Home // THE EXPERT // REPRESENTATIVE CASES

Representative cases

Described without any identification of the parties, in the format that matters to whoever is weighing up hiring an expert: the technical challenge, the method applied and the outcome.

The profile · 2 of 6

Serious forensic work does not expose the client. Under the duty of professional confidentiality, the cases on this page are described without any identification of the parties: names, brands, specific industries, technical addresses, exact dates and system identifiers have been removed, and figures were rounded so as to prevent recognition.

What remains is what matters to a reader deciding whether to retain a forensic expert: the technical challenge faced, the method applied and the result achieved.

Some of the cases below reached the laboratory after other teams had declared the investigation unfeasible, or when the procedural deadline was already running against the party. None of them rests on luck: all rest on documented method, chain of custody and the willingness to look where no one had looked.

Cases with public repercussion, in which the work has already been reported by the press, are identified as such.

Highly complex cases

When the technical answer seemed impossible

Computer forensics · Corporate →

An attack with its command centre hidden inside a public blockchain

The challenge. A payment processing platform was breached, had data destroyed and had no dedicated detection tooling. The intruder had used legitimate remote administration software as a disguise and erased his own traces. The board asked two questions: was the in-house team negligent, and is there any path to the person responsible?

The method. Full timeline reconstruction from weeks of authentication logs, with no gaps, showing the exact moment of the first illegitimate access. Examination of the malicious program revealed what no conventional tool would detect: the command and control channel was not on a server, but written into smart contracts on a public blockchain. The examination decoded the transactions and recovered the control address the intruder had deleted, because a blockchain record is immutable. From there it mapped the agent's financial network: more than ninety interlinked wallets and more than one hundred and twenty thousand transactions preserved as evidence, consulted only in the public ledger, with no interaction whatsoever with the intruder's infrastructure.

The result. The expert report handed the authorities concrete routes to identification: the international exchange operating the central wallet, the stablecoin issuers with legal power to freeze funds, and the platforms holding identity records of the account holders. It also demonstrated technically that the in-house team had not been negligent: the intruder's dwell time stayed within the global average for attacks of that level of sophistication, and the destructive event was detected in little more than twenty minutes, with neutralisation on the same day.

Forensic extraction · Criminal →

Thirteen devices, eight suspects and one innocent person among them

The challenge. A high-profile criminal investigation, with thirteen mobile phones from eight suspects under examination. The police inquiry and the official expert report had already concluded that one of the suspects had taken part. The sheer volume of material was itself part of the problem: the more devices enter the same analysis, the more apparent coincidences appear between them.

The method. Full forensic extraction of the device, with recovery of application data, timeline reconstruction and the building of a link tree between those involved, all written to sealed read-only media. Every correlation put forward as evidence of participation was tested individually against alternative explanations, precisely the examination that the volume of devices had prevented in the earlier analysis.

The result. The links supporting the accusation turned out to be false positives: convergences of contact, timing and message circulation that demonstrated no participation at all. The report, more than three hundred pages delivered in forty-five days, showed the error in the official conclusion, and the accused person was cleared. The sealed media ensured that neither prosecution nor defence could insert or suppress content after collection.

Computer forensics · Party-appointed expert →

Proof that one specific client had not been hit

The challenge. A platform serving more than a hundred organisations in a shared environment had its production server compromised, with code planted to capture card data in transit. Among the hosted clients, a highly visible organisation demanded an immediate answer: was its data captured?

The method. Analysis over a half-terabyte forensic copy, with integrity checked by cryptographic signature before any examination. The reconstruction identified the entry vector in the web application, the chain of remote commands executed, the capture code that was planted and the intended exfiltration destination. The work rigorously separated three actors frequently confused during incidents: the intruder, the legitimate administrators and the response team itself, ruling out false positives. It also identified the structural flaw that had made the attack possible, a single application cryptographic key shared across every portal on the platform.

The result. The examination showed that the capture code had not been planted in that client's directories and that the attempt to extract card data never reached its database, whose service had already been migrated to another environment weeks earlier. The negative proof, technically supported, ended the organisation's exposure to the incident. The examination also documented the intruder's reaction on noticing the response under way, behaviour that reinforced the finding of deliberate action.

Unfair competition · Search and seizure →

The database that gave itself away

The challenge. A company suspected that its client database, built over years, was being used by a competitor. Suspicion is not proof: it had to be shown technically that those specific records, and not records obtained by the competitor's own effort, were on the machines on the other side. The material was seized under a court order, and the analysis had to withstand the claim of coincidence.

The method. The examination started from a simple principle: every database carries marks of its own. Fields with no possibility of accidental collision were selected, among them the internal user code from the company's system and the corporate name spelled exactly as recorded in its register. Those terms were run against the whole seized collection, including deleted files and recovered e-mail content, with the file creation date on the operating system examined recorded for each item.

The result. More than four thousand seven hundred correlations between the company's data and the material found on the competitor's equipment, with thousands of sensitive documents identified and dated. The match of unique fields, impossible to explain by independent work, demonstrated reuse of the database. Here the data was not merely found: it was tied back to its origin.

Digital crimes · Professional privilege →

Hijacked e-mail accounts and the race against the log retention deadline

The challenge. A lawyer had the passwords to her accounts with three different providers changed by a third party, who downloaded and deleted personal and professional files. Beyond the immediate damage, the case struck at professional privilege and at the inviolability that the law guarantees to lawyers in practice. The providers' self-service tools showed only a short window of access records, insufficient to establish authorship.

The method. Technical preservation of what still existed on the three platforms, with a documented chain of custody, and comparative analysis of each provider's security reports. The examination showed technically why the data available to an ordinary user was not enough and what would have to be formally requested from each provider and from the connection carriers.

The result. The technical opinion supported the court application compelling the providers to produce the complete logs, still within the six-month statutory retention period set by the Marco Civil da Internet (Brazil's internet civil rights framework). Without that step in time, the traces of authorship would have expired and the case would have died for lack of evidence, not for lack of merit.

Digital document exam · Civil →

The valid electronic signature that the contracting party never applied

The challenge. A contract signed on an electronic signature platform, with a completion certificate in order, was denied by the supposed signatory. The opposing party argued that the technical validity of the signature settled the matter.

The method. Examination of the platform's audit trail and of the transaction metadata, comparing device, originating address and usage pattern with the contracting party's history.

The result. The signature came from a device never used by the contracting party in any other transaction. The certificate attested to the platform's process, not to the identity of whoever was on the other side of the screen: a distinction that carried the argument in court.

Handwriting · Civil →

Bank contract with a disputed signature

The challenge. An individual sued over a contract she said she had never signed, the classic mass-litigation scenario in which the signature is the only link between the debt and the supposed debtor.

The method. Handwriting comparison against contemporaneous specimens of unquestionable origin, examination of the genetic elements of the writing gesture and photomicrographic recording of the findings.

The result. The technical divergences identified supported the declaration of forgery and the annulment of the contract.

Licensing · Corporate →

A software piracy notice reviewed on technical grounds

The challenge. A company served notice by an international software vendor, with a multimillion claim calculated in the vendor's own audit.

The method. Independent review of the report against the real inventory of the estate: decommissioned machines, licences left uncounted and metrics applied incorrectly.

The result. The technical inaccuracies demonstrated cut the amount initially claimed by around sixty per cent, in a negotiation conducted on verifiable facts.

Forensic phonetics · Family →

The exclusion that cleared a name

The challenge. A covert recording attributed to one of the parties in a family dispute, with a request to identify the speaker.

The method. Comparative phonetic analysis between the questioned sample and voice specimens collected under a directed protocol, with the conclusion expressed as a degree of probabilistic support.

The result. A conclusion of non-identification: the person was excluded as the author of the recording. Negative proof is a result too, and it is often the one that matters most to the person being accused.

Mediation · IT contracts →

A stalled software project, a commercial relationship preserved

The challenge. A dispute between customer and software house over a partially delivered project, with each side blaming the other for the failure.

The method. Independent technical analysis of the contracted scope, of the deliveries actually made and of the dependencies that fell to each side, followed by facilitation of the negotiation on the established facts.

The result. Shared responsibilities demonstrated on technical grounds, with an agreement on partial delivery and a mutual reduction of financial expectations, without going to court.

Public cases

When forensic work made the news

In cases with national repercussion, the technical work was followed and reported by the press. In those episodes, what is presented below is already public knowledge.

International investigation

Fake profiles extorting victims in several countries

An investigation of about two months into a network of fake profiles that used a journalist's images to run scams. Technical flaws in the anonymising tool used by the criminals made it possible to identify the real connection address and reach the location of the person responsible abroad, with the material forwarded to the authorities.

Digital evidence

Forensic demonstration of forged conversations in an electoral case

Screenshots of supposed conversations filed in an electoral case were reproduced in full by the examination, on video and in a matter of minutes, using ordinary devices. The demonstration supported the finding of fraud without any need to access the original files.

Mobile phone forensics

Forensic extraction in a criminal case of national repercussion

Appearances as a specialist on television networks explaining the technical extraction process and what the analysis of the seized devices was able to demonstrate about the chronology of events.

See the press appearances →

Your case also needs a technical answer that holds up

Complex cases start the same way simple ones do: with an honest assessment of what the available evidence allows you to conclude. Confidential consultation, at no cost, with limits stated in writing.

Confidential consultation
Explore the full profile · step 2 of 6

The results have backing: the credentials that support them.

Next: Certificates →

The technical evidence your case requires. The authority courts respect.

Initial feasibility consultation at no cost. Reply within 24h on business days.
Request an Examination