This site uses cookies to provide you with a more responsive and personalized service. By using this site you agree to our use of cookies. Please read our cookie notice for more information on the cookies we use and how to delete or block them.

Bookmark Email Print page

Internal IT Forensics – Tracking an e-mail bully

Abstract

Identifying the source of threatening and distressing e-mails on an internal network.

Challenge

Our client asked for our help in identifying the source of a number of highly offensive and threatening web-mail messages targeted at one of their employees. The culprit was sending the e-mail from an anonymous e-mail address, making it difficult to trace the sender.

Approach

We performed a metadata analysis of the malicious e-mails to determine the internet address of the sender. The address was found to reside on our client’s own computer network.

We performed analysis of our client’s firewall and proxy logs. By this means we were able to determine that the e-mails originated on one of two computers on the network.

We forensically copied both computers and analysed them to evidence of the malicious e-mails.

Solution

We successfully identified the sender of the e-mails.

We identified that other malicious e-mails had been sent to two other victims, neither employees of our client. These e-mails represented a serious legal threat to our client, as the recipients could have taken action for defamation based on the e-mails.

Our report to the client was the basis of a successful disciplinary process against the sender of the email and led to the sender’s summary dismissal.

Our report also demonstrated that our client had no control over the sending of the malicious e-mail, protecting them from legal action by the other recipients.

Material on this website is © 2013 Deloitte Global Services Limited, or a member firm of Deloitte Touche Tohmatsu Limited, or one of their affiliates. See Legal for copyright and other legal information.

Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a private company limited by guarantee, and its network of member firms, each of which is a legally separate and independent entity. Please see www.deloitte.com/ie/about for a detailed description of the legal structure of Deloitte Touche Tohmatsu Limited and its member firms.

Get connected
Share your comments
More on Deloitte
Learn about our site