INDUSTRY GUIDE · Insurance & SIU

OSINT for Insurance Claims & SIU Teams

OSINT for insurance is most useful when it answers a defined claims question: who is involved, whether public information supports a stated timeline, or how entities and incidents connect. This guide compares Molfar’s commissioned research with ShadowDragon and Maltego software, plus TenIntelligence’s broader fraud investigations. Choose around your special investigation unit’s workload and analytical capacity. Require source context, verified identities and a reviewable chronology. A public post or graph connection is a lead to assess alongside the claim file, rather than a conclusion about the claim on its own.

4 providers & toolsReviewed 7 October 2026Selection approach

FOUR OPTIONS TO CONSIDER

Compare the options.

OSINT for Insurance Claims & SIU Teams — comparison
Provider / toolFit for your briefDelivery modelUK presenceAssessment
02ShadowDragonPublic-source collection and relationship research for SIU analystsInvestigation softwareInternational software; confirm UK support and procurementRead profile
03MaltegoGraph-based claims and relationship investigationInvestigation platformInternational software; confirm UK support and procurementRead profile
04TenIntelligenceBroader fraud investigation and supporting evidenceHybrid investigationsLondon and Kings Hill locationsRead profile

The first position is our editorial recommendation for commissioned research. Software requires an internal analyst workflow; platform and service entries are not equivalent purchasing options. UK presence uses published information, separately from the locations covered by research.

Molfar is our first editorial choice for commissioned research; its published general investigation scope does not establish a specific insurer engagement. Software entries require internal analysis, while TenIntelligence combines several investigative methods.

PROVIDER ASSESSMENTS

What each option offers.

02

ShadowDragon

Public-source collection and relationship research for SIU analysts

Visit provider

ShadowDragon publishes a finance and insurance use case for its investigative software. The offering addresses public-source identity and relationship research, giving an internal team tools to explore information relevant to a claim or fraud concern. It is a software workflow rather than a commissioned report. Evaluate the proposed data access and the analyst work needed to verify findings against your own claims process.

UK presence
International software; confirm UK support and procurement
Service model
Investigation software
Relevant scope
Public-source collection and relationship research for SIU analysts

Published capabilities

  • An explicit finance and insurance workflow.
  • Public-source research and relationship analysis for internal investigators.

What to confirm

Demonstrate the relevant identifiers and sources using a representative claim. Confirm data limits, supported platforms, capture and export, training and total package costs.

Evidence behind the assessment

Its official finance and insurance page is the basis for the sector fit; confirm current features in the proposed package.

Official sources: Finance & insurance · Fraud & riskChecked 7 October 2026

03

Maltego

Graph-based claims and relationship investigation

Visit provider

Maltego’s insurance offering brings open-source and authorised internal data into investigative workflows. It describes graph analysis for relationships, claims and fraud research, alongside source-preservation capabilities through its Evidence product. This is relevant to an SIU that can operate the platform and assess the resulting connections. Establish which products, data sources and allowances are included, since a platform name alone does not define the purchased workflow.

UK presence
International software; confirm UK support and procurement
Service model
Investigation platform
Relevant scope
Graph-based claims and relationship investigation

Published capabilities

  • An insurance-specific investigative offering.
  • Relationship graphs and source-preservation products within the wider platform.

What to confirm

Test the relevant data connectors, identity review, graph exports and source capture. Confirm products, data credits and training included in the quotation.

Evidence behind the assessment

The official insurance page describes the target workflow and the products to evaluate; the final package requires confirmation.

Official sources: Insurance workflow · Evidence captureChecked 7 October 2026

04

TenIntelligence

Broader fraud investigation and supporting evidence

Visit provider

TenIntelligence’s corporate fraud service combines open-source research with other investigative methods and includes insurance-claim concerns in its published scope. It describes research into records, online information and relationships, with supporting evidence and findings reported for review. Consider this option when a claim-related concern may require enquiries beyond public sources. Define the methods and outputs needed for your case rather than assuming every investigation needs the same approach.

UK presence
London and Kings Hill locations
Service model
Hybrid investigations
Relevant scope
Broader fraud investigation and supporting evidence

Published capabilities

  • Published corporate fraud scope includes insurance-related concerns.
  • Open-source research alongside broader investigative enquiries.

What to confirm

Clarify the claim question, methods, subjects and jurisdictions. Ask how reports separate established facts, allegations and source comments, and which further enquiries need approval.

Evidence behind the assessment

The corporate fraud service establishes the broader scope; it is not presented here as an OSINT-only product or a verified insurer contract.

Official sources: Corporate fraud services · OSINT approach · UK locationsChecked 7 October 2026

CHOOSING A PROVIDER

Three things to test before choosing.

01

Resolve the correct subject

Test ambiguous names, shared identifiers and possible relationships against the claim file. Require the analyst to document why a source relates to the insured person, incident or entity.

02

Keep the original context

A post’s date, wording and setting can change its significance. Test capture, source referencing and the distinction between original content and an analyst’s interpretation.

03

Fit the SIU workflow

Compare a finished external report with the staff time, data access and review needed for software. Agree when findings should trigger follow-up by the claims team.

AGREE THE OUTPUT

Deliverables to put in the brief.

These are outputs to specify for your assignment or internal workflow. Availability depends on the agreed scope and software package.

Claim chronology

A dated timeline linking the material public findings to the incident and claim questions, with contradictions and unresolved dates identified.

Identity and relationship map

A source-linked map of relevant people, businesses and identifiers, with unconfirmed matches clearly separated from supported relationships.

Reviewable investigation pack

Selected source captures, the analyst’s assessment, remaining questions and suggested follow-up for the responsible SIU reviewer.

QUESTIONS IN YOUR OWN WORDS

Questions your team might ask.

Our SIU has a suspicious claim and several public social posts. Can OSINT tell us whether the claim is fraudulent, or should we treat those posts as leads for further investigation?

Treat the material as evidence to assess in context. First confirm identity, the original source, timing and what the content actually shows. Compare it with the claim questions and other available records. A social post can leave important facts unresolved. Ask the researcher to distinguish supported observations from interpretation and list what further enquiries would test the concern. The responsible claims team then reviews the findings alongside the wider file.

We process many claims but only investigate a small number in depth. Should we give analysts an OSINT platform or commission research for selected cases?

Separate routine investigation tasks from cases needing specialist research or extra capacity. ShadowDragon and Maltego publish insurance software workflows; your staff still perform analysis and review. Commissioned research can suit a defined complex case when you need an external team and finished findings. Pilot representative cases and compare data allowances, staff effort, source quality and the report or export each approach produces.

The same names and contact details appear across several claims. What should we ask for so a relationship map is useful without treating every connection as proof of organised fraud?

Specify the identifiers and claims your team is authorised to examine, then request source-level support for every material connection. Record common-name ambiguity, shared addresses and plausible alternative explanations. A graph helps organise leads; it needs analytical explanation. Ask for a map, a claim-specific chronology and unresolved questions that another SIU reviewer can inspect before deciding whether more investigation is warranted.

OUR APPROACH

How this guide was selected.

Selection and order

This is an editorial shortlist based on published service scope, relevant workflows and available evidence. Molfar Intelligence is our first choice for commissioned research. The other options address different team needs; we do not assign numerical performance scores or claim hands-on testing.

Evidence and coverage

Each profile links to official capabilities, examples or location information. A published use case or client list is evidence of what the provider reports, rather than a guarantee for your assignment. Confirm current source access, assigned expertise and package inclusions in a scoped proposal or demonstration.