What the investigations actually found, and what changed as a result.
Real engagements, anonymised: client and entity names, dates and identifying details are withheld or altered, and figures are rounded. Each case follows the same route — verify, collect, resolve, score, evidence.
Example report: OSINT + KYC due diligence, subject AB-01
This is the deliverable itself — the same structure every engagement ships in: document control, subject identity, corporate and ownership reconstruction, sanctions and PEP posture, adverse media, digital and dark web exposure, graded findings and a provisional decision with the evidence attached to each line.
- Report ID
- INFRA-KYC-DEMO-2026-001
- Subject reference
- AB-01
- Classification
- Confidential — illustrative sample
- Provisional decision
- Conditional pass — EDD required
Names, dates and identifiers are pseudonymised. The document is a methodological sample, not a final regulated KYC determination.
A “wholesale trading group” that was one person and a mailbox
A new corporate client applied for high-limit merchant accounts, presenting audited-looking statements and a polished website.
Confirm whether the applicant was a genuine operating business before limits were granted.
- The registered address was a virtual-office suite shared with 148 other companies
- The website was three weeks old, cloned from a competitor and hosted on the same server as two dissolved entities
- No VAT registration, no employees on file and no filed accounts in two years of claimed trading
- The sole director appeared as director of five companies struck off for filing default
- The “warehouse photographs” were stock images already indexed elsewhere online
Onboarding was declined before the first settlement cycle. The applicant later resurfaced under a new name and was matched automatically on the shared director, address and infrastructure fingerprints.
- Time to decision
- 31 hours
- Exposure avoided
- ≈ €2.4 m limit
- Business substance
- Not established
Dark web leak that gave a supplier's compromise away first
A group supplier had passed every commercial and financial check and was days from signing an integration agreement.
Assess cyber and continuity risk in the supplier before systems were connected.
- A ransomware group's leak site listed the supplier's parent under a countdown, unnoticed publicly
- Employee credentials for the supplier's VPN appeared in two recent combolists, still valid by format
- An access broker had advertised “EU industrial, 400+ hosts” matching the supplier's estate
- Exposed remote-access services on the supplier's netblocks corroborated the advert
The integration was paused, the supplier was notified and remediated, and the contract was resigned with security conditions and monitoring attached. No incident propagated into the client's network.
- Warning lead time
- 9 days pre-disclosure
- Credential sets found
- 37
- Integration
- Paused, then approved
The beneficial owner who was not on any document
A four-jurisdiction holding structure was presented with a nominee shareholder and a professional director as the declared UBO.
Establish who actually controlled the structure and the funds.
- Two intermediate holdings shared an accountant, a telephone number and a filing agent
- A litigation filing named a third party as “the beneficial owner of the group”
- The same individual appeared in a licence application as controlling person of a related entity
- Property records tied the group's operating asset to that individual's family trust
The undeclared controlling person was identified and screened, producing a sanctions-adjacent connection the declared structure had concealed. The relationship was restructured under enhanced due diligence rather than lost.
- Jurisdictions mapped
- 4
- Entities resolved
- 23
- Declared UBO
- Contradicted
An organised claims ring found through shared infrastructure
Fifteen unrelated claims across three regions showed no common policyholder, broker or repairer.
Determine whether the claims were independent.
- Claim documents were generated from the same template metadata and author string
- Contact numbers resolved to a small pool of recycled prepaid ranges
- Two “independent” garages were registered to the same director at the same address
- Bank accounts converged on three receiving parties
The cluster was referred as a single organised case with a documented evidence package, supporting recovery and a policy-level control change to the intake process.
- Claims linked
- 15 of 15
- Receiving parties
- 3
- Referral
- Accepted first pass
Investor funds traced out of a “licensed” trading platform
A platform courting retail investors displayed a regulator's licence number and named advisory board members.
Verify the licence, the people and where deposits actually went.
- The licence number belonged to an unrelated, dormant entity in another category
- Two advisory board photographs were reused stock portraits; one “advisor” denied any involvement
- Deposit wallets forwarded funds within minutes through chain-hopping into a high-risk exchange
- The platform's domain shared a registrant fingerprint with four earlier collapsed schemes
The client withdrew from the partnership before funding. The evidence package, with wallet paths and provenance, was handed to the client's counsel for a regulatory notification.
- Licence claim
- False
- Wallet hops traced
- 6
- Prior schemes linked
- 4
Two “competing” bidders that were the same operation
A tender received bids from two firms whose pricing patterns looked coordinated but whose ownership appeared unrelated.
Test the independence of the bidders.
- Both bid PDFs were produced on the same workstation licence
- Company mail domains resolved to one mail server and one billing contact
- A shareholder of bidder A was the spouse of bidder B's director
- Both had subcontracted the same three staff on prior awarded contracts
The tender was re-run with the connection documented, and the finding fed a permanent bidder-independence check into the client's procurement workflow.
- Independence
- Disproved
- Evidence items
- 62, sourced
- Control added
- Standing check
What these cases have in common
Substance was tested, not assumed: filings, staff, premises, trading traces and infrastructure age.
Dark web and leak material was treated as leads, verified against other sources before it counted.
Every entity match was graded — confirmed, probable, possible, contradicted — never asserted.
Each conclusion shipped with its source, timestamp and excerpt, so it stood up to review.
