inquiries, kept proportionate to the question. We do not obtain information by hacking, impersonation or access to private accounts.

How We Run an OSINT Investigation

In six stages. The method follows the logic of the Berkeley Protocol on digital open-source investigations: collect, preserve, verify, analyze and report.

  1. Define the requirementWe write down the question, the decision it supports, the subjects, the jurisdictions and the deadline, and confirm the purpose is lawful.
  2. Plan the collectionWe choose the registries, archives and online sources that can answer the question, and the languages needed to read them.
  3. Collect and preserveAnalysts gather the records and keep captures with their addresses and dates, so the finding survives if the original page changes.
  4. VerifyEach material finding is tested on three fronts: the source (who published it and why), the content (does it fit other evidence) and the technical traces (dates, metadata, location).
  5. AnalyseWe connect the findings into an answer: ownership maps, timelines, networks and a clear view of what is confirmed, likely or unknown.
  6. Report and reviewA senior analyst checks the report before it reaches you. You receive the findings, the evidence pack and, if you want it, a debrief.

The Berkeley Protocol was published by the UN Human Rights Office and the University of California, Berkeley (OHCHR). It sets professional, methodological and ethical principles for digital open-source investigations, including verification and preservation.

What Does an OSINT Investigation Report Contain?

The answer first, then the evidence: findings with sources, an evidence pack, maps where they help, and a list of what remains open.

  • Answer and risk view. One page that a decision-maker can read in two minutes.
  • Findings. Each material statement with its source, date observed and confidence level.
  • Evidence pack. Captures of the records relied on, with addresses and dates.
  • Maps and timelines. Ownership and control, relationships, assets, events.
  • Open questions. What could not be confirmed from open sources, and the options to resolve it, such as a court application or a local inquiry.

We keep three categories apart in every report: confirmed facts, open questions and material risks. That separation is what makes a report safe to rely on, and it is the first thing to look for when you compare providers.

How Long Does an OSINT Investigation Take, and What Does It Cost?

A focused case takes from 10 business days; a comprehensive, multi-jurisdiction case up to a month. Every case gets a fixed quote after scoping, and urgent delivery costs 50% more.

CaseTypical scopeTypical timeline
Focused checkOne person or company, one or two countriesFrom 10 business days
Standard investigationA subject and its network, ownership mapping, several sources per findingTwo to three weeks
Complex investigationSeveral subjects or countries, offshore layers, asset tracingUp to a month, sometimes phased
Urgent workAny of the above on a shorter deadlineBy agreement, 50% surcharge

Timelines are those published by Molfar (due diligence timelines, FAQ); the middle row is our planning guide. Price is driven by the number of subjects and countries, the depth of mapping, the languages involved and how thin the records are. See OSINT pricing for public benchmarks.

OSINT Investigation Examples

Published Molfar cases show what open sources can establish when they are worked properly.

assets mapped · used for EU freezes

Tracing the assets of a sanctioned official

Molfar mapped Hungarian assets linked to the head of Russia's foreign intelligence service. The dossier was used as a basis for EU-level asset freezes.

Read the case on molfar.com →
3 undisclosed properties

Transparency check on a strategic partner

Before a partnership, Molfar verified a counterparty's disclosures and found three undisclosed European properties worth an estimated €173,000–€312,000.

Read the case on molfar.com →

Case studies are published by Molfar Intelligence, which operates OSINT-S. Most are anonymized at the client's request.

When Is an OSINT Investigation Not Enough?

When the answer sits in private data. Bank statements, phone records, private messages and device contents need consent, a court order or a different kind of specialist.

We tell you at scoping if your question cannot be answered from lawful open sources. The usual next steps are:

  • Legal process. A disclosure order, subpoena or freezing order, often supported by what the OSINT findings have already shown.
  • Digital forensics. Imaging and analysis of devices you own or are entitled to examine.
  • Field work. Licensed private investigators for surveillance or process serving where local law requires a license.

Open-source findings are often what makes these steps possible: they identify the right court, the right asset and the right person to ask.

Have a Question for an Investigator?

Describe the subject, the decision and the deadline. We reply with a scope, a timeline and a fixed price, usually within one business day.

OSINT Investigation FAQ

What is an OSINT investigation?

An OSINT investigation is a structured inquiry that answers a specific question using publicly or commercially available information, verified against independent sources and documented so others can check it.

What can an OSINT investigation find?

Identity and career facts, company ownership and control, litigation and insolvency, assets recorded in registries, media coverage, online accounts and relationships, and exposure in leaked data. It cannot lawfully reach private messages, bank records or phone metadata.

How long does an OSINT investigation take?

A focused case takes from 10 business days. Complex cases with several countries or offshore structures take up to a month. Urgent delivery is possible for a 50% surcharge.

How much does an OSINT investigation cost?

We quote a fixed price after scoping. The main drivers are the number of subjects and countries, the depth of ownership or network mapping, the languages involved and the deadline. See our pricing guide for public benchmarks.

Is an OSINT investigation legal?

Yes, if it has a legitimate purpose, a proportionate scope and lawful methods. We do not hack, impersonate people to obtain records, or access private accounts.

Will the subject know they are being investigated?

We do not contact the subject or alert them through our research. Data-protection law may require notice in some cases; where notice would seriously impair the purpose, for example in a fraud inquiry, an exemption can apply. Your lawyers should confirm your position.

Can an OSINT investigation identify the person behind an anonymous account?

Often, by connecting the account to reused usernames, emails, phone numbers, writing patterns, images or infrastructure. We only take such cases for lawful purposes such as fraud, impersonation, harassment or disinformation, and we report the confidence level honestly.

Can the findings be used in court?

They are regularly used in litigation and arbitration. Admissibility depends on the court and on how the evidence was collected and preserved, so tell us at the brief if proceedings are likely.

What is the difference between an OSINT investigation and a background check?

A background check follows a standard set of checks on one person. An investigation follows the evidence wherever the question leads, across people, companies, assets and countries.

Do you work on cases outside Ukraine and the UK?

Yes. Molfar's investigations have covered 60+ countries, with particular depth in Central and Eastern Europe and Russia-linked networks.