How do hackers get caught? In the cases that reach court, usually not by a better hacker. They are caught by an email address they opened years earlier, a password they liked too much, a login from their home connection, or a trip abroad. We read the court filings, sanctions entries and investigative reporting behind nearly 50 cybercrime cases, and the same handful of OPSEC mistakes shows up again and again.
How do hackers get caught? The short answer
Identification almost never needed an exploit. It came from records that ordinary companies keep: email providers, domain registrars, internet service providers, crypto exchanges and the forums themselves. The table sorts the nine recurring mistakes.
| OPSEC mistake | Case from the record | What the record says tied the persona to the person |
|---|---|---|
| 1. Reusing an old personal email | Yaroslav Vasinskyi (REvil, "Yarik45") | A 2013 forum account and a VK profile in his name were both registered with [email protected] (KrebsOnSecurity) |
| 2. Personal email in operational infrastructure | Alexandre Cazes (AlphaBay) | [email protected] sat in the header of the market's welcome email, per the complaint (VICE). Cazes died in custody in Thailand in 2017, before any trial. |
| 3. Password reuse across personas | Mikhail Matveev ("Wazawaka") | The forum alter egos Krebs tied to him always used one of three distinctive passwords, per breach data (KrebsOnSecurity) |
| 4. Logging in from home | Tyler Buchanan (Scattered Spider, "TylerB") | The domain registrar account behind phishing domains logged in from an IP leased to him (complaint ¶35 to ¶38) |
| 5. Crypto accounts with real ID | Kai West ("IntelBroker") | A wallet traced to a Ramp account opened with his UK driver's license and a Coinbase account tied to the same license; both used his personal email (The Register) |
| 6. Trusting a forum's database | Conor Fitzpatrick ("Pompompurin") | Messages and login IPs from the seized RaidForums database (FBI affidavit) |
| 7. Contacting investigators with an operational address | Diogo Santos Coelho (RaidForums) | He emailed the FBI case agent from the address that registered the forum's backup domains (KrebsOnSecurity) |
| 8. Reusing an alias in a real business name | Ruben Thomson (TeamPCP, alleged) | He incorporated or served as an official in companies including one named "OPSEC Express"; "Express" was the Breachforums nickname Krebs ties to the group (KrebsOnSecurity) |
| 9. Traveling | Oleg Nikolaenko (Mega-D) | Arrested after entering the US to attend a car show in Las Vegas (KrebsOnSecurity) |
The old email address never dies
The single most common thread is an everyday mailbox from years before the crime. In the REvil case, Krebs found that [email protected] registered a cybercrime forum account in 2013 and a VK profile under Vasinskyi's name. The same reporting found that [email protected] registered the "Damnating" account on a breached carding forum in 2008 and tied to a VK profile for Yevgeniy Polyanin, who was indicted and remains at large. Krebs wrote that this lack of OPSEC "is so common that it is hardly remarkable." Vasinskyi was later sentenced to 13 years and 7 months.
The alleged LockBit leader follows the same pattern. According to KrebsOnSecurity, the address [email protected] registered more than a dozen accounts for "NeroWolfe", a persona Krebs tied to Dmitry Khoroshev, and in 2011 a VK account for a Dmitry Yurevich Khoroshev. Khoroshev is indicted and sanctioned, not in custody, and presumed innocent. Silk Road 2.0's alleged operator, Blake Benthall, was charged in 2014 after an undercover agent reported that the marketplace server was controlled by someone using [email protected] (KrebsOnSecurity).
Reusing a password or a handle
A reused password links accounts that share nothing else. Breach data showed that the Wazawaka alter egos always used one of three fairly unique passwords, which let researchers join the personas into one person. Matveev was later indicted and sanctioned, with a $10 million reward offered for information (KrebsOnSecurity).
Handles work the same way, and investigators know why criminals keep them. The FBI complaint against RedLine's alleged developer, Maxim Rudometov, puts it plainly: "cyber criminals are incentivized to use the same moniker in order to establish their reputation within the cybercrime community" (W.D. Tex. complaint). In that case, a leaked forum database showed a Yandex address registering the "Dendimirror" moniker, and the same address later appeared on an Apple account registered in his name. Rudometov is charged, not arrested, and presumed innocent. Our Scattered Spider handle map shows aliases doing the same work.
Trusting that the forum will stay private
Criminal forums keep logs, and forums get seized. When the FBI took RaidForums, it inherited the private messages and login records of its users. The affidavit against Conor Fitzpatrick quotes "pompompurin" telling the RaidForums admin in 2020 that he had looked up "one of my old emails" in a breach and could not find it in a leaked file. That old email was [email protected]. The same seized records showed the account logging in from IP addresses that Verizon tied to mobile devices registered to him.
He did use VPNs. Google records showed his newer Gmail logging in through at least ten VPN providers. But he used the same VPN exits for both lives: of the 31 IP addresses that accessed that Gmail between September 2021 and May 2022, 12 were also used to log into the pompompurin RaidForums account. One VPN address that touched the Gmail on March 7, 2022 logged into a Zoom account named "pompompurin" the next day, registered with the forum's sign-up address. Fitzpatrick pleaded guilty and was resentenced to three years in prison in September 2025. TechCrunch has a readable walkthrough.
Genesis Market shows the same risk at scale. Ruben van Well, who leads the Dutch police cybercrime team in Rotterdam, told KrebsOnSecurity that the market stored all of its data in plain text, and the takedown produced 119 arrests worldwide.
How the FBI identifies hackers
Court filings show the recurring tools:
- Legal process to ordinary companies. Subpoenas and warrants to Google, Apple, Microsoft, ISPs such as Verizon and Virgin Media, and registrars such as NameCheap, as in Buchanan's case.
- Seized databases. One takedown's server becomes the next case's evidence, as RaidForums became for Fitzpatrick.
- Undercover buys and money trails. Undercover agents bought stolen access from IntelBroker and, according to the FBI, traced the bitcoin to Kai West's exchange accounts. West was arrested in France and is charged, not convicted.
- Border searches and travel. Coelho's devices were searched when he tried to enter the US at Atlanta's airport in June 2018. He was arrested in the UK in January 2022 at US request (DOJ). Buchanan was detained at Palma airport in 2024 (CyberScoop) and later pleaded guilty.
- Indictments and sanctions when arrest is impossible. Khoroshev lives in Russia, so the record is an indictment, an OFAC listing and a reward. Russian authorities reportedly arrested Matveev on their own charges in late 2024, but he has not been handed to the US (KrebsOnSecurity).
How journalists and researchers do it
Reporters do not have subpoena power, so they work from open and commercial data. Brian Krebs's identifications lean on breach-data search at Constella Intelligence, forum archives from Intel 471, historical WHOIS from DomainTools and email lookups from Epieos. These are excellent tools. The method: find the oldest handle, the email that registered it, then every account that email touched. In the TeamPCP case, Krebs linked forum personas through identical Tox and Session IDs, then found a HackerOne profile registered under the name Ruben Thomson with the username Deadcatx3. Thomson has since been indicted in the Northern District of California and is presumed innocent. We cover the full method in threat actor attribution with OSINT.
What those old mailboxes return today
In September 2026 we ran the published personal addresses above through the OSINTsearch email lookup, which checks roughly 175 platforms. Every one still returns registrations.

| Address (public record) | Role in the record | Registrations found |
|---|---|---|
[email protected] | Google account in Fitzpatrick's name | 11 |
[email protected] | Personal address tied to the Silk Road 2.0 server | 11 |
[email protected] | 2008 forum registration | 7 |
[email protected] | 2013 forum registration | 6 |
[email protected] | AlphaBay welcome email header | 5 |
[email protected] | Forum persona address | 4 |
The old mailboxes still carry registrations on mainstream services such as Microsoft, Spotify, Dropbox and gaming platforms. A registration shows an account exists on that address, not who opened it or when, and these addresses have been public for years. An email lookup on [email protected] also returns a GitHub account registered to that address that carries the NeroWolfe name Krebs published. Single-purpose addresses in these cases, such as the NameCheap account address in Buchanan's complaint, tell a different story; whether a burner email can be traced covers them.
FAQ
How do most hackers get caught?
Through records kept by ordinary companies: an old personal email, a reused password or handle, a home IP in a registrar or forum log, or ID documents at a crypto exchange. Arrests often follow travel.
Do most hackers ever get caught?
None of the sources we reviewed gives a reliable catch rate, so we will not invent one. What the record does show is that time works against them. Vasinskyi's email trail ran back to 2013 and led to charges in 2021, and Polyanin's to 2008. Some people are identified and charged but not arrested, as with Khoroshev and Rudometov.
Does a VPN stop hackers from being traced?
Not reliably. Fitzpatrick used at least ten VPN providers, but he used the same VPN exits for his real Gmail and his forum account, so 12 shared IP addresses linked the two. Forum logins from his mobile carrier did the rest.
How does the FBI track hackers who live in Russia?
It builds the identification anyway, then indicts, sanctions and offers rewards, as with Khoroshev. Arrest waits for travel to a country that will extradite, as with Nikolaenko, who was arrested after entering the US for a car show.
The takeaway
Hackers get caught by their history, not their tools. The persona is careful; the person behind it has a decade of accounts, and one of them often connects. To see what your own address reveals, try our free digital footprint audit or read how to see behind an email. To check any email or username, run a free search on OSINTsearch. Results show the platform and profile details such as display names and join dates where available, and paid plans export to CSV, JSON or PDF.



