Organised Crime
Organised crime rarely reaches a company as a violent event. It arrives as a supplier that invoices correctly but has no verifiable activity, as a customer who insists on paying through a third country, or as a professional-looking platform that collapses the day the transfer clears. The criminal structure is not visible; its administrative footprint often is.
This area reconstructs that footprint from open sources: company registries, digital infrastructure, corporate relationships and the inconsistencies that appear when an apparently ordinary counterparty is examined in detail. The purpose is not to accuse anyone, but to give the person who has to sign a contract an evidenced basis for the decision.
What the discipline covers
- Shell and front companies: entities with formal existence, minimal accounts and no verifiable operational trace.
- Fraud networks against businesses: invoice diversion, false suppliers, fake investment platforms, recruitment of money mules.
- Shared digital infrastructure: domains, hosting, contact details and templates reused across supposedly unrelated entities.
- Corporate opacity: layered ownership, nominee directors, frequent changes of registered office, name or corporate purpose.
- Use of legitimate business channels — logistics, payment services, professional intermediaries — as a cover for illicit activity.
Scope
Work is limited to what is lawfully published and to what a company needs in order to decide whether to contract, extend credit or continue a business relationship. It is not a criminal investigation and does not substitute for one.
- Documentary profile of a counterparty: registry data, ownership chain, public history and coherence of the declared activity.
- Assessment of a network: relationships between entities, shared people, shared infrastructure and repeated patterns.
- Verification of the plausibility of an offer, a platform or an investment scheme presented to the organisation.
- Explicit exclusions: no surveillance of individuals, no undercover contact, no pretexting, no attribution of criminal liability.
Main risks and threats
- Payment diversion fraud: legitimate invoices redirected to accounts controlled by a third party after a compromised or spoofed exchange.
- Contracting a front company that later disappears, leaving the organisation exposed to loss and to reputational damage.
- Investment and financial platforms with a professional façade, escalating deposits and no verifiable licence.
- Employees recruited unknowingly as intermediaries for the movement of funds, with direct personal and corporate consequences.
- Reputational and compliance contamination through an intermediary that fails due diligence expectations.
- Reuse of the organisation's own brand and identity to defraud its customers or its suppliers.
Relevant indicators and warning signs
No single indicator proves anything. What matters is the accumulation of small inconsistencies between what an entity claims to be and the trace it actually leaves in public records.
- Recently incorporated company presenting a long track record, or a long-dormant company suddenly reactivated.
- Registered address shared with dozens of unrelated entities, or an address with no operational capacity for the declared activity.
- Corporate website created days or weeks before first contact, with content copied from a genuine competitor.
- Bank details in a jurisdiction unconnected with the declared activity, or changed mid-negotiation under time pressure.
- Directors who appear and disappear across a series of short-lived entities in the same sector.
- Urgency, confidentiality requests and resistance to any documentary verification that is standard in the sector.
Application of OSINT
- Reconstruction of the ownership and control chain from company registries and official gazettes across the relevant jurisdictions.
- Correlation of digital infrastructure: domain registration data, certificate history, hosting and reused contact identifiers.
- Mapping of relationships between entities and people to identify repeated roles and hidden overlaps.
- Timeline analysis: comparing incorporation, domain creation, first contact and the moment of maximum pressure to pay.
- Coherence testing between declared activity, physical footprint, staffing evidence and public financial filings.
Zero101OSINT methodology
- Definition of the decision the analysis has to support before any collection begins, so scope stays proportionate.
- Separation of three levels in every deliverable: documented fact, reasonable inference and open question.
- Corroboration rule: no finding is reported on the strength of a single source, and every source is dated and archived.
- Explicit competing explanation for each red flag — poor administration and criminal design can look identical from outside.
- Findings graded by reliability and by relevance to the specific decision, not by how alarming they sound.
- A clear statement of what was not possible to verify, so the reader knows where the residual risk sits.
Open sources used
- Company registries, official gazettes, insolvency filings and published administrative resolutions.
- Published sanctions and restrictive-measures lists, and official regulatory warnings about unauthorised entities.
- Public domain registration and certificate transparency data, and publicly reachable website content and archives.
- Court decisions published in the public domain and official statements by supervisory authorities.
- Sector press and specialised sources, always traced, dated and rated, never used as the sole support for a conclusion.
Applications for companies, organisations and security decision-makers
- Screen a new supplier, distributor or customer before a contract, a credit line or a first shipment.
- Add documented external evidence to onboarding and anti-fraud procedures without expanding internal headcount.
- Give finance and legal teams a factual basis to challenge a payment instruction that has changed unexpectedly.
- Support staff awareness with real, anonymised patterns instead of generic warnings.
- Provide a board or audit committee with traceable grounds for declining or restructuring a business relationship.
Products or analytical outputs Zero101OSINT can provide
- Counterparty due diligence report: ownership chain, public history, inconsistencies and reliability of each finding.
- Network analysis linking entities, people and shared infrastructure, with a graphical view of the relationships found.
- Assessment of a suspicious offer, platform or payment instruction, with a documented verdict on plausibility.
- Brand abuse review: lookalike domains, fraudulent sites and false profiles using the organisation's identity.
- Indicator set and internal checklist so the organisation can apply the same screening on its own.
Legal, ethical and reliability limitations
No access to third-party systems, no interaction with fraudulent infrastructure beyond lawful public observation, no purchase of leaked data and no covert contact with individuals. Personal data is treated with minimisation and only for a security purpose.
Findings describe documented indicators, not criminal liability: only a court can establish that. Public registries can be incomplete, out of date or deliberately misleading, and a jurisdiction with limited transparency will limit what any external analysis can conclude. This work does not replace legal advice, a regulated compliance procedure or a formal report to the competent authorities.
Related reports
No intelligence report published in English is directly relevant to this area yet. The available analysis is covered by the related articles below.
Related articles
Third-party evaluation: how OSINT reduces risks in business relationships
Every business relationship implies a level of trust. Analysis of how open source intelligence transforms third-party evaluation into a real analytical capability.
Read →Corporate relationship analysis: what public connections between companies reveal
Relationships between organizations generate information patterns that can be analyzed from open sources. Analysis of how corporate connections reveal strategic dynamics.
Read →Digital traceability: how an organization's activity can be reconstructed
Every digital action generates a trace. Analysis of how digital traceability enables reconstructing corporate activity patterns from open sources.
Read →Inconsistency signals: detecting contradictions in public information
Inconsistencies in an organization's public information can reveal hidden risks. Analysis of how inconsistency signals function as warning indicators.
Read →Social engineering fraud and bank claims: what really happens when the customer authorises the operation
Why banks reject fraud claims when the customer authorises the operation: the key difference between technical authorisation and real consent, the role of the central bank and realistic options.
Read →OSINT and compliance: the role of intelligence in legal risk prevention
Compliance programs that don't integrate open source intelligence operate with a partial view of risk. Analysis of OSINT's role in extended due diligence and third-party evaluation.
Read →Digital due diligence: beyond the commercial registry
What public information can reveal about a partner, supplier, or candidate before signing. Methodology and legal limits.
Read →Related areas
Need analysis in this area?
Describe the scope, the deadline and the decision the analysis has to support. You will receive the proposed approach, the limits of the assessment and the deliverable that can realistically be produced.
Get in touch