IT Forensics · Private Individuals

Why should I commission LanCologne if I suspect my account has been hacked or my device has been compromised?

Anyone who suspects a cyber attack needs neither reassurance nor a hasty confirmation of their suspicions, but rather a transparent technical investigation.

Enquire without obligation

Why this question is important for private individuals

A potential unauthorised access often involves highly personal data and can cause considerable anxiety. This is precisely why an objective investigation is important: not every anomaly constitutes an attack, but any concrete suspicion should be investigated using appropriate digital evidence.

Technical investigative approach

LanCologne formulates specific research questions based on the observations, collects relevant data, examines primary artefacts and documents incriminating, exonerating and inconclusive findings.

Where the limits of what can be said lie

We do not promise to find a perpetrator or malware on every device. Our findings are based solely on what the existing digital evidence actually reveals.

Why LanCologne?

For private individuals, the possibility of unauthorised access is often much more than just a technical problem. Smartphones and computers contain personal correspondence, photographs, documents, login details and, in many cases, access to other online accounts. That is why we take any suspicion seriously, without treating it as a fact before an investigation has been carried out.

LanCologne does not begin with the question: „Who hacked me?“, but with verifiable technical questions. What observations have been made? What normal technical causes might also be to blame? What evidence would need to be present if the suspected activity had actually taken place? What independent data sources can confirm or refute a claim?

In this regard, we consistently distinguish between technical feasibility and proven action. The presence of a remote maintenance programme does not prove that remote access has taken place. An unknown login does not automatically prove a person’s identity. High battery consumption does not prove the presence of spyware.

Automated scanners and forensic software are tools. A reliable conclusion can only be reached by examining the underlying data, the temporal context and the correlation between multiple pieces of evidence.

A negative result is just as important. If suspected unauthorised access cannot be confirmed on the basis of the available data, this is also clearly documented. Where the data do not allow for a definitive conclusion, we do not replace this uncertainty with conjecture.

How we work

1Take note of the customer’s observations and specific concerns.
2Formulate verifiable technical questions based on this.
3Prioritise urgent safety and damage-limiting measures.
4Preserve data relevant to the case before it is subject to avoidable alteration.
5Only examine devices, accounts and data that have been lawfully provided.
6Document the origin, backup time and integrity of relevant data.
7Also consider standard technical causes and alternative hypotheses.
8Distinguish between account, device, session and user mapping.
9Validate scanner and tool messages against the primary data.
10Assess incriminating and exonerating findings using the same criteria.
11Explicitly identify points that cannot be substantiated and gaps in the data.
12Document the results in a way that is clear to private customers and comprehensible to experts.

We take your concerns seriously – but we do not treat them as a diagnosis

A forensic investigation must also take into account the possibility that an unusual finding may have a normal technical cause. This protects the client from drawing false conclusions and makes a genuinely positive finding considerably more reliable.

Evidence preservation and security must go hand in hand

In the event of acute account misuse, it may be necessary to change passwords, terminate sessions or suspend an account. At the same time, such changes may affect the historical record. We therefore prioritise the preservation of evidence wherever reasonably possible, without artificially prolonging any ongoing damage.

Why choose LanCologne for a private IT forensic investigation?

Our role is not to confirm a client’s fears. We answer a technical question of fact. The underlying data, the methodology and the limitations of the findings are documented in such a way that the result remains comprehensible and, if necessary, can be assessed by a lawyer, a regulatory authority or another qualified IT forensic expert.

Legal framework

In the event of suspected unauthorised access, various criminal offences may be involved. Section 202a of the German Criminal Code (StGB) covers, subject to its conditions, the unauthorised obtaining of access to data—which is specifically protected against unauthorised access and not intended for the perpetrator—by circumventing the access security measures. Section 202b of the German Criminal Code (StGB) covers, subject to its conditions, the unauthorised interception of data not intended for the perpetrator from a non-public data transmission or electromagnetic radiation.

Data tampering (Section 303a of the German Criminal Code (StGB)) or computer sabotage (Section 303b StGB) may also be relevant, depending on the actual facts of the case. In the case of stalking, Section 238 of the German Criminal Code (StGB) takes into account, amongst other things, certain digital acts and expressly refers to offences under Sections 202a to 202c. However, the technical detection of unauthorised access or alteration does not automatically mean that all the elements of the offence are fulfilled or that a specific person is the perpetrator.

To ensure that evidence can be preserved at a later stage, it is important not to alter digital content unnecessarily. The Police Crime Prevention Service also recommends the prompt documentation of digital evidence in cases of online crime; in the case of hacked accounts, the focus is simultaneously on rapid damage limitation and evidence preservation. Both must be coordinated effectively in each specific case.

LanCologne does not make any criminal allegations and is not a substitute for the police or a solicitor. We can establish technical facts and document them in a verifiable manner on devices and data lawfully provided to us. Whether this gives rise to a criminal offence, a civil claim or any other legal consequence is assessed by the relevant authorities.

Frequently Asked Questions

Why should I commission LanCologne if I suspect my account has been hacked or my device has been compromised?
A potential unauthorised access often involves highly personal data and can cause considerable anxiety. This is precisely why an objective investigation is important: not every anomaly constitutes an attack, but any concrete suspicion should be investigated using appropriate digital evidence.
How is such a technical investigation carried out in practice?
LanCologne formulates specific research questions based on the observations, collects relevant data, examines primary artefacts and documents incriminating, exonerating and inconclusive findings.
Can such an investigation always produce a clear result?
We do not promise to find a perpetrator or malware on every device. Our findings are based solely on what the existing digital evidence actually reveals.
Is there a legal basis for this?
In the event of suspected unauthorised access, various criminal offences may be involved. Section 202a of the German Criminal Code (StGB) covers, subject to its conditions, the unauthorised obtaining of access to data that is specifically protected against unauthorised access and not intended for the perpetrator, by circumventing the access security measures. Section 202b of the German Criminal Code (StGB) covers, subject to its conditions, the unauthorised interception of data not intended for the perpetrator from a non-public data transmission or electromagnetic emissions. Data tampering (Section 303a of the German Criminal Code) or computer sabotage (Section 303b of the German Criminal Code) may also be relevant, depending on the actual facts of the case. In the case of stalking, Section 238 of the German Criminal Code (StGB) takes into account, amongst other things, certain digital acts and expressly refers to offences under Sections 202a to 202c. However, the technical detection of access or alteration does not automatically mean that all elements of the offence are fulfilled or that a specific person is the perpetrator. To ensure evidence is preserved for later use, it is important not to alter digital content unnecessarily. The Police Crime Prevention Unit also recommends the prompt documentation of digital evidence in cases of online crime; in the case of hacked accounts, the priority is both rapid damage limitation and safeguarding evidence. Both must be coordinated appropriately in each specific case. LanCologne does not make any criminal attributions of blame and is no substitute for the police or a solicitor. We can establish technical facts and document them in a traceable manner on devices and data lawfully provided to us. Whether this gives rise to a criminal offence, a civil claim or any other legal consequence is assessed by the competent authorities.

LanCologne – IT Forensics for Private Individuals

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now