Skip to main content
Cyber & OSINT · Blog

Online scams: how to identify the scammer and recover your money.

Romance scams, trading and crypto fraud, phishing: how OSINT techniques and digital forensics make it possible to trace whoever is hiding behind an online scam, and what can really be done to recover the money. The guide from Arcadia Company's cyber-investigators for the North Milan area.

A message that looked like the start of a love story, a «safe» investment recommended by a trustworthy profile, an email identical to your bank's: online scams strike thousands of people and companies every day, and leave behind not only financial loss but also embarrassment and a sense of guilt. The victim often stays silent, convinced that the money is gone for good and that the scammer - hidden behind a nickname and a foreign bank account - is untraceable.

That is almost never the case. In most instances the person responsible leaves a trail of digital traces - an email address, a cryptocurrency wallet, a phone number, a stolen photo reused elsewhere - that a cyber-investigation conducted with OSINT (Open Source Intelligence) techniques can reconstruct. This guide explains how the most common online scams work, why it is difficult to trace the culprit on your own and what an authorized investigation agency can concretely do to identify them and support the recovery of your money.

The most common online scams

The phenomenon is vast and constantly evolving, but most cases fall into a few recurring categories. Recognizing the pattern is the first step in understanding which traces to look for:

  • Romance scam: a fake profile builds a long-distance relationship over weeks or months, then invents an emergency and asks for money. It often uses stolen photos and a completely fabricated identity.
  • Trading and crypto fraud: fake investment platforms or «advisers» promise guaranteed returns; the first small, fictitious gains convince the victim to deposit ever larger sums, which then become impossible to withdraw.
  • Phishing and identity theft: emails, text messages (smishing) or clone websites imitate banks, couriers or public authorities to steal credentials, card details or access codes.
  • Fake sales and bogus marketplaces: listings for products, rentals or tickets that vanish after payment, often with a request for a bank transfer or a top-up on a prepaid card.
  • Sextortion and online blackmail: intimate material, real or simulated, used to extort money under the threat of its release.
  • CEO fraud and BEC (Business Email Compromise): within a company, spoofed emails impersonating an executive or a supplier trick the accounts department into authorizing transfers to accounts controlled by the scammers.

Why it is difficult to trace the scammer on your own

Victims who try to investigate on their own almost always run into the same obstacles. Professional scammers are organized precisely to stay anonymous:

  • Fake identities and profiles: made-up names, photos stolen from other people and accounts created with third parties' data make the «name» the victim dealt with useless.
  • Money that disperses: transfers to foreign accounts, cryptocurrency wallets and money mule accounts (unwitting or complicit front men) quickly fragment the flows.
  • Infrastructure abroad: phone numbers, SIM cards and servers hosted in other countries complicate technical attribution.
  • A complaint alone stalls: filing a criminal complaint is essential, but without already well-substantiated elements the investigation risks moving slowly; bringing investigators orderly, verified data greatly increases the chances that the case will progress.

OSINT and cyber-investigation: how a scammer is identified

This is where OSINT and cyber investigation comes into play: the methodical gathering and analysis of information available from open sources, cross-referenced with the technical analysis of the elements the scammer left behind. In practice this means:

  • Profile analysis and reverse image search: checking whether photos, nicknames and texts have already been used in other scams, in order to link several episodes to the same individual.
  • Analysis of emails, domains and IPs: examining message headers, registered domains and metadata to reconstruct the technical origin of the contact.
  • Tracing the flows: reconstructing the path of the money, including analysis of movements across cryptocurrency wallets, to pinpoint where the funds stop or are converted.
  • Cross-referencing and correlating data: connecting numbers, accounts, phone lines and contact details to bring out the real identity or the network behind a single profile.
  • Digital forensics: where devices, chats or company devices are involved, digital forensic analysis extracts and preserves the evidence without altering it.

The output of this work is not a mere «name»: it is a documented technical dossier, complete with the chain of evidence and its provenance, designed to hold up in a criminal complaint or in court.

From evidence to recovery: what can really be done

It is important to be clear, because a great deal of unrealistic promise circulates on this topic: an investigation agency identifies whoever is responsible and produces the evidence, but it does not «unlock» or directly return the money. Recovery always goes through legal channels, and the investigation makes it possible and more effective:

  • A usable dossier: a dated, documented and signed report that your lawyer can attach to a criminal complaint or to a civil claim for damages.
  • Asset tracing: through asset and financial investigations we check whether and where the person responsible holds attachable assets, to understand whether recovery is concretely achievable.
  • Support for lawyers and investigators: providing elements that are already ordered and verified helps steer the investigation and any seizure requests.

All of this must be done in compliance with the law: an operator authorized under art. 134 TULPS acts within the bounds of the GDPR (Regolamento UE 2016/679) and of professional secrecy, so that the evidence remains usable and is not «tainted» by unlawful methods.

Beware of «recovery scams»

Anyone who has suffered a scam is especially vulnerable to a second one: the so-called recovery scams. These are fake recovery agents, often found among the victims themselves, who promise to get all the money back in exchange for an advance to «unlock the funds», pay taxes or cover fees. It is a new scam. A serious agency can be recognized by a few signals:

  • No promise of results: no serious professional guarantees the full recovery of the money, nor asks for payments to «release» the funds.
  • Verifiable authorization: a prefectural licence under art. 134 TULPS, a physical office and a written contract with a clear engagement.
  • A certified method: traceable and verifiable protocols, such as the certifications and prefectural authorizations ISO 9001 that qualify Arcadia Company.

Sesto San Giovanni and North Milan: a confidential analysis of your case

Arcadia Company's operational headquarters is located in Sesto San Giovanni, at Piazza Don Mapelli 60 - a position that allows us to assist individuals and companies across the entire northern belt of Milan, the surrounding towns (Cinisello Balsamo, Cologno Monzese, Bresso, Cusano Milanino) and the province of Monza and Brianza. Cyber-investigation, by its very nature, then operates without geographical boundaries.

Every engagement starts with a preliminary assessment of the case, with a plan and a budget defined before we begin: no surprise costs at settlement and no false promises. If you have fallen victim to an online scam or have a well-founded suspicion, the first step is to understand what can really be reconstructed: request a confidential analysis, protected by professional secrecy and with no commitment whatsoever.

1,000+cases

Cases closed since 2017

9years

of uninterrupted activity

42cities

Operational cities in Italy

100% confidentiality

Zero confidentiality breaches

Let’s talk

Do you have a question?

The first consultation is always free and without obligation. We reply within 24 hours.

Fields marked with * are required.