Skip to content
Skip to main content
IP Addresses & Networks Investigation walkthrough
Pathway: I have been given an IP address

An online fraud has been linked to an IP address. What happens next?

An IP address can move an investigation forward, but it does not name an offender. This walkthrough follows one online-fraud enquiry from a retailer's activity record to a subscriber address, a developing suspect and the next evidential decisions.

You do not need to understand all of the networking before you begin. Open each stage to see the evidence, the next move and what remains unresolved. Follow the linked cards when you need the technical detail behind a decision.

The working principle
Each stage supports the next. No single stage establishes who was responsible for the fraud.
Recorded event
Network connection
Subscriber account
Address and access
Device or account
Person
Responsibility

The investigation can move forwards, backwards or sideways between these stages as new evidence appears.

Scenario note: This is a fictional but realistic training case. Names, organisations, account details and returns are invented. 198.51.100.27 and AS64496 are reserved documentation values.

The case begins

Initial report
Reported offenceStolen payment-card details used online
PurchaseLaptop worth £1,249
FulfilmentCollected the following day

The retailer supplies its customer-account and transaction records. A request reference connects the completed purchase to this activity record:

Retailer activity record
2026-06-18T14:36:42Z   checkout_complete   request_id=7F3A91account_id=884219   source_ip=198.51.100.27   status=success
Time includes UTC markerRequest connects related recordsAccount identifies the retailer accountSource IP is what the retailer observed

The account also contains an email address, a mobile number and collection details. Those are leads; at this point none has been proved to belong to the person who committed the fraud.

Follow the investigation

01 · Establish what the retailer actually recorded

Preserve the complete event and its context, not a copied IP address on its own.

The retailer says that its system recorded a successful checkout on account 884219 at 14:36:42 UTC. It has linked request 7F3A91 to source IP address 198.51.100.27.

The record is useful because it identifies an event, time, account, request and address together. An IP address copied into an email or statement would lose much of that context.

Before relying on the record, work through the immediate checks:

  • Event meaning: confirm what checkout_complete and status=success mean in this system.
  • Record linkage: establish how request 7F3A91 connects the checkout, account and source-IP entries.
  • Time: retain the full timestamp and time zone, including seconds and the UTC basis.
  • Available context: ask whether ports, session identifiers and surrounding events exist.
  • Record form: establish whether this is an original export, a generated report or somebody's summary.

Investigator action
Preserve the original transaction and technical records, the field definitions needed to interpret them, and an explanation of how they were obtained. Record any relevant retention or deletion risk.

An online service records what its systems can see. A content-delivery network, reverse proxy or other intermediary can affect the source field. Establish where the address came from and what the recording system could see before treating it as the customer's connection.

EstablishedThe retailer recorded a completed checkout associated with this account, request, time and source-IP field.
Still openWho controlled the account, what connection reached the retailer and who completed the transaction.

02 · Decide whether the IP address is a usable lead

The record contains enough context to progress, while the limits remain clear.

An IP address becomes useful when it can be tied to a defined event and time. Before deciding where to go next, check the value against the retailer's record:

  • Complete value: 198.51.100.27 contains all four parts of an IPv4 address.
  • Relevant event: it is linked to the completed checkout through request 7F3A91.
  • Precise time: the record includes the date, seconds and UTC time basis.
  • Public or private: it is not within a private range normally used only inside a home or organisation.
  • Recording point: Step 01 established what the retailer's source-IP field represented.

EstablishedThe address is complete, event-linked, precisely timed and suitable for a network lookup.
Still openThe record holder, subscriber connection, user, device and responsibility.

The address from the retailer's record is:

198
.
51
.
100
.
27

Four decimal values separated by dots: the familiar written form of an IPv4 address.

This is IPv4. The format explains what kind of address has been recorded; it does not identify who used it.

The lead is usable. Use an IP registration or network lookup to identify the organisation responsible for the address range and obtain clues about the kind of network involved. A reverse-DNS lookup may add a hostname. Neither result identifies the customer or user.

The result might point to a home or business ISP, mobile network, workplace, public Wi-Fi operator, VPN, proxy or hosting service. That classification shapes the next enquiry.

Investigator action
Record the lookup source, date and complete result. Decide what the address appears to represent before making a routine subscriber request.

03 · Identify the likely record holder

The lookup points to NorthNet Broadband Ltd and an ordinary fixed-broadband range.

The lookup produces the following return:

Registration and routing excerpt
Address range198.51.100.0/24
Responsible organisationNorthNet Broadband Ltd
Network nameNORTHNET-RESIDENTIAL
Origin ASNAS64496
Service indicationFixed broadband
Registered countryGB
The country and organisation describe registration and network responsibility. They do not locate or identify the user.

NorthNet is now the likely holder of allocation records for this connection. That makes a provider enquiry a reasoned next step - not an automatic reaction to seeing an IP address.

Use the appropriate legal and organisational process. Frame the enquiry around the connection seen by the retailer at the recorded time, and ask the provider to explain any qualification affecting the match.

EstablishedThe range is managed by NorthNet and is described as fixed broadband.
Still openWhich subscriber connection held the address then, who could access it and who completed the checkout.

Large providers may operate different ranges for different services, and public registration data can be broad, stale or administrative. A provider name does not by itself reveal the service or user.

04 · Make a precise request and protect relevant records

The provider needs the exact address and event time; other record holders may need prompt preservation.

Public IP address198.51.100.27
Date and time18 Jun 2026
14:36:42
Time basisUTC
Event contextSource recorded at completed checkout

Before the enquiry leaves, verify the request:

  • Preserves the recorded time: retain the date, seconds and UTC basis exactly as supplied.
  • Explains the event: state that the address was recorded as the source at completed checkout.
  • Includes matching fields: supply any source port, protocol or session identifier held with the same event.
  • Tests the clock: record any known offset, uncertainty or reason to question whether the timestamp can be trusted.
  • Invites qualification: ask whether dynamic allocation or shared addressing affected the match.

If the network uses CGNAT, a source port and sometimes the protocol may be needed to distinguish one customer's session from others sharing the public address.

The retailer, NorthNet and collection service may hold different records for different periods. Where justified, make a defined preservation request using the relevant identifiers and time window. Record the holder, scope, reason, reference and any expiry or renewal date.

Investigator action
Preserve the complete originating event and the identifiers required to match it. A focused request is more useful than an undefined request for everything connected with an account.

Preservation protects material that still exists within the stated scope. It does not disclose that material or replace the authority required to obtain it.

05 · Interpret NorthNet's subscriber response

The event matches a household broadband service, but the named subscriber does not appear in the retailer records.

NorthNet returns the following result:

Subscriber match excerpt
Matched public address198.51.100.27
Matched event time18 Jun 2026, 14:36:42 UTC
AllocationDynamic IPv4; source port not required for this range
Subscriber accountNN-4829137
Named account holderJordan Morgan
Installation address14 Market Close
Provider qualification: this match identifies the subscriber service allocated the address at the supplied time. It does not identify the individual using the service.

This is a significant but qualified lead. The investigation now has a household internet connection and installation address associated with the event. Jordan Morgan is the account holder, but that name does not appear in the retailer's transaction or collection records.

  • Address and time: confirm that both exactly match the values supplied.
  • Allocation logic: record whether the address was dynamic, shared and whether a source port was required.
  • Subscriber meaning: establish whether Jordan is the account holder, bill payer or another type of customer contact.
  • Service location: distinguish the installation address from an assertion about where any device or user was located.
  • Qualifications: retain any caveat, ambiguity or limitation in NorthNet's wording.

Investigator action
Record this as a subscriber connection associated with the event time. Develop enquiries around 14 Market Close and the people with access; do not record Jordan - or anybody else - as the user on the strength of this return.

EstablishedNorthNet matched the public address and time to a service account in Jordan Morgan's name at 14 Market Close.
Still openWho could use the connection, which device completed the checkout and whether the subscriber had any involvement.

A household service can be held in one person's name and used by several residents, visitors and devices. The subscriber's name is an account fact, not an identification. The subscriber result does not identify a particular device or prove that it was physically inside the property.

06 · Test the lead against other evidence

Address enquiries, account history, telephone data, CCTV and witness evidence begin to develop Alex Morgan.

The retailer's account history first identifies another person: Alex Morgan. Further proportionate enquiries move the investigation beyond the IP evidence:

Retailer account historyThe email address used for the fraudulent order also appears on an earlier order delivered to Alex Morgan at 14 Market Close.
Address and access enquiriesA witness states that Alex lived with Jordan at 14 Market Close during the relevant period and regularly used the household internet connection.
Collection messageThe collection code was sent at 09:58 to the mobile number recorded on the retailer account. Subscriber information associates that number with Alex.
CCTV · 19 June, 10:12A person resembling Alex is shown collecting the laptop shortly after the code was sent.
Collection-point witnessAn employee states that the collector displayed the collection code on a handset before receiving the parcel.

NorthNet did not name Alex. It supplied a connection and household address; familiar investigative evidence now tests who had access and develops Alex as a suspect.

Treat each identifier and observation as a separate line of enquiry. Establish the provenance and reliability of the email address, telephone number, retailer account, collection record, CCTV and witness evidence. Build a timeline showing which source connects which event, account, address or person.

What the combined evidence suggestsSeveral independent sources now associate Alex with the order, collection code, household address and access to the connection.
What still requires proofWho controlled each account and device, whether the CCTV identification is reliable, and whether Alex knowingly committed the fraud.

An account or number may be shared, transferred, spoofed or used by somebody else. A resemblance on CCTV is not necessarily an identification. Repeated use of the same IP address across events may support an association but does not prove a common user.

07 · Plan the next operational action

The next step should answer defined evidential questions about accounts, devices, access and responsibility.

Several records now converge on Alex, but identity and responsibility still need to be tested. Further provider enquiries, interview, search, seizure and digital examination should flow from the facts and the questions still open.

  • Which device accessed the retailer account and completed the transaction?
  • Are the retailer or email accounts present on a device associated with Alex?
  • Are the stolen payment details, collection message or purchase records present?
  • Is there evidence of linked transactions or further victims?
  • Could another resident, device user or account user explain the activity?
  • Could relevant material be held in an online account rather than on the device?

Before attending
Consider what evidence may exist, where it may be held, what could be lost or remotely changed, and what information a digital-forensics unit needs. Supply the case context, identifiers, time window and questions.

A live, locked, encrypted or remotely managed device may require immediate decisions. Relevant email, application or cloud material may not be stored locally. Finding a device at the subscriber address would still not prove that it completed the transaction; the examination and wider evidence must test that proposition.

This walkthrough only signposts those on-scene and examination issues. Continue into the mobile and device examination guidance, including what to ask a digital-forensics unit before relying on its report.

What the investigation has established

By the end of the walkthrough, the case does not rest on one technical identifier:

Retailer recordA completed checkout was associated with an account, request, time and source IP.
Network returnNorthNet matched the address and time to a subscriber service.
Household leadThe service was installed at 14 Market Close in Jordan Morgan's name; it did not identify the user.
CorroborationAddress enquiries, account history, telephone data, CCTV and witness evidence developed Alex.
Still to testDevice use, account control, identity, intent and responsibility.

The IP address was valuable because it moved the investigation from one record holder and question to the next. The conclusion at each stage remained limited to what the evidence then supported.

Operational takeaway
Use the IP address to develop a lead, not to declare a suspect. Preserve the event, establish what the recording system saw, identify the likely record holder, interpret the subscriber result narrowly and test the developing attribution against independent evidence.

If the lookup takes you elsewhere

This case follows an uncomplicated fixed-broadband result. A different classification changes the next record holder and the questions to ask:

Reference: IP-001IP Addresses & Networks