Darwin Awards

Publicly documented OPSEC failures by threat actors, what happened, the mistake, and the defensive lesson for the rest of us.

Every entry in this section describes a real, publicly documented case in which a threat actor's operational security failure led to their identification. The sources are court filings, government press releases, and established reporting. No rumors, no invention.

Why study criminals' mistakes on a defensive site? Because these are the best-documented OPSEC case studies that exist. When someone with strong skills and everything to lose gets unmasked by a reused username or a photo's GPS tag, that failure mode deserves your attention. The same mistakes, at lower stakes, are how ordinary people get doxxed, stalked, and breached.

Three ground rules for this section:

  • Education, not glorification. The subjects were caught doing harm. The interest here is the mistake, not the crime.
  • Public record only. Every claim traces to a cited source.
  • Defense only. Entries explain what the mistake teaches defenders; they are not operational advice for evading law enforcement.