What payment evidence may exist in email or messaging accounts?¶
Email and messaging accounts may contain the instructions, identifiers and context that explain why a payment occurred.
Avoid the dangerous assumption¶
The dangerous assumption is that a message containing account details proves the sender controlled the receiving account or that the recipient followed the instruction.
Relevant evidence may include invoices, payment requests, bank details, card receipts, payment links, QR codes, gift-card codes, wallet addresses and transaction hashes.
Messages may show who requested payment, what explanation was given, whether urgency or deception was used and what happened after the transfer.
Provider notifications may record logins, password resets, new beneficiaries, payment authorisation, withdrawals, refunds and security alerts.
Attachments may include statements, receipts, order records and cryptocurrency screenshots.
Preserve the complete conversation or email thread, including timestamps, sender and recipient identifiers, attachments, message IDs and headers where available.
Do not rely only on cropped screenshots.
Account compromise, spoofing, forwarding and deleted-message recovery may affect interpretation.
A genuine account may have been controlled by another person.
A message may also contain copied payment details belonging to a third party.
Compare the communication with provider records, device evidence and the actual transaction.
Identify whether instructions changed during the conversation, particularly where bank details or wallet addresses were substituted.
When reporting, distinguish what the message instructed, what the recipient understood and what the payment records show occurred.
Operational takeaway¶
Preserve full email and messaging context so payment instructions, identifiers, deception and account control can be tested against the actual transaction evidence.