Investigating Online Threats Targeting Individuals: An Evidence-Led Response Framework
By Navid Sobbi, Founder and CEO, NSI Global
Personal Safety, Evidence Preservation, Digital Investigation and Protective Action
ORIGINAL PUBLICATION: 1 June 2023 SUBSTANTIVE REVISION: 8 September 2026 (AEST)
This paper offers general information on technical investigations and risk decisions. It is neither legal nor emergency advice and cannot guarantee detection of a responsible actor or surveillance method.
Table of Contents
This paper moves from safety and preservation through technical investigation, attribution, reporting and longer-term protection.
- Executive Summary
- Purpose, Audience and Boundaries
- What Makes an Online Threat Targeted?
- The Modern Individual Attack Surface
- Triage Before Technical Investigation
- Evidence Preservation Without Accidental Destruction
- An Evidence-Led Investigation Framework
- Attribution: What an Investigation Can and Cannot Prove
- Reporting and Escalation Pathways
- Protective Controls After the Immediate Incident
- Commissioning an Online Threat Investigation
- How NSI Global Supports Appropriate Matters
- Immediate Decision Checklist
- Frequently Asked Questions
- In Sum
- Sources and Further Reading
An online threat investigation should answer more than whether something suspicious occurred. It should establish what happened, which accounts, devices, platforms and people were affected, what evidence remains available, what can be attributed with confidence and which action is proportionate to the risk.
That requires a different approach from a generic cyber-security checklist. When a particular person is being targeted, the conduct may combine account compromise, impersonation, doxxing, cyberstalking, spyware, financial fraud, reputational attack and physical-world surveillance. Treating each symptom in isolation can obscure the campaign and destroy the evidence needed to understand it.
This white paper presents a structured framework for targeted individuals and the lawyers, employers, family offices, investigators and security teams supporting them. It explains how to triage personal safety, preserve potential evidence, investigate the digital and online environment, assess attribution cautiously and convert findings into protective action.
IMPORTANT NOTICE – PERSONAL SAFETY AND EVIDENCE PRESERVATION
If there is an immediate threat to life or physical safety, contact emergency services first. In Australia, call Triple Zero (000). In the United Arab Emirates, call Police on 999.
If you suspect spyware, account compromise or unlawful surveillance and may require evidence for court, police, an employer or another formal process, do not factory-reset the device, delete applications, wipe accounts or attempt to remove the suspected software before obtaining appropriate advice. Those actions can alter or destroy valuable evidence. Use a known-safe device to seek help where practical.
Executive Summary
Targeted online harm is not defined by a particular technology. It is defined by intent, selection and effect: an actor focuses on a person, their relationships, identity, devices, accounts, reputation, finances or movements to obtain information, exert control, cause loss or create fear.
The first response decision should distinguish four priorities:
- Immediate safety: a credible threat, location exposure, coercive control or physical approach may require emergency or police involvement before technical work begins.
- Evidence preservation: where legal, employment, insurance or investigative use is contemplated, apparently helpful actions such as deleting messages, blocking accounts, uninstalling software or resetting a phone can remove context or artefacts.
- Containment: active financial loss, account takeover or data exfiltration may require rapid intervention from a bank, platform, employer or incident-response team.
- Longer-term protection: once urgent risks and evidence requirements are addressed, accounts, devices, communications and exposure pathways can be hardened.
No single screenshot, IP address, username, malware alert or search result ordinarily proves who was responsible. Reliable investigation correlates multiple sources, tests alternative explanations and reports conclusions at an appropriate confidence level. A technically accurate finding should be separated from an attribution inference and from a legal conclusion.
For NSI Global, the appropriate engagement may draw on digital forensics, forensic spyware and malware detection, cyber threat intelligence, investigations, technical surveillance countermeasures and litigation support. The mix should follow the risk and evidentiary questions, not a predetermined service list.
Purpose, Audience and Boundaries
This paper is intended for adults who believe they are being deliberately targeted online and for professionals supporting them, including:
- executives, directors, public figures and high-net-worth individuals;
- lawyers and authorised representatives;
- corporate security, risk, cyber-security and human-resources teams;
- family offices and trusted advisers;
- investigators and case managers; and
- organisations responding to abuse directed at an employee because of their work.
It is not a diagnostic tool and does not establish that a particular person, organisation or state actor is responsible. Many warning signs have ordinary explanations. Battery drain, an unfamiliar application, repeated password prompts or targeted advertising can arise from configuration, software defects, legitimate account activity or commercial data collection. They become investigative leads only when assessed in context.
NSI Global accepts digital-forensic work through a lawful, authorised and appropriate instruction pathway. In domestic and family violence, child-safety, criminal, family-law, protection-order or similarly sensitive matters, instructions may need to come through a lawyer, police officer, case officer, recognised support organisation, government agency or other authorised representative. The appropriate pathway depends on the circumstances and jurisdiction.
This publication provides general information, not legal advice, emergency advice or a guarantee that every surveillance or attribution pathway can be detected.
1. What Makes an Online Threat Targeted?
Most people encounter background cyber risk: untargeted scam messages, credential-stuffing attempts, commodity malware and mass data breaches. A targeted matter is different because the actor selects or adapts activity around a particular person.
Indicators of targeting may include:
- Messages that demonstrate knowledge of private events, relationships or movements;
- Repeated contact across several accounts after blocking or account changes;
- Impersonation that uses accurate professional, family or transaction details;
- Publication of home, workplace or family information intended to cause harm;
- Account-recovery attempts timed around travel, litigation, negotiations or personal conflict;
- Malicious content sent to colleagues, clients, family members or journalists;
- Evidence that confidential communications have been anticipated or quoted; or
- Online conduct occurring alongside unexplained physical access, tracking or information leakage.
These signs do not determine the method. An actor may know a location because it was posted publicly, obtained from a shared account, visible through a family location service, disclosed by another person or collected using device or physical surveillance. The investigation must test each plausible route.
Targeting Can Cross Personal and Organisational Boundaries
An executive’s private email, personal phone and family information can be used to reach corporate systems or influence a commercial decision. Conversely, access obtained through an employer can expose private messages, identity information or travel details.
The scope should therefore follow the information pathway. Restricting an investigation to a single handset when the relevant activity also involves cloud accounts, employer logs, social platforms and third parties may produce false reassurance.
2. The Modern Individual Attack Surface
The useful question is not, “Which list of attack vectors applies?” It is, “Through which assets, relationships and services could this person be observed, impersonated, influenced or harmed?”
How the Original Ten Attack Vectors Fit the Current Framework
The original NSI Global article identified ten useful areas of concern. Each remains relevant, but several require more precise treatment in a modern investigation:
- Social engineering: manipulation through email, telephone, messaging, social platforms or impersonation remains a primary route to credentials, money and information. Investigation should preserve the communication, sender infrastructure, recipient actions and independently known facts used to make the approach convincing.
- Password attacks: brute-force attempts, password spraying, credential stuffing and recovery abuse may produce similar symptoms but require different evidence. Sign-in records, failed-attempt patterns, exposed credentials, active sessions and recovery changes are more informative than a password change alone.
- Malware and exploitation: malicious applications, documents, links, remote-access tools and software vulnerabilities can provide access to a device or its data. A finding should identify the observed artefact and capability without assuming every anomaly is malicious.
- Online identity theft: an actor may combine breached identity records, account access and social engineering to impersonate the target or obtain services in their name. The investigation should identify which attributes were exposed, where they appeared and whether there is evidence of actual misuse.
- Phishing and spear phishing: mass phishing seeks any viable victim; spear phishing is adapted to a selected person, role or event. Original emails, headers, linked domains, attachments, authentication records and payment instructions can help reconstruct the pathway.
- Social-media exploitation: public posts, photographs, professional profiles, social connections and location information may support targeting without any technical intrusion. Analysis should distinguish information published by the target from data disclosed by associates, employers, platforms or third parties.
- Public Wi-Fi and hostile networks: modern encryption reduces the historic risk of simple content interception, but fraudulent access points, deceptive captive portals, malicious redirects, metadata collection and attacks against an exposed device remain relevant. The network, device configuration and user interaction must be examined rather than assuming every public network caused the compromise.
- Online tracking and profiling: ordinary advertising technology, platform analytics, data brokers and malicious reconnaissance are not the same activity. The investigation should determine what data was available, who could access it and whether there is evidence it was used for targeting.
- Online scams and fraud: advance-fee, investment, romance, invoice, support and impersonation fraud often combine social engineering with account or identity intelligence. Communications and transaction records should be preserved promptly because financial recovery options can be time-sensitive.
- Internet of Things exposure: smart cameras, speakers, doorbells, vehicles, wearables, home hubs and other connected devices may reveal audio, video, location, access or household routines. Their associated cloud accounts, shared-user settings, logs and physical access should be included when the facts justify it.
| Threat domain | Typical activity | Potential evidence | Immediate consideration |
| Accounts and identity | Credential theft, recovery abuse, session hijacking, SIM-related takeover or unauthorised forwarding | Provider alerts, sign-in history, recovery changes, forwarding rules, sessions and device lists | Preserve relevant records; secure access from a known-safe device where containment is urgent |
| Impersonation and social engineering | Lookalike accounts, spoofed communications, executive or family impersonation, manipulated audio or video | Message headers, profile identifiers, URLs, original files, payment instructions and recipient records | Warn likely recipients through an independently verified channel |
| Harassment, doxxing and cyberstalking | Repeated contact, threats, publication of personal data, coordinated abuse or unwanted location awareness | Screenshots, message links, usernames, timestamps, account URLs, platform reports and witness records | Prioritise personal safety; preserve before blocking when safe to do so |
| Device compromise | Spyware, stalkerware, malicious applications, remote-access tools or abused management features | Forensic images, system artefacts, application data, logs, configuration and network indicators | Do not uninstall, update or reset solely to test a suspicion when evidence may be required |
| Data exposure and intelligence collection | Leaked credentials, breached personal data, dark-web discussion, aggregation of public and commercial information | Breach notifications, credential exposure, forum records, domain data and collection timelines | Determine whether the data is current, authentic and being operationalised |
| Fraud, extortion and image-based abuse | Payment diversion, investment fraud, sextortion, coercive demands or threats to publish material | Transaction records, wallet or account details, communications and platform records | Contact the financial institution promptly; do not pay solely on an attacker’s assurance |
| Physical-digital convergence | GPS tracking, covert audio or video collection, compromised meeting technology or surveillance-informed contact | Device findings, RF and physical anomalies, access records, location patterns and digital timelines | Expand beyond cyber analysis where the facts support a physical surveillance hypothesis |
Account and Identity Compromise
Email is often the control point for other services because it receives recovery links, security alerts and sensitive correspondence. An attacker who obtains a valid session may continue to access an account even after a password is changed. Investigation should consider active sessions, delegated access, forwarding and filtering rules, recovery details, application authorisations and changes to authentication methods.
Identity misuse may also follow a data breach without direct access to a device. Australian identity information can include driver licence, passport, Medicare, financial, tax, address and account-recovery data. The response depends on what information was exposed and how it is being used.
Impersonation and Synthetic Content
The evidentiary object is not just a screenshot of a fake profile. Useful material can include the full profile URL, platform identifier, creation and change history where available, the original message or file, email headers, domain-registration and hosting information, payment instructions, delivery metadata and records from recipients.
Manipulated or AI-generated media should not be declared authentic or false from appearance alone. Provenance, original-file metadata, source history, independent corroboration and technical analysis may all be relevant. Even where content is synthetic, investigators must distinguish who created it, who distributed it and who benefited; those may be different actors.
Harassment, Doxxing and Cyberstalking
The Australian eSafety Commissioner defines doxxing as the intentional online exposure of identifying or private information without consent and with an intent to cause harm. A targeted campaign may combine disclosure with repeated messages, threats, false allegations, impersonation or encouragement of others to contact the target.
Patterns matter. A single post may appear ambiguous, while a timeline showing repeated contact across services, references to private events and escalation after specific real-world interactions may be highly significant. The investigation should preserve both harmful content and the surrounding context.
Spyware, Stalkerware and Device Compromise
Suspected spyware cannot be confirmed or excluded reliably through symptoms alone. Heat, battery drain, data use, crashes and unusual permissions are leads, not proof. Some surveillance occurs through legitimate account features, shared credentials or cloud access rather than malware resident on the device.
A forensic examination may look for malicious or misused applications, configuration changes, persistence, remote-access tools, account artefacts, relevant logs and inconsistencies across the timeline. The achievable result depends on the device, operating system, available artefacts, time elapsed and the surveillance method. A negative examination means relevant evidence was not identified within the scope and available data; it is not a universal guarantee that surveillance never occurred.
Public Information, Data Brokers and Breach Material
Open-source information can reveal professional relationships, travel, property, family connections, contact details and routines without any system intrusion. Commercially available information and breached datasets can add historical addresses, credentials or identity attributes.
Cyber threat intelligence can help determine whether exposed information, impersonation infrastructure, malicious discussion or targeting indicators appear across the clear, deep or dark web. Collection must remain lawful, necessary and proportionate. Finding a record in a breach corpus does not prove that it was used against the person.
3. Triage Before Technical Investigation
Poor sequencing can increase danger, alert the suspected actor or destroy evidence. The first consultation should decide what must happen immediately and what should wait.
Priority One: Immediate Personal Safety
A credible threat, knowledge of a current location, unwanted physical attendance or conduct linked to coercive control may require police or specialist support before account or device changes. Safety planning must account for the possibility that a device, account or shared service is being monitored.
In Australia, call Triple Zero (000) for immediate danger. For non-urgent police assistance, call 131 444. In the UAE, call Police on 999 in an emergency. International readers should use the emergency and cybercrime reporting arrangements in their jurisdiction.
Priority Two: Active Loss or Continuing Access
Where money is moving, an account is actively being used, or sensitive data is being distributed, containment may need to occur before a complete examination. Contact the financial institution or service provider through a verified channel. Record what was changed, when, why and by whom so later analysis can distinguish responder actions from attacker activity.
For account recovery, use a device and communication channel that is reasonably believed to be safe. Review active sessions and recovery methods rather than changing only the password. Where supported, passkeys or phishing-resistant multi-factor authentication can reduce future credential-phishing risk, but authentication changes do not invalidate every existing session automatically.
Priority Three: Preserve Evidence
Where it is safe, preserve relevant content before blocking, reporting or deleting it. The eSafety Commissioner recommends capturing the content together with identifying context such as usernames, profile or account names, URLs, the service used, and dates and times.
Screenshots are useful but incomplete. They may omit message identifiers, headers, deleted context or metadata. Where available and lawful, retain original emails, exported account data, original media files, platform-report references, bank records, call records and witness notes.
Do not download, copy or redistribute unlawful material merely to preserve it. Special caution applies to sexual images involving anyone under 18. Seek police, legal or specialist guidance.
4. Evidence Preservation Without Accidental Destruction
Digital evidence is volatile. Platforms remove content, logs age out, devices synchronise, applications update and users unintentionally change timestamps or state. Preservation should be deliberate and documented.
Preserve the Context, Not Just the Offensive Statement
For online content, record:
- the full URL or message link;
- the account name, username and visible profile identifier;
- the date, time and time zone;
- the platform or service;
- the content before and after the relevant item where context matters;
- any associated image, video, audio, attachment or payment instruction;
- the person who captured it and the method used; and
- any report made to the platform, eSafety, police, an employer or another body.
A contemporaneous chronology can be as important as an individual screenshot. Record when each event was first noticed, who had access, what response occurred and whether the behaviour changed afterward.
Preserve Devices and Accounts Proportionately
If formal evidence may be required, avoid exploratory actions that substantially alter the source. Factory resets, application removal, bulk deletion, operating-system updates, anti-malware remediation and repeated login attempts can change evidence or trigger remote actions.
This does not mean a threatened person must remain exposed while waiting for an examination. Safety and containment can take priority. The decision should be recorded, and a specialist may recommend isolating a device, preserving an account through provider tools, using an alternative device or making a forensic acquisition before remediation.
NIST’s guidance on digital evidence preservation treats acquisition, storage and evidence handling as distinct processes. In practice, an examiner should be able to explain what was received, how it was acquired, how integrity was checked, what changed and what limitations remain.
Maintain Provenance and Chain of Custody
Evidence intended for litigation, a protection-order application, employment action or criminal investigation should have a defensible provenance. Relevant records include who collected an item, the source, date and time, transfer history, storage location, integrity controls and every material examination or transformation.
Forwarding an email or resaving a media file may be convenient but can remove or replace metadata. Preserve the original form where possible and create working copies for review.
5. An Evidence-Led Investigation Framework
The following framework is designed to keep safety, technical analysis and attribution aligned. Not every matter requires every workstream.
Stage 1: Establish Authority, Objectives and Safety Constraints
Confirm who owns or controls the devices and accounts, who is authorised to instruct, whether legal privilege is contemplated, and whether another person’s data is likely to be captured. Define the questions the investigation is expected to answer.
Examples include:
- Was an account accessed without authority?
- Was a device configured or used to monitor the person?
- How did an impersonator obtain the information used in a message?
- Are several online accounts likely to be part of the same campaign?
- What information has been exposed, and is it being distributed?
- What evidence can be supplied to counsel, police, a platform or an employer?
The scope should also identify safety constraints. Contacting a suspected actor, logging out of a shared account or disabling location access may cause escalation in some circumstances.
Stage 2: Stabilise and Preserve
Create an incident chronology, capture volatile online material, preserve provider notifications and identify devices or accounts requiring acquisition. Record urgent containment already performed.
Where appropriate, legal counsel can help determine preservation notices, compulsory-process options and privilege arrangements. A private forensic provider cannot compel a platform, telecommunications carrier or financial institution to disclose third-party records merely because those records would be useful.
Stage 3: Examine Devices, Accounts and Communications
The examination should be hypothesis-led. Relevant sources may include phones, computers, tablets, external storage, email, cloud accounts, social media, messaging applications, browser data, authentication records, backups and employer systems within authority.
The work may test for unauthorised sessions, forwarding rules, credential or recovery changes, suspicious applications, remote-access capability, persistence, configuration abuse, malicious files, data-transfer artefacts and correlations with reported events.
Tools do not interpret intent. An application with powerful permissions may be legitimate; an apparently ordinary cloud session may be the actual surveillance route. Findings require technical context and, where relevant, user and organisational evidence.
Stage 4: Develop the External Intelligence Picture
Cyber threat intelligence and lawful online investigation can examine domains, profiles, infrastructure, leaked data, forum discussion, malicious campaigns, impersonation, exposed credentials and relationships between indicators.
The collection plan should define the subject, time period, platforms, languages, identifiers and legal boundaries. Broad, indiscriminate collection creates privacy and analytical problems. The objective is to resolve a specific threat question, not assemble every available fact about every associated person.
Stage 5: Correlate Events Across Sources
A timeline can connect an online post to an account login, a device event, a payment request, a physical encounter or an internal information disclosure. Link analysis may identify common infrastructure, reused identifiers, shared payment destinations or coordinated accounts.
Correlation is strongest when sources are independent. Five copies of the same allegation are not five confirmations. Analysts should record source origin, reliability, corroboration and plausible alternative explanations.
Stage 6: Assess Attribution and Confidence
Attribution should separate at least three propositions:
- Technical association: two events share infrastructure, an account, artefact or identifier.
- Operational association: the events appear to form part of the same activity or campaign.
- Actor attribution: a particular person or organisation directed or performed the conduct.
The first does not automatically establish the third. IP addresses can be shared or masked, accounts can be compromised, devices can be borrowed and identifiers can be copied deliberately. Reports should state what is known, what is inferred, the confidence attached to the inference and what additional evidence would be needed.
Stage 7: Report for the Intended Decision
A useful report is structured around the recipient’s decision. Counsel may need provenance, methodology and limitations. Police may require a clear chronology and identifiers. A platform may need URLs, account IDs and policy-relevant conduct. An employer may require a scoped finding tied to its systems and policies.
Technical detail should support the conclusion without obscuring it. The report should distinguish:
- Verified facts;
- Analytical assessments;
- Unresolved anomalies;
- Excluded or unsupported explanations;
- Limitations and unavailable evidence; and
- Recommended next actions.
Stage 8: Remediate and Monitor
Once preservation requirements permit, remediation may include terminating sessions, changing recovery channels, replacing exposed credentials, enabling stronger authentication, updating or rebuilding devices, removing malicious persistence, changing information-sharing practices and monitoring for recurrence.
The controls must address the path actually used. Replacing a phone will not solve continuing access through a cloud account. Changing passwords will not remove publicly exposed personal information. Blocking one profile will not stop coordinated impersonation across several services.
6. Attribution: What an Investigation Can and Cannot Prove
Clients understandably want a name. The evidence may instead support a narrower but still valuable conclusion: that an account was accessed from an unrecognised environment; that several profiles are technically associated; that a device contained a particular monitoring capability; or that confidential information most likely left through one of several defined pathways.
An investigation should not convert suspicion into certainty. Common attribution errors include:
- Treating an IP address as a person;
- Assuming the registered subscriber operated an account;
- Relying on a display name or profile photograph;
- Treating shared malware as proof of a particular actor;
- Overlooking compromised infrastructure or false flags;
- Accepting an online database’s identity linkage without validating its provenance; and
- Reporting temporal coincidence as causation.
A defensible report may use terms such as confirmed, highly likely, likely, plausible, unlikely or unable to determine, provided the scale is defined and the supporting reasoning is transparent.
The inability to identify an actor does not make the investigation unsuccessful. Establishing the compromised assets, exposure pathway, evidentiary record and effective controls may be the most important outcome.
7. Reporting and Escalation Pathways
Different harms require different recipients. Reporting everywhere at once can be counterproductive; failing to report an urgent matter can also increase harm.
Australia
- Immediate danger: call Triple Zero (000).
- Threats that are not an immediate emergency: contact local police on 131 444.
- Cybercrime: use ReportCyber. Cybercrime reports are referred to the relevant Australian law-enforcement agency.
- Cyber-security advice: the Australian Cyber Security Hotline is available on 1300 CYBER1 (1300 292 371).
- Adult cyber abuse, image-based abuse and specified harmful content: review the eSafety reporting pathways.
- Identity fraud: notify affected institutions, financial providers and identity-document issuers; the OAIC identity-fraud guidance also directs affected people to ReportCyber and IDCARE.
United Arab Emirates
- Immediate police emergency: call 999.
- Cybercrime: the Official Platform of the UAE identifies police stations and official police or Ministry of Interior reporting channels.
An adviser should verify the current pathway for the relevant emirate and type of conduct. NSI Global is not an emergency service and contacting NSI Global does not replace a report to police or another competent authority.
Platforms, Employers and Financial Institutions
Platform reports should retain the report number and submitted material. An employer should be notified when organisational accounts, data, personnel or duties are implicated. Financial institutions should be contacted immediately through a verified channel when transactions, cards or accounts may be affected.
Legal advice may be appropriate before approaching a suspected actor, making a public allegation, seeking third-party records or taking action that could affect proceedings.
8. Protective Controls After the Immediate Incident
Protection should be based on the investigation’s findings and residual uncertainty.
Identity and Account Controls
- Use unique credentials stored in a reputable password manager where passwords remain necessary.
- Prefer passkeys or phishing-resistant multi-factor authentication where supported.
- Review and revoke unknown sessions, application permissions, delegates and recovery methods.
- Secure the primary email account and mobile-service account because they often control recovery for other services.
- Establish independent verbal or in-person verification for unusual payment, credential or information requests.
Exposure Reduction
- Review public profiles, professional biographies, data-broker exposure and historical posts for unnecessary location, family or contact information.
- Separate public-facing contact channels from recovery and high-trust communications.
- Ask organisations that publish staff details to consider whether role, travel and direct contact information are necessary.
- Monitor for impersonation, newly registered lookalike domains and recurrence of harmful content where the risk justifies it.
Device and Communications Security
- Maintain supported operating systems and applications after evidentiary requirements have been addressed.
- Limit unnecessary administrative, accessibility, location and application permissions.
- Replace or rebuild a device when justified by the findings and threat model rather than as a symbolic response.
- For high-risk communications, obtain advice on the whole communication environment, including endpoint, account, participant and physical-room risks.
Physical and Counter-Surveillance Measures
If confidential information continues to leak despite account and device controls, or if the matter includes physical access, vehicles, meeting spaces or tracking concerns, the assessment may need to extend beyond cyber security. A risk-based TSCM survey can examine defined physical, electronic and communications environments. Its scope and limitations should be explicit; a negative survey is not a guarantee that every surveillance pathway is absent.
9. Commissioning an Online Threat Investigation
A clear brief improves both cost control and evidentiary value. Before appointing a provider, the client or instructing professional should be able to state:
- The immediate safety issue, if any;
- The events that caused concern and when they occurred;
- The decisions the findings must support;
- The devices, accounts, platforms, locations and organisations potentially involved;
- Who owns or controls each source and who can authorise access;
- Whether litigation, police reporting, insurance, employment action or a protection order is contemplated;
- What urgent containment has already occurred;
- The relevant jurisdictions and languages;
- The required output, recipient and deadline; and
- The risk of alerting the suspected actor.
The scope should identify exclusions as clearly as inclusions. A phone-only examination cannot answer every question about cloud access, impersonation, dark-web exposure or physical surveillance. Similarly, an online intelligence review cannot determine whether a device contains malware without appropriate technical examination.
Questions to Ask a Provider
- What precise questions will the proposed scope answer?
- Which devices, accounts, platforms and external sources are included?
- How will evidence be preserved and integrity documented?
- Which actions could alert the suspected actor or change evidence?
- How will analytical inference be separated from verified fact?
- What licensing, authority or consent is required?
- What limitations will apply to a negative result?
- Can the report be adapted for counsel, police, a platform, an employer or court if needed?
10. How NSI Global Supports Appropriate Matters
NSI Global can coordinate several workstreams under a risk-based scope where the instruction is lawful, authorised and appropriate.
Digital Forensics and Account Investigation
NSI Global’s digital forensic services can preserve and analyse relevant data from authorised devices, accounts, communications platforms and digital systems. The purpose may include reconstructing activity, assessing unauthorised access, preserving evidence and explaining technical findings.
Forensic Spyware and Malware Detection
Where device compromise is a credible hypothesis, forensic spyware and malware detection can examine available artefacts for malicious or misused software, remote-access capability, persistence and other indicators. Findings and limitations should be documented for the intended investigative or legal use.
Cyber Threat Intelligence
Cyber threat intelligence can examine defined indicators across relevant open, technical, deep and dark-web sources. Depending on the scope, this may assist with leaked information, malicious infrastructure, impersonation, threat discussion or relationships between online indicators.
Investigations and Link Analysis
NSI Global’s investigation services may support lawful enquiries, interviews, background research, surveillance or coordination with digital findings where those methods are appropriate and permitted. Cross-source analysis can help build a chronology and test whether apparently separate events are connected.
TSCM and Communications Security
Where the evidence indicates a physical or communications-surveillance dimension, technical surveillance countermeasures or communications-security advice may be incorporated. The engagement should cover the relevant locations, devices, systems, time periods and surveillance channels rather than defaulting to a single-room sweep.
Litigation and Expert Support
Where a matter may proceed to court, a commission, regulatory action or another contested process, litigation support can help align preservation, analysis and reporting with the legal team’s requirements. Legal conclusions remain a matter for qualified counsel and the relevant decision-maker.
For a confidential preliminary discussion in Australia, call NSI Global on 1300 000 NSI (674). For the UAE office, call +971 (0)4 409 6824. Alternatively, use the NSI Global contact page.
Immediate Decision Checklist
- Is anyone in immediate physical danger?
- Could the communication channel currently being used be monitored?
- Is financial loss, account misuse or data disclosure continuing?
- Does evidence need to be preserved before blocking, deletion or remediation?
- Have URLs, usernames, platform identifiers, dates, times and original files been retained?
- Which devices, accounts, people and organisations fall within the actual information pathway?
- Who has lawful authority to provide access and instruct the examination?
- What action has already been taken, and was it documented?
- Which question must the investigation answer first?
- Who will receive the report, and what decision must it support?
Frequently Asked Questions
What Is an Online Threat Investigation?
It is a structured examination of authorised digital, online and contextual evidence to determine what happened, which assets were affected, whether events are related, what can be attributed and what response is justified. It may combine digital forensics, account analysis, cyber threat intelligence and conventional investigation.
Can an Investigator Identify an Anonymous Online Attacker?
Sometimes, but not from a username or IP address alone. Attribution may require corroborating technical, platform, financial, behavioural and real-world evidence. Certain records may only be available to police, courts or authorised agencies through legal process. A responsible report states its confidence and limitations.
Should I Reset a Phone if I Suspect Spyware?
Not automatically. A reset may remove malicious software, but it may also alter or destroy evidence. If personal safety is at immediate risk, safety takes priority. If legal or investigative evidence may be required, seek advice using a known-safe device before resetting, uninstalling applications or making major changes.
Are Screenshots Sufficient Evidence?
Screenshots are valuable for volatile online content but may omit metadata, headers, message identifiers and surrounding context. Preserve URLs, usernames, dates, times, original messages or files, account exports and report references where they are available and lawful to retain.
Does a Clean Malware Scan Prove That a Device Is Safe?
No. A scan examines what the tool can detect in the available environment. Surveillance may use an undetected method, an account or cloud service, a legitimate feature used without authority, another device or a physical collection channel. Conclusions should be limited to the scope and evidence examined.
When Should Police Be Contacted?
Contact emergency services immediately where there is a current threat to life or safety. Police or ReportCyber may also be appropriate for threats, stalking, fraud, unauthorised access, identity crime, extortion or other suspected offences. A lawyer or specialist adviser can assist with sequencing in complex matters, but should not delay an emergency report.
Can NSI Global Accept Instructions Directly From Any Individual?
Not in every matter. The engagement must be lawful, authorised and appropriate. Sensitive domestic-violence, family-law, child-safety, criminal or protection-order matters may require instructions through a lawyer, police or case officer, government agency, recognised support organisation or authorised representative.
Is Public Wi-Fi Automatically Unsafe?
No. Modern encrypted services reduce some historic interception risks, but a hostile or fraudulent network can still facilitate deceptive login pages, malicious redirects, metadata collection or attacks against a poorly secured device. Use trusted networks where possible, keep devices updated and avoid acting on unexpected authentication prompts.
In Sum
When a person is deliberately targeted, the problem rarely remains confined to one message or device. The actor may move between identity information, accounts, social platforms, cloud services, colleagues, family members and physical access. A narrow technical check can miss that wider pathway.
The effective response is evidence-led and properly sequenced. Protect safety, stop urgent loss, preserve what may matter, examine the right sources, assess attribution without overclaiming and implement controls that address the route actually used.
The central commissioning question is not, “Can you check my phone?” It is:
What evidence and investigative scope are required to explain the targeting, support the intended decision and reduce the risk of recurrence?
For a confidential discussion about an authorised online threat, cyber-intelligence, forensic or counter-surveillance matter, contact NSI Global.
Sources and Further Reading
- Australian Signals Directorate – Annual Cyber Threat Report 2024-2025
- Australian Signals Directorate – Report and recover
- Australian Signals Directorate – Passkeys
- Australian Signals Directorate – Multi-factor authentication
- eSafety Commissioner – Adult cyber abuse
- eSafety Commissioner – How to collect evidence
- eSafety Commissioner – Cyberstalking
- eSafety Commissioner – Doxxing
- eSafety Commissioner – Report online harm
- Office of the Australian Information Commissioner – Identity fraud
- NIST IR 8387 – Digital Evidence Preservation: Considerations for Evidence Handlers
- NIST SP 800-101 Rev. 1 – Guidelines on Mobile Device Forensics
- Official Platform of the UAE – Cyber safety and digital security
- NSI Global – Digital Forensics
- NSI Global – Forensic Spyware and Malware Detection
- NSI Global – Cyber Threat Intelligence
- NSI Global – Investigations
- NSI Global – Technical Surveillance Countermeasures
- NSI Global – Litigation Support