Certify unauthorized access to your email account (logins, IPs, devices and malicious rules) with EU qualified timestamp (international option available)
If your email account has been hacked, compromised or breached – Gmail, Outlook/Microsoft 365, Yahoo, ProtonMail, corporate email – our forensic certification service transforms access logs and intrusion evidence into legally valid and admissible proof in criminal and civil proceedings. Through certified forensic methodologies and eIDAS qualified timestamp, we acquire and authenticate every element of the breach – access history, suspicious IPs, unauthorized devices, malicious forwarding rules, configuration modifications – creating a complete evidentiary package for immediate complaints.
We certify all types of email breach: unauthorized account access, credential theft (phishing/keylogger), hidden forwarding rules installation, password recovery configuration modification, access from anomalous devices/IPs, abusive account use for illicit activities, business email espionage. Each acquisition follows ISO/IEC 27037:2012 protocols ensuring full procedural admissibility and GDPR compliance with maximum confidentiality.
What we certify in email account breaches
- Complete access history: all recent accesses with precise date/time, origin IP, geolocation, device/browser used, session status (active/terminated)
- Highlighted suspicious accesses: sessions from anomalous IPs/countries, unusual times, unknown devices, multiple geographically impossible simultaneous accesses
- Attacker IP addresses: complete IPs with precise geolocation (city/country), ISP/hosting provider, IP reputation (proxy/VPN/botnet), domain whois if available
- Unauthorized devices: complete list of connected devices with type (desktop/mobile/tablet), operating system, browser, last access, revocations performed
- Malicious forwarding rules: automatic filters installed by attacker to forward emails to external addresses, automatic email deletion rules (to hide traces), filters to move to hidden folders
- Unauthorized account delegations: external accounts added as delegates with full access, POP/IMAP permissions activated for mass email download
- Security configuration modifications: password recovery email modified, recovery phone number changed, 2FA authentication disabled, security questions altered
- Suspicious email activity: emails sent by attacker (spam/phishing/extortion), emails deleted by attacker, exported contacts, searches performed
- Provider security events: Google/Microsoft “New device” notifications, “Access blocked” alerts, identity verifications requested, passwords changed
- POP/IMAP/SMTP configurations: external connections configured for programmatic access, suspicious authorized third-party applications
Types of certifiable email account breaches
🔓 Unauthorized access to personal account
What we certify: Breached personal Gmail/Outlook/Yahoo account with – accesses from IPs/countries where you’ve never been, multiple geographically impossible simultaneous sessions, unknown devices, anomalous times (e.g. 3AM while sleeping), password modification without your consent, emails sent that you didn’t write.
Acquired elements: Complete captures of “Recent account activity” page with all accesses from last 28 days, detail of each suspicious session (date/time/IP/device/location), comparison of your usual locations vs anomalous accesses, security notifications received from provider, any installed forwarding rules.
Legal use: Criminal complaint for discovery and disclosure of computer secrets (relevant criminal code provisions), if sensitive/financial data aggravating circumstances, civil compensation for privacy violation damages, precautionary measures to restore account security.
🎣 Phishing and credential theft
What we certify: Password theft through – phishing email impersonating legitimate provider, fake login page identical to Google/Microsoft, keylogger installed on PC, man-in-the-middle attack on public WiFi, credential stuffing from previous database leaks.
Acquired elements: Complete received phishing email with original headers (sender IP, relay servers, SPF/DKIM verification), fake page URL if still active (complete forensic acquisition), comparative capture of legitimate vs fake page, first unauthorized access post-phishing with attacker IP, immediate modifications made (password, recovery email).
Legal use: Phishing complaint to competent authorities, notification to Anti-Phishing Working Group (APWG), takedown of fake page with hosting provider, attacker identification through IP/whois, civil action for damages if identity theft results.
📮 Hidden malicious forwarding rules
What we certify: Attacker installs invisible rules that – automatically forward ALL your emails to external address (business email compromise), filter/delete specific emails to hide communication traces, move important emails to hidden folders, copy only emails containing sensitive keywords (invoices/contracts/passwords).
Acquired elements: Captures of filter/rules configuration page showing installed malicious rules, detail of each rule (activation conditions, actions executed, forwarding destination email, rule creation date), forwarded email logs if available, before/after comparison of rule removal.
Legal use: Criminal complaint for communication interception, if business emails industrial espionage charges, quantification of business damages from stolen emails, disciplinary proceedings if attacker is disloyal employee.
💼 Business Email Compromise (BEC)
What we certify: Compromised business email account used to – send fake CEO/CFO emails requesting urgent transfers (CEO fraud), modify bank details in intercepted invoice emails, access confidential M&A/contract/IP information, steal customer/supplier databases, install backdoor for persistent future access.
Acquired elements: Business account access history with unauthorized sessions, fraudulent emails sent from account (with complete headers), email signature modifications to add fake bank details, mass export of contacts/emails, access to confidential folders never consulted by legitimate owner, Microsoft 365/Google Workspace audit logs if available.
Legal use: Criminal complaint for aggravated unauthorized access, computer fraud if fraudulent transfers, industrial espionage if business secrets theft, recovery of transferred funds through urgent proceedings, GDPR incident notification if personal data compromised.
🕵️ Partner/ex harassment and email espionage
What we certify: Partner/ex abusively accesses your email to – read private communications with third parties, monitor dates/movements from email confirmations, access online chats through links received by email, control purchases/transactions from order confirmations, capture private conversations for use in divorce/separation.
Acquired elements: Accesses from devices attributable to ex/partner (shared home IP, previously shared device), access pattern coinciding with their time availability, forwarding rules to their email address, sessions during times when you’re documentably elsewhere, password modifications from their locations.
Legal use: Harassment complaint if obsessive pattern, unauthorized access charges, correspondence violation charges, use of evidence in separation/divorce to demonstrate violent/controlling behavior, request for protection/restraining orders.
🌐 Botnet/proxy accesses for illicit activities
What we certify: Your compromised account used by attackers to – send mass spam (thousands of emails/hour), phishing campaigns to your contacts, distribute malware through attachments, participate in DDoS attacks, host botnet C&C servers, illegal activities making you appear responsible.
Acquired elements: Accesses from multiple botnet/VPN/Tor IPs demonstrating account under automated control, emails sent in anomalous volume (thousands vs your daily average), massive unknown recipients, spam/phishing email contents, massive bounce-backs, IP blacklists where listed, provider account suspension notifications.
Legal use: Criminal complaint demonstrating you’re not the material author of illicit activities, request for IP blacklist removal (Spamhaus, SORBS), email reputation restoration, defense against provider accusations for ToS violation, quantification of business reputational damages.
Request immediate quote
Describe the email breach to certify (provider, breach symptoms, visible suspicious accesses). You’ll receive within 2-4 hours technical feasibility assessment, acquisition methodology, urgent timeframes and detailed economic quote. WARNING: Access logs expire quickly (7-28 days), immediate action is crucial.
Why screenshots are not sufficient evidence for email breaches
❌ PROBLEM 1: Access logs expire quickly
Gmail retains access history only 28 days, Outlook/Microsoft 365 typically 90 days but detailed logs 30 days, Yahoo 6 months but limited details. After expiration EVERYTHING DISAPPEARS permanently – no recovery possible. Screenshot made after expiration has no value because it doesn’t prove what complete original logs contained.
❌ PROBLEM 2: New accesses overwrite old ones
If you continue accessing normally after breach, new sessions fill logs and old attacker sessions are rotated out of visible time window. Repeated access by investigators/technicians to “understand what happened” DESTROYS older evidence. IMMEDIATE forensic acquisition needed before critical logs disappear.
❌ PROBLEM 3: Screenshots easily falsifiable
Attacker’s defense will claim “screenshot manipulated with Photoshop/browser Inspect Element”. Without qualified timestamp and complete forensic acquisition with metadata, screenshot is contestable. Judge has no way to verify if screenshot shows actual original Gmail/Outlook page or artificially modified version.
✅ SOLUTION: Urgent forensic certification with full evidentiary value
Our certification solves everything: IMMEDIATE forensic acquisition (within 24h) before log expiration, eIDAS qualified timestamp certifies exact date/time of suspicious access existence, SHA-256 hash of each capture proves integrity, signed digital legal mandate guarantees access legality, technical analysis of IP geolocation + reputation, email header extraction if sent by attacker, optional navigation video showing acquisition process, FEDIS declaration guarantees court/authority admissibility.
How email breach certification works
- Urgent contact: Contact us IMMEDIATELY after breach discovery. We provide free 15min phone consultation on immediate actions (DON’T change password yet, DON’T access repeatedly, activate 2FA if not done yet).
- Digital legal mandate signature: Send via email/registered mail mandate conferring us power of access to your account for forensic purposes. This legally protects both you and us. Mandate specifies limited scope only for security log acquisition, not reading private email contents.
- Forensic account access: We access your account with your credentials (provided once via secure channel) or you share screen while we guide acquisition. We navigate provider security/activity pages.
- Complete log acquisition: We forensically capture: complete access history (all IPs/devices/dates), current security configuration, active filter/forwarding rules, account delegations, authorized third-party apps, connected devices, recovery email, phone numbers, received security notifications.
- Deep technical analysis: For each suspicious IP we perform: precise geolocation (city/country/coordinates), ISP/hosting whois, IP reputation (botnet/proxy/VPN database verification), geographic distance from your usual locations, physical impossibility of simultaneous accesses from distant locations.
- Suspicious email extraction (optional): If attacker sent emails, we extract with your consent complete headers (real origin IP, relay servers, precise timestamps) for sender forensic analysis.
- Qualified timestamp: We apply eIDAS timestamp on all captured screens/logs certifying exact date/time of breach existence. For international complaints, RFC 3161 upon request.
- Specialized technical-legal report: We create detailed report with: chronological event timeline, highlighted anomalous accesses with clear technical explanations for non-technical people, attacker IP analysis, discovered malicious rules, security remediation recommendations, breach severity assessment.
- Account remediation (optional additional service): We assist with: malicious forwarding rules removal, unauthorized device access revocation, secure password change, robust 2FA activation, recovery email/phone verification/change, third-party app audit, 30-day post-incident monitoring.
- Package delivery: Receive via encrypted email: certified PDF report, ultra-high resolution captures of all logs, navigation video if requested, JSON/CSV metadata files of logs for further analysis, qualified timestamp, digital signature, FEDIS declaration, pre-filled criminal complaint template with applicable offenses.
- Post-certification legal support (optional): Assistance in filing complaint with authorities, expert witness availability for technical explanations to prosecutor/judges, collaboration with your lawyer for civil actions.
Timestamp and compliance options
📍 eIDAS qualified timestamp (standard – included)
Timestamp of acquired logs with EU legal value. Sufficient for: complaints to national authorities, criminal proceedings in national/EU courts, civil actions for damage compensation. Compliance with eIDAS Regulation 910/2014 guarantees automatic admissibility without additional expert opinions.
🌍 RFC 3161 international timestamp (optional)
Global cryptographic standard for non-EU proceedings. Required for: FBI/IC3 complaints if USA attackers, UK proceedings post-Brexit, Interpol collaboration in transnational cases. Includes Hague Apostille for recognition in 120+ countries.
🔒 GDPR compliance and maximum confidentiality
Account access ONLY with signed legal mandate. Data processed according to GDPR Art. 32 (processing security). NO reading of private email contents except explicit written request for specific emails sent by attacker. Technicians bound by professional NDA. Data stored encrypted, deleted after delivery except legal retention obligation.
Email breach certification package contents
- IT security technical-legal report: Detailed breach analysis with criminal code references, event timeline, incident severity, privacy/business impacts.
- Complete certified access history: All accesses from last 28-90 days (depending on provider) with date/time/IP/device/location for each, visual highlighting of anomalous accesses.
- Attacker IP analysis: For each suspicious IP: geolocation with map, complete whois, reputation (proxy/VPN/botnet verification), geographic distance from your locations, ISP/hosting provider.
- High-resolution certified captures: Complete “Recent activity” page, detail of each suspicious session, security configuration, filter rules, connected devices, delegations, authorized third-party apps.
- Malicious forwarding/filter rules: Capture of each rule installed by attacker with conditions/actions, forwarded email estimation if quantifiable, safe removal instructions.
- Certified navigation video (optional): Screencast recording of acquisition process for absolute forensic procedure transparency.
- Suspicious email headers (if applicable): Complete headers of emails sent by attacker with origin IP analysis, relay server route, SPF/DKIM/DMARC verification.
- Structured format log export: JSON/CSV files with all logs for further analysis by your technicians/experts.
- SHA-256 cryptographic hashes: Each capture/log file with unique digital fingerprint proving integrity.
- Qualified timestamp: eIDAS or RFC 3161 certificate attesting certain date/time of log acquisition before expiration.
- Qualified digital signature: Complete report authenticated with certifier’s qualified certificate.
- Cyber-incident FEDIS declaration: Specialized forensic declaration in incident response guaranteeing admissibility.
- Remediation recommendations: Immediate account remediation action checklist, security hardening, future incident prevention.
- Criminal complaint template: Pre-filled complaint draft for authorities with applicable offenses, technical references to attach.
- Signed legal mandate: Copy of mandate signed by you authorizing forensic access, integral part of chain of custody.
FAQ – Email breach certification
Q: How much does it cost to certify an email breach?
A: Costs vary by complexity. Request free quote describing situation: we provide within 2h detailed quote + free phone consultation on immediate actions.
Q: How much time do I have to certify before logs disappear?
A: VERY URGENT. Gmail: 28 days max, Outlook: 30-90 days, Yahoo: limited details 30 days. BUT attention: new accesses by you/technicians overwrite old logs. Rule: certify within 48-72h from breach discovery, before attacker accesses exit visible window. WE guarantee acquisition within 24h from order confirmation.
Q: Must I give you my password? Is it safe?
A: TWO safe options: (1) You share screen via meeting software (Google Meet, Zoom) while WE guide acquisition – you maintain full control, WE never see password. (2) You provide credentials via one-time encrypted secure channel, we access, acquire logs, then YOU immediately change password. Always with legal mandate signed preventively that authorizes us and legally protects mutually.
Q: Will you read my private emails?
A: NO, categorically. We access ONLY security log pages (Recent activity, Devices, Configuration). NO reading of inbox/sent/email folders except you explicitly request in writing extraction of headers of specific emails sent by attacker (and even there we read only technical headers, not email body). Technicians bound by NDA, GDPR Art. 32 compliant procedure, maximum confidentiality guaranteed.
Q: Can I use certification for complaint to authorities?
A: Yes, it’s the main objective. Package includes: technical report with criminal code references, pre-filled complaint template, qualified timestamp for admissibility, FEDIS declaration. We regularly collaborate with authorities providing technical clarifications when prosecution requests. Documentation format optimized for investigators who might not be technical.
Q: What should I do IMMEDIATELY after breach discovery?
A: IMMEDIATE ACTIONS: (1) DON’T change password yet (first password change resets some logs), (2) DON’T access repeatedly (overwrites old logs), (3) Contact us IMMEDIATELY for urgent acquisition, (4) Activate 2FA if not done yet (but AFTER our acquisition), (5) Verify forwarding/filter rules and make captures for us as backup, (6) DON’T notify attacker if you know them (gives time to erase traces). Then after our certification: change password, revoke devices, remediate account.
🚨 EMERGENCY: Logs expire QUICKLY – Act NOW
Gmail access logs expire after 28 days. Outlook after 30-90 days. Each new access overwrites old ones. Each lost hour = evidence lost PERMANENTLY. There’s no way to recover expired logs – NOBODY can do it, not even Google/Microsoft. Forensic certification MUST occur BEFORE expiration otherwise attacker goes unpunished.
If you’ve discovered email breach, DON’T wait. DON’T “think about it”. DON’T “ask IT cousin what to do”. Every minute counts. Logs expire. Evidence disappears. Attacker gets away with it.
- Authenticating Webpage Evidence in Court
- Unauthorized Account Access Certification with IP | FEDIS
- Accounting Records Certification for Injunctions
- Analysis and Certification of Fake Photos and Videos
- Certified Web Permanence of Online Content
- Click Fraud & Web Traffic Certification
- Crypto Scam Evidence Certification (Web, Wallet & On-Chain)
- Copyright Infringement Certification
- Deepfake and Manipulated Content Certification | Legal Validity
- DM Instagram chat certification
- Defamation & Threats Certification
- Email Account Breach Certification
- Give legal value to the messages sent to your customers via whatsapp
- Google Location History Certification
- Google Takeout Certification
- Certificación de Robo de Imagen
- Identity Theft Certification
- Legal Web Page Certification | Certified Web Content
- Legal Warning Certification
- Microsoft Account Export Certification
- Messenger chat certification
- Online Email Certification
- OnlyFans Content Certification
- Original Authorship Certification
- Past Web Content Existence Certification (Archived & Non-Archived Evidence)
- Social Network Content Certification
- Patreon Content Certification
- Reviews Certification
- Server Logs Certification
- Trademark & Unfair Competition Certification
- Unpaid Overtime Certification (GPS Data)
- Web Page Certification with text and images
- Web Page Certification with Video
- Web Page Certification with File
- Whatsapp and Telegram Chat Certification
