← All examples Full example — Forensic Report + Formal Statement

Phishing / Credential Theft

Fictitious case. Fake Lloyds Bank email led to credential harvesting via cloned login page. £4,200 transferred from current account within minutes. IP addresses, device fingerprints and phishing infrastructure fully traced.

1
Forensic Investigation Report
7 pages • Phishing infrastructure analysis + IP tracing + Financial flow
2
Formal Statement
6 pages • Ready to submit to Action Fraud / Police
Document 1 — Forensic Investigation Report
🔎
Forensic Report — Phishing Attack
TraceProof_Forensic_Report.pdf • 7 pages • Classification TLP:AMBER
Risk 78/100
TP-2026-3156 Method: Email phishing + Credential theft Amount: £4,200 Vector: Spoofed Lloyds email Faster Payment to mule

Spoofed Lloyds Bank email — cloned login page — real-time credential relay

⚙ Investigation methodology
1. Email header analysis: SPF/DKIM/DMARC failure, originating IP, mail server identification • 2. Phishing site analysis: Domain WHOIS, hosting, SSL certificate, phishing kit reverse engineering • 3. Access log analysis: IP addresses, device fingerprints, session timing • 4. Financial tracing: Faster Payment routing to receiving account • 5. Infrastructure mapping: Link to phishing-as-a-service platform

Attack timeline

22 May 2026 — 08:14
Victim receives email appearing to be from Lloyds Bank (“security@lloyds-banking.com” — lookalike domain). Subject: “Urgent: Suspicious activity detected on your account”. Email passes basic visual inspection but fails SPF check.
22 May 2026 — 08:17
Victim clicks link to “lloyds-secure-verify.com” (registered 6 hours prior via GoDaddy). Page is pixel-perfect clone of Lloyds online banking login. Victim enters customer ID and password.
22 May 2026 — 08:18
Real-time relay: Attacker’s backend immediately uses stolen credentials to log into victim’s real Lloyds account. Triggers SMS OTP. Phishing page shows “Please enter the verification code sent to your phone”.
22 May 2026 — 08:19
Victim enters OTP on phishing page. Attacker uses it to authorise a Faster Payment of £4,200 to a Monzo account (identified as money mule).
22 May 2026 — 08:22
Funds immediately moved from Monzo mule account to a Revolut account, then converted to USDT and withdrawn to external wallet.

Phishing infrastructure

ElementFindingRisk
Sending domainlloyds-banking.com — registered 2 days prior, no SPF/DKIM. Hosted on Hostinger (LT)HIGH
Phishing domainlloyds-secure-verify.com — registered 6 hours prior. Let’s Encrypt cert. Backend PHP kit “Kr3pto”HIGH
Attacker IP185.234.XX.XX (NL, DataCamp VPS) — same IP linked to 47 other phishing domainsHIGH
Receiving accountMonzo — account opened 5 days prior, minimal KYC. Funds moved within 3 minutesHIGH
Document 2 — Formal Statement (extract)
Formal Statement — Phishing Fraud
TraceProof_Statement.pdf • 6 pages • Ready for Action Fraud / bank dispute

I, REDACTED, report that on 22 May 2026 I was the victim of a phishing attack. A fraudulent email impersonating Lloyds Bank directed me to a cloned website where my online banking credentials and a one-time passcode were captured. The perpetrators used these to make an unauthorised Faster Payment of £4,200 from my current account.

The attached forensic report identifies: the phishing infrastructure (domains, hosting, IP addresses), the phishing kit used (“Kr3pto” panel), the attacker’s access IP (185.234.XX.XX, Netherlands), and the money mule account receiving the funds. This evidence supports both a criminal complaint and a bank reimbursement claim under the CRM Code.

Generation time: ~45 seconds • Format: Print-ready PDFs • Supports bank dispute: Evidence formatted for CRM Code reimbursement claim • Updates: Free regeneration if new evidence emerges

Have you been a victim of a similar scam?

Start your free report: within minutes you will receive a forensic investigation report and a formal statement ready to submit to the authorities.

Start your report →

No obligation. You only pay if you decide to download the documents.