Live data from Hacker News

How to Catch a "Thief"

news.ycombinator.com

1–10 of 19 posts

How to Catch a "Thief"

#1
I work at an international school and an incident has recently arisen. A disgruntled employee has downloaded the parent email list (thus the thievery) and is sending defamatory emails a few times a week based on meeting minutes and general gossip. The individual is switching emails each time (they are using protonmail and gmail accounts). I also suspect that they are using an AI language filter or some sort of program that alters writing style.

The suspect list has been narrowed down to a handful of admin.

My first inclination is to send different (juicy as it were) information to different people coming from a teacher unaware of the situation and claim that I accidentally used bcc instead of cc and apologize in an email sent to all the admin staff for "my poor use of tech", thus lessening the suspicion of misinformation. This would hopefully entice the perpetrator to share some identifying info in their next email.

What do you think is the best course of action?

I know this is weird, but there are a lot of people here who are smarter than me and I figured it was worth a shot.

Re: How to Catch a "Thief"

#2
Disinformation, carefully used, would be my first line of investigation.

As an aside, the Humble Bundle Choice releases were being reliably leaked. Until this month ... https://redd.it/1bqpp2l - so I suspect HB did the same, and carefully distribued info to establish the mole's identity.

Re: How to Catch a "Thief"

#3
post #2

Disinformation, carefully used, would be my first line of investigation. As an aside, the Humble Bundle Choice releases were being reliably leaked. Until this month ... https://redd.it/1bqpp2l - so I suspect HB did the same, and carefully distribued info to establish the mole's identity.

Thanks for the reply. The school is trying to go about a "normal" investigation processes. I'm trying to do due diligence before suggesting a full on disinformation route to the principle. It's getting messy though.

Re: How to Catch a "Thief"

#4
Get full email samples - forward them "as attachment" so all headers are intact. Look over the headers and determine the source IP for the initial email connections - they might be the same for multiple messages in the same batch - or will be from the same ISP. The MX Toolbox has a header analyzer that can help figure where they start from.

If the user is using a mobile device, this can present challenges - and if they sat in coffee shops to send this email you'll have a lot harder time ID'ing the user.

Once you have an idea what IP address(es) are sending these, then you check your VPN logs to compare the source IP's. This should be fairly easy and could directly finger your sender.

With these logs and some suspected source IP's, you might be able to figure out which user is doing this - even with ISP's using dynamic addressing, IP's are still held for weeks/months on networks - so this should hold up.

If the user is using a unique mobile service or a cloud emailing service - this can also be correlated to their mobile devices using DNS request logs. If they're using Google to do this, your lawyer could subpeona the user from them.

Re: How to Catch a "Thief"

#5
Find a more discreet way to send unique bad information.

I think something where you say "whoops!" afterwards is a little obvious.

Is there no access log for the parent email list?

Re: How to Catch a "Thief"

#6
Sounds like a good time to involve the cops possibly? Sounds illegal to me...? They'll be able to link the protonmail and gmail accounts back pretty easily I assume

If there's some kind of staff site/portal/whatever with authentication, send them a unique link and somehow trick them into clicking it?

Re: How to Catch a "Thief"

#7

Get full email samples - forward them "as attachment" so all headers are intact. Look over the headers and determine the source IP for the initial email connections - they might be the same for multiple messages in the same batch - or will be from the same ISP. The MX Toolbox has a header analyzer that can help figure where they start from. If the user is using a mobile device, this can present challenges - and if th…

> Look over the headers and determine the source IP for the initial email connections

You won't see anything, just that it was sent from gmail and protonmail. They don't insert the user's IP address in the headers.

Not through web interface at least.

Re: How to Catch a "Thief"

#8
I have a few ideas.

Sometimes when you reset an email account password it will tell you a part of the recovery email if there is one. This could be a clue.

Send an email to one of the emails used by the perpetrator while in a meeting and see if any of your staff reacts.

If you have access to the routers, compare device names of people logged on while the emails are sent out (if they’re sending in the building).

Are any of your staff using protonmail as their main email provider? Search slack for any discussion or snippets with proton emails.

Does downloading the parent email list cause a log to trigger?

While in a meeting speak as normal and then when you mention something that is slightly gossipy, observe whose eyes widen or body language changes.

Simply speak to your staff and determine whether they are happy in their positions. This is good practice anyway.

Don’t be obvious.

Re: How to Catch a "Thief"

#9
post #8

I have a few ideas. Sometimes when you reset an email account password it will tell you a part of the recovery email if there is one. This could be a clue. Send an email to one of the emails used by the perpetrator while in a meeting and see if any of your staff reacts. If you have access to the routers, compare device names of people logged on while the emails are sent out (if they’re sending in the building). Are a…

Thanks for the suggestions.

It appears that the individual is using their phone to log into the company email, so there's no trail coming from the school routers or email account.

I hadn't thought about trying to trigger the reset notifications. I'll look into that.

We have a few people in mind, but with no actual proof the school is afraid of taking steps due to litigation based on "unfounded accusations".

Re: How to Catch a "Thief"

#10
post #5

Find a more discreet way to send unique bad information. I think something where you say "whoops!" afterwards is a little obvious. Is there no access log for the parent email list?

Sadly no. The school has been pretty lax with personal information. Staff is also expected to use their personal devices for internal communication because they don't want to pay give all the teachers' aids laptops. It's pretty common for everyone to access their email on their personal phones.
Post reply on HN