See our process in action
Everything below is fictional. These are illustrative walkthroughs, not real clients or engagements — no real names, evidence, or engagement data is used anywhere on this page. We built this page purely for transparency, to show how our process actually works before you ever have to trust us with a real situation. For our actual methodology, see How We Work.
Impersonation documentation
A small business owner discovered a fake social media account using their name and photos, contacting their real customers and asking for payment to a different account.
A short intake call established the timeline, which platform was affected, and what evidence the client already had — screenshots of the fake profile and messages it had sent.
Working from the fake profile the client reported, the analyst reverse-image-searched the profile photos, checked the account's creation date, and cross-referenced its follower/messaging pattern against the client's real account — using only publicly available information.
Findings were compiled into an evidence package matching the platform's impersonation-policy language, with sourced, timestamped screenshots.
The client submitted the package through the platform's official impersonation report. The fake account was removed within the platform's standard review window.
Romance / investment scam — documentation support
A client reported an online relationship that gradually turned into pressure to invest in a cryptocurrency trading platform they'd never heard of independently.
The first priority was stopping further payments and confirming the client hadn't deleted any conversation history — that history is the core record in requests like this.
Analysts organized the domain, profile photos, and wallet addresses the client supplied, and formatted the platform's publicly listed registration data the client pointed us to — all from public sources and the client's own records.
A timeline report was built connecting the contact pattern, the platform's red flags, and the transaction trail the client supplied, labeled by confidence level (Confirmed / Probable / Possible).
The client used the report to support a fraud dispute with their bank and filed with the FBI's IC3 and the FTC.
Harassment incident documentation
A client was receiving a sustained pattern of harassing messages across multiple platforms and needed it documented well enough to support a workplace complaint and a police report.
The client was walked through preserving evidence correctly first — not deleting or blocking accounts until the record was captured, since blocking can hide message history on some platforms.
Analysts organized the timestamped, source-linked messages and posts the client provided from every affected platform, and mapped the pattern into a single chronological timeline.
The timeline was compiled into a clear report with a plain-language summary up front, ready for the client to bring to whoever they chose.
The client chose to bring the same report to their workplace HR process and the local police non-emergency line, so both worked from one consistent record instead of two different retellings.
Digital footprint exposure review
A client who had recently been doxxed on a forum wanted to know exactly what personal information about them was publicly discoverable before it happened again.
The client listed every name, handle, and email they'd ever used publicly, so the review could search broadly instead of missing older accounts.
Analysts searched public data broker listings, old forum posts, breached-credential indexes, and social account privacy settings tied to those identifiers.
Findings were grouped by exposure type (address/phone, breached passwords, public social settings) and ranked by how easily each could be found.
The client received a prioritized action list — which data broker opt-outs to file first, which passwords to rotate immediately, and which account settings to lock down.
Brand impersonation threat sweep
A small business kept hearing from customers about a lookalike website and social accounts running a fake promotion using their branding.
The client shared their real domain, logo assets, and social handles as a baseline, plus every customer report they'd already collected.
Analysts searched for lookalike domains, typosquats, and cloned social profiles, and documented which ones were actively soliciting payments versus dormant.
Each fraudulent asset was logged with registrar, hosting, and platform details, and matched to the correct abuse-report channel for that specific host or platform.
The client used the report to file takedowns with the relevant registrars and platforms in parallel, instead of discovering each new fake one at a time from customer complaints.
What a report looks like
A fictional sample built to match the real structure of a GhostTrace evidence dossier — the same sections, the same plain-language explanations, the same disclaimers. Any name, handle, amount, or identifier a real report would contain is either invented or blacked out here.
- Log into your payment provider and open the Resolution Center.
- Open a dispute for the transaction in question.
- Attach this report as supporting evidence.
This report organizes your evidence so a reviewer can quickly understand what happened. The platform or bank makes the final decision — this report is designed to help your request be taken seriously.
Attention reviewer: this document provides verified background and evidence regarding a suspected commercial scam. The seller directed the buyer to an unshielded payment method and provided a fabricated delivery-tracking site to simulate shipment. Findings and matching evidence are below.
- Day 1: Buyer and seller agree on a price for a custom item over a third-party chat platform.
- Day 3: Seller instructs the buyer to pay using a "friends & family" transfer option and to leave the payment note blank.
- Day 5: Buyer sends payment to the seller's requested account handle.
- Day 8: Seller sends a tracking link for a delivery service. The link is confirmed fake.
- Avoiding payment protection: requesting a "friends & family" transfer strips away standard purchase protection.
- Blank payment notes: used to slip past automated fraud-detection filters.
- Mismatched identities: the name on the shipping label, the payment account, and the delivery confirmation did not match each other.
| Confidence | Finding | Source |
|---|---|---|
| Confirmed | Tracking link does not resolve to a real delivery carrier | Manual link verification |
| Confirmed | Payment sent to requested handle, no goods received | Transaction receipt |
| Probable | Delivery confirmation photo shows signs of digital editing | Image analysis |
| Asset | Type | What it proves |
|---|---|---|
| chat_log_01.png | Screenshot | Seller's payment instructions, timestamped |
| receipt_01.png | Screenshot | Confirms funds were sent to the seller's handle |
Cut off contact with the seller's account. Change the password and enable MFA on any email or account shared during the interaction. Watch for follow-up scams targeting the same contact details.
- File a complaint with the FBI's IC3 (ic3.gov) and the FTC (reportfraud.ftc.gov).
- This request can be upgraded to a full Entity & Domain Due Diligence engagement for deeper business and domain verification.
Every real report follows our internal redaction standards before any external release — personal identifiers, exact dates, ongoing-engagement details, and internal methodology are never included in anything shared outside the engagement it was written for.
Confidence-labeled findings
We never present speculation as fact — every finding is labeled Confirmed, Probable, or Possible.
Nothing you share leaves this engagement
Personal identifiers and engagement-specific details are never reused in public materials — see our Trust Center.
Have a real situation?
Book a free intake call — no pressure, no commitment.
Book a free 15-min intake call