A handful of private companies now sell the ability to turn a single email address into a person's entire digital life. OSINT Industries, Skopenow, Constella Intelligence, Maltego, ShadowDragon and a dozen others have built a multi-billion-dollar business on publicly available data, and increasingly on data that was never meant to be public at all. This report covers who they are, where their data comes from, and why regulators are finally paying attention.
There is a category of software that most people have never heard of and that quietly underpins a great deal of modern investigative work. Type an email address into it, and within seconds you get back the accounts registered to that address across Facebook, Instagram, WhatsApp, Telegram, Strava, Venmo, Airbnb and several hundred other services, plus breach records, associated phone numbers, profile photos, and often a map of where the person has been.
The industry calls this open-source intelligence, or OSINT. Its critics call it commercial surveillance. Both descriptions are defensible, and the tension between them defines the market.
What follows is a survey of the major providers, a look at where their data comes from, and an assessment of the legal and reputational risk now attached to buying it.
What the market actually sells
"OSINT vendor" is a loose label covering at least five distinct product categories that are frequently confused with one another. The distinction matters, because the compliance profile of each is different.
Selector resolution. You supply an identifier such as an email, phone number, username or wallet address, and the tool returns every account and record it can associate with that identifier. This is the fastest-growing and most commoditised segment. OSINT Industries, Epieos, Predicta Search and UserSearch compete here.
Automated investigation reports. You supply a name and a location, and the platform assembles a formatted, timestamped, court-defensible report. Skopenow is the clearest example.
Breach and identity intelligence. Vendors maintain large curated corpora of leaked credentials and stolen records, then sell query access. Constella Intelligence, SpyCloud, Intelligence X and DeHashed operate in this space.
Link analysis and case management. The analyst's workbench: a graph canvas that ingests entities and draws relationships between them. Maltego is the reference implementation, with Palantir and DataWalk serving the heavier end.
Mission-scale collection and monitoring. Continuous, high-volume collection across social platforms, deep web and dark web, usually sold to national security and federal law enforcement customers. Fivecast, Babel Street, ShadowDragon, Penlink and Voyager Labs compete here.
Most serious investigative teams run a stack rather than a single product: a collection platform, fed by specialist selector and breach sources, with a link-analysis tool on top and an evidence-capture tool preserving everything for court.
The providers
OSINT Industries
The company that has done the most in recent years to popularise selector-based lookup as a mainstream product. Its pitch is speed and breadth. Enter an email, phone number, username, real name or crypto wallet, and the platform queries what it says are 1,500 or more sources in real time, returning linked accounts, breach flags cross-referenced against Have I Been Pwned, geospatial visualisation, and an activity timeline. Results export to PDF, DOCX, XLSX or JSON, and an API is available for teams that want to embed lookups into an existing workflow.
Two design decisions define the product. First, queries execute live rather than against a stored index, which the company argues eliminates stale results and false positives. Second, it says it retains no record of searches or results, a meaningful claim in a sector where query logs are themselves sensitive intelligence.
Commercially, the company has pursued public sector adoption aggressively, offering free platform access and free training to law enforcement with a particular focus on child protection units. It claims support for more than 5,000 law enforcement and investigative agencies, with Interpol, Europol and several national and regional police forces named publicly. Recent capability additions include face search.
That go-to-market strategy is also the source of the strongest criticism. A tool this capable, priced for individual professionals rather than federal budgets, sits much closer to the general public than the enterprise platforms it competes with. The gap between a vetted investigator and anyone with a credit card and a plausible story is narrower than the marketing suggests.
Skopenow
New York based, Techstars backed, founded in the mid-2010s, and notably capital-efficient. Public funding trackers put total raised somewhere between $3.5M and $5.4M across a handful of seed rounds, against roughly 60 employees and reported revenue in the mid-single-digit millions. It claims over 1,500 customers, including a fifth of the Fortune 500.
Skopenow's differentiator is workflow rather than raw data. The platform ingests a name, phone number, email or business and returns a structured analytical report covering social profiles, photos, previous addresses, corporate records, vehicle records and dark web leaks, with forensic screen captures, metadata and hashes preserved so the output survives evidentiary challenge. Users never have to log into a social platform themselves, which removes a common source of both contamination and platform terms-of-service violations.
The product line has expanded steadily: Workbench for deep investigation, Grid for location-based situational awareness and alerting, Pre-Check for lightweight screening, and Rabbit for rapid triage. A Guidewire marketplace integration signalled a serious push into insurance claims and SIU work, which alongside legal and corporate security is where the company is strongest. Frost & Sullivan ranked it at the top of its OSINT radar in 2023. Access requires vetting, and pricing reaches five figures.
Constella Intelligence
Constella is better understood as a data asset than as a search tool. It formed in December 2020 from the merger of 4iQ, a breach-data specialist founded by AlienVault co-founder Julio Casal, and Madrid-based Alto Analytics, which brought social and misinformation analytics. Headquarters are split between Los Altos, California and Madrid.
The company's value sits in the size and curation of its breach corpus. Its 2026 Identity Breach Report describes a pool approaching a trillion correlated attributes: 567,061 breaches hunted during 2025, a 159% year-on-year increase attributed to agentic AI automation, yielding 27.9 billion curated records. The findings that matter most for anyone assessing this market are the structural ones. Nearly 60% of ingested datasets were recycled credential compilations rather than novel breaches, only 7.4% represented unique leak events, and 68.89% of exposed credentials sat in plaintext, largely courtesy of infostealer malware.
Constella's framing is defensive. It sells identity risk intelligence to enterprises worried about executive impersonation and account takeover. But the same corpus that lets you check whether your CEO's credentials are circulating is the corpus that lets an investigator unmask an anonymous account. The company's data has appeared repeatedly as a research input in KrebsOnSecurity investigations, which is a fair proxy for both its quality and its dual-use character.
Maltego
The consolidator. Maltego's graph-based link analysis has been the analyst's default canvas for over a decade, and its Transform Hub of third-party data connectors, including a long-running integration with Social Links, turned it into a platform rather than a tool.
Since 2024 it has been buying aggressively: PublicSonar and Social Network Harvester in April 2024, and evidence-capture tool Hunchly in May 2025. In October 2025 it consolidated the portfolio under Maltego One, spanning Graph, Search, Monitor and Evidence, with Data Pass providing brokered access to third-party sources. Frost & Sullivan gave it a 2025 product leadership award.
The strategic logic is clear. Own the entire investigative workflow from collection through analysis to evidence preservation, so that specialist point tools become features rather than competitors. It is the single best indicator of where this market is heading.
Social Links
Provides access to more than 500 open sources including social platforms, messengers, blockchains and dark web content, delivered either standalone or as Maltego transforms. It claims deployment across S&P 500 companies and law enforcement agencies in over 80 countries, with particular strength in Latin America and continental Europe. Its Russian origins have complicated its position in some Western procurement processes, and the company has restructured accordingly.
ShadowDragon
Founded by Daniel Clemens, headquartered in Alabama, roughly 83 employees, backed by Sverica Capital. Its flagship SocialNet monitors publicly available data across more than 200 websites. Other products cover dark web monitoring (OIMonitor), malware infrastructure (MalNet), alias correlation (AliasDB) and collection (Spotter).
ShadowDragon is also the vendor most consistently in the crosshairs of privacy reporting, largely because of its federal customer base. An ICE acquisition document quoted by the EFF described persistent access to major social platforms via SocialNet as being of "the utmost importance" to the agency. Reporting has also documented collection extending into gaming platforms and parenting forums, sources that are technically public but that few users would consider surveilled.
Fivecast
Adelaide based, founded in 2017 as a spin-out of Australia's Data to Decisions Cooperative Research Centre, with roughly 140 staff and around $24M to $28M raised, including a $20M Series A led by Ten Eleven Ventures in 2023 and material funding from the US Department of Defense.
Fivecast sells AI-enabled collection and risk analytics across surface, deep and dark web, targeted at Five Eyes national security, defence and federal law enforcement customers, with growing traction in financial intelligence. Its positioning as a trusted-ally vendor is a real commercial advantage in a market where several competitors carry sovereignty questions.
Babel Street
Babel Street sells Babel X, a multilingual collection and analysis platform used widely across US federal agencies, and, far more controversially, Locate X.
In October 2024, privacy firm Atlas Privacy obtained trial access to Locate X and demonstrated to 404 Media, KrebsOnSecurity and other outlets that it could follow an individual device from a residence in Alabama across state lines to a Florida reproductive health clinic and back. The data underneath came from the mobile advertising bidstream. Atlas obtained access simply by asserting an intention to work with law enforcement in future. The story reshaped the policy conversation around this entire industry, and it remains the most-cited example of what commercially available data enables.
Penlink (and Cobwebs Technologies)
Nebraska-based Penlink acquired Israeli intelligence firm Cobwebs Technologies in 2023, folding Cobwebs' Tangles (social media and web intelligence) and Webloc (device location) into its communications-analysis portfolio.
DHS purchased licences for Penlink tools in September 2025 at a reported value around $5M. Roughly 70 lawmakers subsequently called for an inspector general investigation into what they characterised as warrantless purchases of Americans' location data, and the DHS inspector general opened an audit of the department's data management practices in February 2026.
The adjacent tier
Several companies are frequently listed as OSINT vendors but are better understood as neighbours. Flashpoint and Intel 471 sell illicit-community and threat intelligence. DarkOwl and Searchlight Cyber index dark web content. Intelligence X and DeHashed sell breach and leak search. Recorded Future, acquired by Mastercard for $2.65 billion in 2024, sits at the intersection of OSINT and cyber threat intelligence, and that price tag is the clearest available signal of how the market values this category. Palantir, LexisNexis Risk Solutions and Thomson Reuters CLEAR overlap on the government and public-records side.
At a glance
| Vendor | Primary category | HQ | Core products | Typical buyer |
|---|---|---|---|---|
| OSINT Industries | Selector resolution | UK / US | Platform, API, Face Search | Police, PIs, fraud, journalists |
| Skopenow | Automated reports | New York | Workbench, Grid, Pre-Check, Rabbit | Insurance SIU, legal, corporate security |
| Constella | Breach / identity data | Los Altos & Madrid | Hunter, identity risk intelligence | Enterprise security, researchers |
| Maltego | Link analysis | Munich | Maltego One (Graph, Search, Monitor, Evidence) | Analysts across all sectors |
| Social Links | Data access / transforms | Amsterdam | SL Professional, SL Private Platform | Law enforcement, enterprise |
| ShadowDragon | Collection & monitoring | Alabama | SocialNet, OIMonitor, MalNet, Spotter | Federal law enforcement, national security |
| Fivecast | Collection & analytics | Adelaide | AI-enabled OSINT platform | Defence, national security, financial intelligence |
| Babel Street | Collection & location | Virginia | Babel X, Locate X | Federal agencies |
| Penlink | Comms & web intelligence | Nebraska | Tangles, Webloc | Federal and local law enforcement |
The money, and why the market numbers are unreliable
Analyst estimates for the OSINT market in 2026 range from under $3 billion to over $22 billion. That is not a rounding error. It is evidence that nobody agrees on what counts. Narrow definitions capture only dedicated investigative platforms. Broad ones sweep in social listening, media monitoring, threat intelligence and parts of the geospatial industry, which is how some reports end up naming Google as the market leader.
Treat any single headline number with suspicion. The directionally reliable signals sit elsewhere: Mastercard paying $2.65B for Recorded Future, Maltego executing four acquisitions in eighteen months, and ICE's procurement pipeline, which the EFF has documented as including $4.2M across Fivecast and ShadowDragon, roughly $5M with Penlink, and stated plans to spend $20M to $50M standing up a 24/7 social media monitoring centre staffed by at least 30 full-time agents.
Note also how modest the private funding is relative to the influence. Skopenow raised a few million dollars. ShadowDragon raised roughly $6M. Fivecast raised under $30M. These are small companies with outsized reach, a structural feature of a market where the expensive asset is data access and government relationships rather than engineering headcount.
Where the data comes from
This is the part vendor marketing tends to skip, and the part that determines your legal exposure.
Live platform queries. Many selector tools work by probing account-recovery and registration endpoints, asking a service whether an email is registered without triggering a notification to the account holder. This is technically publicly available information, but it depends on platform behaviour that platforms actively try to change, which is why coverage fluctuates.
Breach corpora. Constella's own research makes the position plain. The majority of what circulates is recycled compilations of previously stolen credentials, increasingly harvested by infostealer malware rather than through novel database breaches. Stolen data does not become open-source data by virtue of having been widely copied, and several jurisdictions take that view legally.
Licensed records. Court filings, corporate registries, property records, voter files, vehicle registrations. The most defensible layer of the stack, and the least interesting to critics.
Advertising bidstream and SDK location data. The most legally exposed layer, and what powers Locate X and similar products. In December 2024 the FTC brought actions against Gravy Analytics, Venntel and Mobilewalla over the collection and sale of sensitive location data, requiring deletion or de-identification of historic sensitive location records. Companies whose products depend on this supply chain face both regulatory action and the possibility that upstream suppliers simply disappear.
Scraped content. Social posts, forum activity, reviews, marketplace listings. Legally contested, platform-hostile, and the subject of ongoing litigation between platforms and scraping companies.
The regulatory picture in 2026
Three developments have changed the risk calculus for buyers.
The DOJ Data Security Program. Codified at 28 CFR Part 202 and implementing Executive Order 14117, the rule took effect on 8 April 2025 with full compliance expected from 8 July 2025 and enforcement phasing through 2026. It prohibits data brokerage transactions involving bulk US sensitive personal data, explicitly including precise geolocation, with countries of concern or persons under their control. It also restricts vendor, employment and investment agreements absent a compliance programme meeting CISA security requirements. Civil penalties run to the greater of roughly $368,000 or twice the transaction value, and wilful violations carry criminal exposure up to $1M and 20 years. Plaintiffs' firms have already begun citing the rule as a predicate for consumer privacy class actions.
For anyone procuring OSINT tooling, the practical consequence is that vendor data provenance and ownership structure are now a national security compliance question rather than a procurement footnote.
FTC enforcement on location data. The 2024 actions against Gravy Analytics, Venntel and Mobilewalla established that selling precise location data tied to sensitive venues is an enforceable unfair practice, independent of any comprehensive federal privacy statute.
Political scrutiny of federal procurement. Expanded ICE surveillance contracting, congressional letters demanding an inspector general investigation, and an active DHS IG audit have together made "which agencies use this tool" a live reputational question for vendors in a way it was not five years ago.
Outside the US, the GDPR remains the binding constraint. Processing personal data scraped or purchased at scale requires a lawful basis, and "it was publicly available" is not one. EU enforcement against facial recognition and data scraping companies has been consistent enough that any European deployment needs real legal review rather than a terms-of-service checkbox.
How to evaluate a provider
If you are buying rather than reading, these are the questions that separate serious vendors from the rest.
Data provenance, in writing. Ask which categories of data the platform touches: live queries, licensed records, breach corpora, bidstream, scraped content. Get the answer contractually. A vendor that will not answer precisely is a vendor whose answer you would not like.
Retention and query logging. Are your searches stored? Who can see them? Query logs are themselves intelligence, and in litigation they are discoverable.
Vetting and access control. How does the vendor decide who becomes a customer? The Locate X episode is instructive, because the failure was procedural rather than technical. Ask what would have stopped it.
Evidentiary defensibility. If output will be used in a claim, a hearing or a disciplinary process, it needs hashes, timestamps, source URLs and capture metadata. Screenshots are not evidence.
False positive handling. Selector tools that promise zero false positives are describing an aspiration. Ask how confidence is scored and what happens when two people share an identifier.
Operational security. Aggressive scanning is visible to targets. Understand what your queries reveal about you before you run them.
Jurisdiction and ownership. Under the DSP rule, where a vendor's data sits and who controls the vendor are compliance-relevant facts.
Where this goes next
Three trends are worth tracking.
The first is consolidation. Maltego's acquisition run and Mastercard's purchase of Recorded Future point the same direction. Point tools become features, and buyers increasingly want one platform covering collection, analysis and evidence rather than a stack of six subscriptions.
The second is agentic automation. Constella already attributes a 159% expansion in breach detection to autonomous AI collection, and vendors across the category are moving from search interfaces to systems that run investigative workflows with minimal human direction. That compresses investigation time considerably. It also compresses the time available for a human to notice that an investigation has gone somewhere it should not.
The third is a widening gap between the two halves of the market. Enterprise platforms with six-figure price tags, vetting processes and audit trails are pulling further away from the low-cost selector tools available to almost anyone. The capability difference between the tiers is shrinking. The accountability difference is not.
That gap is the real story of this industry. The tools work. They locate fugitives, identify people who abuse children, unwind fraud rings and give journalists the ability to verify claims that would otherwise be unverifiable. They also make it trivially easy to assemble a comprehensive dossier on someone who has done nothing at all. Nothing in the technology distinguishes between those uses. Only the people selling it, and the rules governing them, ever have.