people-search.md (44796B)
1 --- 2 title: "People Search & Public Records" 3 description: "Registries, court records, aggregators and breach data for identifying a person and the records that mention them." 4 category: osint 5 subcategory: "People & Identity" 6 tags: [osint, people, public-records, breach-data] 7 tools: [hibp, intelx, aleph, alephclient, courtlistener, opensanctions, yente, edgar, ratsit, hitta] 8 difficulty: intermediate 9 updated: 2026-10-04 10 references: 11 - name: "Bellingcat's Online Investigation Toolkit" 12 url: "https://bellingcat.gitbook.io/toolkit" 13 author: "Bellingcat" 14 license: none 15 relation: derived 16 note: "Tool catalogue: names, descriptions, cost flags and links for this area." 17 - name: "OSINT Newsletter Tools Library" 18 url: "https://tools.osintnewsletter.com" 19 author: "The OSINT Newsletter" 20 license: none 21 relation: derived 22 note: "Second tool catalogue, cross-checked against the above." 23 - name: "Have I Been Pwned API v3" 24 url: "https://haveibeenpwned.com/API/v3" 25 author: "Troy Hunt" 26 relation: link-only 27 note: "Endpoint paths, required headers and rate-limit behaviour." 28 - name: "Intelligence X SDK (Python)" 29 url: "https://github.com/IntelligenceX/SDK/tree/master/Python" 30 author: "Kleissner Investments" 31 relation: link-only 32 note: "CLI flags, API endpoint paths and the sort/media enumerations." 33 - name: "alephclient documentation" 34 url: "https://docs.aleph.occrp.org/developers/alephclient/" 35 author: "OCCRP" 36 relation: link-only 37 note: "alephclient subcommands and the ALEPHCLIENT_* environment variables." 38 - name: "CourtListener REST API v4" 39 url: "https://wiki.free.law/c/courtlistener/help/api/rest/v4/overview" 40 author: "Free Law Project" 41 relation: link-only 42 note: "Endpoint paths, search type values, throttles and the OPTIONS convention." 43 - name: "OpenSanctions API reference" 44 url: "https://api.opensanctions.org/openapi.json" 45 author: "OpenSanctions" 46 relation: link-only 47 note: "Scope paths and query parameters for search, match and statements." 48 - name: "yente" 49 url: "https://github.com/opensanctions/yente" 50 author: "OpenSanctions" 51 relation: link-only 52 note: "Self-hosted matching engine: image, port and YENTE_* environment variables." 53 --- 54 55 ## What this covers 56 57 Finding the records that name a person: civil registries, corporate filings, court dockets, 58 electoral rolls, phone books, and the commercial aggregators that resell all of it. Coverage is 59 wildly uneven by country, and the aggregators are frequently wrong, so this is an area where 60 knowing which source is authoritative matters more than knowing many sources. 61 62 ## Method 63 64 1. **Start with the authoritative registry**, not an aggregator. If a country publishes its company 65 register or land registry, use it — the aggregator is a stale copy with errors added. 66 2. **Establish the jurisdiction first.** People-search coverage is national. A US-focused 67 aggregator has close to nothing on a Swedish resident, and Nordic registries are far more open 68 than most. 69 3. **Cross-reference two independent sources** before accepting an address, date of birth or 70 relationship. Aggregators copy each other, so two of them agreeing means nothing. 71 4. **Pivot through documents.** A court filing names an address, an employer and often relatives. 72 One good document beats twenty aggregator hits. 73 5. **Treat breach data as intelligence, not evidence.** It tells you an email existed on a service 74 at some point. It does not tell you who typed it in. 75 76 ## Regional registries worth knowing 77 78 Nordic countries publish personal data that is closed almost everywhere else, which makes them 79 unusually productive: 80 81 - **Sweden** — [Ratsit](https://www.ratsit.se/), [Hitta.se](https://www.hitta.se/), and the 82 Swedish Name Register give addresses, income brackets and dates of birth. 83 - **Norway / Finland / Denmark** — equivalents exist; tax records are partly public in Norway. 84 - **Nigeria** — NigeriaPhonebook for telephone-to-name lookups. 85 - **United States** — county-level court and property records are the real source; national 86 aggregators are convenience layers over them. 87 [Search Systems](https://www.searchsystems.net/) is a directory of the underlying databases, 88 organised by state and record type. 89 90 None of these publish an API. They do take their search term in the query string, which is worth 91 knowing because it means a registry lookup can be scripted into a browser or a note template 92 rather than retyped: 93 94 ```text 95 https://www.hitta.se/sök?vad=Anna+Andersson name or address; returns people and companies 96 https://www.hitta.se/sök?vad=08-555+012+34 reverse telephone, same parameter 97 ``` 98 99 The `vad` parameter is the only one you need; the rest of the query string the site adds is UI 100 state. Note that the path segment is the Swedish word `sök`, so it percent-encodes to 101 `s%C3%B6k` when you paste it into `curl` — a shell that mangles the UTF-8 is the usual reason a 102 hand-built Hitta URL 404s. Ratsit and the US brokers sit behind bot protection that returns 403 103 to anything without a browser fingerprint, so for those, drive the search box rather than the 104 URL. 105 106 ## Key tools 107 108 ### Have I Been Pwned 109 110 The reference for which breach corpora hold an address, and the only tool in this area with a 111 stable documented API. Account lookups sit behind a paid key now — the cheapest tier is a few 112 dollars a month — while the breach catalogue and the password range endpoint stay free and need 113 no key at all. 114 115 The keyless half, which is where to start because it costs nothing and tells you what the corpus 116 even is: 117 118 ```bash 119 # the breach catalogue: free, no key, useful for dating a corpus 120 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breaches' \ 121 | jq -r '.[].Name' | head 122 123 # one breach in detail — when it happened, how big, what fields leaked 124 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breach/Adobe' \ 125 | jq '{BreachDate,AddedDate,PwnCount,IsVerified,DataClasses}' 126 127 # which breaches carried the field you actually care about, sorted oldest first 128 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breaches' \ 129 | jq -r '[.[] | select(.DataClasses | index("Physical addresses"))] 130 | sort_by(.BreachDate)[] | "\(.BreachDate) \(.PwnCount) \(.Name)"' 131 132 # every breach attributed to one domain — the pivot when you know the employer, not the person 133 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/breaches?Domain=adobe.com' 134 135 # the field vocabulary, so a report says "Physical addresses" and not "address data" 136 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/dataClasses' | jq -r '.[]' 137 138 # what was added most recently, for deciding whether a re-run is worth the quota 139 curl -s -H 'user-agent: osint-research' 'https://haveibeenpwned.com/api/v3/latestBreach' \ 140 | jq '{Name,AddedDate}' 141 ``` 142 143 Then the keyed half. `user-agent` is mandatory on every call and `hibp-api-key` on everything 144 that names an account: 145 146 ```bash 147 # confirm which tier the key actually buys before you plan a run around it 148 curl -s 'https://haveibeenpwned.com/api/v3/subscription/status' \ 149 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' \ 150 | jq '{SubscriptionName,Rpm,DomainSearchMaxBreachedAccounts}' 151 152 # which breaches hold this address; truncateResponse=false is what gets you the dates 153 curl -s 'https://haveibeenpwned.com/api/v3/breachedAccount/target@example.com?truncateResponse=false' \ 154 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' \ 155 | jq -r '.[] | "\(.BreachDate) \(.Name)"' 156 157 # include unverified corpora — more hits, weaker provenance, so record the flag you used 158 curl -s 'https://haveibeenpwned.com/api/v3/breachedAccount/target@example.com?truncateResponse=false&IncludeUnverified=true' \ 159 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' | jq 'length' 160 161 # k-anonymity account search: the address never leaves your machine, only six hex characters do 162 H=$(printf 'target@example.com' | shasum -a 1 | cut -c1-40 | tr 'a-f' 'A-F') 163 curl -s "https://haveibeenpwned.com/api/v3/breachedaccount/range/${H:0:6}" \ 164 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' \ 165 | jq -r --arg suffix "${H:6}" '.[] | select(.hashSuffix == $suffix) | .websites[]' 166 167 # paste sites that carried the address, which often predate the breach being named 168 curl -s 'https://haveibeenpwned.com/api/v3/pasteAccount/target@example.com' \ 169 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' 170 171 # every breached address under a domain you have proven you control 172 curl -s 'https://haveibeenpwned.com/api/v3/breachedDomain/example.com' \ 173 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' 174 175 # which domains you have actually verified, when a run comes back suspiciously empty 176 curl -s 'https://haveibeenpwned.com/api/v3/subscribedDomains' \ 177 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' | jq -r '.[].DomainName' 178 179 # stealer-log hits — infostealer output, so far more recent than breach corpora 180 curl -s 'https://haveibeenpwned.com/api/v3/stealerLogsByEmail/target@example.com' \ 181 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' 182 183 # the same, across a verified domain: which of your subject's colleagues ran malware 184 curl -s 'https://haveibeenpwned.com/api/v3/stealerLogsByEmailDomain/example.com' \ 185 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' 186 187 # which sites a stealer-infected machine had credentials for — a browsing-history proxy 188 curl -s 'https://haveibeenpwned.com/api/v3/stealerLogsByWebsiteDomain/example.com' \ 189 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' 190 ``` 191 192 The password range endpoint needs no key, is not rate limited, and never sees the password: 193 194 ```bash 195 # only the first five SHA-1 characters leave your machine 196 printf 'hunter2' | shasum -a 1 | tr 'a-f' 'A-F' | cut -c1-5 \ 197 | xargs -I{} curl -s "https://api.pwnedpasswords.com/range/{}" | head -3 198 199 # pad the response with dummy rows so its size tells an observer nothing about the 200 # prefix; padded rows always carry a count of 0, so discard them before reading 201 curl -s -H 'Add-Padding: true' 'https://api.pwnedpasswords.com/range/5BAA6' \ 202 | awk -F: '$2 != 0' | head -3 203 204 # NTLM suffixes instead of SHA-1, for checking a dumped AD hash against the corpus. 205 # NTLM suffixes are 27 characters where SHA-1 suffixes are 35 — a length mismatch 206 # when you diff against a local list means you queried the wrong mode 207 curl -s 'https://api.pwnedpasswords.com/range/8846F?mode=ntlm' | head -3 208 ``` 209 210 The k-anonymity account endpoint is the one worth building a habit around: it sends six hex 211 characters of a SHA-1 and matches the remaining suffix locally, so the address you are 212 investigating is never transmitted. The response carries `hashSuffix` and `websites` — not 213 `breaches`, which is the field name people assume and then silently get `null` from. 214 215 Omitting `user-agent` returns 403 rather than a useful error. `breachedAccount` truncates by 216 default, returning only breach names — if your output has no dates in it, you forgot 217 `truncateResponse=false`, and a report built on that output cannot say when anything happened. A 218 429 carries a `retry-after` header in seconds; honour it, because the limit is per key and 219 hammering it gets the key suspended. And the output tells you a corpus containing that address 220 was published — not that your subject created the account, not that they still use the address, 221 and not what the password was. 222 223 ### Intelligence X 224 225 Web-first, and the broadest selector search available without a corporate contract: it indexes 226 leaks, darknet pages, document dumps and its own historical web crawl, and it searches by 227 selector type rather than free text. Reach for it when an identifier returns nothing elsewhere. 228 229 Paste the selector at [intelx.io](https://intelx.io/) and read the result pane by bucket — the 230 left-hand facets split hits into leaks, darknet, web and documents, and the bucket matters more 231 than the hit count. Selectors it understands: 232 233 ```text 234 target@example.com email address 235 example.com domain, including subdomain hits 236 198.51.100.0/24 CIDR range 237 +14155550123 phone number, E.164 238 1BoatSLRHtKNngkdXEeobR76b53LETtpyT cryptocurrency address 239 d41d8cd98f00b204e9800998ecf8427e hash or document selector 240 ``` 241 242 For the record, capture the item's **date added** and its bucket, not just the snippet — 243 Intelligence X keeps items long after the source is gone, so the snippet alone cannot be re-verified. The API 244 takes the key from the developer tab of your account in an `x-key` header; phonebook (bulk 245 selector extraction) and most export volume are paid tiers, and the free tier is metered tightly 246 enough that you will feel it inside an hour. 247 248 ### OCCRP Aleph and Library of Leaks 249 250 Aleph is a document-and-entity index built for cross-border corruption work: leaked archives, 251 scraped registries, sanctions lists and court filings normalised into one searchable entity 252 graph. It beats a people-search aggregator whenever the subject appears in documents rather than 253 directories. [Library of Leaks](https://search.libraryofleaks.org/) is the same software over a 254 different, leak-heavy corpus. 255 256 ```bash 257 pipx install alephclient 258 259 # register free, then take the key from your Aleph user profile — anonymous API calls get a 401 260 export ALEPHCLIENT_HOST=https://aleph.occrp.org 261 export ALEPHCLIENT_API_KEY=REPLACE_ME 262 263 # people matching a name, across every dataset you can read 264 curl -s -G 'https://aleph.occrp.org/api/2/entities' \ 265 -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" \ 266 --data-urlencode 'q=Sergei Ivanov' --data-urlencode 'filter:schema=Person' \ 267 | jq -r '.results[] | "\(.properties.name[0]) \(.collection.label)"' 268 269 # companies instead of people — the usual pivot off a director's name 270 curl -s -G 'https://aleph.occrp.org/api/2/entities' \ 271 -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" \ 272 --data-urlencode 'q=Sergei Ivanov' --data-urlencode 'filter:schema=Company' | jq '.total' 273 274 # which datasets exist, so you can say what you did and did not search 275 curl -s 'https://aleph.occrp.org/api/2/collections?limit=50' \ 276 -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" \ 277 | jq -r '.results[] | "\(.foreign_id) \(.label)"' 278 279 # one entity in full, including the documents it was extracted from 280 curl -s 'https://aleph.occrp.org/api/2/entities/ENTITY_ID' \ 281 -H "Authorization: ApiKey $ALEPHCLIENT_API_KEY" | jq '.properties' 282 283 # push your own case documents in so they are indexed alongside the public corpora 284 alephclient crawldir --foreign-id my-case-2026 ./case-documents 285 ``` 286 287 Names in Aleph are transliterated inconsistently because the sources are, so run the variants 288 from [username and account work](/sheets/osint/usernames-and-accounts) before concluding a name 289 is absent. An entity is an extraction from a document, which means both the spelling and the 290 role can be wrong; open the source document before you cite it. Uploading case documents sends 291 them to someone else's server — check that is acceptable for your material first. 292 293 ### CourtListener and RECAP 294 295 Free, keyless-to-browse access to US federal dockets, opinions and PACER filings that other 296 researchers have paid for and donated. For a US subject this is the best single documentary 297 source on this page, because a filing names addresses, employers, counsel and relatives in one 298 place. 299 300 ```bash 301 # token from your free account profile; note the literal word "Token" 302 export CL_TOKEN=REPLACE_ME 303 304 # federal dockets mentioning a name (type=r gives dockets with nested documents) 305 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \ 306 -H "Authorization: Token $CL_TOKEN" \ 307 --data-urlencode 'q="Dana Whitfield"' --data-urlencode 'type=r' \ 308 | jq -r '.results[] | "\(.dateFiled) \(.court) \(.caseName)"' 309 310 # case law opinions instead of dockets 311 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \ 312 -H "Authorization: Token $CL_TOKEN" \ 313 --data-urlencode 'q="Dana Whitfield"' --data-urlencode 'type=o' | jq '.count' 314 315 # narrow to one court and a date window 316 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \ 317 -H "Authorization: Token $CL_TOKEN" \ 318 --data-urlencode 'q=Whitfield' --data-urlencode 'type=d' \ 319 --data-urlencode 'court=txwd' --data-urlencode 'filed_after=2020-01-01' 320 321 # judges, for checking who heard a case 322 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \ 323 -H "Authorization: Token $CL_TOKEN" \ 324 --data-urlencode 'q=Whitfield' --data-urlencode 'type=p' 325 326 # the docket itself, including the parties 327 curl -s 'https://www.courtlistener.com/api/rest/v4/dockets/?id=12345' \ 328 -H "Authorization: Token $CL_TOKEN" | jq '.results[0] | {case_name,date_filed,assigned_to_str}' 329 330 # page with the cursor the previous response handed back, not an offset 331 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' \ 332 -H "Authorization: Token $CL_TOKEN" \ 333 --data-urlencode 'q=Whitfield' --data-urlencode 'type=r' --data-urlencode 'cursor=CURSOR' 334 ``` 335 336 RECAP holds what somebody has already fetched from PACER, so absence means nobody bought that 337 document, not that the case does not exist — check PACER's own index before saying there is no 338 case. Search results are cached for ten minutes, so polling for new filings wastes your quota; 339 use the Alert API for monitoring. State courts are mostly absent, which is where most US 340 litigation actually happens. 341 342 ### OpenSanctions 343 344 Sanctions lists, politically-exposed-person data and criminal watchlists, merged and deduplicated 345 into one entity model with a matching API. Use it to answer "is this person on a list" properly, 346 rather than eyeballing a dozen national PDFs — and to record a clean negative. 347 348 ```bash 349 export OS_KEY=REPLACE_ME 350 351 # full-text search, for when you only have a name 352 curl -s -G 'https://api.opensanctions.org/search/default' \ 353 -H "Authorization: ApiKey $OS_KEY" --data-urlencode 'q=Sergei Ivanov' \ 354 | jq -r '.results[] | "\(.caption) \(.schema) \(.datasets|join(","))"' 355 356 # proper screening: describe the entity and let the matcher score candidates 357 curl -s -X POST 'https://api.opensanctions.org/match/default' \ 358 -H "Authorization: ApiKey $OS_KEY" -H 'Content-Type: application/json' \ 359 -d '{"queries":{"q1":{"schema":"Person","properties":{"name":["Sergei Ivanov"],"birthDate":["1965"],"country":["ru"]}}}}' \ 360 | jq -r '.responses.q1.results[] | "\(.score) \(.caption) \(.datasets|join(","))"' 361 362 # one entity in full, with every list that carries it and why 363 curl -s 'https://api.opensanctions.org/entities/NK-A7z1Z' \ 364 -H "Authorization: ApiKey $OS_KEY" | jq '{caption,datasets,properties}' 365 366 # which lists are in the index, so your negative result has a defined scope 367 curl -s 'https://api.opensanctions.org/catalog' | jq -r '.datasets[].name' | head -30 368 ``` 369 370 A date of birth or a country code moves the score far more than extra name tokens; a bare name 371 query on a common name returns confident nonsense. The score is a similarity, not a finding — 372 anything you publish needs the underlying list entry read by a human. Trial keys come free with 373 a business email and public-interest keys are granted for journalism and research; if the metering 374 gets in the way, the matching engine (`yente`) is open source and self-hostable against the same 375 free bulk data. 376 377 ### EDGAR full-text search 378 379 Free, keyless, and routinely forgotten in people work: every SEC filing since 2001 is full-text 380 searchable, and filings name directors, officers and beneficial owners with addresses. A 381 Form D or a proxy statement is a dated, signed document naming a person — which is exactly the 382 kind of source an aggregator hit is not. 383 384 ```bash 385 # the SEC requires a descriptive User-Agent with contact details; without one you get blocked 386 UA='osint-research research@example.com' 387 388 # every filing mentioning a name 389 curl -s -A "$UA" 'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22' \ 390 | jq -r '.hits.hits[] | "\(._source.file_date) \(._source.display_names[0])"' 391 392 # restrict to a form type — Form D names the directors of a private placement 393 curl -s -A "$UA" 'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22&forms=D' 394 395 # date-bounded, which is how you tie a person to a company in a given year 396 curl -s -A "$UA" \ 397 'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22&dateRange=custom&startdt=2019-01-01&enddt=2021-12-31' 398 399 # every filing by one company, from its CIK 400 curl -s -A "$UA" 'https://data.sec.gov/submissions/CIK0000320193.json' \ 401 | jq '{name,addresses,formerNames}' 402 ``` 403 404 The browsable version is at [sec.gov/edgar/search](https://www.sec.gov/edgar/search/), and it is 405 the right place to read a hit. Full-text coverage starts in 2001; older filings are indexed by 406 company but not searchable by content. A name in a filing is the name as filed, so middle 407 initials and suffixes are inconsistent across years. 408 409 ### Ratsit 410 411 Web only, Sweden only, and far more revealing than anything equivalent elsewhere: registered 412 address, year and month of birth, income bracket, property and vehicle flags, and who else is 413 registered at the address. Swedish population-register data is public, so this is a legitimate 414 primary source rather than a broker's guess. 415 416 Search the name at [ratsit.se](https://www.ratsit.se/), narrow by county when the name is common, 417 and read the profile page. For the record, capture these fields and nothing inferred from them: 418 419 ```text 420 Folkbokförd adress registered address, i.e. where the state believes they live 421 Född birth year and month (day is withheld on the free view) 422 Inkomst / Taxeringsår income bracket AND the assessment year it belongs to 423 Fordon / Fastighet vehicle and property flags, each a pointer to another register 424 Personer på adressen others registered at the same address — household, not family 425 ``` 426 427 The income figure is always a year or two behind and is meaningless without the assessment year 428 printed beside it. 429 430 **Search logged out.** Ratsit sells subjects a paid feature listing the logged-in users who 431 looked them up; anonymous searches leave no entry in that log. Mrkoll, the nearest competitor, 432 shows subjects a profile-view count but not identities. Either way, an account turns a passive 433 lookup into something the subject can notice. 434 435 ### US people-search aggregators 436 437 [FastPeopleSearch](https://www.fastpeoplesearch.com/), [That's Them](https://thatsthem.com/) and 438 [Radaris](https://radaris.com/) are free, web only, and the fastest route to a candidate address 439 and phone for a US subject. They are also data brokers reselling scraped and purchased records of 440 unknown age. 441 442 Enter the name plus a city or state — a bare name on a common surname is unusable. Read the 443 result page as three separate claims with separate reliability: current address, phone numbers, 444 and "possible relatives". The first two are checkable against a county property or voter record; 445 the third is inference from shared addresses and surnames and is wrong often enough that 446 repeating it is reckless. 447 448 ```text 449 Dana Whitfield Austin TX name + city: the only query form that works 450 Dana Whitfield 78701 name + ZIP, when the city name is ambiguous 451 (512) 555-0123 reverse phone, usually the highest-precision entry point 452 1200 Example St, Austin TX reverse address, to enumerate the household 453 ``` 454 455 Capture the page with an archiving tool, because broker pages change without notice — see 456 [archiving and evidence](/sheets/osint/archiving-and-evidence). 457 458 These sites are also the mechanism by which your subject's data is public in the first place; most 459 carry an opt-out form, and a subject who has used it will be absent from the broker while still 460 present in the underlying county record. Absence here means nothing. 461 462 ### Pipl 463 464 **Sales-gated since its pivot to enterprise identity resolution.** There is no self-serve tier, 465 no web search for individuals, and contracts start in the thousands of dollars a year. Treat the 466 Pipl entry in the table below as historical. For the same job without a contract, the live 467 options are the registry-first route above, Intelligence X for selector search, and OSINT 468 Industries or Osintly if you need a commercial aggregator with per-query pricing. 469 470 ## Breach and leak data 471 472 Useful for confirming that an identifier was in use, and for pivoting between an email, a username 473 and a phone number. Handle carefully: this is other people's stolen data. 474 475 | Tool | What it does | Cost | 476 | --- | --- | --- | 477 | [Have I Been Pwned](https://haveibeenpwned.com/) | Authoritative check for whether an address appears in a known breach. Does not expose passwords. | free | 478 | [DeHashed](https://dehashed.com/) | Searchable breach aggregator across emails, usernames, names, phones and IPs. | partly free | 479 | [Intelligence X](https://intelx.io/) | Searches leaks, darknet, document archives and historical web by selector. | partly free | 480 | [Leak-Lookup](https://leak-lookup.com/) | Breach index with API access. | partly free | 481 | [DiscordLeaks](https://discordleaks.unicornriot.ninja/) | Searchable archive of leaked far-right Discord servers, maintained by Unicorn Riot. | free | 482 483 Do not put a live target's credentials into a third-party lookup you do not control, and do not 484 treat a password from a breach as authorisation to use it. 485 486 DeHashed is the one worth a note on access: it is credit-metered now, and the old 487 basic-auth `api.dehashed.com/search?query=` endpoint that circulates in every scripted wrapper is 488 retired. The current API is v2, documented behind a login at 489 [dehashed.com/docs](https://dehashed.com/docs), so check the endpoint there rather than copying a 490 wrapper. The web search works without any of 491 that. Leak-Lookup's free tier is a hash-only check; its searchable API is paid. 492 493 ## Tool reference 494 495 | Tool | What it does | Cost | 496 | --- | --- | --- | 497 | [192](http://www.192.com/) | Searching for someone's address in the UK, phone number and who they live with according to electoral rolls. | free | 498 | [Eniro](https://www.eniro.se/) | Yellow Pages (Swedish Edition) | free | 499 | [Epieos](https://tools.epieos.com/holehe.php) | Checks where an email has been used. Based on Holehe. | paid | 500 | [FastPeopleSearch](http://fastpeoplesearch.com/) | Mostly good for US. | free | 501 | [GetContact](https://www.getcontact.com/en/) | Phonenumber ID app - draws from crowdsourced contactbooks | free | 502 | [Ghunt](https://github.com/mxrch/GHunt) | A command line tool for obtaining information about Google accounts. | free | 503 | [Hitta.se](https://www.hitta.se/) | Mapping service for Sweden | free | 504 | [Intelx](http://intelx.io/) | Find user details in data breaches | partly free | 505 | [NigeriaPhonebook](https://nigeriaphonebook.com/) | Look up by name, state, and phone number. Last names are partially censored for free accounts. | free | 506 | [Person Lookup](https://personlookup.co.za/) | find individuals, phonenumbers, and adresses | free | 507 | [Pipl](http://pipl.com/) | Identity information for professionals | paid | 508 | [Ratsit](https://www.ratsit.se/) | Look up phone numbers/names (Sweden) | free | 509 | [Search Systems](https://www.searchsystems.net/) | Finding public record information online in over 70,000 databases organized by type and location to help you find property, criminal, court, birth, death… | free | 510 | [Skopenow](https://www.skopenow.com/) | Social Media Investigations - name, phone, email, username searches. | paid | 511 | [Spokeo](http://spokeo.com/) | People search through email, phone, name | paid | 512 | [Swedish Name Register](https://scb.se/hitta-statistik/sverige-i-siffror/namnsok/) | Find out how common a name is in Sweden based on census data | free | 513 | [The Law Pages](https://www.thelawpages.com/court-cases/court-case-search.php?mode=1) | Search criminal court case details in the UK, such as sentence, hearing, defendant, etc. | free | 514 | [ThisNumber](https://sur.ly/o/numberway.com/AA000014) | An international directory of white pages and yellow pages phone books, and online directory enquiries. It's a free, independent and up-to-date guide to… | free | 515 | [TrueCaller](https://www.truecaller.com/) | Truecaller is a caller ID app that identifies incoming calls, blocks unwanted numbers, and gathers phone numbers and names from contact lists. It also… | partly free | 516 | [TruffleHog](https://trufflesecurity.com/trufflehog) | Find leaked credentials. | free | 517 | [Worldwide Osint Tools map](https://cipher387.github.io/osintmap/) | Global overview of yellow/white pages, court cases, business registries etc. | free | 518 | USA court case databases | State-by-state guide for researching criminal and civil court cases | partly free | 519 520 ## Pitfalls 521 522 - **Aggregators invent relatives.** "Possible relatives" lists are inference from shared addresses 523 and surnames. They are frequently wrong and occasionally defamatory. 524 - **Stale addresses.** Someone moved five years ago; the aggregator still shows the old address as 525 current. Date every claim. 526 - **Name collisions.** Common names across a large population produce confident, wrong matches. 527 Require a second identifier — date of birth, middle initial, employer. 528 - **Jurisdiction and legality.** Accessing some records requires a declared lawful purpose. Bulk 529 collection of personal data about EU residents engages the GDPR regardless of the data being 530 public. 531 532 ## Worked example 533 534 One datum: the name **Dana Whitfield**, typed under a signature on a PDF that also carries a 535 Travis County, Texas address block. Nothing else. 536 537 1. **Establish the jurisdiction's real sources.** [Search Systems](https://www.searchsystems.net/) 538 lists the Travis County clerk, district clerk and appraisal district portals. That tells you 539 where the authoritative property and civil records live before you touch an aggregator. 540 2. **Federal dockets.** `type=r` search on CourtListener for `"Dana Whitfield"` returns one 2021 541 docket in the Western District of Texas. The docket's party block gives a street address and 542 the name of a law firm — two new pivots, from a dated court document. 543 3. **Filings.** EDGAR full-text search for the same name, `forms=D`, returns a 2022 Form D naming 544 her as a director of a private company, with a business address in Austin and a company CIK. 545 4. **Company side.** The CIK into `data.sec.gov/submissions/CIK….json` gives the company's former 546 names and address history, which is how you find out the entity was renamed in 2023 — the 547 reason a plain name search missed it. 548 5. **Screening, including the negative.** The OpenSanctions `/match/default` call with 549 `name`, `country=us` and the birth year inferred from the docket returns no result above 0.6. 550 Record that as a checked negative with the datasets listed, not as "nothing found". 551 6. **Identifier confirmation.** The business email in the Form D goes into HIBP 552 `breachedAccount`. Two corpora dated 2019 and 2021 hold it, which confirms the address was in 553 use across that window — and nothing more. 554 7. **Aggregator, last.** That's Them on "Dana Whitfield, Austin TX" returns three candidate 555 addresses, one matching the docket. The other two, and the whole "possible relatives" block, 556 stay in the notes as unverified inference. 557 558 The whole run, as commands: 559 560 ```bash 561 UA='osint-research research@example.com' 562 export CL_TOKEN=REPLACE_ME OS_KEY=REPLACE_ME HIBP_KEY=REPLACE_ME 563 564 curl -s -G 'https://www.courtlistener.com/api/rest/v4/search/' -H "Authorization: Token $CL_TOKEN" \ 565 --data-urlencode 'q="Dana Whitfield"' --data-urlencode 'type=r' | jq -r '.results[].caseName' 566 567 curl -s -A "$UA" 'https://efts.sec.gov/LATEST/search-index?q=%22Dana+Whitfield%22&forms=D' \ 568 | jq -r '.hits.hits[] | "\(._source.file_date) \(._source.display_names[0])"' 569 570 curl -s -A "$UA" 'https://data.sec.gov/submissions/CIK0001234567.json' | jq '{name,formerNames}' 571 572 curl -s -X POST 'https://api.opensanctions.org/match/default' -H "Authorization: ApiKey $OS_KEY" \ 573 -H 'Content-Type: application/json' \ 574 -d '{"queries":{"q1":{"schema":"Person","properties":{"name":["Dana Whitfield"],"country":["us"]}}}}' \ 575 | jq -r '.responses.q1.results[] | "\(.score) \(.caption)"' 576 577 curl -s 'https://haveibeenpwned.com/api/v3/breachedAccount/dana@example.com' \ 578 -H "hibp-api-key: $HIBP_KEY" -H 'user-agent: osint-research' | jq -r '.[].Name' 579 ``` 580 581 What you can assert: a named person, tied by two independent dated documents to one company and 582 one city, with one address corroborated by a court filing. What you cannot: anything the 583 aggregator alone said, and any relationship nobody filed. 584 585 What would falsify it: the docket and Form D resolving to different people once a middle name, 586 date of birth or signature is compared; the apparent address match being a forwarding or business 587 address shared by unrelated parties; or the filing being amended or withdrawn. The company-and- 588 city link survives only while the two primary documents point to the same natural person. 589 590 ## Broader catalogues 591 592 - [People OSINT](https://tools.osintnewsletter.com/tool-categories/people-osint) 593 - [Public Records OSINT](https://tools.osintnewsletter.com/tool-categories/public-records-osint) 594 - [Breached Data Provider OSINT](https://tools.osintnewsletter.com/tool-categories/breached-data-provider) 595 596 597 ## More tools 598 599 Further tools for this area from the OSINT Newsletter Tools Library ([People OSINT](https://tools.osintnewsletter.com/tool-categories/people-osint), [Public Records OSINT](https://tools.osintnewsletter.com/tool-categories/public-records-osint), [Breached Data Provider OSINT](https://tools.osintnewsletter.com/tool-categories/breached-data-provider)), excluding those already listed above. 600 601 | Tool | What it does | 602 | --- | --- | 603 | [192.com](https://www.192.com/) | UK-based online directory that helps you find information about people, addresses, businesses, and property records in the UK. | 604 | [4shared](https://www.4shared.com/) | File-sharing and cloud-storage platform with a public search function. | 605 | [Aeroleads](https://aeroleads.com/) | A prospecting and contact discovery platform that helps users find professional email addresses, phone numbers, company… | 606 | [AllPeople](https://allpeople.com/) | A people-search and contact directory tool (US) that aggregates publicly available contact information to help identify… | 607 | [Analyst Research Tools](https://analystresearchtools.com/) | A browser-based investigative research platform pulling together a collection of free lookup tools to help you gather, organise… | 608 | [AnyWho](https://www.anywho.com/) | US- focused people-search and directory tool to find publicly available contact information, including names, phone numbers, and… | 609 | [Australia Public Record](https://www.australiapublicrecord.com/) | Searches Australian public records to uncover people, businesses, properties, court records, and other publicly available… | 610 | [BeenVerified](https://www.beenverified.com/) | People-search and background research platform that aggregates publicly available records into a single interface. | 611 | [BIS Data Portal](https://data.bis.org/) | Public platform for exploring, analysing, and downloading international financial and economic statistics. | 612 | [Business registers in EU countries](https://e-justice.europa.eu/topics/registers-business-insolvency-land/business-registers-eu-countries_en) | An official European Union portal providing access to national business registers across EU Member States. | 613 | [Buzzglobe](https://buzzglobe.com/) | Social-media search aggregator for discovering publicly indexed profiles, pages, posts and images across multiple platforms. | 614 | [Congressional Trader](https://congressional-trader.com/) | Search and review public U.S. congressional stock trade disclosures for lawmakers, tickers, states, and recent transactions. | 615 | [Corp Watch](https://www.corpwatch.org/) | A non-profit investigative research platform that tracks corporate activity, accountability, environmental issues, human rights… | 616 | [Corporation Wiki](https://www.corporationwiki.com/) | An online corporate intelligence database that aggregates public records on companies, directors, officers, and business… | 617 | [dilisense](https://dilisense.com/en) | An AML/KYC screening and risk-intelligence platform that consolidates sanctions, PEPs, criminal watchlists, and adverse-media… | 618 | [District 4 Labs Darkside](https://portal.district4labs.net/search) | An OSINT search platform that aggregates breached data, darknet intelligence, and leaked datasets into one searchable interface. | 619 | [EDGAR Full Text Search](https://www.sec.gov/edgar/search/#) | Enables search across millions of filings submitted to the U.S. Securities and Exchange Commission (SEC). | 620 | [EU Sanctions Map](https://www.sanctionsmap.eu/#/main) | An official public resource that provides a user-friendly overview of sanctions regimes adopted by the European Union. | 621 | [Eyedex](https://www.eyedex.org/) | An open directory search engine that indexes publicly accessible web directories & allows users to search across petabytes of… | 622 | [Federal Procurement Data System (FPDS)](https://sam.gov/contracting) | Official U.S. government database for federal contract spending. | 623 | [Footprint IQ](https://footprintiq.app/) | Scans usernames, emails, and phone numbers across 500+ public sources to map a subject's digital footprint and calculate an… | 624 | [Forebears](https://forebears.io/) | A global surname and genealogy database. | 625 | [Free Full PDF](https://www.freefullpdf.com/) | Academic search engine focused on locating freely available full-text scientific PDFs, including journal articles, theses… | 626 | [FreewareWeb FTP Search](https://www.freewareweb.com/copyright.shtml) | A specialised search engine that searches indexed FTP sites for files and directories using filenames, keywords, file types… | 627 | [Gravatar](https://gravatar.com/site/check) | An avatar service that allows you to determine whether an email address is associated with a publicly available Gravatar profile. | 628 | [GrayhatWarfare](https://grayhatwarfare.com/) | Search engine for publicly exposed files stored in cloud storage services such as AWS S3, Azure Blob Storage, Google Cloud… | 629 | [Have I Been Pwned?](https://haveibeenpwned.com/) | Check whether an email address, password, or domain has appeared in known data breaches. | 630 | [Hippie OSINT Toolkit](https://osint.hippie.cat/) | An OSINT web toolkit that allows you to reverse search a domain, a TikTok post, an image, or username (and more). | 631 | [Hudson Rock](https://www.hudsonrock.com/) | A cybercrime intelligence platform that lets you search for compromised credentials, infected machines, and exposed corporate… | 632 | [IDCrawl](https://www.idcrawl.com/) | A free people, username, reverse phone and reverse email search tool. | 633 | [Import Yeti](https://www.importyeti.com/) | A supply chain intelligence tool that helps users discover who imports products into the United States and which overseas… | 634 | [Indicia](https://indicia.app) | A Software-as-a-Service (SaaS)) platform for professional investigations, leveraging AI-powered tools to perform digital… | 635 | [LeakData.io](https://leakdata.io/en) | A breach intelligence platform that checks authorised emails, usernames, phone numbers, and domains against indexed breach data. | 636 | [Leaker](https://github.com/vflame6/leaker) | A passive reconnaissance CLI tool that aggregates credential leak data from multiple breach databases, supporting searches by… | 637 | [LeakIX](https://leakix.net/) | Search engine and monitoring platform that indexes exposed services, misconfigurations, and leaked/publicly accessible data from… | 638 | [Library of Leaks](https://search.libraryofleaks.org/) | A searchable archive of leaked datasets, documents, and exposed information sources. | 639 | [LittleSis](https://littlesis.org/) | A public-interest database that maps relationships between powerful people and organisations (mostly U.S.) | 640 | [Lullar](https://com.lullar.com/en/tools) | A free people-search engine that checks a username, email, or name across 170+ social media and online platforms in one query. | 641 | [Names Directory](https://namesdir.com/) | A web-based name-association search tool to search for first names associated with surnames and surnames associated with first… | 642 | [NAMINT](https://seintpl.github.io/NAMINT/) | A web app that generates multiple username, email, and naming combinations from a person’s first, middle, and last name. | 643 | [North Data](https://www.northdata.com/) | A business intelligence platform providing access to company records, corporate structures, financial information and ownership… | 644 | [Nuwber](https://nuwber.com/) | People-search and data-broker platform used to identify and cross-reference individuals using names, telephone numbers, addresses… | 645 | [OFAC Sanctions List Search](https://sanctionssearch.ofac.treas.gov/) | The U.S. Office of Foreign Assets Control (OFAC) sanctions database that identifies individuals, companies, vessels and… | 646 | [OpenCorporates](https://opencorporates.com/) | One of the largest open databases of company information in the world, aggregating official corporate registry data from… | 647 | [OpenSecrets](https://www.opensecrets.org/) | A non-partisan transparency platform that tracks money in U.S. politics. | 648 | [OSINT Industries](https://app.osint.industries/) | An all-encompassing OSINT platform that gathers and correlates publicly available digital data such as emails, domains, phone… | 649 | [OSINT Tools Map](https://cybdetective.com/osintmap/) | An interactive directory of country-specific OSINT resources, including phonebooks, cadastral maps, business registers, court… | 650 | [Osintly](https://osint.ly/) | A unified OSINT platform that searches for information across pseudonyms, email addresses, phone numbers, IP addresses, domains… | 651 | [Predicta Search](https://www.predictasearch.com/) | Reverse email, phone number, username or name lookup. | 652 | [Radaris](https://radaris.com/) | A people-search and information-aggregation service that allows you to search for information associated with individuals… | 653 | [Sanctions Atlas](https://sanctionsatlas.com/) | A sanctions intelligence platform that brings together global sanctions lists, watchlists and ownership data. | 654 | [SearchShared](https://www.searchshared.info/) | File-sharing search engine for locating publicly indexed/shared files across multiple hosting services. | 655 | [Sherlock Eye](https://www.sherlockeye.io/) | AI-powered OSINT assistant that automates investigations, links data, and surfaces insights fast. | 656 | [SynapsInt](https://synapsint.com/) | A web-based search platform that aggregates publicly available data about people, organisations, domains, IP addresses, email… | 657 | [That's Them](https://thatsthem.com/) | A free people-search engine (US) to help find individuals through names, phone numbers, emails, and addresses. | 658 | [The World Bank Open Data Catalog](https://datacatalog.worldbank.org/) | A searchable repository of development-related datasets, providing access to data, metadata, downloadable resources and, for some… | 659 | [TheBigBrother](https://github.com/chadi0x/TheBigBrother) | All-in-one OSINT toolkit that helps track usernames across the web, investigate emails and domains, extract metadata, and follow… | 660 | [UN Comtrade Database](https://comtradeplus.un.org/) | United Nations' database of detailed international trade statistics providing official trade data reported by countries and areas. | 661 | [United States Patent and Trademark Office (USPTO)](https://www.uspto.gov/) | A public database for digging into patents, trademarks, and intellectual property filings. | 662 | [Wikispooks](https://wikispooks.com/wiki/Main_Page) | An independent, collaboratively edited research wiki focused on people, organisations, events, documents and alleged networks of… | 663 | [XposedOrNot](https://xposedornot.com/) | Free data breach search engine. | 664 665 ## Sources 666 667 Both catalogues below are maintained by other people and are considerably larger than 668 this page. Use them as the canonical index; this sheet is a working route through them. 669 670 - [Bellingcat's Online Investigation Toolkit](https://bellingcat.gitbook.io/toolkit) — ~340 tools, each with its own 671 review page covering cost, difficulty, requirements and limitations. 672 - [OSINT Newsletter Tools Library](https://tools.osintnewsletter.com) — ~280 tools, organised by investigative goal. 673 674 Neither publishes a licence, so nothing here is copied from them: tool names, one-line 675 descriptions, cost flags and links are catalogue facts, and the method and commentary are 676 this site's own. See [credits](/credits).