Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Digital intelligence analysis centre and signal map
Editorial illustration

Private digital intelligence unit

Digital intelligence and OSINT for informed decisions.

Internet Intelligence Service produces digital intelligence, cyber exposure and due diligence reports for individuals, executives, companies and advisers. We locate useful information, verify it, place it in context and turn it into practical options, using only lawful sources and client-supplied material.

OSINTCyber monitoringOnline reputationDue diligenceFraud & disputes
1999historic web culture
6working languages
0unlawful intrusion
72hpossible initial report

Doctrine

Private digital intelligence for decisions, disputes, acquisitions and crises.

We turn public traces, weak signals, web history, already visible leaks, social networks, registers, indexed content and reputation anomalies into a clear view of risk. A single search result is never enough: information is traced to its origin, dated, compared with other sources and placed within the wider timeline.

Our approach prioritises rigour, discretion, evidence preservation, competing hypotheses and a clear separation between established fact, credible signal and unresolved possibility. The final brief is written for decision-makers: what is known, what remains uncertain and what action is reasonable now.

Data & qualification

From raw data to intelligence that supports a decision.

A volume of search results is not intelligence. Every useful element is linked to its origin, dated, corroborated and assessed before it reaches the final brief. This model separates established facts, signals requiring confirmation and unresolved gaps.

Analysis modelCASE / 01
05source families
04confidence states
03priority levels
01unified timeline
01CollectOrigin + URL
02NormaliseDate + entity
03CorroborateConvergence
04AssessConfidence + impact

Every conclusion retains a review path to the material that supports it and states its limitations explicitly.

Research universe5 families selected as required
WEBSites, search engines and indexed contentOrigin · date · archive
REGRegisters and institutional dataEntity · status · jurisdiction
SOCSocial networks and publicationsAccount · relay · context
INFInfrastructure and public exposureDomain · service · history
MEDMedia, archives and reputationNarrative · reach · timeline

Bars show the relative place of each family in this visual model, not a volume of client data.

Decision gridConfidence × priority
AEstablishedconverging sources
BProbablestrong indicators
CPossibleconfirmation needed
DUnknowninsufficient data
P1Actcurrent or imminent impact
P2Verifycredible incomplete signal
P3Monitorweak or isolated signal
Coverage matrixIndicative view — scope tailored to each mission
MissionIdentitiesEntitiesInfrastructureTimelineReputationDeliverable
OSINT investigationPrimaryPrimaryTargetedPrimaryContextSourced report
Cyber monitoringTargetedTargetedPrimaryPrimaryContextExposure note
Due diligencePrimaryPrimaryContextPrimaryTargetedRisk brief
Online reputationTargetedContextContextPrimaryPrimaryNarrative map
Fraud & disputePrimaryTargetedTargetedPrimaryContextEvidence timeline
Crisis unitTargetedTargetedTargetedPrimaryPrimaryDecision brief
PrimaryTargetedContext
Processing ledgerDATA / LIFECYCLE
01Receivedinitial element
02Preservedcopy and reference
03Datedtime and zone
04Attributedapparent source
05Corroborateddistinct sources
06Assessedconfidence and impact
07Reporteddecision and caveat

2025 public data

The digital threat in numbers.

Three complementary official scopes: events handled in France, incidents analysed across the European Union and assistance requests from French audiences. These figures describe different populations and should not be added together.

FRANCEANSSI2025
3,586security events handled
1,366recorded incidents
460events classed as possible leaks
42%linked to a confirmed data leak
2025 Cyber Threat Overview ↗
EUROPEAN UNIONENISAJul. 2024 — Jun. 2025
4,875incidents analysed
77%classified as DDoS
60%initial access through phishing
21.3%through vulnerability exploitation
ENISA Threat Landscape 2025 ↗
ASSISTANCE — FRANCECybermalveillance.gouv.fr2025
> 500,000victims assisted
≈ 33%of individual requests linked to phishing
+159%fake bank adviser scams · individuals
+196%bank-transfer fraud · individuals
2025 activity report ↗

Official logos are displayed solely to identify the organisations whose data is cited. Their presence does not imply affiliation, partnership or endorsement of Internet Intelligence Service.

France trendANSSI · 2024 → 2025
20244,386events
20253,586events
20241,361incidents
20251,366incidents
−18% events+0.4% incidents
Most targeted sectors — FranceANSSI · 2025
Education & research34%
Ministries & local government24%
Health10%
Telecommunications9%
Other sectors23%
Most targeted sectors — EUENISA · 2025
Public administration38.2%
Transport7.5%
Digital infrastructure4.8%
Finance4.5%
Manufacturing2.9%
Other sectors42.1%
Ransomware victims known to ANSSI2024 distribution
  1. 37%SMEs & mid-caps
  2. 17%Local authorities
  3. 12%Higher education
  4. 12%Strategic companies
  5. 22%Other victims
Source: ANSSI 2024 overview ↗
Vectors & impactENISA · EU · 2025
≈80%Hacktivismapproximate incident share
53.7%Essential entitiesunder NIS 2
2%Disruptionof hacktivism incidents
Fraud signalsCybermalveillance.gouv.fr · France · 2025
+71%individual phishing assistance searches
≈ 15,000individual fake bank adviser assistance searches
≈ 13,000individual bank-transfer fraud assistance searches
+517%phone-number spoofing · individuals
Public dataset4 datasets · 39 structured values · JSONValues, units, periods, scopes and source URLs collected in a reusable file.
Download the data

How to read: data published by the cited organisations and accessed on 24 August 2026. Definitions of an event, incident and assistance request differ between sources. Changes are those reported by the source organisations.

Capabilities

Intelligence, protection and anticipation for exposed digital lives.

Every mission begins with strict scoping: legitimate purpose, authorised perimeter, lawful sources, confidentiality level and expected deliverables. This first stage removes irrelevant noise, identifies the questions that matter and limits collection to information that can genuinely help the client.

OSINT research and open-source mapping
01

OSINT investigation

Mapping of identities, aliases and public assets across domains, social profiles, publications, archives and accessible registers. Relationships are documented with confidence levels so that a possible connection is never overstated.

Explore OSINT investigation →
Cyber exposure monitoring at an analysis workstation
02

Cyber intelligence

Monitoring of public exposure, already visible leaks, impersonation, typosquatting and hostile mentions. Findings are ranked by urgency and translated into practical defensive priorities.

Explore cyber monitoring →
Document review for a sensitive decision
03

Due diligence

Structured risk analysis before partnerships, sensitive hires, investments, acquisitions or disputes. The report compares stated claims with public facts, meaningful inconsistencies and questions that still require direct confirmation.

Explore digital due diligence →
Structured preservation of material for a case file
04

Individual protection

Support with scams, harassment, impersonation, blackmail, damaged reputation or a worrying online relationship. Available traces are organised into a timeline to clarify events and preserve useful evidence.

Discuss a personal situation →
Analysis of public narratives and online reputation signals
05

Influence & reputation

Narrative analysis, relay mapping, manipulation signals and assessment of the visible media footprint. The report distinguishes an isolated criticism from a lasting dynamic and recommends a proportionate response.

Explore online reputation →
Analysis unit and timeline for a digital situation
06

Crisis unit

Rapid initial assessment, a verified timeline, urgency levels and a clear action plan for executives, legal teams, communications advisers or families facing an active situation.

Explore the operations team →

Individuals & leaders

When a digital signal raises a concrete concern.

  • Check a person, profile or contact before sharing sensitive information.
  • Document impersonation, exposure or a coordinated online attack.
  • Reduce uncertainty before taking a decision or escalating a case.

Companies & advisers

A clear view of the facts before action.

  • Map public exposure across people, brands and digital assets.
  • Identify weak signals, inconsistencies and relevant connections.
  • Produce a sourced account that supports an informed response.

Protocol

A discreet, documented and actionable intelligence method.

01

Scoping

We define the objective, legitimate purpose, urgency, people concerned, useful perimeter and legal limits before research begins.

02

Collection

Relevant open sources, registers, search engines, archives, networks and specialist monitoring are consulted, with links and dates preserved for review.

03

Correlation

Information is sorted, corroborated and assigned a confidence level. Competing explanations and blind spots remain visible whenever the evidence is incomplete.

04

Report

The report combines a verified timeline, supporting evidence, ranked risks, an executive summary and recommended actions that can be prioritised immediately.

Resources & reference points

Understand a digital risk before responding to it.

Warning signs, urgency, preserving useful evidence and essential terminology: our resource centre helps you organise the first hours of a sensitive situation.

Explore the resources
Assess a signal Preserve useful evidence Identify urgent steps Prepare a confidential brief

Frequently asked questions

Understand private digital intelligence.

What is an OSINT investigation?

An OSINT investigation collects and corroborates lawfully accessible information from search engines, registers, archives, websites, social platforms and client-supplied material. The work checks origin, date, consistency and relevance while excluding intrusion, private interception and access-control circumvention.

When should I contact Internet Intelligence Service?

A mission can help before a sensitive decision, partnership, hire, investment or acquisition, and when fraud, impersonation, harassment, reputation damage or a digital crisis makes it important to establish a reliable timeline. Initial scoping confirms whether open-source research can provide a useful answer.

What does the report contain?

Depending on the mission, it includes a decision brief, a timeline, dated sources and confidence levels, ranked risks, unresolved questions and recommended actions. The summary supports quick reading while the detailed sections preserve the evidence and reasoning.

How is confidentiality protected?

Initial scoping limits requested information to what is necessary. Scope, recipients and deliverables are defined before collection, with additional care for sensitive material. The first message should summarise the situation without passwords, identity documents, banking data or unnecessary attachments.

Can a person or company be checked without invading privacy?

Research can be appropriate when it serves a legitimate, proportionate purpose such as a business decision, fraud prevention, personal protection or verification of claims already made public. It remains limited to useful, lawful information available without bypassing private access.

How long does an initial assessment take?

Timing depends on urgency, the number of entities, languages, jurisdictions, research depth and the quality of the starting material. A rapid initial brief may be possible in some cases, while multi-source or cross-border work requires more corroboration. Timing is confirmed after scoping.

Can advisers, insurers or internal teams use the report?

The report is designed for review: dated facts, traceable sources, a timeline, confidence levels, caveats and next-step options. It can support legal, executive, cyber, communications or HR teams, but it does not replace their own professional assessment.

What should I do if fraud or a threat is active now?

Protect the people and accounts concerned, notify the appropriate provider or authority and preserve URLs, messages, dates, identifiers and unedited captures. For immediate danger, extortion, bank fraud or confirmed compromise, contact the relevant emergency, banking, insurance or law-enforcement service without delay.

Confidential channel

Describe the situation in plain terms. We will identify what can be verified, what needs further work and what can be handled lawfully.

Submit a case