It used to be enough to cover your tracks and disappear. Today, however, we leave digital fingerprints almost everywhere – in emails, metadata, network traffic and cryptocurrency transactions. And digital forensics – a field on the border between IT and detective work – now helps unravel the biggest cybercrimes and even decades-old murders.
In the following five real cases it played a key role, from cracking a ransomware attack on a hospital to catching a serial killer thanks to a floppy disk. Each shows that a single inconspicuous detail can decide between anonymity and a life sentence.
In April 2025, Marks & Spencer customers began complaining en masse that online orders weren't working. It soon became clear this was no ordinary outage but one of the biggest cyberattacks on British retail ever.
The attackers got into the system through a third party – the consulting firm Tata. Using sophisticated social engineering they gained access to the internal infrastructure, deployed ransomware, encrypted key servers and exfiltrated sensitive customer data. M&S practically lost the ability to operate online overnight.
Digital forensics experts analyzed network logs, traced the attackers' movement through the system and found traces leading to four young hackers aged 17–20. Ransomware metadata and on-site forensic investigation also helped. The case was solved quickly, but the cost was high: the company estimated losses of up to £300 million.
Silk Road was one of the largest black markets on the darknet. It ran anonymously over TOR and enabled trade in drugs, weapons and hacking services. Its creator was long practically untouchable. But in the background, dozens of investigators, digital forensic analysts and blockchain specialists were carefully piecing the traces together.
The breakthrough came when agents went back to old posts from the days when Silk Road was just getting started. In one of them someone promoted the site and listed their email as a contact: rossulbricht@gmail.com. This tiny mistake later became the key lead.
For years investigators tracked bitcoin transactions, the administrator's communication style and IP address movements, building a digital profile of the suspect. Everything pointed to one name: Ross Ulbricht.
The decisive moment came in October 2013. Ulbricht regularly worked on his laptop in a New York library. Two FBI agents staged an argument near his table, and the moment Ulbricht looked up from the screen, another agent grabbed his laptop from behind. The computer was open, logged in and still running the Silk Road admin panel.
Digital forensic analysts immediately imaged the disk and RAM and obtained access keys, trade logs, encryption scripts and a diary in which Ulbricht described building the Silk Road empire in detail. After years of anonymous crime, he was caught by one old message and a few minutes of inattention.
In 2015 Ross Ulbricht was sentenced to life in prison without the possibility of parole.
In May 2017 the world experienced an attack that definitively showed how vulnerable modern digital infrastructure can be. Within a few days, WannaCry ransomware infected more than 300,000 devices in more than 150 countries – from British hospitals and transport systems to factories in Japan and Russia. Computers were locked, files encrypted and ransom demands in bitcoin appeared on screens.
While the public panicked, digital forensics teams immediately began assessing the damage. They managed to dissect malware samples and identify the vulnerability exploited in the attack – the EternalBlue exploit, originally developed by the US NSA and later leaked to the public. Forensic analysts also identified the malware's command servers and tracked how it spread across networks.
They also performed reverse engineering of the ransomware, which revealed weaknesses and led to decryption tools for some versions of the attack. The rapid response of security teams helped many institutions restore systems from backups and minimize the impact.
Based on digital evidence and analysis of the network infrastructure, the FBI and other agencies later attributed the attack to the Lazarus hacker group, linked to the North Korean regime.
Dennis Rader, known as the BTK Killer (short for Bind, Torture, Kill), terrorized Kansas from the 1970s to the early 1990s. He committed ten brutal murders and after each one sent mocking letters to the police. Then he went silent for more than a decade. Only in 2004, as if craving renewed attention, did he reach out again – this time digitally.
He sent the police a floppy disk with an anonymous document claiming he was the real BTK. He believed this medium would leave no traces. But digital forensic analysts focused on something he had overlooked – metadata.
Analyzing it, they found two key pieces of information: the name “Dennis” and the name Christ Lutheran Church. Both led to the same man, Dennis Rader, an active member of that church. Ironically, the serial killer who had evaded capture for years was caught because of a single overlooked digital trace.
In 2024 one of the large US hospitals became the target of a sophisticated ransomware attack. Using a so-called SIM swap, the attackers took control of an administrator's phone number and thereby gained access to two-factor authentication. Before long the hospital's entire IT system was locked: medical records, access to test results, surgery scheduling. Lives were literally at stake.
Through network analysis, the digital forensics team identified the ransomware's communication infrastructure – the servers through which the malware received instructions and sent data. A technique called sinkholing played a key role: malicious traffic was redirected to the specialists' own servers, giving them visibility into how the attack worked and allowing them to block it in a controlled way.
Thanks to the timely intervention, they managed to isolate the affected parts of the system, restore operations from security backups and avoid paying the ransom. The hospital stayed operational, though for several days it ran in a significantly limited mode.
The attackers have not yet been caught, but the case showed how crucial it is to have a ready team of experts who can stop even a critical cyberattack within hours before irreversible damage is done.
Author: Kateřina Slezáková