As we continue to rely on digital solutions, cyber threats are becoming increasingly sophisticated and prevalent. We specialise in digital intelligence and cyber investigations, helping individuals, businesses, and legal professionals uncover misuse, fraud, and malicious activity online.
Backed by over 20 years of experience in IT and Cyber Security through our sister company Millsit, our team brings both the technical expertise and the investigative insight needed to trace and evidence computer-based wrongdoing.
What Cyber Investigations Do We Do ?
We assist in a range of cyber-related investigations some which include:
- Harassment, Cyber Stalking, And Online Abuse
- Online Blackmail
- Phishing And Impersonation Scams
- Unauthorised Access To Email Or Social Media Accounts
- Ransomware Attacks
- Malware Distribution
- Distributed Denial Of Service (DDoS) Attacks
- Suspicious Employee Activity And Data Leaks
- Identity Theft And Financial Fraud
- Reputation Damage Through Fake Reviews Or Impersonation
- Website & Domain Misuse
- Computer Misuse Act Case Support
- Online Scam & Crypto Fraud Tracing
If you’re not sure whether your situation fits one of these categories, just get in touch we’ll advise you confidentially.
Cyber Investigation Case Studies
We were called to assist a small but successful consultancy based in Chelsea, London. The company had grown concerned after multiple long standing clients claimed they had settled invoices yet no payments had been received.
The business owner suspected something was wrong, but couldn’t pinpoint how. Their IT system appeared functional. Their finance software was intact, but something just didn’t add up.
We began a forensic review of the company’s email platform. The business used a cloud-based email system, and all invoicing correspondence ran through a single shared mailbox. We obtained permission to conduct a full mailbox audit, including access logs and mailbox rule histories.
It quickly became clear that this was no internal error, this was a targeted Business Email Compromise (BEC).
A malicious actor had successfully gained access to the company’s email system. But instead of locking them out or deleting data, the attacker had taken a more subtle, calculated approach:
They had created a hidden mailbox rule that diverted incoming emails.
This allowed the attacker to silently monitor payment conversations between the company and its clients. Over time, they used the information gathered to impersonate the business using a lookalike email address, issuing fake invoices with alternative bank details.
The attacker had been active for over four months before discovery. During this time, several high-value payments had been redirected costing the company tens of thousands of pounds and damaging client trust.
During a high-profile international sporting event at a major London stadium, operations were severely disrupted when the venue’s internal systems began to fail without warning. The event drew over 35,000 spectators, with a significant portion of attendees arriving from abroad to support their national team.
At around 12:45 PM, shortly before the match began, multiple critical stadium services went offline.
These included:
Payment terminals at food and beverage stalls.
Mobile ordering and ticketing applications.
Staff communication tools and network-dependent systems.
Within minutes, the ability to process transactions or communicate internally was lost, leading to widespread operational chaos. Alcohol sales, merchandise transactions, and mobile check-ins were all affected.
Our forensic investigation, supported by infrastructure logs and firewall telemetry, revealed that the stadium’s firewall had been directly targeted by a coordinated Distributed Denial of Service (DDoS) attack.
The attackers launched an overwhelming volume of traffic from multiple global sources—many of them leveraging hijacked cloud services and botnets—designed to flood and crash the stadium’s perimeter firewall. As a result, all internet-reliant services within the stadium were cut off from the outside world.
Notably, the internal Wi-Fi network, cloud-based point-of-sale systems, VoIP handsets, and mobile ordering platforms all became inoperable due to the network isolation caused by the overloaded firewall.
Our analysts noted that, during the week of the event, there were heightened political tensions related to the teams involved. Media coverage highlighted controversial developments, and online chatter suggested the potential for protest or disruption.
While no definitive attribution could be made, the timing and focus of the attack, combined with its strategic impact on a high-visibility public event, strongly suggested a politically motivated cyber disruption.
We delivered a full report including:
- Attack vector analysis showing traffic concentration on specific firewall ports.
- Botnet and infrastructure fingerprinting to help identify patterns.
- A timeline of the attack and its escalation.
- Mitigation guidance including traffic shaping, firewall rule revision, and rapid failover strategies.
A client approached us after discovering that someone was using their identity on a popular dating app to deceive and manipulate others. Friends and acquaintances alerted them to suspicious profiles bearing their photos and personal details, messaging other users under their name.
The impersonator was exploiting the client’s reputation and relationships, leading to emotional distress and potential financial loss for those targeted.
Using open-source intelligence (OSINT) tools, we monitored the activity patterns, linked devices, and possible login locations to pinpoint the perpetrator.
The impersonator had:
Created multiple fake profiles mimicking the client’s photos and personal information
Contacted friends, colleagues, and potential romantic interests to solicit money and gifts
Sent convincing messages designed to exploit trust and emotional vulnerability
Our investigation revealed a consistent pattern of behaviour linked to a single individual operating from a specific region.
We provided the client with:
Recommendations on how to report the impersonation to the dating app and request profile removal.
Guidance on safeguarding personal data and strengthening online privacy.
Support in contacting law enforcement and preparing evidence for civil or criminal proceedings.
Why KittyHawk Investigations?
Unlike many private investigation firms, KittyHawk Investigations is uniquely positioned through our in-house expertise in IT security and infrastructure.
- We understand how digital systems work under the hood.
- We leverage advanced forensics and OSINT (Open-Source Intelligence).
- We know how to preserve, analyse and report on digital evidence correctly.
This makes our cyber investigations thorough, credible, and technically sound.