OSINT and the Digital Footprint: How Investigators Trace Online Criminal Activity
Open-source intelligence has transformed criminal investigation. Understanding how digital footprints are traced — and how they are obscured — is essential knowledge for law enforcement, legal teams, and organisations managing post-incident recovery.
Every act of online criminal activity leaves traces. The nature, volume, and accessibility of those traces has changed fundamentally with the growth of digital infrastructure, social media, cryptocurrency transaction records, and the aggregation of data across commercial platforms. Open-source intelligence — the collection and analysis of publicly available or legally accessible information — has become one of the primary investigative tools for financial crime, cybercrime, harassment, fraud, and online abuse. Understanding its capabilities and limitations is essential for any team managing the aftermath of a digital incident.
The digital footprint of an online offender typically includes: IP address records from platform logs; account registration data including email addresses and phone numbers used for verification; device identifiers that persist across account changes; geolocation metadata embedded in images and files; financial transaction records from payment processors and cryptocurrency blockchains; and behavioural patterns that establish identity even where nominal anonymity has been attempted. The skill of OSINT investigation lies in aggregating these traces across multiple sources to build a coherent identity picture.
Cryptocurrency transactions, widely assumed to provide anonymity, have proven one of the most traceable elements of the digital footprint. Public blockchain records create an immutable transaction history. Forensic blockchain analysis — now a mature discipline with dedicated commercial tools and court-recognised methodology — can trace funds across hundreds of transactions, identify clustering patterns that associate addresses with real individuals, and follow proceeds to exchanges with KYC obligations. The practical anonymity of cryptocurrency in criminal activity has been substantially overstated.
The legal framework governing OSINT collection varies significantly by jurisdiction and determines what material is admissible and what collection methods expose investigators to liability. Material that is publicly accessible is not always legally obtainable in ways that preserve admissibility. Platform data obtained without appropriate legal process may be excluded. OSINT investigation in support of criminal proceedings requires forensic rigour and legal awareness in equal measure — technical capability alone is insufficient.
For organisations managing post-incident recovery, OSINT capability serves multiple purposes: identifying the threat actor where possible, establishing the scope of data exposure by identifying where exfiltrated material has appeared online, and supporting law enforcement with intelligence that accelerates formal investigation. Custodia One's investigative team conducts OSINT operations to the standard required for evidentiary use, coordinating findings with law enforcement and legal counsel in a format that preserves both intelligence value and legal admissibility.
"The assumption that online anonymity makes digital criminals untraceable is consistently disproved by forensic investigation. The question is not whether a digital footprint exists. It is whether anyone with the capability and the legal authority to follow it has been engaged."
Custodia One Advisory Perspective
What Your Organisation Should Do
Preserve all digital artefacts from an incident in original form before any OSINT investigation begins: collection methodology directly affects admissibility
Engage investigators with both OSINT tradecraft and legal awareness: technical skill without legal rigour can undermine the prosecution case
Treat cryptocurrency as traceable: involve blockchain forensics specialists for any incident involving financially motivated crime with crypto payments
Coordinate OSINT findings with law enforcement early: intelligence developed in support of an active investigation carries different weight than material developed independently
Advisory Enquiries
Facing this issue in your organisation?
Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.
