⚠️ Educational Purpose

This page explains what a coordinated group can do so you can defend against it. The goal is your own threat modeling and self-OSINT: understanding what a group could assemble about you, then reducing it. Nothing here is a how-to for targeting other people. Capabilities are described only at the level needed to defend, and every factual claim links to a primary source.

TL;DR: Organized groups (private-investigator networks, harassment and doxxing collectives, criminal and scam rings, and stalkerware operators) beat a lone individual through resources, not genius. They pool separate findings into a mosaic, pay for professional databases that link your Social Security number, phone, vehicles, relatives, and property, and buy aggregated breach data covering billions of accounts. Defend by making cross-referencing hard: unique passwords in a manager plus two-factor authentication, breach monitoring, compartmentalized identities, removal from data-broker feeders, and a harassment-response plan prepared in advance.

A lone person searching for you is limited by their own time and their own budget. An organized group removes both limits. When several people pool what each of them finds, when the group can pay for investigative databases built for professionals, and when it can buy breach data that was already stolen and packaged for resale, the picture it assembles about you moves far beyond anything a single searcher could reach. This page covers the second adversary tier: coordinated actors, and specifically what their resources add over one determined stranger.

What a coordinated group can do

The three capabilities below all scale with the number of people and the money behind them. That is the pattern to watch: none of these depend on unusual technical skill, only on coordination and spending.

Pooled manpower and the mosaic

Individual data points look harmless on their own. Combined, they identify you. A group multiplies this effect because each member can chase a different thread, one working your usernames, another your photos, another public records, and then merge the results into a single dossier. The Federal Trade Commission warned in 2014 that "people search" products built on aggregated data can be used to facilitate harassment, or even stalking, and can expose domestic-violence victims, law enforcement officers, and public officials to retaliation.[1] The same report described one broker holding 1.4 billion consumer transactions and over 700 billion aggregated data elements, with another adding three billion new records every month.[1] A group does not need to compile that itself. It needs only to pool access to it.

Stalkerware and monitoring

Some coordinated threats run inside your own devices. Stalkerware, the commercial "spouseware" sold to monitor a partner's phone, turns a single planted app into a continuous feed of messages, location, and calls. Kaspersky counted 31,031 unique individuals affected by stalkerware worldwide in 2023, a 5.8 percent rise from 29,312 in 2022 that reversed an earlier decline.[2] These are commercial products with support desks and reseller networks behind them, operating at a multi-thousand-victim scale rather than as isolated incidents.

Coordinated harassment and doxxing

Groups also apply pressure in numbers. PEN America's work with more than 230 writers who had faced online harassment found two-thirds changed their behavior as a result, including refraining from publishing their work, deleting social-media accounts, or fearing for their personal safety, and over a third avoided certain topics in their writing.[3] Coordinated harassment is often spread deliberately across several platforms at once, taking advantage of the fact that most platforms only moderate content on their own site.[3] Amnesty International's crowdsourced "Troll Patrol" study counted 1.1 million abusive or problematic tweets sent to 778 women politicians and journalists in a single year, one every 30 seconds, with women of color 34 percent more likely to be targeted than white women and Black women 84 percent more likely.[4]

What resources add over a lone individual

This is where a group stops resembling a determined stranger. Money buys access to tools built for professionals, and it buys reach through the intermediaries that sit between raw data and the people who want it.

Paid investigative databases

A lone person uses free people-search sites. A funded group buys the databases those sites are a thin copy of. Thomson Reuters CLEAR, sold to investigators, corporate security, and law enforcement, offers linked searches across Social Security numbers, live phone data (cell, VoIP, landline, and pager), motor-vehicle registration in 44 U.S. states, license-plate and vehicle lookups, and nationwide real-property and owner records.[5] TransUnion's TLOxp draws on more than 10,000 public and proprietary databases refreshed daily and is built specifically to map a subject's relatives and associates, not just the individual.[6] IRBsearch, sold to private investigators, process servers, and skip tracers, advertises hundreds of billions of records from over ten thousand sources including all three credit bureaus, plus a "Vehicle Sightings" product that locates vehicles nationwide using license-plate-recognition data.[7] Access is meant to be gated by a claimed permissible purpose, but a group willing to misrepresent that purpose gains a profile no free tool assembles.

Aggregated breach data

The second resource is data that was already stolen and then packaged for reuse. Have I Been Pwned, a free lookup, indexes more than 17.6 billion breached accounts drawn from over 1,000 separate breached sites, a cross-referenceable surface no lone attacker compiles from scratch.[8] Paid and pirated compilations go further. The 2019 "Collection #1" dump merged 772,904,991 unique email addresses and 1,160,253,228 unique email-and-password pairs, pulled from thousands of individual breaches, into one searchable set.[9] Commercial indexers packaged the same material for sale: "Data Viper," marketed to organizations, investigators, and law enforcement, offered roughly 15 billion records exposed in more than 8,000 website breaches.[10] For a group, this turns one old reused password into a key it can try everywhere you hold an account.

The reseller chain

Resources also buy reach through intermediaries, and a data point rarely travels alone. In 2019 a reporter paid a bounty hunter 300 dollars to locate a test phone in near real time; the location had passed from the carrier to an aggregator to a reseller before reaching the bounty hunter.[11] In 2024 the FCC fined AT&T, Verizon, T-Mobile, and Sprint roughly 200 million dollars combined for selling customer-location access to aggregators that resold it onward to dozens of downstream third parties (88, 67, 86, and 75 entities respectively).[11] Each link in that chain is a place where a paying group can buy a capability that started as a single data point held by someone else.

Organized scam infrastructure

Criminal rings turn these resources into an assembly line. The FBI's Internet Crime Complaint Center logged 16.6 billion dollars in reported losses across 859,532 complaints in 2024, up 33 percent from the year before.[12] Cryptocurrency fraud alone accounted for 9.3 billion dollars across 149,686 complaints, investment fraud (much of it the "pig butchering" pattern, where scammers build a fake relationship before steering victims into a fraudulent crypto platform) was the largest single loss category at 6.57 billion dollars, and victims aged 60 and over lost 4.885 billion dollars.[12] These are staffed operations with scripts, tooling, and shared victim lists, not lone opportunists.

Run this on yourself

Model the group by doing a small piece of its work against your own name, then closing what you find. None of this needs paid tools.

  • Check your breach exposure. Look up your email addresses on Have I Been Pwned and note the accounts and passwords tied to them. Every hit is a credential a group could try elsewhere.[8]
  • Search your name against your usernames. Query your real name alongside the handles you post under, across the platforms where you are active, the way several people splitting the work would. Notice which results connect a pseudonymous account back to your legal identity.
  • Picture the paid-database view. Imagine what a professional database would assemble from the public record: your relatives and associates, your current and past addresses, and the vehicles registered to you. That combined view, not any single fact, is the product a group buys.

How these techniques work

Each capability on this page has a dedicated explainer. This section summarizes and links rather than repeating them.

  • The Mosaic Effect covers how individually harmless data points combine into a profile that identifies you, the core of the "pooled findings" advantage.
  • Dark Web and Breach Data OSINT covers how leaked databases feed the cross-referencing and re-identification a group depends on.
  • Synthetic Identity Fraud covers how stolen fragments are recombined into new fake identities used against you and others.
  • The Pig Butchering Scam Guide covers the relationship-first cryptocurrency investment fraud pattern that drives much of the loss data above.

Defend against an organized group

The group's advantage is cross-referencing, so most defenses aim at breaking the links between your data points.

  • Use unique passwords with a manager and 2FA. A different password for every account, stored in a password manager and protected by two-factor authentication, blunts breach-data cross-referencing: one leaked password no longer opens your other accounts.
  • Turn on breach monitoring. Get alerted when your credentials surface in a new dump so you can rotate them before a group acts on them.
  • Compartmentalize identities. Keep separate emails, usernames, and where possible phone numbers for separate parts of your life, so a single lookup cannot merge them.
  • Remove yourself from paid-database feeders. Data brokers and people-search sites are where much of the professional data starts. Opting out reduces what a group can buy about you.
  • Prepare a harassment-response plan. Decide in advance on documentation habits, reporting contacts, and trusted people to escalate to, so a coordinated wave does not have to be handled alone.

Two guides go deeper: A Surveillance-Resistant Digital Life on compartmentalization and OPSEC for sustained threats, and Protecting Yourself From OSINT on shrinking what any searcher can find in the first place.

💰 Resources can buy up a tier

These tiers describe a baseline, not a ceiling. A well-funded group buys the same corporate data brokers sell, hires the investigators who hold the professional databases, and rents the reseller chains that move location data. At the extreme, organized crime has bought nation-state-grade spyware. When you model this adversary, weigh not only who is interested in you, but how much they can spend.

Frequently Asked Questions

What makes an organized group more dangerous than a lone stalker?

Resources rather than skill. A group pools the manpower of several people, splits the searching between them, and can pay for investigative databases and pre-packaged breach data that a single person would never assemble. The result is a fuller picture of you, built faster than one searcher could manage alone.

Can a private group really buy the same data the police use?

Much of it, yes. Databases like Thomson Reuters CLEAR, TransUnion TLOxp, and IRBsearch are marketed to private investigators, collections agencies, and skip tracers as well as to law enforcement. Access is supposed to be gated by a claimed permissible purpose, but that control depends on honest use and can be misrepresented.

How common is stalkerware?

Kaspersky counted 31,031 unique individuals affected by stalkerware worldwide in 2023, an increase of almost six percent from 29,312 the year before. These are commercial monitoring apps with support and reseller networks behind them, not one-off improvised hacks.

How do I find out if my data is in a breach compilation?

Enter your email addresses at Have I Been Pwned, a free service that indexes more than 17.6 billion breached accounts. Any match is a credential a group could try against your other accounts, so change any reused password wherever it appears.

What is the single most effective defense against this tier?

Break the cross-referencing. A unique password for every account, kept in a password manager and backed by two-factor authentication, means one leaked password no longer unlocks the rest of your accounts, which is the exact advantage aggregated breach data gives a group.

Sources

  1. Federal Trade Commission. "Data Brokers: A Call for Transparency and Accountability." May 2014. ftc.gov
  2. Kaspersky. "Global Kaspersky report reveals digital violence has increased (State of Stalkerware 2023)." March 13, 2024. kaspersky.com
  3. PEN America. "Online Harassment Field Manual." 2024. pen.org
  4. Amnesty International. "Troll Patrol Findings: crowdsourced Twitter study of online abuse against women." December 2018. amnesty.org
  5. Thomson Reuters. "CLEAR: investigative research overview (submitted as Maryland General Assembly testimony)." March 2020. mgaleg.maryland.gov
  6. TransUnion. "Investigations powered by TLOxp." 2024. transunion.com
  7. IRBsearch, LLC. "Data Solutions Tailored for Private Investigators." 2024. irbsearch.com
  8. Have I Been Pwned. "Pwned websites and accounts (live statistics)." 2026. haveibeenpwned.com
  9. Troy Hunt. "The 773 Million Record Collection #1 Data Breach." January 16, 2019. troyhunt.com
  10. Brian Krebs, Krebs on Security. "Breached Data Indexer Data Viper Hacked." July 2020. krebsonsecurity.com
  11. Brian Krebs, Krebs on Security. "FCC Fines Major U.S. Wireless Carriers for Selling Customer Location Data." April 29, 2024. krebsonsecurity.com
  12. FBI Internet Crime Complaint Center. "2024 Internet Crime Report." 2025. ic3.gov