602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Cyber Investigations

Cyber Services

Cyber Investigations

Anonymous harassment, rogue numbers, DMCA takedowns and geolocation work — conducted by licensed investigators, documented for court.

SDVOSBCertified
9FNE2CAGE Code
24 / 7 / 365SOC Monitoring
In-HouseForensic Capability

Anonymous is rarely as anonymous as it looks

Someone is harassing you, your family or your business from behind a burner number, a throwaway account or an anonymous email. Law enforcement may not have the bandwidth, and the platform may not respond. That is the gap this service fills.

Because Honeybadger holds a private investigations license and runs its own digital forensics capability, a cyber investigation can move from attribution to evidence to a report your attorney can actually file. Findings are corroborated across independent sources before they enter a report.

What is included

Anonymous Harassment

Attribution work on anonymous accounts, messages, emails and persistent online harassment campaigns.

Rogue Numbers & Accounts

Identification of burner numbers, spoofed callers and impersonation accounts targeting you or your brand.

DMCA & Content Takedowns

Removal of stolen, leaked or infringing material, with documentation of the chain and the actors.

Geolocation Work

Location development supporting protective decisions, service of process and law enforcement referral.

Who this is for

  • Private clients
  • Executives & public figures
  • Law firms
  • Corporate HR
  • Small business
  • Domestic matters
  • Brand protection

What a cyber investigation answers

Cyber investigation is the work of attributing online conduct to a person and documenting it to a standard someone else will accept — a court, a regulator, an employer’s disciplinary process, or a platform’s abuse team. It is a different discipline from incident response, which asks how a system was compromised. This asks who did it, and it lives closer to investigation than to engineering.

The cases arrive in recognisable shapes. Anonymous harassment, stalking and threats against an individual. Impersonation and fake accounts used to defame a person or a business. Extortion, including the sextortion cases that increasingly target teenagers and older adults. Business email compromise and payment fraud, where the money left legitimately because the instruction looked legitimate. Intellectual property theft by a departing employee. Fake reviews and coordinated reputational attacks. Romance and investment fraud, which is now overwhelmingly cryptocurrency-based. And insider misuse, where someone with legitimate access did something they should not have.

What connects them is that the answer is a person, and the evidence is scattered across platforms, devices, records and payment rails that each have their own rules about who may see what.

How attribution actually works

Anonymity online is usually shallower than it feels to the person relying on it. Attribution is built from accumulation, not from one dramatic discovery.

It starts with preservation, and this is the step clients most often skip and most often regret. Content gets deleted, accounts get closed, and platforms have retention limits. Capturing what exists — properly, with hashes and metadata rather than as phone screenshots — is the first hour’s work, not the second week’s. Where a device or account you control is involved, that is digital forensics, and it should happen before anyone starts looking around inside it.

Then open-source research: account histories, writing style and vocabulary, timing patterns across time zones, reused usernames and email addresses, images and their reverse-search history, artefacts in files and posts, and the connections between accounts that the subject believes are unconnected. People are consistent, and consistency is identifying.

Then records and correlation: public and lawfully accessible records, corporate and domain registrations, financial and payment trails where lawful, and blockchain analysis where cryptocurrency is involved — see blockchain forensics.

And then the honest part: where private records are needed, they need legal process. Subscriber information behind an IP address, platform account records, and payment provider records are obtained by subpoena, court order or law enforcement — not by an investigator. What we do is build the case that makes that process targeted and successful, which is usually the difference between a subpoena that returns something and one that returns nothing.

What we will not do, and why it matters to your case

We do not access accounts, devices or systems we are not authorised to access. We do not deploy monitoring software on anyone’s device. We do not use pretexts to obtain records from providers, financial institutions or telecoms. We do not buy data from sources that obtained it unlawfully. We do not conduct “hack-back” of any kind — it is illegal, it is frequently aimed at the wrong party, and it converts you from victim to defendant.

Beyond the legality, there is a practical reason: evidence obtained unlawfully is generally inadmissible, and the party who obtained it stops being the sympathetic one. A case built carelessly is worse than no case, because it also costs you the moral position.

Investigative work in Arizona is licensed under A.R.S. Title 32, Chapter 24; Honeybadger holds Private Investigations Agency licence 1759795. We are not law enforcement, hold no compulsory powers, and will tell you plainly when a matter should go to them rather than to us.

Working alongside law enforcement and counsel

Some of these matters belong with police from the outset — credible threats of violence, extortion, offences against a minor, and organised fraud above the threshold an agency will act on. We will say so and help you make the report usable rather than competing with it. A well-organised private file, with preserved evidence and a clear timeline, materially improves the chance that an under-resourced unit takes a case forward.

Others are civil matters where the objective is an order, an injunction, a takedown or a recovery. There the file is built for counsel: preserved evidence with a documented chain, a factual timeline, an attribution analysis with its reasoning shown, and clear statements of what is established and what is inference. Where a subpoena is the next step, we identify precisely which provider, for which records, covering which period.

Recovery expectations, stated honestly

For fraud and theft cases, the honest position: recovery is possible and it is time-critical and it is not the norm. Funds moved through domestic banking can sometimes be frozen if the institution is alerted within hours — which is why the first call in a business email compromise is your bank, not an investigator. Cryptocurrency can be traced and is occasionally frozen at an exchange with legal process. Funds that have moved offshore and been converted are usually gone.

What investigation reliably delivers is attribution, documentation, a route to legal process, and the evidence to stop it continuing. Anyone guaranteeing recovery of stolen cryptocurrency is running the second fraud on the same victim, and we see those cases regularly.

How it is priced

Quoted per engagement in phases: preservation and initial assessment first, then attribution work, then reporting and support to legal process — with a decision point between each. Phasing matters here because the first phase frequently determines whether attribution is realistic at all, and you should be able to stop there.

Included: preservation, open-source research, records analysis, and a written report with sourcing and reasoning. Quoted separately: device forensics, blockchain tracing, surveillance where a subject must be physically identified, out-of-state or international coordination, and declaration or testimony.

Frequently asked questions

Someone is harassing me anonymously. Can you identify them?

Often, and rarely in one step. Attribution comes from accumulated patterns — writing style, timing, reused identifiers, image history, account connections — plus records obtained through legal process where needed. Preserve everything now and do not engage with them; both matter more than they sound.

Can you get the IP address and find out who it is?

Not directly. Subscriber information behind an IP address is a provider record obtained by subpoena, court order or law enforcement. What we do is build the targeted case that makes that request specific and successful, and identify exactly which provider and which period to ask for.

We sent a wire to a fraudulent account. What do we do right now?

Call your bank immediately and ask for a recall — this is measured in hours. Then report it to law enforcement. Then call us. In that order. Preserve the emails and do not delete anything, including from the sent folder.

Can you recover our stolen cryptocurrency?

We can trace it and document where it went, and occasionally that supports a freeze at an exchange through legal process. We will never guarantee recovery. Firms that do are frequently running a second fraud on people who have already been defrauded once.

Can you get the fake account taken down?

We document it to the standard platforms actually respond to, which is more than a report button submission, and support counsel where a legal demand is the faster route. Takedown and attribution are separate objectives — decide which one you want first, because the fastest takedown can also destroy the evidence.

Should I confront them or reply?

No. Engagement escalates, and it also tells the subject what you know and what to delete. Preserve, document, take advice, and let the sequence be chosen rather than reactive.

In detail

Anonymous online harassment, identifying a rogue phone number, DMCA take-down notices, & geolocation by SMS are all examples of our cyber investigation services. As the capacity of criminal creativity in this area seems to be limitless, so are the types of the resolutions we offer.
 

Scope your requirement

Everything discussed is confidential. A short intake establishes the objective, the jurisdiction, the legal authority we are operating under, and the deadline you are working against — all defined in writing before work begins.