OSINT Case Studies: 12 Cybercrime Investigations Checked Against the Public Record

An index of OSINT case studies built on public-record identifiers from charged, convicted and sanctioned cybercrime cases. The method, a table of all 12 posts and the technique each teaches, six lessons that hold across cases, and the ethics rules the series follows.

Patrick Saif9 min read

ShareXLinkedInHacker News
Dark editorial cover with a dotted grid with a sparse scatter of lit cells beside the words OSINT case studies
Dark editorial cover with a dotted grid with a sparse scatter of lit cells beside the words OSINT case studies

These OSINT case studies start where the investigators finished. Every email address and alias in them was first printed by a court filing, a US Treasury sanctions entry or named investigative reporting, about a person who has been charged, convicted or sanctioned for cybercrime. In September 2026 we ran those identifiers through the OSINTsearch email lookup and username search, then wrote up what came back. This page indexes the series: what each post covers, the technique it teaches, and the lessons that hold across cases.

What these OSINT case studies are

Each post takes identifiers that are already public and asks two questions. How far does this address or alias travel on live platforms today? And what does that teach about investigation method? Six posts follow one case or group, from Scattered Spider to TeamPCP. Six are guides that draw on several cases to teach one technique. Together they work as OSINT investigation examples with every input shown.

Search results are presence and profile data layered on the record. A display name or location is whatever the account holder typed, and none of it replaces the record.

The method in plain language

  1. Start from a document that prints the identifier. An indictment, complaint, affidavit, sentencing memo, OFAC entry or named news report. Addresses that circulate online for well-known defendants but appear in no primary source are not searched.
  2. Copy it letter by letter. Krebs printed [email protected] in 2018 and [email protected] in 2019 for the same registration. One letter changes the result.
  3. Run each email through the email lookup. It checks about 175 platforms and reports registrations found, plus the profile where a platform exposes one: a GitHub handle, display name and creation date, for example.
  4. Run each alias through the username search. It checks about 760 platforms. Any handle the email side returned gets the same treatment.
  5. Put every date on the case timeline. Created before the alias existed, while it was in use, or after the name went public.
  6. Grade each result against the record, and log contradictions next to matches.

The case studies and guides

PostCase from the public recordTechnique it teaches
How hackers get caughtCourt records in cases including RaidForums, REvil, AlphaBay and Scattered SpiderThe nine recurring OPSEC mistakes, and what the published personal mailboxes still return
Scattered Spider handle mapSixteen charged people, from US indictments and complaints and the UK Transport for London prosecution (Krebs)Mapping a whole group's published aliases and separating noise and post-charge squatters from profiles that fit the record
KFC Watermelon and LuminosityLinkColton Grubbs, sentenced to 30 months in 2018Email to GitHub display name to a dated handle trail
Galochkin and volhvbMaksim Galochkin, sanctioned on 7 September 2023 and named in three indictmentsOne coined handle reused across four mailboxes, and why the oldest account is often the most useful
Joeleoli: username vs emailJoel Martin Evans, sentenced to 24 months on August 27, 2026When the handle carries a name and the mailbox returns no handle
Find a GitHub account by emailSeven public-record addresses, including those tied to Grubbs, Benthall and KhoroshevCommit attribution, and display names read as corroboration
Threat actor attribution with OSINTOFAC aliases and addresses, plus the TeamPCP and LockBit reportingA graded evidence ladder, from alias collisions to email-anchored accounts
Can a burner email be traced?Affidavits and complaints in the Fitzpatrick, Coelho, Buchanan and Rudometov casesHow persona addresses were traced through what they touched
LockBitSupp on the recordDmitry Khoroshev, whose indictment was unsealed and who was sanctioned on 7 May 2024Anchoring on published mailboxes and dating the accounts on a famous alias
OFAC SDN list email addresses23 addresses from ten cyber-related designations on the SDN listFinding and searching the email fields in sanctions entries
How to find when an account was createdThe LockBitSupp alias, a TrickBot sanctions entry and the spdr01 alias Krebs tied to Daniel KayeReading creation dates as evidence: before, during or after the case
TeamPCP arrestsRuben Ian Thomson, arrested in Perth in August 2026 and indicted in CaliforniaFollowing a journalist's attribution chain, then testing its published addresses and aliases

Khoroshev, Thomson, Coelho and Rudometov are charged, not convicted, and are presumed innocent, as is every other person here who has not been convicted.

Six lessons that hold across cases

Every example below comes from a post in the table.

1. The everyday mailbox is the one that talks

Persona addresses rarely identified anyone. The Fitzpatrick affidavit describes a Riseup address used to register on RaidForums; an email lookup found no registrations for it, consistent with that role, while the personal Gmail that Google records tie to him returned 11 registrations. In the TeamPCP case, the lookup found no registrations for the address the record ties to the BreachForums "Express" account, consistent with the forum-only use the record describes, while a Gmail Krebs tied to a Microsoft account in Thomson's name returned 24 results. Persona addresses were traced instead through what they touched, as the burner email post shows.

2. A coined handle is a fingerprint; a dictionary word is camouflage

volhvb returned 11 exact matches and no near misses. joeleoli returned 33 results, all exact matches. deadcatx3 returned 21 exact-match results, including the HackerOne profile Krebs reported. Common strings behave differently: Express, the BreachForums name Krebs ties to the group, returned 316 exact-match results and the TrickBot alias mango 439. A hit on a common word is a starting point, never an answer.

3. An email anchor beats a handle match

nerowolfe, the name of a fictional detective, returned 113 exact matches. Only one of them, the GitHub account reached through [email protected], is anchored to the public record, and it carries the NeroWolfe persona Krebs tied to Khoroshev. The same pattern holds for Grubbs, whose published Gmail resolves to a GitHub account displaying "Colton Grubbs", and for the OFAC address on Maksim Rudenskiy's entry, which resolves to a GitHub account displaying "Max Rudensky".

4. Dates sort owners from squatters

A creation date is the one profile field the owner cannot type. On the lockbitsupp alias, a Steam account held by an unrelated gamer dates from 2004, years before LockBit existed (Steam lets users change a profile URL, so the handle itself may be newer). A Codeforces account appeared five days after the indictment was unsealed and TikTok and Twitch accounts followed in December 2025, all possible squatters or impersonators. In the Joeleoli case, a GitLab profile displaying "Joel Evans" dates from September 2017, before the conspiracy he admitted, while a MyAnimeList account on the handle was created roughly 21 months after the arrest and carries the same squatter hedge. On the volhvb handle, none of the dated accounts was created after the designation.

5. The record anchors, and the search illustrates

The HackerOne profile at deadcatx3 displays "ruben thomson", exactly as Krebs reported. The Medium profile on volhvb displays the Cyrillic spelling of the name on the sanctions entry. Both mean something only because a public record had already tied the handle to the name. Good sources say so. Of his LockBit reconstruction, Krebs wrote: "Does the above timeline prove that NeroWolfe/Khoroshev is LockBitSupp? No." On a handle that appears nowhere in the record, a matching display name is a lead, not a conclusion.

6. Know which document prints identifiers

The Khoroshev indictment prints no email address at all, and the IntelBroker complaint refers to "West Email Account-1". The OFAC entry for Khoroshev prints two addresses. In the Scattered Spider cases, UK and European authorities published names, ages, towns and sentences but no alias, mailbox or handle; the US filings and journalists supplied the strings to search. Our SDN email guide shows how to find them on the list.

The ethics rules this series follows

  • Public record only. Subjects are people publicly charged, convicted or sanctioned. Every identifier searched was first printed by a court, Treasury or named reporting, and every claim links to that source.
  • Presumption of innocence. Charged means alleged. Persona ownership is attributed to whoever established it, such as "the NeroWolfe persona Krebs tied to him".
  • No minors and no victims. Neither is identified or described.
  • No unpublished handles. When a lookup surfaces a handle or display name the record never printed, the post describes it generically, for example as a profile whose display name matches the sanctioned name. Unrelated people who share a handle are never named.
  • A zero result is not proof. A lookup that finds no registrations says what that lookup found, not that no account exists. A mailbox is called a persona or burner address only when the record describes it that way.
  • Later accounts are hedged. Anything created after an arrest, unsealing or designation is treated as a possible squatter or impersonator.
  • Some published details stay out. Phone numbers, passwords, passport and tax numbers, and relatives' details are left out even when a source prints them.

FAQ

What is an OSINT case study?

A worked example of open source investigation with its inputs shown: the identifier, the document that published it, the search run, and what came back. Here, every input is a public-record email or alias, so anyone can check the source and repeat the search.

Where do the identifiers in these case studies come from?

From indictments, complaints, affidavits, sentencing memos, OFAC sanctions entries and named reporting such as KrebsOnSecurity and BleepingComputer. The journalists and firms behind that work, including Intel 471 and OpenSanctions, deserve most of the credit.

Does a matching username or display name prove who owns an account?

No. A match shows a string is registered, and display names are self-typed. The attribution guide grades each kind of evidence, and the username verification checklist gives you a worksheet for the comparison.

Can I repeat these investigations myself?

Yes. Take an identifier from a primary source, run the email lookup first, search any handle it returns, sort the results by creation date and log results that contradict the record next to those that fit it.

Run your own case study

The method works on any lead, or on your own footprint. Run a free search on OSINTsearch for an email address or username. Results show the platform and profile details such as display names and join dates where available, and paid plans export to CSV, JSON or PDF.

ShareXLinkedInHacker News
All articles

Guides9 min

Threat Actor Attribution With OSINT: From Alias to Name, With Evidence Grades

A username match is not an attribution. Using aliases and email addresses already printed in sanctions entries, court filings and named reporting, this guide grades each kind of OSINT evidence on a six-rung ladder, from common-word collisions like "mango" (439 exact-match results) to email-anchored accounts and display names that reproduce a published identification. It also covers what never counts and how to verify a "hacker's email" before you pivot.

Try it

Run a live search on any username.

Free preview, no account needed. Sign up to view available profile details.

For other identifiers, try reverse email lookup or phone number lookup.