OSINT for Law Enforcement: Open-Source Investigation
OSINT for law enforcement: trace accounts from a phone number, username or email address, link fraud cases and document findings in a traceable report.
From an Email Address to the Next Step in an Investigation
Imagine receiving a fraud complaint. The victim has paid for a product. The seller first delayed delivery, then stopped responding to messages. The listing has been removed, and the profile name has changed.
The case file contains a phone number, an email address, and a few screenshots.
These seemingly limited details may contain links that bring an investigator closer to other accounts, other victims, and the person behind the incident. A contact detail may have been used for more than communicating with the victim. The same number might appear on a messaging account, the same email on another platform, or a similar username in an older listing.
So, what difference does knowing which platform a number is registered on actually make to an investigation?
A discovered account points to the next source of information

Open-source intelligence, or OSINT, involves collecting, verifying, and assessing publicly available information to answer a specific research question. For law enforcement, that question is often very concrete: Who uses this account? Which other accounts is it connected to? Is there a common trace across different complaints?
When an indication of an account associated with an email address is found, the investigator has identified a new source of information. Depending on the result, this could be just a signal that a registration exists on a platform, or a specific profile that can be examined. These do not provide the same level of information.
The distinction affects the next step. Account information that can be verified may help define the scope of a legal request to the relevant platform.
The investigation can then move from “Where might this person be online?” to “What records are available about this account?”
From account records to IP and device information
Once an account has been found, competent authorities can request available records from the platform through the appropriate legal process.
For example, Snap’s law enforcement guide, dated 19 August 2026, describes account creation information, associated emails and phone numbers, IP addresses and timestamps for certain account activities, and device identifiers that may be available. Access depends on the legal basis of the request and the records retained. Cross-border requests also involve different procedures.
This is where the contribution of open-source research becomes clear: identifying the relevant account helps direct requests to the right source. Information returned by the platform can then be compared with the victim’s messages, payment activity, and other evidence.
An IP address or an account match alone does not conclusively identify the person behind an account. Shared connections, reassigned numbers, and compromised accounts must be considered. Findings that corroborate one another, however, can help identify and apprehend a suspect and move legal proceedings forward. A decision on pretrial detention depends on the case as a whole and the applicable legal conditions.
How can a fraud investigation expand?

Let us return to the opening example.
The investigator examines the number and email address used to contact the victim. An account association is found on one platform, and a profile using the same username elsewhere. Comparing the profile’s public content leads to another sales listing.
Below the second listing is a comment from someone who says they paid but never received their product.
That comment alone is not proof of another offence. It may, however, help locate a second victim and investigate their account of events. Comparing the payment details, messages, and contact numbers supplied by both people may establish a stronger connection between the cases.
If records lawfully obtained from the relevant platforms also support that connection, the scope of the investigation changes. What initially appeared to be a single sales dispute may be investigated as suspected fraud targeting multiple people.
This is where identifying a registered account becomes valuable: it gives the investigator new questions to ask and new connections to verify.
A real case: the Hushpuppi investigation
One real-world example of this approach is the investigation into Ramon Olorunwa Abbas, known online as “Hushpuppi”.
An FBI affidavit published by the US Department of Justice describes how a publicly accessible Instagram profile listed a Snapchat username. Records obtained from Instagram included an email address, a verified phone number, and login IP addresses. Subscriber records supplied by Snap showed the same email address. Records obtained from other providers and financial information were used to assess the links relating to his identity.

Abbas was arrested in Dubai in June 2020. After pleading guilty to conspiracy to engage in money laundering, he was sentenced to 135 months in prison in November 2022.
The instructive aspect of this case is the use of public profile research alongside platform records and other evidence. A connection beginning with a username is tested against information from different sources. OSINT’s contribution to an investigation is best understood within that combined process.
Changing accounts in a blackmail case
In another scenario, a victim reports receiving threats from different accounts. The account names change, but some messages use the same contact number.
The investigator can examine possible links through that number and the usernames. Public content from discovered profiles can be assessed alongside the correspondence provided by the victim. Where accounts are thought to be controlled by the same person, investigators seek records that support or disprove that assumption.
Time matters in cases like these. Snap’s guide recommends promptly requesting preservation of relevant available data. A preservation request is separate from disclosure to the authorities, its purpose is to preserve existing information for the legal process that follows.
Identifying an account early can therefore help preserve records that might otherwise be lost, as well as advance the investigation.
How we support investigations with ORCA Scanner
At OSINTCTI, we built ORCA Scanner to help investigators follow digital traces from a username, email address, or phone number. We bring together account discovery across social media, forums, gaming, and shopping platforms so investigators can explore connections from a single starting point.
With our latest update, we redesigned the interface and added more than 1,500 new modules, expanding the sources investigators can examine when tracing accounts across the internet.
These details give investigators additional clues to compare with information already in a case file. A masked email hint may support a possible link to a known address, while a handset model provides another detail to assess alongside other evidence.
We also support recurring scans for usernames, email addresses, and phone numbers, with alerts when new platform traces are discovered. This helps investigators follow developments in an ongoing case and identify connections that were not visible in earlier searches.
Findings must remain traceable in the report

The person reviewing a case later needs to be able to understand the connection the original investigator observed.
Which information came from which source? When was it observed? How was the account connection verified? Which part is an observation, and which part is the investigator’s assessment?
The Berkeley Protocol on Digital Open Source Investigations, published by the UN Office of the High Commissioner for Human Rights (OHCHR) and the Human Rights Center at UC Berkeley School of Law, sets out standards for gathering, analysing, and preserving digital open-source information. Although written for international criminal and human rights investigations, its emphasis on documenting sources and verification steps is equally relevant to other investigations that rely on online material.
With ORCA, we let investigators export findings in Word, PDF, JSON, and Excel, making it easier to prepare reports and share results with their teams. The evidentiary value of a report depends on how its information was obtained, verified, and preserved.
At the start of an investigation, there may be only a number. Finding the account it points to can provide a starting point for reaching another victim, preserving relevant records, or recognising a connection between separate cases.
Sometimes, the detail that moves an investigation forward is discovering where else the information you already have has been used.