Home // BLOG // COMPUTER FORENSICS

Crimes on social media: establishing authorship and evidentiary validity

How forensics establishes authorship in social media crimes, why the screenshot is not enough, and how to preserve evidence.

Computer Forensics · March 17, 2026 · 7 min read

Authorship examination in crimes committed on social media

An offensive post published by a faceless profile. A scam run by someone using stolen photos. A threat sent from an account created the day before. The victim's reaction is usually the same: the feeling that there is no way to find out who is on the other side. Forensic practice shows a different picture. Every social media account operates on infrastructure that records connections, and those records, when preserved and requested the right way, make it possible to establish authorship with evidentiary validity.

The false sense of anonymity

Social networks today concentrate most of the incidents that reach authorship examinations: offensive posts, threats, fake profiles, romance scams, defamatory montages, and hate crimes. Whoever publishes racial or religious bigotry hidden behind an anonymous profile tends to believe they are protected by the distance of the screen. They are not. Freedom of expression does not cover crime, and the author answers for what they publish. What exists is a false sense of impunity, fed by how easy it is to create accounts.

Not even concealment tools deliver the anonymity they promise. In one investigation of fake profiles used in romance scams, the criminal kept every conversation behind a VPN, a service that masks the origin of the connection. No system is completely secure: at isolated moments the VPN failed, the real IP address leaked, and the analysis pointed to a specific city, along with access points abroad that revealed the structure of an international criminal ring. The material was forwarded to the competent authorities for further action.

What traces a profile leaves

Even a fake account produces traces on several layers. The IP address and logical ports of each connection, recorded by the application provider. The account metadata: registration email, creation date, latest logins, and services tied to the same credentials. The writing patterns: recurring expressions, characteristic mistakes, the way victims are approached, the so-called modus operandi. And the activity hours, which reveal the routine and time zone of whoever operates the profile. In isolation, each trace says little. Correlated, they converge on a person.

"Anonymity on social media is a feeling, not a technical fact. Every trace has an author, and method finds them."

How authorship is established, and the risk of false positives

The technical route runs through a court-authorized disclosure of telematic records. The application provider (the social network) reports the IP and the logical ports used in the publication; the connection provider identifies the subscriber behind that access. The request demands precision: on IPv4 networks, a single address is shared by dozens of simultaneous users, and without the logical ports the identification is lost. Time zone conversion also has to be exact, because a difference of hours points to someone else. In one real case, a single transposed digit in the IP supplied by the provider placed a worker with no connection to the facts as defendant in a 400,000-real lawsuit.

Hence the central rule of the investigation: the person behind the IP is not always the author. The subscriber may be the owner of an establishment offering Wi-Fi to customers, the holder of the residence where someone else used the network, the shopkeeper who shared internet access without registration. The forensic examination works precisely on excluding these false positives, cross-referencing connection records with writing patterns, activity hours, relationships between the accounts involved, and the modus operandi.

Why a screenshot is not enough as evidence

A screen capture is an image, nothing more. It carries no origin metadata, allows no integrity verification, and can be fabricated by anyone with two phones and a few minutes. In a recent electoral case, screenshots of alleged WhatsApp conversations were filed in a proceeding as if they were real. The forensic demonstration reproduced, in a few minutes and on video, the entire content of the screenshots: all it took was creating a group, saving contacts in the address book under the desired names (which makes the real number disappear from the screen), swapping the profile pictures, and typing the messages. The result was visually identical to the document presented, and the traces of the montage allowed the examination to declare the fraud without even needing the original files.

This does not mean the screenshot is useless: it documents the moment and guides the investigation. It means that, on its own, it is fragile. Evidence challenged by the opposing party's technical assistant can collapse if there is no sound collection behind it.

How to preserve evidence correctly

Before any confrontation with the offender, the priority is to preserve. Record the exact URL of the profile and of each publication, the account identifier and, when available, the phone number. Do not delete conversations or block the contact before collection. Note the date, time, and time zone of each event. Whenever possible, the capture should be made with a forensic tool that generates an integrity code (hash) or through a notarial certificate, which lends public faith to the content. And time matters: providers retain records for short statutory periods, generally six months for applications and one year for connections. The police report is a necessary first step, but it does not identify authorship by itself.

When the forensic examination enters the case

The ideal moment is before the judicial request. A poorly drafted disclosure request, without logical ports, without a defined time zone, without a connection period, tends to come back incomplete or to point at the wrong person, with the risk of liability for moral damages. A prior expert opinion grounds the injunction, specifies what to request from each provider, and uses the same request to map services tied to the account under investigation. In the judicial phase, the forensic examination correlates the providers' responses, excludes false positives, and consolidates authorship in a expert report or expert opinion fit for adversarial scrutiny. Anyone facing a case of this kind gains by involving technical analysis early: the feasibility consultation indicates, before any larger expense, whether the available traces can sustain the investigation.

VALLIM

Adriano Vallim

Forensic expert specializing in digital crimes, working across computer forensics, handwriting and document examination, and forensic phonetics. He combines technical, academic and institutional credentials that place him among the most complete references in the field in Brazil. See the full background →

Read next

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination