We picked one username and ran it through three paid username-OSINT engines on the same afternoon. The username was richard. Revealer.US returned 488 profiles. fingerprint.to returned 483. osint.industries, on its premium module set, returned 301. Infobreach.net, included for context, returned 231. Those counts are real, from one day, from one handle. They are also the least interesting part of the run.
The interesting part is what happened after a hit landed. One of those richard profiles was a guns.lol card. Every paid tool found the page. Only two of them read the contact handles sitting in the body. One of those handles resolved to an active threat-actor channel. That is the difference between a result counter and an investigation.
Disclosure up front: we build Revealer.US. Assume bias and check our work. The numbers below are a same-day snapshot, not a lab study. Module lists change. Run your own handle before you spend money.
How we tested
The rules were simple, and we kept them even when a number came out unflattering.
One handle, chosen to hurt. richard is a common English given name that thousands of people use as a username. Soft 404s, parked profiles, and surname collisions all show up at once. A rare handle makes any tool look accurate. This one does not.
Same day, consecutive runs. Paid tiers wherever the platform sells one. No reruns to shop for a better number. No handle shopping. Whatever the tool reported is the number in this article.
Counts as each tool reports them. Every platform has its own version of "sources checked" and "profiles found." We recorded both. Module pools are not comparable across vendors, so every hit rate below is a tool measured against its own pool. Revealer.US and fingerprint.to counts come from JSON exports. osint.industries and infobreach.net counts come from the results page, because those two offer no export.
This is a snapshot of one common handle. Treat it as a use case, not a ranking of every feature each vendor ships.
The scoreboard
| Platform | Sources checked | Rows returned | Unique profiles after dedup | Hit rate | Tier used |
|---|---|---|---|---|---|
| Revealer.US | 751 | 488 | 486 | 65.0% | Paid |
| fingerprint.to | 620 | 483 | 481 | 77.9% | Paid |
| osint.industries | 396 | 301 | not exported | 76.0% | Premium |
| infobreach.net | 332 | 231 | not exported | 69.6% | Paid |
Profiles found for the username richard, one run each:
Raw reach, same runs. How many sources each platform actually attempted:
If you stopped at the scoreboard, fingerprint.to looks like the story. Highest hit rate in the set (77.9 percent), five profiles off the lead, 481 unique URLs, and zero duplicate URL groups. That is a real showing. It is also not how a case ends.
Reach is not a vanity metric
Hit rate measures how often a tool agrees with its own module list. Reach measures how big that list is. Both numbers are true. Only one of them decides whether the account you needed was even attempted.
fingerprint.to posted the best hit rate among the four paid platforms, on a pool 131 sources smaller than Revealer's 751. osint.industries posted the second-best paid rate at 76.0 percent, on a 396-module pool, and still finished 187 profiles behind the leader. A high hit rate on a 396-module pool still misses the accounts the larger pool never stopped looking for.
Revealer's 65.0 percent on the largest pool is the unflattering number in this table, and it is worth saying plainly. A lower rate on a bigger list can mean more false starts to triage. On a collision-prone handle like richard, holding two-thirds of 751 sources without drowning in junk is still the harder job, and the export backs that up: 488 rows, 486 unique profile URLs, two duplicate rows (0.4 percent). fingerprint.to was equally clean: 483 rows, 481 unique, zero duplicate URL groups. osint.industries is the quality problem in this run. There is no export to audit, and the raw results page showed roughly 20 percent duplicate rows. A tool reporting 301 rows where a fifth are repeats is really reporting about 240 unique profiles.
When your case turns on the account the subject forgot they had, you do not get partial credit for the hits you never attempted. That is the reach argument. The next section is why reach alone is still not enough.
The guns.lol test: the page everyone found and almost nobody read
This is the use case. One row decided more of the investigation than the 187-profile gap.
One of the richard hits was a guns.lol page. If you have not seen the service: guns.lol is a profile-card host out of the Discord scene. Users get a single fast-loading page with a background image, music, badges, and whatever links they want to pin. Threat actors adopted the format heavily, because the page looks like a harmless aesthetic flex while it holds every contact point they operate.
Every paid tool in this comparison has a guns.lol module. Every one of them found the page. Finding it is a status code. Reading it is the product.
Exactly two platforms, Revealer.US and fingerprint.to, returned the contact handles buried in the page body: Telegram handles, a Discord ID and username, a GitHub. osint.industries reported the profile and stopped. Infobreach.net, in the context run, did the same kind of existence check. Detection without extraction turns a lead back into a browser tab.
Here is a trimmed version of what a parsed hit looks like (Discord ID partially redacted):
{
"account_created": 1717026322,
"badges": ["premium", "gifter", "christmas_2024", "christmas_2025"],
"custom_metadata": {
"description": "t.me/imlostt4words",
"title": "richard"
},
"discord": {
"id": "4042034437******",
"username": "lacieismine",
"user_badges": ["HypeSquad Bravery", "Discord Nitro"]
},
"page_views": 556,
"second_tab": {
"discord": "discord.gg/rayhitta",
"github": "github.com/lostwordss"
},
"typewriter": ["t.me/cybrcriminal", "cybersec", "dms off"]
}
Count the new identifiers in that one hit. Two Telegram handles, one sitting in the typewriter rotation and one in the page metadata where almost nobody looks. A Discord account with its ID, username, and badge list, which is a fingerprint you can age and correlate. A GitHub. An invite server. The creation timestamp and view count for timing analysis.
One of those Telegram handles resolved to an active threat-actor channel. A platform that returned the page without the handles returned none of that. You can stare at 301 confirmed accounts and still miss the pivot that names the operator.
That is the argument for extraction over detection, in one result row. The five-profile gap between Revealer and fingerprint.to did not decide this case. The parse did. fingerprint.to passed the same test, which is why it belongs in a serious stack. osint.industries did not, which is why a premium hit rate on a smaller pool is not the same thing as a finished lead.
The third axis: breach and stealer correlation
A username search that stops at live profiles leaves the historical record on the table. People delete accounts. They do not delete the copies that landed in a breach dump or a stealer log.
The same Revealer export that produced 488 profile rows also carried 500 breach-database hits and 503 stealer-log hits. The stealer search surfaced 129 email addresses. Those are not 129 confirmed identities. On a common given name like richard they are leads, and leads are what you pivot. An email from a stealer row is a second query. A password reuse pattern is a third. The graph grows inside one report instead of across three products and a spreadsheet.
osint.industries has a different superpower, and it is a real one. Feed it an identifier and its email-provider module set tells you whether that identifier is registered across Microsoft's consumer domains, Outlook, and a set of other mail providers. Nobody else in this test matched that coverage. If the question is "does this person hold a Microsoft account," that module set can justify the seat on its own. What it did not do, on this run, is hand you a breach-and-stealer bundle next to the username hits, and it offered no export to take the 301 rows with you.
fingerprint.to is the closest peer on live enumeration. It was not the source of the 500 / 503 / 129 correlation set in this snapshot. Username-keyed breach and stealer hits are still leads, not proof of one person. Treat them that way and they still save hours you would have spent grepping dumps by hand.
Three things have to land in the same result set before a username search starts to look like an investigation:
- Reach. Enough sources that the forgotten account is even in the attempt list. 751 vs 396 is not a rounding error.
- Extraction. Enough parsing that a guns.lol card yields Telegram, Discord, and GitHub instead of a URL and a status code.
- Correlation. Enough adjacent data that a handle becomes emails, stealer rows, and former exposures without a second product.
Missing any one of those sends you back to manual work. The scoreboard only measures the first.
What this means for your workflow
Do not pick a winner from a hit rate. Pick coverage, then decide which engine owns which job.
Run two engines on anything you will stand behind. Revealer.US and fingerprint.to were five profiles apart on raw count and both passed the guns.lol parse. Their module lists still do not overlap cleanly. A miss on one tool is usually a module difference, not a contradiction. Budget for the second seat from day one.
Give Revealer the first pass when you need the whole loop. Widest sweep in this run (488 from 751), parsed extraction on the guns.lol card, and the breach / stealer bundle in the same export (500 breach hits, 503 stealer hits, 129 emails). That is the path from a handle to a pivot without changing windows. Start on username search. The adjacent work lives on data breach lookup and stealer logs. AI Deep Search automates the loop: an identifier found in round one becomes a query in round two until the graph stops growing. Paid self-serve starts on pricing, with an API if this needs to sit in a pipeline.
Keep fingerprint.to as the second enumerator. 483 from 620, best hit rate in the set, clean unique-URL export, and it read the same guns.lol contacts. If your workflow is enumeration-first and you want a second opinion on every handle, this is the pair.
Keep osint.industries for mailbox existence, not for the sweep. 301 confirmed accounts from 396 modules is sharp detection on a small pool. The Microsoft / Outlook registration checks are the reason to keep paying. They are not a reason to skip the larger engines, and they are not a reason to trust a results page that padded roughly 20 percent of its rows.
Use infobreach.net as triage, not as the record. 231 from 332 is an honest mid-tier showing. Useful when you want a third aggregator's opinion. Not useful as the only pass on a case that might turn on a buried Telegram handle.
Two rules held up on this handle. Never build a conclusion on one tool's negative result. And never confuse "we found the page" with "we read the page." The richard run produced four different counts and one actual lead. The lead was in the parse.
Revealer is not a consumer reporting agency, and its data may not be used for employment, tenant, credit, or insurance eligibility decisions.
Frequently asked questions
Which engine found the most profiles for richard? Revealer.US, with 488 profiles from 751 sources checked (486 unique after dedup). fingerprint.to was second at 483 from 620. Same handle, same day, one run each.
Did the highest hit rate win? No. fingerprint.to posted 77.9 percent, the best in this set, and still trailed by five live profiles. osint.industries posted 76.0 percent and trailed by 187. Hit rate is agreement with a tool's own list. Reach is whether the account you needed was on that list.
What did the guns.lol test show? Every paid tool found the guns.lol profile-card page. Only Revealer.US and fingerprint.to returned the Telegram handles, Discord ID and username, and GitHub buried in the body. osint.industries reported the profile and stopped. One of those Telegram handles resolved to an active threat-actor channel.
What extra data did Revealer return besides profiles? The same export carried 500 breach-database hits and 503 stealer-log hits. The stealer search surfaced 129 email addresses. Those are leads on a common name, not a single identity. They are still the fastest pivot off a username in this comparison.
Should I drop osint.industries? Not if you need Microsoft and Outlook registration-existence checks. That coverage was unmatched in this test. Drop it as your only username engine. 396 modules and a results page with roughly 20 percent duplicate rows is not a complete sweep.
Can I use these tools for background checks? Not Revealer. It is not a consumer reporting agency, and its data may not be used for employment, tenant, credit, or insurance eligibility decisions. Use an FCRA-compliant provider for those purposes.