Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence

Private digital intelligence unit

See weak signals before they become a crisis.

Internet Intelligence Service produces digital intelligence, cyber exposure and due diligence reports for individuals, executives, companies and advisers. We locate useful information, verify it, place it in context and turn it into practical options, using only lawful sources and client-supplied material.

OSINTCyber monitoringOnline reputationDue diligenceFraud & disputes
1999historic web culture
6working languages
0unlawful intrusion
72hpossible initial report

Doctrine

Private digital intelligence for decisions, disputes, acquisitions and crises.

We turn public traces, weak signals, web history, already visible leaks, social networks, registers, indexed content and reputation anomalies into a clear view of risk. A single search result is never enough: information is traced to its origin, dated, compared with other sources and placed within the wider timeline.

Our approach prioritises rigour, discretion, evidence preservation, competing hypotheses and a clear separation between established fact, credible signal and unresolved possibility. The final brief is written for decision-makers: what is known, what remains uncertain and what action is reasonable now.

Data & qualification

From raw data to intelligence that supports a decision.

A volume of search results is not intelligence. Every useful element is linked to its origin, dated, corroborated and assessed before it reaches the final brief. This model separates established facts, signals requiring confirmation and unresolved gaps.

Analysis modelCASE / 01
05source families
04confidence states
03priority levels
01unified timeline
01CollectOrigin + URL
02NormaliseDate + entity
03CorroborateConvergence
04AssessConfidence + impact

Every conclusion retains a review path to the material that supports it and states its limitations explicitly.

Research universe5 families selected as required
WEBSites, search engines and indexed contentOrigin · date · archive
REGRegisters and institutional dataEntity · status · jurisdiction
SOCSocial networks and publicationsAccount · relay · context
INFInfrastructure and public exposureDomain · service · history
MEDMedia, archives and reputationNarrative · reach · timeline

Bars show the relative place of each family in this visual model, not a volume of client data.

Decision gridConfidence × priority
AEstablishedconverging sources
BProbablestrong indicators
CPossibleconfirmation needed
DUnknowninsufficient data
P1Actcurrent or imminent impact
P2Verifycredible incomplete signal
P3Monitorweak or isolated signal
Coverage matrixIndicative view — scope tailored to each mission
MissionIdentitiesEntitiesInfrastructureTimelineReputationDeliverable
OSINT investigationPrimaryPrimaryTargetedPrimaryContextSourced report
Cyber monitoringTargetedTargetedPrimaryPrimaryContextExposure note
Due diligencePrimaryPrimaryContextPrimaryTargetedRisk brief
Online reputationTargetedContextContextPrimaryPrimaryNarrative map
Fraud & disputePrimaryTargetedTargetedPrimaryContextEvidence timeline
Crisis unitTargetedTargetedTargetedPrimaryPrimaryDecision brief
PrimaryTargetedContext
Processing ledgerDATA / LIFECYCLE
01Receivedinitial element
02Preservedcopy and reference
03Datedtime and zone
04Attributedapparent source
05Corroborateddistinct sources
06Assessedconfidence and impact
07Reporteddecision and caveat

2025 public data

The digital threat in numbers.

Three complementary official scopes: events handled in France, incidents analysed across the European Union and assistance requests from French audiences. These figures describe different populations and should not be added together.

FRANCEANSSI2025
3,586security events handled
1,366recorded incidents
460events classed as possible leaks
42%linked to a confirmed data leak
2025 Cyber Threat Overview ↗
EUROPEAN UNIONENISAJul. 2024 — Jun. 2025
4,875incidents analysed
77%classified as DDoS
60%initial access through phishing
21.3%through vulnerability exploitation
ENISA Threat Landscape 2025 ↗
ASSISTANCE — FRANCECybermalveillance.gouv.fr2025
500,000victims assisted
33%of requests linked to phishing
+159%fake bank adviser scams
+196%bank-transfer fraud
2025 activity report ↗
France trendANSSI · 2024 → 2025
20244,386events
20253,586events
20241,361incidents
20251,366incidents
−18% events+0.4% incidents
Most targeted sectors — FranceANSSI · 2025
Education & research34%
Ministries & local government24%
Health10%
Telecommunications9%
Other sectors23%
Most targeted sectors — EUENISA · 2025
Public administration38.2%
Transport7.5%
Digital infrastructure4.8%
Finance4.5%
Manufacturing2.9%
Other sectors42.1%
Ransomware victims known to ANSSI2024 distribution
  1. 37%SMEs & mid-caps
  2. 17%Local authorities
  3. 12%Higher education
  4. 12%Strategic companies
  5. 22%Other victims
Source: ANSSI 2024 overview ↗
Vectors & impactENISA · EU · 2025
≈80%Hacktivismapproximate incident share
53.7%Essential entitiesunder NIS 2
2%Disruptionof hacktivism incidents
Fraud signalsCybermalveillance.gouv.fr · France · 2025
+71%phishing-related assistance searches
15,000fake bank adviser assistance cases
13,000bank-transfer fraud assistance cases
+517%phone-number spoofing
Public dataset4 datasets · 39 structured values · JSONValues, units, periods, scopes and source URLs collected in a reusable file.
Download the data

How to read: data published by the cited organisations and accessed on 24 August 2026. Definitions of an event, incident and assistance request differ between sources. Changes are those reported by the source organisations.

Capabilities

Intelligence, protection and anticipation for exposed digital lives.

Every mission begins with strict scoping: legitimate purpose, authorised perimeter, lawful sources, confidentiality level and expected deliverables. This first stage removes irrelevant noise, identifies the questions that matter and limits collection to information that can genuinely help the client.

01

OSINT investigation

Mapping of identities, aliases and public assets across domains, social profiles, publications, archives and accessible registers. Relationships are documented with confidence levels so that a possible connection is never overstated.

02

Cyber intelligence

Monitoring of public exposure, already visible leaks, impersonation, typosquatting and hostile mentions. Findings are ranked by urgency and translated into practical defensive priorities.

03

Due diligence

Structured risk analysis before partnerships, sensitive hires, investments, acquisitions or disputes. The report compares stated claims with public facts, meaningful inconsistencies and questions that still require direct confirmation.

04

Individual protection

Support with scams, harassment, impersonation, blackmail, damaged reputation or a worrying online relationship. Available traces are organised into a timeline to clarify events and preserve useful evidence.

05

Influence & reputation

Narrative analysis, relay mapping, manipulation signals and assessment of the visible media footprint. The report distinguishes an isolated criticism from a lasting dynamic and recommends a proportionate response.

06

Crisis unit

Rapid initial assessment, a verified timeline, urgency levels and a clear action plan for executives, legal teams, communications advisers or families facing an active situation.

Protocol

A discreet, documented and actionable intelligence method.

01

Scoping

We define the objective, legitimate purpose, urgency, people concerned, useful perimeter and legal limits before research begins.

02

Collection

Relevant open sources, registers, search engines, archives, networks and specialist monitoring are consulted, with links and dates preserved for review.

03

Correlation

Information is sorted, corroborated and assigned a confidence level. Competing explanations and blind spots remain visible whenever the evidence is incomplete.

04

Report

The report combines a verified timeline, supporting evidence, ranked risks, an executive summary and recommended actions that can be prioritised immediately.

Frequently asked questions

Understand private digital intelligence.

What is an OSINT investigation?

It collects and corroborates lawfully accessible information from search engines, registers, archives, websites, social platforms and client-supplied material. The work checks origin, date, consistency and relevance while excluding intrusion, private interception and access-control circumvention.

When should I contact Internet Intelligence Service?

A mission can help before a sensitive decision, partnership, hire, investment or acquisition, and when fraud, impersonation, harassment, reputation damage or a digital crisis makes it important to establish a reliable timeline. Initial scoping confirms whether open-source research can provide a useful answer.

What does the report contain?

Depending on the mission, it includes a decision brief, a timeline, dated sources and confidence levels, ranked risks, unresolved questions and recommended actions. The summary supports quick reading while the detailed sections preserve the evidence and reasoning.

Confidential channel

Describe the situation in plain terms. We will identify what can be verified, what needs further work and what can be handled lawfully.

Submit a case