Every entry in this section describes a real, publicly documented case in which a threat actor's operational security failure led to their identification. The sources are court filings, government press releases, and established reporting. No rumors, no invention.
Why study criminals' mistakes on a defensive site? Because these are the best-documented OPSEC case studies that exist. When someone with strong skills and everything to lose gets unmasked by a reused username or a photo's GPS tag, that failure mode deserves your attention. The same mistakes, at lower stakes, are how ordinary people get doxxed, stalked, and breached.
Three ground rules for this section:
- Education, not glorification. The subjects were caught doing harm. The interest here is the mistake, not the crime.
- Public record only. Every claim traces to a cited source.
- Defense only. Entries explain what the mistake teaches defenders; they are not operational advice for evading law enforcement.