GhostTrace LLC — Security Awareness Training for Small Businesses

GhostTrace LLC is a Georgia-based security awareness training and cybersecurity practice (Control No. 26142915), run by founder Daniel Upperman. We run live security awareness training that keeps small businesses insured and compliant.

Who is GhostTrace LLC?

GhostTrace LLC is owned and founded by Daniel Upperman. The company is registered in Georgia, USA with Georgia Control Number 26142915. Founded in 2026, GhostTrace's primary service is live security awareness training for small businesses, producing the documented completion records cyber insurers and regulators require. GhostTrace also provides incident documentation support, exposure monitoring, business and domain due diligence, impersonation takedown packaging, and digital safety reviews. Ethics complaints are reviewed directly by the founder under our published Ethics Complaint process. This is not a law enforcement agency. We do not conduct unauthorized hacking, surveillance, or data theft. We use only legal, public-source research methods, and we do not research individuals.

Founder Details

Founder & Owner: Daniel Upperman | Email: Founder@ghosttrace.net | Company: GhostTrace LLC | Location: Georgia, USA | Registration: Control No. 26142915

GhostTrace isn't a private investigator, a law firm, or law enforcement, and doesn't locate, profile, or run background checks on people.

Who runs this

Founder and Owner: Daniel Upperman

Email: Founder@ghosttrace.net

Daniel Upperman founded GhostTrace LLC in 2026 to help people affected by online fraud, impersonation, and digital abuse document what happened and figure out what to do next. GhostTrace is one person; every request is handled directly by Daniel.

Ethics & Compliance

Ethics complaints come straight to the founder: complaint reviews, policy compliance, and research standards. File a concern via our Ethics Complaint form.

Business registration

GhostTrace LLC is a registered Georgia limited liability company (Control No. 26142915, status Active), formed June 25, 2026. Full registration and registered-agent details are on the Legal page.

Contact Information

Services

Popular questions we answer

Contact

Email support@ghosttrace.net — replies within one business day. Anonymous intelligence submissions accepted (no account required).

Enable JavaScript to access the full interactive site, client portal, and staff portal. Content below is rendered by React once JavaScript is available.

PROMO

CodeGabe partner code20.0% off, referred by CodeGabe

CODEGABE5CF6View pricing
← Back to articles
Article

Account Takeover 101: How Identity Theft Starts Online

Jul 12, 2026 · GhostTrace Team

Account takeover — an attacker gaining unauthorized control of an existing account — is one of the most common precursors to identity theft, and one of the least understood by the people it happens to. It rarely looks like a movie hack. It usually looks like a password that was reused one too many times.

The most common path

  1. A service the victim used years ago (a forum, a small retailer, a now-defunct app) gets breached. Emails and passwords leak.
  2. The victim reused that same password — or a close variation — on more important accounts: email, banking, social media.
  3. Automated tools test the leaked credentials against thousands of other sites (credential stuffing). A match on even one important account gives the attacker a foothold.
  4. From email access specifically, an attacker can often reset passwords on nearly everything else — banking, shopping, social media — turning one compromised account into a cascade.

Why email is the real target

A compromised social media account is bad. A compromised email account is often catastrophic, because email is the recovery mechanism for almost every other account a person holds. Attackers who understand this specifically prioritize email access over any single "flashier" target.

Warning signs that are easy to dismiss

  • An unexpected password-reset email you didn't request — often dismissed as spam, sometimes a sign someone else just tried.
  • A login notification from an unfamiliar location or device.
  • Being logged out of an account unexpectedly, with no memory of doing so yourself.
  • Contacts reporting messages from you that you didn't send.

Any one of these, treated as noise, is exactly how attackers get the time they need to move to the next account before anyone notices.

The controls that actually stop this

  1. Unique passwords per account, managed with a password manager rather than memory or reuse — this alone breaks the entire credential-stuffing chain.
  2. Multi-factor authentication everywhere it's offered, prioritizing email first.
  3. Check whether your email has appeared in known breaches and treat a match as a signal to rotate that password immediately, not eventually.
  4. Review account recovery information periodically — a backup email or phone number an attacker quietly added is a common way they maintain access after a victim resets their password.

If you suspect an account has already been taken over, or that someone is actively impersonating you using stolen information, that's a documentation problem as much as a technical one — see Someone Is Impersonating Me Online for next steps.