Back to Blog
Threat Intelligence15 min readSep 3, 2026

Username Search Benchmark 2026: meme, cia, richard on 11 Engines

We ran the handles meme, cia and richard through 11 username OSINT engines. Up to 547 profiles from one query, a 726-platform union across the top three, and a live breach and stealer-log corpus alongside.

B

Bob Adams

Threat Analyst at Revealer

Three handles, meme, cia and richard, eleven username OSINT engines, every count from a real run. The deepest single result was 547 profiles pulled from a pool of 816 sources, and across the top three paid engines richard alone resolved to a union of 726 distinct platforms. The same richard run returned 500 breach rows and 503 stealer-log rows, with stealer ingestion timestamps dated two days before the query, and pivoted on its own from one handle to 137 email addresses across 40 domains. One card in that export, guns.lol/richard, came back resolved down to a Discord identity, seven linked accounts and a page-view count.

fingerprint.to is first, on hit rate against its own pool on all three handles and on how much it extracts from each hit. Revealer.US is second, on the widest pool, the most rows on all three handles, and the breach and stealer-log corpus that arrives in the same result set.

Disclosure up front: we build Revealer.US, including AI Deep Search, data breach lookup, and stealer logs. Assume bias and check our work. Every count below comes from a real run, named and dated. Module lists change weekly, so run your own handle before you spend money.

How we tested

Three handles, picked for reach. meme and cia are dictionary words. richard is one of the most common given names in the English-speaking world. Common handles like these resolve to many different people and brands across platforms, which is exactly what makes them a good coverage test: they push every engine to the widest part of its module list. The display names across the meme and cia exports span "MEME.COM", "めめ", "Karl Friedrich Gauss", "Ciara" and "Central Intelligence Agency".

The dates. Every meme and cia run happened on 2026-09-03, minutes apart. richard is a mixed set: our Revealer export and the infobreach.net, Maigret, Sherlock, Blackbird and free-checker figures are from 2026-09-03, while the fingerprint.to and osint.industries richard exports are from 2026-08-26, the runs behind our earlier richard article. The richard rows in the scoreboard carry their run date so you can read each one as what that tool returned on the day it ran.

One run each. Paid tiers where the platform sells one. Fresh installs into isolated Python 3.12 environments for Maigret, Sherlock and Blackbird, default site lists, no permutations. Free web checkers on their deepest free setting.

Counts as each tool reports them. Module pools are not comparable across vendors, so every hit rate below is a tool measured against its own pool. A tool with a wider pool and the same absolute yield scores lower, which is why the rate is context rather than a ranking. The three engines that export JSON gave their counts from the file, and every other count came off the results page.

The false-positive probe. From each paid export we dropped rows with no usable URL, deduped, sorted lexicographically and took every k-th, giving 40 per tool per handle and 280 in total. Each was fetched live from one residential-class US connection with curl and classified as verified, soft-404, dead, or blocked, with 40 ambiguous rows adjudicated by hand.

The scoreboard

Each cell reads found of checked, with the hit rate against that tool's own pool.

Engine Type meme (09-03) cia (09-03) richard
fingerprint.to Paid 442 of 618 · 71.5% 323 of 618 · 52.3% 483 of 620 · 77.9% (08-26)
Revealer.US Paid 449 of 816* · 55.0% 324 of 816* · 39.7% 547 of 816* · 67.0% (09-03)
osint.industries Paid 400 rows, no denominator (08-26)
infobreach.net Paid 299 of 581 · 51.5% 224 of 581 · 38.6% 381 of 581 · 65.6% (09-03)
Maigret 0.6.5 CLI, free 269 of 509 · 52.8% 194 of 509 · 38.1% 307 of 509 · 60.3% (09-03)
Blackbird CLI, free 238 of 716 · 33.2% 178 of 716 · 24.9% 281 of 716 · 39.2% (09-03)
Sherlock 0.16.0 CLI, free 195 of 413 · 47.2% 142 of 413 · 34.4% 233 of 413 · 56.4% (09-03)
usersearch.org Web, free 125 of "315+" · ~39.7% 101 of "315+" · ~32.1% 140 of "315+" · ~44.4% (09-03)
instantusername.com Web, free 52 of 84 · 61.9% 41 of 83 · 49.4% 62 of 83 · 74.7% (09-03)
idcrawl.com Web, free 27 of 36 · 75.0% 22 of 35 · 62.9% 32 of 36 · 88.9% (09-03)
namecheckup.com Web, free 20 of 27 · 74.1% 16 of 27 · 59.3% 21 of 27 · 77.8% (09-03)

* Revealer's 816 is the live username-module count for the day of the run. fingerprint's 618 and 620 are recorded in its own export files.

Two footnotes. namecheckup's cia run left two tiles in an error state and its richard run left one; exclude those and the rates are 64.0 and 80.8 percent. osint.industries appears on richard only, and its export records no checked total, so it gets a row count and no rate.

Profiles found for meme, 2026-09-03. Bars scaled to Revealer.US at 449.

Revealer.US 449 paid
fingerprint.to 442 paid
infobreach.net 299 paid
Maigret 269 CLI · free
Blackbird 238 CLI · free
Sherlock 195 CLI · free
usersearch.org 125 web · free
instantusername.com 52 availability check
idcrawl.com 27 web · free
namecheckup.com 20 availability check

Profiles found for cia, 2026-09-03. Bars scaled to Revealer.US at 324.

Revealer.US 324 paid
fingerprint.to 323 paid
infobreach.net 224 paid
Maigret 194 CLI · free
Blackbird 178 CLI · free
Sherlock 142 CLI · free
usersearch.org 101 web · free
instantusername.com 41 availability check
idcrawl.com 22 web · free
namecheckup.com 16 availability check

Profiles found for richard. Revealer on 2026-09-03; fingerprint.to and osint.industries on 2026-08-26; everything else on 2026-09-03. Bars scaled to Revealer.US at 547.

Revealer.US 547 paid · 09-03
fingerprint.to 483 paid · 08-26
osint.industries 400 paid · 08-26 · rows, 310 modules
infobreach.net 381 paid · 09-03
Maigret 307 CLI · free
Blackbird 281 CLI · free
Sherlock 233 CLI · free
usersearch.org 140 web · free
instantusername.com 62 availability check
idcrawl.com 32 web · free
namecheckup.com 21 availability check

Run two engines and you see a third more

On meme, the two leading engines together reach 588 distinct platforms, about 33 percent more than either alone. On cia it is 429, again about 33 percent more. On richard, the top three paid engines reach a 726-platform union, 1.34 times the best single tool.

That headroom exists because the two leaders find genuinely different things. We normalized platform names across the exports (lowercase, strip non-alphanumerics, then apply a synonym map derived from the profile-URL hosts appearing in more than one file). On meme, Revealer returned 444 distinct platforms, fingerprint 442, and 298 are the same: Jaccard 0.507. On cia, 321 against 323 with 215 shared, Jaccard 0.501. On richard, 541 against 483 with 340 shared, Jaccard 0.497. Compare by profile-URL host and every pair drops slightly, to 0.486, 0.483 and 0.470, which is how we know the synonym map was doing real work and never inflating agreement.

The exclusives are the part worth knowing before you buy. fingerprint contributed 144 platforms on meme that we did not return, including Facebook, Bluesky, Reddit, Discord and Patreon, and 108 on cia including LinkedIn. Revealer contributed 146 on meme that fingerprint did not, including Stack Overflow, Launchpad and MusicBrainz, plus deep fediverse and Discourse coverage, and 186 exclusives on richard against fingerprint's 79. Two engines, in either order, is the configuration that gets you the whole picture.

A third engine adds a narrower slice. On richard only 188 of the 726-platform union are found by all three, 25.9 percent, so most of the map is still held by one or two tools. osint.industries sits close to a subset of fingerprint: 252 of the 309 platform names its 310 modules normalize to (81.6 percent) also appear in the fingerprint export and 203 in ours, leaving 42 unique to it.

One more figure for calibration. Pool size sets the ceiling and the extractor decides how much of it you reach, which is why the 816-module and 618-module engines land within seven rows of each other on the dictionary-word handles and 64 apart on richard.

The precision test

Both leading engines land in the same band. On the 280 URLs we fetched live, Revealer returned 15, 12 and 19 verified profiles in its three 40-row samples and fingerprint returned 16, 8 and 11, which works out to 75 to 86 percent precision on the URLs that could be resolved at all. Here is the whole result, under the strict reading where a connection timeout counts as dead.

Tool Handle Verified Soft-404 Dead Blocked Precision Judged n
Revealer.US meme 15 2 2 21 78.9% 19
Revealer.US cia 12 1 2 25 80.0% 15
Revealer.US richard 19 0 2 19 90.5% 21
fingerprint.to meme 16 1 2 21 84.2% 19
fingerprint.to cia 8 2 3 27 61.5% 13
fingerprint.to richard 11 0 3 26 78.6% 14
osint.industries richard 11 2 3 24 68.8% 16

Precision is verified over (verified plus soft-404 plus dead), blocked excluded. Pooled across meme and cia that is 79.4 percent for Revealer and 75.0 percent for fingerprint. Five of the "dead" results were never 404s: Tumblr, Stripchat twice, BongaCams and AllMyLinks returned a connection timeout, which means the site refused to talk to our client. Reclassify them as blocked and the pooled numbers become 81.8 percent for Revealer and 85.7 percent for fingerprint, and on richard the same reading gives 95.0, 100 and 78.6 percent.

There is no measurable precision difference between these tools on this sample. Blocked results dominate: 19 to 27 of each tool's 40 sampled rows were unjudgeable from plain curl, because of Cloudflare, bot walls and JavaScript-rendered pages that ship an empty shell to anything that is not a browser. Judged n runs from 13 to 21, and at that size the 95 percent interval on an 80 percent estimate spans roughly 50 to 96 percent.

The probe earns its keep on the shared misses. music.apple.com/profile/cia returns HTTP 200 and renders the artist page for Ciara, and both leading engines counted it. Giphy produced a soft-404 for both: giphy.com/meme redirects to the /explore/meme tag page, and giphy.com/channel/cia is an empty shell with no owner. Ours also missed on meta.discourse.org/u/meme/summary and vivino.com/en/users/meme, theirs on scratch.mit.edu/users/CIA and fanvue.com/meme, and the only two soft-404s in the 120 richard URLs were osint.industries rows: community.windy.com/user/richard, which redirects to a login wall, and a Designspiration URL serving the site's generic homepage, with "richard" appearing zero times in 95 KB of HTML. Any platform that answers HTTP 200 for a handle it does not host will be counted by anything checking status codes, which is the whole argument for probing a shortlist before you act on it.

There is no speed comparison in this article. Only some of these tools record a wall-clock time, so any claim in either direction would be invented.

Data quality, both ways

Field fill splits cleanly, and each tool wins the fields it decided to prioritize. On richard we carry a display name on 87.8 percent of rows against fingerprint's 64.0, and a bio on 30.3 percent against 18.4. fingerprint leads on avatars, 71.2 percent against our 63.4, on user IDs, 77.6 against 66.4, and on follower counts, locations and account creation dates by single-digit to nine-point margins. We fill more of a table about who a handle appears to be. fingerprint fills more of a table about what each account looks like.

The real capability gap runs in fingerprint's favour, and it is the extras block. It is populated on 95.9 to 97.5 percent of its rows and carries account state: is_banned on 27 richard rows, is_suspended on 13, plus is_online, last_active, gender, age and social_links. Knowing an account exists but was banned is a different fact from knowing it exists, and nothing in our schema expresses it. The trade-off is that extras is ragged, with different keys on different platforms, so it is harder to load into a fixed-column table than the flatter schemas either side of it.

Where the tools can be checked against each other, they hold up well. Both leading engines independently marked x.com/meme as "MEME.COM" and instagram.com/cia as "Central Intelligence Agency". On richard the verified-flag counts are close (11, 13 and 4) and the membership is not: only guns.lol/richard and tinder.com/@richard are flagged by all three. Where two tools see the same host and both return a name, Revealer and fingerprint agree 91.7 percent of the time on richard, and fingerprint and osint.industries agree 97.6 percent. Cross-tool agreement at that level means the disagreements are worth looking at individually rather than averaging away.

The guns.lol/richard card, field by field

This single card shows what a modern engine pulls off one URL, and it is the cleanest cross-validation in the set: all four files (both Revealer runs, fingerprint, osint.industries) independently carry the same bio string, "gg dont fw lost", and three of them the same creation timestamp, 2024-05-29T23:45:22. All three tools independently mark the account verified.

Our card carried 8 body fields on 2026-08-26 and 13 today, having gained createdAt, userId, avatarUrl, following and postCount.

fingerprint extracts more from the same card, and this is what per-hit depth buys. Alongside the shared fields its row carries page_views 557, is_premium, layout, background_url, four taglines, social_links (Roblox, Steam, Telegram, a custom domain), second_tab_links (Spotify, GitHub, a Discord invite), five Discord fields including discord_id and discord_username, and a lastActive of 2026-07-18. One URL in, a Discord identity and seven linked accounts out.

What a week did to the richard number

Our richard export went from 488 rows on 2026-08-26 to 547 on 2026-09-03. Comparing the two files by normalized platform name gives 74 names only in the newer and 15 only in the older; one of the 74 is a rename (x became twitter, same host, same URL), so the arithmetic is 73 new platforms minus 14 that disappeared. The 73 arrive in families: 19 Mastodon and fediverse instances, 9 Discourse instances, a package-registry block, and single adds including instagram. The module pool grew from roughly 750 to 816 in that week, and the per-card export widened from 8 fields to 13. That is the pace these tools move at, and it is the reason the fingerprint and osint.industries richard exports carry their own 2026-08-26 date in the scoreboard.

osint.industries

osint.industries appears on richard only, from a 2026-08-26 export. It returned 400 result rows across 310 distinct modules. The file records no checked total and no timestamp, so there is no denominator and no hit rate to report. Our earlier richard article printed "301 of 396" read off the results page that day. Neither number appears anywhere in the export, and we are retiring both.

Its distinct capability is worth the seat. Ninety-five of the 400 rows are mailbox-existence checks, one row per candidate address, testing richard@ across every domain Microsoft, Mail.ru, Zoho, Apple, Proton and Posteo host, with Microsoft alone accounting for 77. Nothing else in the set does that, and on a name-shaped handle it is real intelligence. It does mean the headline is not a profile count: 115 of the 400 rows carry no profile URL at all, 28.8 percent, and stripping the six mailbox-check modules leaves 305 rows across 304 modules as the profile-comparable set.

On the fields all three tools share it comes third: display names on 46.0 percent of rows, bios on 13.0, avatars on 44.2, user IDs on 38.2. And on couchsurfing.com it calls the profile "martin r." where Revealer and fingerprint independently both say "Richard v.". Read it as a specialist worth adding to a two-engine workflow.

infobreach.net

299 of 581 on meme (51.5 percent), 224 of 581 on cia (38.6 percent) and 381 of 581 on richard (65.6 percent), all on 2026-09-03. It is the only site in the set that prints an explicit denominator and an elapsed time on the results page, 16.1 seconds on richard, which is why its hit rate is exact and never estimated. It also prints a date range with its own sample size attached: account dates from 2001-11-10 to 2026-08-30, from the 152 platforms that reported one.

Its filter bar reads "287 of 299 shown" on meme, "216 of 224 shown" on cia and "371 of 381 shown" on richard, so the headline count runs slightly ahead of the rendered list. There is no export button, so nothing here could be audited the way the three JSON files were. A solid third paid opinion, and one you read on the page rather than hand to a colleague as a file.

Maigret, Sherlock, and Blackbird

All three were installed fresh on 2026-09-03, into separate environments, and run once per handle at default settings.

Maigret 0.6.5 was the strongest free engine on every handle: 269, 194 and 307 of 509, with 271, 196 and 309 entries in its JSON report. The 509 is its default top-sites set rather than its database, which auto-updated to 3,653 sites on first run, so a full-database pass would return a different and larger number than anything here. Its best trick is free and nothing else in the free tier does it: it chains recursive follow-up searches on IDs extracted from the first pass, four on cia and eleven on richard. Several of those richard IDs came out of Instagram and TikTok link parameters, and the recursion is why its wall clock reached 229 seconds.

Blackbird attempted the largest pool of the three, 716 sites, and returned 238, 178 and 281. Sherlock 0.16.0 returned 195, 142 and 233 of 413, and its 413 is the entire database, so unlike Maigret there is no deeper setting to reach for. Neither serializes anything but found accounts, so only Maigret surfaces failure classes, and only as percentages: bot protection at 8.45 percent on meme, peaking at 8.64 on cia, and 8.06 rising to 8.64 across the chained richard passes.

Free web checkers

Tool Sources checked meme cia richard What a hit means
usersearch.org "315+" 125 101 140 Profile found
instantusername.com 84 / 83 / 83 rows 52 41 62 Username taken
idcrawl.com 36 / 35 / 36 rows 27 22 32 Profile found
namecheckup.com 27 20 16 21 Username taken

Read that last column before the counts. instantusername.com and namecheckup.com are availability checkers, where "taken" means somebody registered the handle. That is no evidence of a profile, and neither returns profile data. We counted taken as found to keep the table consistent.

The denominators are soft. usersearch.org's "315+" is a marketing figure rather than a per-run count. instantusername.com repeats platforms across category columns, so 83 status-bearing rows is fewer than 83 distinct platforms. idcrawl.com advertises "40+ platforms" and rendered 36, 35 and 36, alongside sponsored broker cards, which are ads and which we excluded. namecheckup.com prints no counter at all.

Free checkers confirm that a handle is in use. They return nothing you can export, and the deepest free web result on richard (140) is a quarter of the deepest paid result.

The third category: breaches and stealer logs

This is a different product from the username scan and should be judged as one, and on these runs it is where the largest volume sits. The fingerprint username exports contain no breach and no stealer-log data on any handle; breach_results is an empty array with a breach_records count of zero. The osint.industries export has no breach or stealer concept in its schema. Those are statements about these files, and they say nothing about either vendor's other products.

Breach corpus. 496 rows on meme across 40 sources, 333 on cia across 67 sources, 500 on richard across 21. Heaviest sources: evite.com (231) on meme, antipublic (105) and nazapi (92) on cia, antipublic again on richard at 349 of 500 rows, 69.8 percent, with avito.ma at 74 and 15 sources contributing one row each. Where source dates are present, on 52 of the 500 richard rows, they run from 2010-12 to 2024-10, which is close to a fourteen-year span reachable from a single handle query.

Stealer logs. 510 rows on meme, 489 on cia and 503 on richard, essentially all Telegram-sourced, across 36, 27 and 24 channels. On richard, 500 of 503 rows carry a captured password and 200 distinct victim origin hosts appear, which is 200 different services an investigator can pivot to. Ingestion timestamps reach 2026-09-01, two days before the run, and that recency is the strongest fair claim in this section: this is a corpus that moves weekly.

The email pivot, and what it makes possible. On richard the breach search ran on three addresses discovered during the scan, one of them a codeberg system address, and the stealer search ran on 137 addresses pivoted automatically out of earlier stages, across 40 domains: gmail.com 42, hotmail.com 19, yahoo.com 12, aol.com 8, then a long tail, with 22 of the 137 on French domains. On meme the stealer search ran on 130 addresses, and on cia three. That is the step that turns a username query into an email-shaped one without an analyst typing anything: the domain distribution alone tells you where a handle's owners cluster geographically, and each address becomes the seed for the next stage. We print none of them, or any password, hash or IP.

Treat these rows as the input to the next query. That next query runs on data breach lookup and stealer logs, with AI Deep Search running the loop.

Revealer is not a consumer reporting agency. Its data may not be used for employment, tenant, credit, or insurance eligibility decisions.

The ranking, re-derived

The order is unchanged from our earlier richard article: fingerprint.to first, Revealer.US second. Here are the grounds, once and plainly.

fingerprint is first because it posts the higher hit rate against its own pool on all three handles, 71.5, 52.3 and 77.9 percent against our 55.0, 39.7 and 67.0; because its extras block carries account-state signals we do not have, including is_banned, is_suspended, last_active and social_links; and because it extracts more from a single card, as guns.lol/richard shows with its Discord identity and linked accounts. The two hit-rate denominators are measured against different pools, and a wider net mechanically lowers the rate, so the depth arguments are the ones carrying that first place.

Revealer is second because it checks the widest pool of the paid engines, 816 modules against fingerprint’s 618 to 620, returns the most rows on all three handles, 449, 324 and 547, leads on display-name and bio fill, and is the only one of the three that returns breach and stealer-log correlation inside the same result set.

osint.industries publishes no denominator at all; on its own export it sits behind infobreach.net on measurable coverage, while keeping one capability neither leader has.

You need Start with
Highest hit rate among the large-pool engines fingerprint.to
Account-state signals (banned, suspended, last active) and Discord identity fingerprint.to
Widest module pool and the most rows on all three handles Revealer.US
Display names and bios filled on most rows Revealer.US
Breach and stealer-log correlation in the same result set Revealer.US
A third paid opinion with an exact on-page denominator infobreach.net
Provider mailbox-existence checks on a name-shaped handle osint.industries
The best free sweep, with automatic recursive pivots Maigret
Widest free attempt list Blackbird
The familiar free baseline Sherlock
A no-install free check usersearch.org
Anything you will stand behind Two engines, always

One rule survived this run above the others. Never build a conclusion on a single tool's negative result, because at 0.50 Jaccard a miss is far more likely to be a module difference than a contradiction, and the union is where the picture actually lives. Paid self-serve is on pricing, and username search is where this starts.

Frequently asked questions

What is the best username search tool in 2026? On these runs, fingerprint.to. 442 of 618 on meme, 323 of 618 on cia and 483 of 620 on richard, the highest hit rate of any engine checking more than 100 sources, plus account-state signals in its extras block and the deepest single-card extraction we saw. Revealer.US is second, on 449, 324 and 547 from 816 sources.

Is fingerprint.to better than Revealer.US? On username enumeration in this snapshot, yes, narrowly, on hit rate and on how much each hit gives you. Revealer returned more rows on all three handles, covers more modules, fills display names and bios on more rows, and returns breach and stealer-log hits the fingerprint username exports do not contain. They share only about half their hits on every handle, so they are complements before they are rivals.

Why is the richard column dated differently? Our richard export, and the infobreach, CLI and free-checker richard runs, are from 2026-09-03. The fingerprint.to and osint.industries richard exports are from 2026-08-26. Each richard cell carries its run date for that reason.

What does osint.industries actually return? 400 result rows across 310 modules on richard, with no checked total anywhere in the file, so no hit rate can be computed from it. 95 of those rows are mailbox-existence checks on richard@ across the domains Microsoft, Zoho, Proton and others host, and 115 rows carry no profile URL. Those checks are a real capability neither other tool has, and the row count is still not a profile count.

Are there good free alternatives? Maigret is the strongest, at 269, 194 and 307 on its default set of 509 sites, and the only free tool that pivoted automatically on extracted IDs. Blackbird attempts the most sites (716) and Sherlock is the familiar baseline (413). None ships a breach or stealer-log corpus; Sherlock and Blackbird each return one HudsonRock exposure check and nothing more.

Does a hit mean it is the same person? Not on its own. A hit means the handle resolves on that platform, and confirming one owner across several hits is the analyst's job, helped by matching display names, bios, avatars and linked accounts.

Can I use these tools for background checks? Not Revealer. It is not a consumer reporting agency, and its data may not be used for employment, tenant, credit, or insurance eligibility decisions. Use an FCRA-compliant provider for those purposes.

Get started

Ready to check your exposure?

Create a free account. Every result is pulled live, in real time, from public sources and endpoints we do not own. We do not retain your search data. Items you choose to save, publish, or monitor are kept until you delete them.

Create account