OSINT & Personnel Security

Find out what data about you and your employees is publicly available - and who can use it

Hackers don’t always attack systems – they often attack people. Phishing, spear phishing, blackmail, impersonation. We examine what information about you and key employees is circulating on the internet and dark net.The result: a clear exposure map + specific protective steps.

PLN 99 net

– one-time report/person

or 399 PLN net/msc

– continuous monitoring of people

PROCESS

The problem - why it matters

Phishing is the most common type of attack on companies in Europe. In more than 80% of cases, the attack begins with a carefully personalized message aimed at a specific individual – usually a board member, CFO or employee with access to critical systems. The effectiveness of such an attack depends on how much information the attacker manages to gather about the victim before sending the first message.

Meanwhile, much of this information is publicly available – on LinkedIn, in social media, in databases of data leaks, in business registries, in industry forums. OSINT is the discipline of collecting and analyzing information from open sources. We use the same methods that attackers use – to show you what they know about you before they try to take advantage.

PROCESS

What exactly are we checking

For each person you commission for analysis, we conduct a systematic search in more than a dozen categories of sources – from the publicly available Internet to the dark net. The entire analysis is passive: we don’t contact the person under study, we don’t try to get additional information by social engineering methods, we don’t violate privacy beyond what is publicly available anyway.

Leaked emails and passwords

Check all known leak databases (Have I Been Pwned and others, including dark net)

Social media profile

LinkedIn, X, Facebook, Instagram: what job data, location, contacts are visible

Personal data in open sources

Address, phone number, PESEL (if visible in records), family photos

Links to companies

Function performed, employment history, ownership structure, cross capital ties

Dark net presence

Check known marketplaces and hacking forums for offers to sell data

Vulnerability to phishing and spear phishing

Assessing how much of the collected data would be enough for an effective personalized attack

Risk of blackmail

Identification of information that could be used as a leverage point

solution

What you get

OSINT report (15-30 pages, for subject + supervisor)

Full map of a person’s digital exposure – all the information found, sources, screen captures. Organized into clear categories with a risk assessment for each. A format consciously prepared for secure internal distribution – it can be shown to the subject without the risk of becoming a leak in itself.

Risk rating on a scale of 1-10

Synthetic vulnerability assessment for four types of attacks: phishing, spear phishing, blackmail, identity theft. Each category is given a score with justification and a list of the strongest risk factors.

Recommendations at the general level
We point out the areas where the subject’s exposure is greatest, and typical best practices that help reduce that exposure – from social media privacy settings, to verifying accounts for leaks, to communication hygiene recommendations. Our role is to show the risk and its magnitude – concrete implementation of changes on the part of the subject or the company’s IT department.
Delivery format
PDF + secure view in customer panel (access requires login). Notification of the finished report sent only to the e-mail of the ordering person.

Every piece of information found, every leak – with an assessment of “what the attacker can do with it” and, where possible, with an indication of the source.

How does it work?

Process in 3 steps

01

You indicate the person to be analyzed

In the customer panel you provide basic data: first name, last name, business e-mail, optionally company name and position. Each person surveyed must consent to the OSINT analysis – in the case of your own person, the consent is given automatically when you place the order, in the case of another person (e.g., board member, key employee) we require a signed consent.

02

Analysis (up to 48 hours)

Our engines search more than a dozen categories of sources, collect the information found, verify its validity and classify it by risk. All analysis is passive and does not reveal to anyone that a person is being analyzed.

03

Report ready

You receive an email notification with a secure link to the report. The report remains available in your customer panel for the duration of your active subscription, or up to 12 months after purchase for a one-time report. In a continuous subscription, automatic alerts notify you of new leaks or the arrival of new data on your network – sent when the next scan cycle is completed.

solution

Price variants

One-time report

99 zł/person

Full OSINT profile of 1 person + report + recommendations

Monthly subscription
399 zł/msc

Continuous monitoring of 1 person + alerts on new leaks

The subscription can be extended to include additional people – upon request. For multi-person boards, we recommend the Guardian package (Cyber Monitoring + OSINT) for PLN 1,099/msc.

Who this service is for

OSINT and Personal Security is recommended primarily for board members, CFOs, IT directors and people with access to critical company systems – in other words, those who are typically the targets of spear phishing attacks. The second audience is publicly exposed persons (PEPs) – politicians, journalists, well-known businessmen, who are particularly vulnerable to social engineering attacks and disinformation campaigns.

The third group is small business owners and partners, who often combine a personal role with a business role – an attack on an individual translates directly into company security. Continuous subscription makes sense especially for those who have recently changed positions, entered the public domain or, as a result of an incident, noticed their data circulating online.

Frequently Asked Questions (FAQ)

Can I have a third party analyzed without their consent?

No – but if you have an IT team, they’ll be happy too. Each report exists in two versions: a summary for management (threats in PLN) and a full technical analysis for IT (CVSS, vulnerability details, recommendations). If you don’t have an IT department – we can help you find a partner.

Yes, the analysis includes known databases of leaked data available on the dark net, which we access through certified Threat Intelligence providers. The analysis itself of data from leaks that have already been published is legal and is standard practice in the cybersecurity industry. We don’t buy new leaks, we don’t commission any illegal activities – we only verify the presence of already known information.
The report will show in which leak, when and in what form the password was found (usually a full password, a hashed password or a fragment). The first recommendation will always be the same: immediately change that password everywhere you used it, and enable two-factor authentication. The report includes a short step-by-step action path – in future versions we plan to expand it with a broader guide to secure password hygiene.
The report can only be seen by the logged-in user who placed the order. The report is not shared with any third parties.
Some data – yes, some – unfortunately not. From social media, you can effectively remove data (or reduce visibility). From leak databases, archives and dark net – it is practically impossible to remove them, but you can minimize their harmfulness by changing passwords, enabling 2FA and monitoring new occurrences. The report always indicates what can realistically be done and what cannot.

Limitations of the service (disclaimer)

OSINT analysis is inherently informative and based on data publicly available at the time of the scan. Incomplete results (some data may be hidden or unavailable at the time of the scan) and false positives (e.g., data from another person with the same name) are possible. The results do not constitute evidence in legal proceedings – if necessary, a formal notification of the leak is recommended in accordance with RODO procedures. We use third-party data providers Threat Intelligence – see Terms and Conditions for details.

offer

Packages and related services

OSINT and Personnel Security is most often ordered together with:

Cyber Monitoring & Scanning

249,00 

Comprehensive diagnosis: technology + people

Verification of Regulatory Compliance

499,00 

Checks the company’s obligations as a result of detected leaks

Recon Package

749,00 

all three of the above services in one package at a discount of ~12%

Guardian Package

1 099,00  / month

Cyber Monitoring + OSINT in continuous monitoring, at a discount

See what they know about you - before they take advantage

Full exposure report in 48 hours.

Only £99 for a full person analysis.