marker is a build seam - edit the markup around them, never the marker text itself. --> When you're asked to "find the culprit" - but your capability isn't built for it
Due Diligence & Background Checks

When you're asked to "find the culprit" - but your capability isn't built for it

When you're asked to "find the culprit" - but your capability isn't built for it

Recently I was approached with a very sensitive case involving the spread of fake content online.

The request was clear: locate the source of distribution, stop it quickly, and remove the content.

On the surface, this sounds like a classic open-source intelligence task. But that's exactly where the problem begins.

I want to share with you, with professional honesty, where OSINT is strong and where it simply isn't enough.

Where OSINT delivers real value: you can map how content spreads, identify groups, channels and distribution hubs, track recurring users across different platforms, and understand who is "pushing" the story forward. This provides a very important intelligence picture.

But here comes the critical limitation: you cannot identify with certainty who the person behind the account is, prove who created the content, access closed information (IP, devices, logs), or guarantee complete removal from the internet.

And when it comes to sensitive incidents, especially involving minors or privacy violations, the smallest mistake in identification can turn into a serious legal problem.

The real risk: the problem is not only technological - it is managerial. When you make promises like "we'll find who did it" and "we'll take everything off the web" without understanding the limits, that's a recipe for disappointment at best, and for damage at worst.

So what is the right thing to do in such cases? The right approach is always multidisciplinary: OSINT for mapping and understanding, DFIR for collecting evidence from devices and systems, legal support for approaching the platforms, damage control and prevention of repeated distribution, and continuous monitoring. Anyone who handles this alone, from a single angle, misses the picture.

The bottom line: open-source intelligence is a very powerful tool - but it is not magic.

Knowing what can be done is important. But knowing what cannot be done - that is what separates professional work from risk.

Get these breakdowns in your inbox, plus the six steps for closing the offboarding window as a one-page brief.Get the one-pager

Stay sharp

Get our insights in your inbox.

New cases, red flags and reliability lessons - a short email when something worth reading goes up. No spam, unsubscribe anytime.