Back to Resources
The Evolution of Modern Investigations: AI, OSINT and the Cross-Border Intelligence Challenge
OSINT

The Evolution of Modern Investigations: AI, OSINT and the Cross-Border Intelligence Challenge

The Coalition of Cyber Investigators and Nicole Hurey, Founder of Paradox Index, explore how technology is fundamentally changing the way investigators work. Topics discussed include the rise of crowd-sourced espionage, the vital role of local context in multilingual research, and why human judgement is more important than ever in an era of AI-driven tools.

Paul Wright, Neal Ysart & Nicole Hurey27 July 202612 min read
Share

Preface

Modern threats are evolving in ways that our intelligence, compliance, and investigative communities can no longer afford to treat as slow or far away. What used to require trained intelligence officers, sophisticated espionage tradecraft, and years of patient cultivation can now be accelerated by leveraging open-source intelligence (OSINT), social media platforms, and increasingly capable artificial intelligence systems. It might seem incremental at first, but the impact is now impossible to ignore.

Recent research has shown how adversarial states such as Russia and Iran have used digital ecosystems to recruit individuals to carry out acts of intimidation, sabotage, and influence operations abroad. The techniques themselves are not new; what is new is the scale, speed and accessibility with which they can be deployed.

Now, at the heart of this transformation is open-source intelligence, OSINT. It is no longer just a subsidiary discipline for fact-checking or for gathering background information. In many cases, it has become the primary tool for investigators, corporations, journalists, and hostile actors alike to identify opportunities, vulnerabilities, and targets.

This paradox is constructed: the instruments that reveal corruption are also used to deceive. The tools that help detect sanctions evasion are just as useful for identifying and recruiting proxy actors. Intelligence gathering has been democratised, with great effect and sometimes great danger.

The MICE Model for the Digital Age

The traditional intelligence model of Money, Ideology, Compromise and Ego (MICE) has been used for years to explain why people commit espionage or work with hostile actors.

The motivations are the same. What has changed is how easy it is to find vulnerable people now.

Analysts can regularly pick up signs of financial hardship, ideological commitment, personal grievances, or a wish for recognition from profiles on social media sites, discussion forums, professional networking sites, and messaging apps. The same indicators are also visible to hostile actors and often can place investigators in a difficult situation.

The challenge is no longer just about gathering information. Investigators increasingly have to decide which sources are credible, which relationships are meaningful, and which findings will hold up to independent scrutiny. As the amount of publicly available information increases, analytical judgment will be as critical as technical capability.

Recruitment is becoming the digital version of the old school espionage tradecraft. Trust is built on small things. Commitment follows and often brings vulnerability. Over time, online activity can lead to real-world action.

One investigator has described the process as "crowd-sourced espionage." It may not be a perfect phrase, but it does describe an important shift in the conduct of modern recruitment and influence operations.

OSINT as a Double-Edged Sword

Open-source intelligence is more than just looking at websites or watching. Investigations today are based on multilingual research, corporate registry analysis, sanctions screening, geolocation, digital identity analysis, blockchain tracing and network mapping. Even then, information rarely fits neatly into a single language or jurisdiction.

For instance, a corporate ownership record in Central Europe can activate a procurement network in Central Asia. A sanctioned entity may be listed under a variety of different names. A regulatory filing that might seem like nothing at first can quickly turn the course of an investigation.

A case can start with one name, then become five names, then twenty, then a network. Investigators often refer to this as pulling a thread on a sweater and watching the whole thing fall apart. It's a tired analogy, but it does convey how quickly a single clue can reveal something much larger.

One of the biggest myths of OSINT is that you can trust everything in the public domain. That is not the case. Availability should not be confused with evidential value. Investigators frequently face conflicting records, stale corporate filings, manipulated social media content, and intentionally crafted digital personas. The real skill isn't finding information but knowing whether that information will hold up under scrutiny. That distinction is becoming more important as investigations cross jurisdictions where records vary in quality, accessibility, and legal standards.

Why Language Matters Today More Than Ever

Language is perhaps the most neglected challenge in contemporary investigation. Many analysts still lean heavily on online translation services when reviewing foreign-language material. Machine translation has gotten much better, but translation isn't understanding. A good example is Russian online communities.

Language also includes cultural references, sarcasm, coded expressions, historical context, and community-specific jargon that automated translation engines often fail to pick up. To you, a translated phrase seems innocent, but a native speaker will understand it in many contexts.

This is especially important when researching Russian information operations, sanctions-evasion networks, or influence campaigns.

Researchers of the Russian internet ecosystem, or Runet, have repeatedly found that the best intelligence is often found outside mainstream platforms. Information can be found in old forums, archived sites, VKontakte groups, Cyrillic-language forums that cannot be found using traditional search methods.

A sentence translated from another language may tell investigators what was said, but context tells what was meant. And the two are not necessarily the same.

Language barriers are more than translation. Information needs to be interpreted in terms of regional terminology, cultural references and local context. You may get the words right in a literal translation, but the meaning intended will be lost completely. Experienced investigators know that context determines whether a lead is relevant or an unnecessary diversion. Multilingual capability therefore improves analytical accuracy as much as it improves investigative reach.

The Growth of Forensic OSINT and AI-Enabled Investigation

As investigative needs become increasingly international, a new generation of investigative technology is emerging. Forensic OSINT is an example of a platform that supports evidence-led intelligence gathering in digital environments, helping analysts to identify relationships, entities and behavioural indicators that might otherwise be missed.

At the same time, AI-enabled platforms are starting to change how investigations are conducted. Tesari AI's latest vAlpha version highlights the transition from traditional search-based approaches to workflow-driven investigative environments.

This matters because investigations are rarely linear. A researcher could start with a person, locate a company, determine a beneficial owner, find procurement records elsewhere, and finally connect the activity to sanctions exposure or political influence operations.

These connected investigative trails seldom evolve in a linear fashion, and traditional search tools may struggle to track them. Tesari's approach is designed to mirror how investigators think, jumping between entities, testing relationships and refining leads as new information comes to light. The model is not perfect, but it is closer to how experienced investigators develop and test leads than many traditional search-based systems.

There's no doubt that artificial intelligence has sped up investigative workflows, especially in analysing large amounts of information that would otherwise require a huge amount of manual effort. But speed should never be at the expense of investigative judgement. AI can detect trends, reveal relationships, and rank leads, but it can't assign evidential weight or investigative significance without human guidance. Therefore, correlation should be viewed as a beginning, not as an end. Information presented with confidence must still be tested, corroborated, and validated before it is used to inform any operational or legal decision.

Just as important is the ability to record how those findings were obtained. Investigative findings should be reproducible, based on independently verifiable sources, and withstand scrutiny by others. Any conclusion, no matter how it was obtained, that cannot be explained or replicated has limited evidential value.

The real value is in the investigative experience. Modern investigative platforms do more than simply retrieve records; they help analysts to see relationships, timelines and networks that might otherwise go unseen.

GAI Translate and Multilingual Intelligence Collection

Another major development is the emergence of specialised investigative translation tools, such as GAI Translate.

Unlike generic translation services, these platforms are built to preserve contextual meaning, domain-specific jargon, and evidential integrity. That is particularly important when investigators are conducting cross-border work within different legal, regulatory and intelligence environments.

  • A mistranslation in a corporate filing can sink an investigation.
  • Misunderstanding a colloquialism can twist a false story.

Therefore, many investigators now view multilingual competence as a fundamental research skill rather than a desirable one. In view of the increasing international character of contemporary inquiries, it is difficult to dispute that view.

Often, the most valuable intelligence is not hidden at all; it is just written in a language the investigator cannot read.

The Proxy Problem

Another challenge is the growing sophistication of digital deception. Synthetic identities, AI-generated images, and fake online personas can all help create a sense of legitimacy while masking a coordinated influence campaign or other criminal activity. Investigators must therefore consider not only the information that exists, but also whether the digital identity itself shows consistency of behaviour over time. In terms of historical activity, independent corroboration and network relationships are now becoming as important as the initial discovery of the account.

One of the more disturbing trends noted by intelligence researchers is the increasing use of proxy actors.

Traditionally, foreign intelligence agencies use trained agents. Now foreign actors can use publicly available information to identify people who may be willing to work on their behalf. The implications are huge.

These actors do not always need to identify trained spies. They can use OSINT and social media to find people who are willing to act as proxies, making it much harder for intelligence services and law enforcement to attribute and disrupt them.

This trend is apparent in recent criminal cases in the UK, where prosecutors have accused individuals of being recruited online via Telegram networks connected to Russian-speaking handlers.

It operates similarly to the gig economy and is an uncomfortable comparison, but one that demonstrates how low barriers to entry have transformed the recruitment landscape.

Together, these factors make attribution, disruption, and prosecution much harder for investigators and intelligence agencies alike. For example:

  • The recruiter may be operating in another jurisdiction.
  • The supporting infrastructure may reside in another country.
  • The proxy actor may have little to no formal training in intelligence.
  • The result can be a major security headache.

Recap

The future of investigation will be multilingual, AI-assisted, and more reliant on open-source intelligence.

Cross-border investigations are becoming more complex, interconnected and time-sensitive. Investigators no longer have to conduct database searches or jurisdictional checks in isolation. They require both data and context.

Technical and language skills are also required, along with AI-augmented analytical tools that support, rather than replace, their judgement. Most importantly, investigators need to remember that today's influence operations, sanctions-evasion networks and illicit financial structures seldom respect geographic boundaries.

As AI continues to develop and the power of investigations grows, the real advantage will not go to those with the most tools, but those who know how to use them responsibly. Effective investigations still rely on disciplined methodology, evidential integrity and the ability to parse meaningful intelligence from digital noise. Technology can accelerate the investigative process, but it cannot replace professional judgement or experience.

OSINT is both a microscope and a telescope, revealing not just hidden details, but larger patterns. The difficulty for investigators isn't a lack of information; it's too much of it. The challenge is to know what fragments are important, why they are important, and to recognise that apparently unrelated signals might one day coalesce into a coherent picture.

Intelligence grading and globally recognised standards, policies, procedures, processes, and best practices must also keep pace with the OSINT investigative tradecraft to remain effective.

This is exactly what intelligence work looks like. It is defined by persistent uncertainty -messy, frustrating and sometimes exhilarating.

Authored by:

The Coalition of Cyber Investigators, Paul Wright (United Kingdom) & Neal Ysart (Philippines), with contributions from guest author, Nicole Hurey (USA), Founder, Paradox Index, and Creator of The OSINT Vault.

©2026 The Coalition of Cyber Investigators. All rights reserved.

The Coalition of Cyber Investigators is a collaboration between Paul Wright (United Kingdom) - Experienced Cybercrime, Intelligence (OSINT & HUMINT) and Digital Forensics Investigator;

Neal Ysart (Philippines) - Elite Investigator & Strategic Risk Advisor, Ex-Big 4 Forensic Leader; and

Lajos Antal (Hungary) - Highly experienced expert in cyberforensics, investigations, and cybercrime.

The Coalition unites leading experts to deliver cutting-edge research, OSINT, Investigations, & Cybercrime Advisory Services worldwide.

Our co-founders, Paul Wright and Neal Ysart, offer over 80 years of combined professional experience. Their careers span law enforcement, cyber investigations, open source intelligence, risk management, and strategic risk advisory roles across multiple continents. They have been instrumental in setting formative legal precedents and stated cases in cybercrime investigations and contributing to the development of globally accepted guidance and standards for handling digital evidence. Their leadership and expertise form the foundation of the Coalition's commitment to excellence and ethical practice.

Alongside them, Lajos Antal, a founding member of our Boiler Room Investment Fraud Practice, brings deep expertise in cybercrime investigations, digital forensics, and cyber response, further strengthening our team's capabilities and reach.

The Coalition of Cyber Investigators, with decades of hands-on experience in cyber investigations and OSINT, is uniquely positioned to support organisations facing complex or high-risk investigations.

Our team's expertise is not just theoretical - it's built on years of real-world investigations, a deep understanding of the dynamic nature of digital intelligence, and a commitment to the highest evidential standards.