Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Incident timeline and evidence cards in a daylight analysis office

Open editorial reference · 2026

Digital incident triage: 16 practical situations.

Find a proportionate first response when a signal involves an account, a payment, exposed data or a circulating claim. Each scenario states what to do first and what to record before details disappear.

How to use it

Start with the facts and the possible harm.

This reference helps organise an initial response. It describes typical situations, not an automatic diagnosis. Priority depends on the facts, the person affected and the possible consequences. Preserve original material and contact the appropriate services in an emergency.

Immediate means act now through known official channels; prompt means organise a response without delay; routine means document and verify before reacting. Any immediate danger to a person calls for emergency services.

Filterable reference

Find the relevant situation.

16 scenarios displayed

Identity and accounts · ImmediateBusiness account takeover

Unknown sign-in, password change or messages sent without your action.

First action: Use a trusted device to revoke sessions, change access and enable multi-factor authentication; alert the IT team.

Preserve: Times, sign-in alerts, available logs and sent messages.

Escalate: If other accounts or data may be affected, activate the incident process and assess notification duties.

Identity and accounts · PromptImpersonating profile

A profile copies a name, photo or role to contact third parties.

First action: Warn exposed contacts through a known channel and report the profile to the platform without engaging the apparent operator.

Preserve: Exact URL, handle, dated captures and messages received by contacts.

Escalate: For fraud, threats or harm, contact the appropriate services and record each report.

Identity and accounts · PromptExecutive spoofing message

An urgent request for payment or documents uses a leader's name.

First action: Pause the request and call the person using a previously known number outside the received thread.

Preserve: Full message with headers, sending address and payment instructions.

Escalate: If a transfer was made, contact the bank and internal response team immediately.

Identity and accounts · PromptLost business device

A device with access to accounts or files is no longer under control.

First action: Report the loss, revoke sessions and apply authorised remote management actions.

Preserve: Last known location, time, model and accessible accounts.

Escalate: Assess sensitive data exposure and required next steps with the responsible teams.

Fraud and payment · PromptSuspicious link opened

Someone followed an unexpected sign-in or delivery link.

First action: Return to the service through its official address; if credentials were entered, change them and revoke sessions.

Preserve: Received URL, original message, time and actions after opening.

Escalate: If a file ran or business access was used, alert the IT team.

Fraud and payment · ImmediateSuspicious bank transfer made

A payment went to an unverified or changed beneficiary.

First action: Contact the bank immediately through its official channel to request recall or blocking steps.

Preserve: Transfer order, references, exchanges, invoice and approval timeline.

Escalate: Alert relevant owners and make reports appropriate to the case.

Fraud and payment · PromptInvoice bank details changed

An email announces a new account number or beneficiary.

First action: Hold payment and confirm the change with a previously verified supplier contact.

Preserve: Old and new invoices, full emails and approval records.

Escalate: If payment was made, follow the suspicious transfer procedure.

Fraud and payment · VerifyQuestionable recruiter or job offer

A listing quickly asks for identity documents, bank details, fees or software installation.

First action: Find the role on the employer's official site and contact recruitment through an independent channel.

Preserve: Listing, recruiter profile, email domain and requests made.

Escalate: If data was already shared, assess its nature and protect affected accounts.

Fraud and payment · PromptDomain mimicking an organisation

A site copies a brand under a slightly different address.

First action: Do not enter information; alert the brand owner and domain owners.

Preserve: Full URL, dated captures, redirects and messages distributing the link.

Escalate: If the site actively collects credentials or payments, accelerate reports and warnings to affected people.

Data and exposure · PromptSensitive file publicly accessible

An internal document appears in a search result or at an open URL.

First action: Restrict access with the service owner without spreading the URL; assess the exposure scope.

Preserve: URL, date, server response, data type and minimal proof of visibility.

Escalate: Have the appropriate owners assess duties tied to the affected data.

Data and exposure · ImmediateCredential or secret disclosed

A password, token or key appears in an accessible source.

First action: Revoke the secret, rotate dependent access and review abnormal use.

Preserve: Location, discovery time, secret type and usage logs without copying the secret into notes.

Escalate: Treat as an incident if unauthorised use is possible or observed.

Data and exposure · PromptData export shared in error

A file containing personal data was sent or published to the wrong recipient.

First action: Stop sharing, request removal through the proper channel and identify recipients and data precisely.

Preserve: Original file, recipient list, timestamps and removal actions.

Escalate: Promptly assess notification duties and impact on individuals.

Data and exposure · ImmediatePrivate details published with a threat

Address, phone number or other private details are posted with a targeted threat.

First action: Prioritise the person's safety and contact emergency services for immediate danger; request platform removal.

Preserve: Links, dated captures and threat context without republishing the details.

Escalate: Involve security owners and relevant authorities according to severity.

Reputation and content · VerifyUnusual wave of negative reviews

Several similar reviews appear over a short period.

First action: Document the timeline, check verifiable facts and respond only once the context is understood.

Preserve: URL, date and content of each review and any real transaction link.

Escalate: Report reviews breaching platform rules with factual evidence.

Reputation and content · PromptPotentially manipulated audio or video

Media attributes disputed words or acts to a person.

First action: Pause distribution and seek the original version, surrounding frames and independent corroboration.

Preserve: Original file, URL, publication date, apparent author and repost chain.

Escalate: If it drives fraud or threats, coordinate protection and reporting.

Reputation and content · VerifyOnline rumour spreading

A claim spreads without a clear primary source.

First action: Identify the earliest traceable post and separate reposts from independent confirmation.

Preserve: URLs, dates, versions of the claim and supporting or contradicting evidence.

Escalate: Choose a response proportionate to actual reach and verified harm.

FAQ

Using this reference responsibly.

Is the urgency label a diagnosis?

No. It is a starting point. Human safety, actual exposure, timing and local obligations can make any situation more urgent.

Should I send evidence to IIS immediately?

Start with a factual summary and avoid including passwords, full identity documents or sensitive files in the first message. A secure channel can be agreed later.

Can the reference be reused?

The JSON and CSV are available for reuse with attribution to IIS, the version date and the cautions attached to each case.