These OSINT case studies start where the investigators finished. Every email address and alias in them was first printed by a court filing, a US Treasury sanctions entry or named investigative reporting, about a person who has been charged, convicted or sanctioned for cybercrime. In September 2026 we ran those identifiers through the OSINTsearch email lookup and username search, then wrote up what came back. This page indexes the series: what each post covers, the technique it teaches, and the lessons that hold across cases.
What these OSINT case studies are
Each post takes identifiers that are already public and asks two questions. How far does this address or alias travel on live platforms today? And what does that teach about investigation method? Six posts follow one case or group, from Scattered Spider to TeamPCP. Six are guides that draw on several cases to teach one technique. Together they work as OSINT investigation examples with every input shown.
Search results are presence and profile data layered on the record. A display name or location is whatever the account holder typed, and none of it replaces the record.
The method in plain language
- Start from a document that prints the identifier. An indictment, complaint, affidavit, sentencing memo, OFAC entry or named news report. Addresses that circulate online for well-known defendants but appear in no primary source are not searched.
- Copy it letter by letter. Krebs printed
[email protected]in 2018 and[email protected]in 2019 for the same registration. One letter changes the result. - Run each email through the email lookup. It checks about 175 platforms and reports registrations found, plus the profile where a platform exposes one: a GitHub handle, display name and creation date, for example.
- Run each alias through the username search. It checks about 760 platforms. Any handle the email side returned gets the same treatment.
- Put every date on the case timeline. Created before the alias existed, while it was in use, or after the name went public.
- Grade each result against the record, and log contradictions next to matches.
The case studies and guides
| Post | Case from the public record | Technique it teaches |
|---|---|---|
| How hackers get caught | Court records in cases including RaidForums, REvil, AlphaBay and Scattered Spider | The nine recurring OPSEC mistakes, and what the published personal mailboxes still return |
| Scattered Spider handle map | Sixteen charged people, from US indictments and complaints and the UK Transport for London prosecution (Krebs) | Mapping a whole group's published aliases and separating noise and post-charge squatters from profiles that fit the record |
| KFC Watermelon and LuminosityLink | Colton Grubbs, sentenced to 30 months in 2018 | Email to GitHub display name to a dated handle trail |
| Galochkin and volhvb | Maksim Galochkin, sanctioned on 7 September 2023 and named in three indictments | One coined handle reused across four mailboxes, and why the oldest account is often the most useful |
| Joeleoli: username vs email | Joel Martin Evans, sentenced to 24 months on August 27, 2026 | When the handle carries a name and the mailbox returns no handle |
| Find a GitHub account by email | Seven public-record addresses, including those tied to Grubbs, Benthall and Khoroshev | Commit attribution, and display names read as corroboration |
| Threat actor attribution with OSINT | OFAC aliases and addresses, plus the TeamPCP and LockBit reporting | A graded evidence ladder, from alias collisions to email-anchored accounts |
| Can a burner email be traced? | Affidavits and complaints in the Fitzpatrick, Coelho, Buchanan and Rudometov cases | How persona addresses were traced through what they touched |
| LockBitSupp on the record | Dmitry Khoroshev, whose indictment was unsealed and who was sanctioned on 7 May 2024 | Anchoring on published mailboxes and dating the accounts on a famous alias |
| OFAC SDN list email addresses | 23 addresses from ten cyber-related designations on the SDN list | Finding and searching the email fields in sanctions entries |
| How to find when an account was created | The LockBitSupp alias, a TrickBot sanctions entry and the spdr01 alias Krebs tied to Daniel Kaye | Reading creation dates as evidence: before, during or after the case |
| TeamPCP arrests | Ruben Ian Thomson, arrested in Perth in August 2026 and indicted in California | Following a journalist's attribution chain, then testing its published addresses and aliases |
Khoroshev, Thomson, Coelho and Rudometov are charged, not convicted, and are presumed innocent, as is every other person here who has not been convicted.
Six lessons that hold across cases
Every example below comes from a post in the table.
1. The everyday mailbox is the one that talks
Persona addresses rarely identified anyone. The Fitzpatrick affidavit describes a Riseup address used to register on RaidForums; an email lookup found no registrations for it, consistent with that role, while the personal Gmail that Google records tie to him returned 11 registrations. In the TeamPCP case, the lookup found no registrations for the address the record ties to the BreachForums "Express" account, consistent with the forum-only use the record describes, while a Gmail Krebs tied to a Microsoft account in Thomson's name returned 24 results. Persona addresses were traced instead through what they touched, as the burner email post shows.
2. A coined handle is a fingerprint; a dictionary word is camouflage
volhvb returned 11 exact matches and no near misses. joeleoli returned 33 results, all exact matches. deadcatx3 returned 21 exact-match results, including the HackerOne profile Krebs reported. Common strings behave differently: Express, the BreachForums name Krebs ties to the group, returned 316 exact-match results and the TrickBot alias mango 439. A hit on a common word is a starting point, never an answer.
3. An email anchor beats a handle match
nerowolfe, the name of a fictional detective, returned 113 exact matches. Only one of them, the GitHub account reached through [email protected], is anchored to the public record, and it carries the NeroWolfe persona Krebs tied to Khoroshev. The same pattern holds for Grubbs, whose published Gmail resolves to a GitHub account displaying "Colton Grubbs", and for the OFAC address on Maksim Rudenskiy's entry, which resolves to a GitHub account displaying "Max Rudensky".
4. Dates sort owners from squatters
A creation date is the one profile field the owner cannot type. On the lockbitsupp alias, a Steam account held by an unrelated gamer dates from 2004, years before LockBit existed (Steam lets users change a profile URL, so the handle itself may be newer). A Codeforces account appeared five days after the indictment was unsealed and TikTok and Twitch accounts followed in December 2025, all possible squatters or impersonators. In the Joeleoli case, a GitLab profile displaying "Joel Evans" dates from September 2017, before the conspiracy he admitted, while a MyAnimeList account on the handle was created roughly 21 months after the arrest and carries the same squatter hedge. On the volhvb handle, none of the dated accounts was created after the designation.
5. The record anchors, and the search illustrates
The HackerOne profile at deadcatx3 displays "ruben thomson", exactly as Krebs reported. The Medium profile on volhvb displays the Cyrillic spelling of the name on the sanctions entry. Both mean something only because a public record had already tied the handle to the name. Good sources say so. Of his LockBit reconstruction, Krebs wrote: "Does the above timeline prove that NeroWolfe/Khoroshev is LockBitSupp? No." On a handle that appears nowhere in the record, a matching display name is a lead, not a conclusion.
6. Know which document prints identifiers
The Khoroshev indictment prints no email address at all, and the IntelBroker complaint refers to "West Email Account-1". The OFAC entry for Khoroshev prints two addresses. In the Scattered Spider cases, UK and European authorities published names, ages, towns and sentences but no alias, mailbox or handle; the US filings and journalists supplied the strings to search. Our SDN email guide shows how to find them on the list.
The ethics rules this series follows
- Public record only. Subjects are people publicly charged, convicted or sanctioned. Every identifier searched was first printed by a court, Treasury or named reporting, and every claim links to that source.
- Presumption of innocence. Charged means alleged. Persona ownership is attributed to whoever established it, such as "the NeroWolfe persona Krebs tied to him".
- No minors and no victims. Neither is identified or described.
- No unpublished handles. When a lookup surfaces a handle or display name the record never printed, the post describes it generically, for example as a profile whose display name matches the sanctioned name. Unrelated people who share a handle are never named.
- A zero result is not proof. A lookup that finds no registrations says what that lookup found, not that no account exists. A mailbox is called a persona or burner address only when the record describes it that way.
- Later accounts are hedged. Anything created after an arrest, unsealing or designation is treated as a possible squatter or impersonator.
- Some published details stay out. Phone numbers, passwords, passport and tax numbers, and relatives' details are left out even when a source prints them.
FAQ
What is an OSINT case study?
A worked example of open source investigation with its inputs shown: the identifier, the document that published it, the search run, and what came back. Here, every input is a public-record email or alias, so anyone can check the source and repeat the search.
Where do the identifiers in these case studies come from?
From indictments, complaints, affidavits, sentencing memos, OFAC sanctions entries and named reporting such as KrebsOnSecurity and BleepingComputer. The journalists and firms behind that work, including Intel 471 and OpenSanctions, deserve most of the credit.
Does a matching username or display name prove who owns an account?
No. A match shows a string is registered, and display names are self-typed. The attribution guide grades each kind of evidence, and the username verification checklist gives you a worksheet for the comparison.
Can I repeat these investigations myself?
Yes. Take an identifier from a primary source, run the email lookup first, search any handle it returns, sort the results by creation date and log results that contradict the record next to those that fit it.
Run your own case study
The method works on any lead, or on your own footprint. Run a free search on OSINTsearch for an email address or username. Results show the platform and profile details such as display names and join dates where available, and paid plans export to CSV, JSON or PDF.



