Sample — Fictional Scenario — For Demonstration Purposes Only — Not an Active Engagement
Blackthorn Intel  ·  Confidential Intelligence Brief
Pre-Election Opposition Exposure Audit
Fictional Candidate · State · 2026 Cycle · Sample Brief
Classification Sample — Redacted / For Review Only
Prepared By Blackthorn Intelligence Group
Date June 2026
Reference BT-SAMPLE-2026-001

1. Executive Summary

This assessment was conducted at the direction of the client to evaluate the publicly accessible digital footprint of the subject prior to an upcoming state-level electoral contest. The subject is a first-time candidate with no prior electoral history. Our investigation surfaced significant personal exposure across four primary categories: publicly indexed identifying information, historical financial disclosure gaps, anomalous digital activity patterns, and未经授权 affiliations with prior business entities of concern.

Of the 14 data categories assessed, 4 findings are assessed as presenting material risk to the subject's candidacy if disclosed by an opponent or media outlet prior to the election. An additional 3 findings represent moderate surface area that could be leveraged in a negative narrative campaign.

Overall exposure rating: Elevated. Immediate remediation is recommended across all critical findings prior to public campaign launch.

2. Key Findings

Finding A — Publicly Indexed Home Address with Family Co-Location Critical
Subject's residential address and the addresses of two immediate family members are indexed across [REDACTED — 2 data brokers]. Address records include property owner names, assessed values, and lien status. This information has been present on these platforms for a minimum of [REDACTED — 3+ years]. No indication that subject has submitted removal requests to any of the indexed platforms.

Risk: Physical security threat to subject and family members. Potential forSWATTING or direct harassment if address data is weaponized by bad actors or coordinated opposing campaigns.
Finding B — Undisclosed Business Entity with Regulatory Flag Critical
Subject holds a [REDACTED — entity type] interest in [REDACTED — company name], registered in [REDACTED — state] in [REDACTED — year]. This entity has an active regulatory action pending with [REDACTED — agency], docket number [REDACTED], filed [REDACTED — date]. The entity does not appear in any of the subject's campaign financial disclosures or prior public statements. A search of news archives and regulatory databases confirms no prior public coverage of this matter.

Risk: If discovered and publicized by an opponent or journalist, presents as concealment. Severity is compounded by non-disclosure in required state filings.
Finding C — Social Engineering Surface Area (Phishing Exposure) High
Subject's personal email address and professional email address are both indexed in a [REDACTED — 2021 breach name] breach dump containing approximately [REDACTED — scale] credentials. The plaintext password associated with the personal email address was recovered from the dump. Credential format suggests reuse across multiple services.

Risk: Credential stuffing attacks against subject's accounts are technically feasible. Personal email inbox access would expose pre-campaign strategy communications, donor lists, and internal staff correspondence.
Finding D — Anomalous Digital Activity Timing Pattern High
OSINT analysis of publicly available posting metadata and engagement patterns indicates irregular activity timing on [REDACTED — platform(s)] inconsistent with a first-time candidate narrative. Detailed timing analysis is reserved for the confidential annex — this finding is presented at summary level per NDA restrictions.

Risk: Could be weaponized as evidence of undisclosed prior political activity or coordination with a prior campaign entity.
Finding E — Prior Employment Record Gap Inconsistency Medium
Subject's publicly stated employment history covers a period of approximately [REDACTED — 18 months] that is not corroborated by corporate records, professional license databases, or archived web presence data from that period. Entity registrations show active status during the gap period. The significance of this inconsistency depends on further document review not yet completed.

Risk: Low probability of external discovery unless opponent gains access to original research materials.

3. Methodology Overview

Blackthorn Intel conducts all-source open-source intelligence (OSINT) investigations using legally compliant, publicly available information. No unauthorized access, no social media account compromise, no purchase of leaked or stolen data. All findings are verified through cross-referencing across multiple independent sources before inclusion in any report.

Phase 01
Identity Construction
Build comprehensive subject profile from public records, corporate filings, property records, and board appointments.
Phase 02
Surface Area Mapping
Identify all indexed personal information across data brokers, people-search sites, and dark-web aggregators.
Phase 03
Credential & Breach Audit
Correlate exposed credentials to public breach datasets and assess account exposure surface.
Phase 04
Narrative Audit
Evaluate how assembled public information could be packaged into a negative narrative against the subject.
Phase 05
Digital Activity Analysis
Analyze posting patterns, engagement metadata, and account history for anomalies or inconsistencies.
Phase 06
Adversarial Scenario Modeling
Model the realistic threat landscape: what a sophisticated opponent would find, how they would use it, and in what sequence.

4. Recommended Actions

Priority Action Rationale
P1 Initiate data broker removal across top 40 indexed platforms; engage removal service for persistent platforms Eliminates primary vector for home address and family member information disclosure
P1 Reset all credentials on personal email, cloud storage, and any device that may share the exposed password hash Removes immediate credential-stuffing risk; implement passkey/phishing-resistant auth
P1 Retain campaign legal counsel to review regulatory action disclosure obligations in state filing requirements Undisclosed regulatory matter represents legal exposure for the campaign independent of electoral risk
P2 Conduct internal review of all pre-announcement communications to assess exposure if inbox is compromised Limits blast radius of potential credential compromise by reducing sensitive content in email
P2 Audit and document employment history with corroborating records for rapid response preparation Enables proactive narrative control if opponent surfaces employment gap information
P2 Establish ongoing monitoring for subject's name, address, and entity associations across data broker ecosystem Ongoing re-indexing is common; continuous monitoring provides early warning for new exposures

5. Engagement Timeline & Pricing Reference

Standard single-profile assessment timeline for a client engagement:

Day 0
Intake consultation & NDA execution. Scope confirmation, information request, mutual NDA signed. Engagement formally commences.
Day 1–2
Research phase. Full all-source investigation — public records, OSINT, data broker surface, breach correlation, narrative audit.
Day 2–3
Analysis & drafting. Findings verified, prioritized by severity, drafted into professional PDF report with remediation guidance.
Day 3
Delivery. Encrypted PDF delivered via secure link. Senior analyst available for debrief call within 24 hours of delivery.
Ongoing
Remediation support & monitoring. Follow-on removal coordination and periodic surface-area monitoring available as add-on service.

Single-Profile Assessment (Standard) $7,500 — Flat Fee
Extended Scope (Multi-Entity / Family / International) Quoted at intake consultation
Ongoing Monitoring (12-month) $2,500 / quarter
Expedited Delivery (24-hour) $1,500 surcharge
Remediation Coordination (Data Broker Removal) $1,200 — one-time
Debrief Call with Senior Analyst Included — up to 60 minutes

Pricing subject to scope confirmation. Complex cases with extended family, multiple entities, or international exposure are quoted separately. No surprise billing — final scope and price confirmed before research commences. NDA executed at engagement.