IT Forensics · Private Individuals

How can I have an identity theft investigated and documented online?

When a digital identity is misused, email addresses, telephone numbers, accounts, identity details and payment services may all be linked.

Enquire without obligation

Why this question is important for private individuals

Following a digital fraud incident, financial loss, time pressure and technical uncertainty all come into play. A well-structured investigation can help to organise the available evidence and distinguish between assumptions and events that can actually be substantiated.

Technical investigative approach

We compile an overview of events using legally available account, device, communication and document data, and retain the relevant original supporting documents.

Where the limits of what can be said lie

IT forensics can document which digital identity characteristics have been misused; it cannot identify every person involved without reliable data.

Why LanCologne?

In cases of digital fraud, it is not just the fact that money is missing that matters. To establish the facts, it must be clarified which technical sequence of events can actually be verified: Was a phishing page opened? Were login details entered? Was there a successful login afterwards? Was a device compromised? How was a payment authorised? Which of these questions can actually be answered using the available data?

LanCologne treats these steps separately. A fraudulent payment is not automatically regarded as evidence of malware on the smartphone. A password that has been compromised does not in itself prove a successful login. Nor does an unauthorised login automatically identify the person behind it.

A clear timeline is particularly important when it comes to financial losses. That is why we cross-reference messages, browser and device data, account activity, security alerts and payment information, insofar as this information is lawfully available to the customer.

Automated scanners, screenshots and visible app displays can provide important clues, but are not accepted as evidence without verification. Where original messages, original files or primary artefacts are available, they are generally given greater weight in technical examinations.

A robust conclusion may also be that a particular alleged sequence of events cannot be technically proven. This openness regarding the conclusion is particularly important if the report is to be submitted at a later date to a bank, an insurance company, the police, a solicitor or a court.

How we work

1Record the dates of financial irregularities and disputed transactions.
2Secure outstanding accounts and payment channels immediately.
3Receive relevant news, emails, links and original files.
4Protect device and account data from avoidable changes.
5Check for phishing, credential misuse, session misuse and device compromise separately.
6Normalise timestamps and time zones on a per-source basis.
7Give preference to the original communication over mere screenshots.
8Do not confuse login, device and user mapping.
9Assess payment authorisation and technical device activity separately.
10Examine counter-hypotheses and standard technical explanations.
11Identify data gaps and instances where provider information is unavailable.
12Document the main findings in a clear and understandable manner and ensure that the technical derivation is documented in a way that is easy to follow.

Not every fraudulent payment means that the device has been hacked

Phishing, social engineering, stolen login credentials, compromised sessions and an actual device infection are technically distinct scenarios. We examine these possibilities separately and only explain the sequence of events as a finding that is supported by the available data.

Rapid damage control is a priority

If unauthorised transactions or account misuse are still taking place, the bank, payment service provider, card and affected accounts should be secured without delay. A forensic investigation will be planned around this; it must not artificially prolong any further damage that could be avoided.

Why LanCologne following a digital scam?

LanCologne does not attempt to spin a financial loss into the most dramatic account of an attack possible. We reconstruct the technically verifiable steps, document original sources and the limitations of witness statements, and present the findings in such a way that they remain understandable to the client whilst remaining technically comprehensible to lawyers, banks, insurance companies or investigating authorities.

Legal framework

Depending on the circumstances, different criminal law provisions may be relevant. Section 263 of the German Criminal Code (StGB) concerns fraud, and Section 263a of the StGB concerns computer fraud. Section 263a covers, amongst other things, financial losses resulting from the manipulation of a data-processing operation, for example through the unauthorised use of data. Which provision applies in a specific case is a legal question and is not decided by the IT forensic expert.

In the case of compromised accounts, Sections 202a et seq. of the German Criminal Code (StGB) may also be relevant. In the case of manipulated digital evidence, Section 269 of the StGB – which deals with the forgery of evidence-relevant data – may be particularly relevant, provided the legal requirements are met. However, the technical finding that a file or message has been altered does not automatically establish all the elements of the offence or the identity of the perpetrator.

For those affected, the priority following an ongoing fraud is to minimise the damage. The police and the BSI recommend taking swift protective measures in the event of hacked accounts or phishing, whilst at the same time documenting relevant digital evidence. A forensic investigation must not delay the necessary blocking of accounts, cards or payment methods.

In cases of disputed payments, issues relating to civil law and payment services law may also be relevant. Whether a payment was authorised, whether duties of care were breached or whether there is a claim for a refund must be assessed from a legal perspective. LanCologne can investigate the technical facts and chronology of events in this regard, but it does not replace legal advice and does not determine whether a refund is due.

A privately commissioned IT forensic report can document technical details in a way that is understandable to lawyers, banks, insurance companies or investigating authorities. It does not replace the investigative powers of the authorities, nor does it replace a court’s assessment of the evidence.

Frequently Asked Questions

How can I have an identity theft investigated and documented online?
Following a digital fraud incident, financial loss, time pressure and technical uncertainty all come into play. A well-structured investigation can help to organise the available evidence and distinguish between assumptions and events that can actually be substantiated.
How is such a technical investigation carried out in practice?
We compile an overview of events using legally available account, device, communication and document data, and retain the relevant original supporting documents.
Can such an investigation always produce a clear result?
IT forensics can document which digital identity characteristics have been misused; it cannot identify every person involved without reliable data.
Is there a legal basis for this?
Depending on the circumstances, different criminal law provisions may be relevant. Section 263 of the German Criminal Code (StGB) concerns fraud, and Section 263a of the StGB concerns computer fraud. Section 263a covers, amongst other things, financial losses resulting from the manipulation of a data-processing operation, for example through the unauthorised use of data. Which provision applies in a specific case is a legal question and is not decided by the IT forensic expert. In the case of compromised accounts, Sections 202a et seq. of the German Criminal Code (StGB) may also be relevant. In the case of manipulated digital documents, Section 269 of the German Criminal Code (StGB), concerning the forgery of evidence-relevant data, may be particularly significant, provided the statutory conditions are met. However, the technical finding that a file or message has been altered does not automatically establish all the elements of the offence or the identity of the perpetrator. For those affected by an ongoing fraud, the priority is initially to minimise the damage. The police and the BSI recommend taking swift protective measures in the event of hacked accounts and phishing, whilst at the same time documenting relevant digital evidence. A forensic backup must not delay the necessary blocking of accounts, cards or payment channels. In cases of disputed payments, issues relating to civil law and payment services law may also come into play. Whether a payment was authorised, whether duties of care were breached, or whether there is a claim for a refund must be assessed from a legal perspective. LanCologne can investigate the technical facts and chronology of events in this regard, but does not replace legal advice and does not determine whether a refund is due. A privately commissioned IT forensic report can document technical circumstances in a way that is comprehensible to lawyers, banks, insurance companies or investigating authorities. It does not replace the investigative powers of the authorities nor a judicial assessment of evidence.

LanCologne – IT Forensics for Private Individuals

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now