Case studies

What the investigations actually found, and what changed as a result.

Real engagements, anonymised: client and entity names, dates and identifying details are withheld or altered, and figures are rounded. Each case follows the same route — verify, collect, resolve, score, evidence.

(0)

Example report: OSINT + KYC due diligence, subject AB-01

This is the deliverable itself — the same structure every engagement ships in: document control, subject identity, corporate and ownership reconstruction, sanctions and PEP posture, adverse media, digital and dark web exposure, graded findings and a provisional decision with the evidence attached to each line.

Report ID
INFRA-KYC-DEMO-2026-001
Subject reference
AB-01
Classification
Confidential — illustrative sample
Provisional decision
Conditional pass — EDD required

Names, dates and identifiers are pseudonymised. The document is a methodological sample, not a final regulated KYC determination.

Cover page
First page of the INFRA OSINT and KYC due diligence example report
(a)

A “wholesale trading group” that was one person and a mailbox

The situation

A new corporate client applied for high-limit merchant accounts, presenting audited-looking statements and a polished website.

The question

Confirm whether the applicant was a genuine operating business before limits were granted.

What the investigation surfaced
  • The registered address was a virtual-office suite shared with 148 other companies
  • The website was three weeks old, cloned from a competitor and hosted on the same server as two dissolved entities
  • No VAT registration, no employees on file and no filed accounts in two years of claimed trading
  • The sole director appeared as director of five companies struck off for filing default
  • The “warehouse photographs” were stock images already indexed elsewhere online
Outcome

Onboarding was declined before the first settlement cycle. The applicant later resurfaced under a new name and was matched automatically on the shared director, address and infrastructure fingerprints.

Result
Time to decision
31 hours
Exposure avoided
≈ €2.4 m limit
Business substance
Not established
(b)

Dark web leak that gave a supplier's compromise away first

The situation

A group supplier had passed every commercial and financial check and was days from signing an integration agreement.

The question

Assess cyber and continuity risk in the supplier before systems were connected.

What the investigation surfaced
  • A ransomware group's leak site listed the supplier's parent under a countdown, unnoticed publicly
  • Employee credentials for the supplier's VPN appeared in two recent combolists, still valid by format
  • An access broker had advertised “EU industrial, 400+ hosts” matching the supplier's estate
  • Exposed remote-access services on the supplier's netblocks corroborated the advert
Outcome

The integration was paused, the supplier was notified and remediated, and the contract was resigned with security conditions and monitoring attached. No incident propagated into the client's network.

Result
Warning lead time
9 days pre-disclosure
Credential sets found
37
Integration
Paused, then approved
(c)

The beneficial owner who was not on any document

The situation

A four-jurisdiction holding structure was presented with a nominee shareholder and a professional director as the declared UBO.

The question

Establish who actually controlled the structure and the funds.

What the investigation surfaced
  • Two intermediate holdings shared an accountant, a telephone number and a filing agent
  • A litigation filing named a third party as “the beneficial owner of the group”
  • The same individual appeared in a licence application as controlling person of a related entity
  • Property records tied the group's operating asset to that individual's family trust
Outcome

The undeclared controlling person was identified and screened, producing a sanctions-adjacent connection the declared structure had concealed. The relationship was restructured under enhanced due diligence rather than lost.

Result
Jurisdictions mapped
4
Entities resolved
23
Declared UBO
Contradicted
(d)

An organised claims ring found through shared infrastructure

The situation

Fifteen unrelated claims across three regions showed no common policyholder, broker or repairer.

The question

Determine whether the claims were independent.

What the investigation surfaced
  • Claim documents were generated from the same template metadata and author string
  • Contact numbers resolved to a small pool of recycled prepaid ranges
  • Two “independent” garages were registered to the same director at the same address
  • Bank accounts converged on three receiving parties
Outcome

The cluster was referred as a single organised case with a documented evidence package, supporting recovery and a policy-level control change to the intake process.

Result
Claims linked
15 of 15
Receiving parties
3
Referral
Accepted first pass
(e)

Investor funds traced out of a “licensed” trading platform

The situation

A platform courting retail investors displayed a regulator's licence number and named advisory board members.

The question

Verify the licence, the people and where deposits actually went.

What the investigation surfaced
  • The licence number belonged to an unrelated, dormant entity in another category
  • Two advisory board photographs were reused stock portraits; one “advisor” denied any involvement
  • Deposit wallets forwarded funds within minutes through chain-hopping into a high-risk exchange
  • The platform's domain shared a registrant fingerprint with four earlier collapsed schemes
Outcome

The client withdrew from the partnership before funding. The evidence package, with wallet paths and provenance, was handed to the client's counsel for a regulatory notification.

Result
Licence claim
False
Wallet hops traced
6
Prior schemes linked
4
(f)

Two “competing” bidders that were the same operation

The situation

A tender received bids from two firms whose pricing patterns looked coordinated but whose ownership appeared unrelated.

The question

Test the independence of the bidders.

What the investigation surfaced
  • Both bid PDFs were produced on the same workstation licence
  • Company mail domains resolved to one mail server and one billing contact
  • A shareholder of bidder A was the spouse of bidder B's director
  • Both had subcontracted the same three staff on prior awarded contracts
Outcome

The tender was re-run with the connection documented, and the finding fed a permanent bidder-independence check into the client's procurement workflow.

Result
Independence
Disproved
Evidence items
62, sourced
Control added
Standing check
(g)

What these cases have in common

01

Substance was tested, not assumed: filings, staff, premises, trading traces and infrastructure age.

02

Dark web and leak material was treated as leads, verified against other sources before it counted.

03

Every entity match was graded — confirmed, probable, possible, contradicted — never asserted.

04

Each conclusion shipped with its source, timestamp and excerpt, so it stood up to review.