- The FBI was the first to use computer forensics to investigate computer-related crimes.
- Cliff Stoll is credited with the rise of the science, having investigated a problem related to a financial report in 1986.
- Digital forensics does not improve business; it only helps when security fails or a crime occurs.
A ‘selfie’ from social media revealed a Russian diplomatic lie, a Word document from a floppy disk uncovered a mass murderer after thirty years of playing cat and mouse with American police, and a mistake in a financial report of less than one dollar exposed a German hacker who infiltrated systems and sold stolen data to a secret service… All these secrets were revealed by digital forensics.
Although Russia vehemently denied that its military units were present in Ukraine after the violent annexation of Crimea in 2014, a photograph of Russian army sergeant Alexander Sotkin published on Instagram exposed the diplomatic lie. While on duty, moving between a military base in Russia and Ukraine, Sotkin took a selfie and posted it with a geographical tag on the social network Instagram.
This is just one example of digital forensics and how digital forensic experts gather evidence. In another case, digital forensics played a crucial role in finding a mass American murderer, a case known as ‘BTK’. Dennis Rader tortured and killed at least ten people but remained undetected for three decades. For thirty years, he sent strange messages to the American police during his killing sprees, and he was only uncovered in 2005 when he sent them a Word document on a floppy disk. Digital forensic experts managed to trace the data from the disk, which helped reveal the true identity of the BTK killer, leading to Rader’s eventual arrest.
From Pornography to Espionage
Digital forensics is a branch of forensic science that involves the collection and processing of data stored in digital form, usually related to crimes involving the use of computers; it includes the collection of digital evidence from various devices, tools, or infrastructures such as computers, mobile devices, email, hard drives, and cloud storage systems. The term ‘computer forensics’ has been in use since 1984 – the FBI was the first to use it to investigate computer-related crimes when it launched the first computer forensics program (Magnet Media Program).
However, the rise of digital forensics is largely credited to Cliff Stoll from the Lawrence Berkeley National Laboratory, who investigated a problem related to a financial report in 1986. Although it involved an amount of less than a dollar, Cliff’s meticulous investigation led him to a German hacker who was infiltrating systems and selling the collected data to the Russian secret service, the KGB. This was the first discovery of digital forensics. Soon, it began to be used by American police to uncover child pornography and other criminal investigations, and then by the U.S. military in the wars in Iraq and Afghanistan.
After computer forensics gained momentum, primarily in combating child pornography, it expanded to all areas containing digital data. Today, companies also widely use it, where digital forensic experts uncover instances where employees mishandle sensitive information and the consequences of cyber attacks.
The First Policemen
Chad Gough, owner of the American computer forensics company 4Discovery, who has collaborated with Fortune 500 companies for over twenty years and led hundreds of digital forensic investigations, stated that ‘digital forensics is a forensic science just like toxicology because computer artifacts can be identified, examined, tested, replicated, and reviewed.’
According to the Vantage Market Research report on forensic technology markets for 2022, the global forensic industry is expected to generate around $27 billion by 2028. The digital forensics market is growing due to the fact that computers are an integral part of smartwatches, mobile phones, CCTV systems, and even smart sprinkler systems, making it impossible for any industry to progress without integrating digital technology into business processes.
The ministries of internal affairs (police) were the first institutions to start applying digital forensics, and later, once its usefulness was recognized and where it could be applied, it expanded to other law enforcement agencies: tax authorities, customs, competition protection agencies, financial police, state security agencies, the military…
