Real investigations

Case studies

Anonymized write-ups of real investigations run through CryptoSec Labs. Names and specific targets removed to protect clients.

Email Forensics

Attributing a business-email-compromise to a known threat actor

A mid-size firm was hit by a BEC scam. Email header chain, SPF/DKIM analysis and breach lookup connected the actor to 12 prior campaigns.

Time to answer
2 days
Outcome
Attribution confirmed, insurance claim approved
OSINT / Domain Intelligence

Uncovering a 47-domain phishing cluster from a single WHOIS lead

One suspicious domain led to a full phishing operation running across 3 registrars and 6 hosting providers. Reverse WHOIS and passive DNS revealed the whole cluster.

Time to answer
90 minutes
Outcome
All 47 domains reported and taken down in 48h
Blockchain Forensics

Tracing a $2.4M ransomware payment through a cross-chain mixer

A client's cold wallet was drained via a phishing approval. We followed the USDC through Tornado Cash, bridged to Solana, and identified the receiving exchange.

Time to answer
4 hours
Outcome
Receiving exchange account identified and frozen

Your investigation, on this list

Get full access to every tool used in these cases. $5/month, cancel anytime.

Get access now →