Digital Attacks
Fake Reviews, an Impersonating Profile, a Cloned Website: How to Build an Evidence File That Holds Up in Court
A screenshot is not enough. What to preserve, in what order, and how to document a digital attack so the evidence survives a defamation suit, a platform complaint and a police report.
In short
- A screenshot is the easiest evidence to attack. The address, a timestamp, the page source and a digital fingerprint turn it into something defensible.
- Order matters: preserve first, report second. A post removed before it was documented is evidence lost.
- Israel's Defamation Law allows damages without proof of loss, up to 50,000 shekels, and up to double that where the publication was intended to harm.
- Unmasking an anonymous poster by court order is a hard road in Israel. In most files, identification comes from investigative work, not from the platform.
- A coordinated attack leaves infrastructure: domains, tracking IDs, recycled photos. The infrastructure is usually the link that breaks.
The typical inquiry reaches us after the client has already done two things: taken a screenshot, and reported to the platform. Both are instinctive, and both, in that order, damage the file. The platform removes the post, the screenshot remains the only evidence, and in court the other side asks one question: “How do we know this wasn’t edited?” This article explains how to do it properly, from the first minute.
Why a screenshot is not enough
A screenshot is a picture. It carries no full page address, no verifiable timestamp, no source code, and it can be edited in any basic program. It is not worthless, but it is evidence that is easy to challenge, and an experienced lawyer will.
Documentation that stands in court answers four questions: what exactly was published, where (the exact address), when (the time of viewing, and the time of publication if shown), and who documented it and how. All four must be reproducible by another person.
Step 1: preserve, before anything else
The first rule of digital-attack files: do not report, do not respond and do not make contact before everything is saved. A post removed, from a profile deleted, by a user who was blocked, is a post that can almost never be recovered.
What to save, for every item:
- The full address of the post, of the profile that published it, and of every comment or share.
- A capture of the whole page, not only the damaging part, including the address bar and the on-screen time.
- The page source (saved as HTML), which contains user identifiers, timestamps and metadata invisible to the eye.
- A digital fingerprint (hash value) of every saved file, so it can later be proven the file has not changed.
- A save in a public web archive, where the page is accessible without login. An independent archive is a witness that does not depend on you.
- A documentation log: who saved, when, from which device, and what was done. That sequence is what is called chain of custody.
For a cloned website, add: the domain registration (when, through which registrar), DNS records, the site’s security certificate, and the hosting location. All of these change or vanish the moment the attacker realises someone is looking.
Step 2: map, don’t just collect
A coordinated attack almost never starts with a single post. Arrange every item on a timeline: what was published first, where, and what followed. Very often it emerges that “spontaneous” reviews on three different platforms were posted on the same day, minutes apart, in near-identical wording, from accounts opened the same week.
The timeline answers a question the court always asks: is this a few unhappy customers, or a campaign. That difference is the difference between permitted criticism and defamation.
Step 3: attribution, from where the attacker slipped
Unmasking an anonymous poster through an order against the internet provider is a road Israeli law makes very difficult, and in practice most files are not solved that way. Identification comes from the infrastructure the attacker built and the mistakes he made:
- Recycled photos. The impersonator’s profile picture already appeared elsewhere, sometimes on the real profile of whoever runs it.
- Shared identifiers. A cloned site using the same analytics or advertising ID as another, legitimate, site belonging to the same person.
- Writing pattern. Recurring spelling errors, distinctive punctuation, expressions that also appear in signed publications.
- Registration details. A domain registered with an email address already used elsewhere, or through a small registrar few people use.
- The knowledge itself. Whoever knows details about your business that only a former partner, a former employee or a specific client could know has narrowed the suspect list himself.
Attribution does not always succeed, and anyone who promises certain identification in advance is not telling the truth. But when it succeeds, it almost always comes from here.
Step 4: the legal routes, and what each one requires
The platform complaint. After preservation, report under the platform’s own rules: impersonation, fabricated review, trademark infringement. An organised file, with a timeline and infrastructure, is handled differently from a complaint with a screenshot. The removal itself is also evidence: the platform determined the content broke its rules.
A defamation suit. Israel’s Prohibition of Defamation Law allows the court to award damages without proof of loss, up to 50,000 shekels, and up to 100,000 shekels where it is proven the publication was made with intent to harm. But a suit requires an identified defendant, which is why the attribution stage is the precondition for this one. A genuine customer’s review, however harsh, is protected. An invented review, by someone who was never a customer, is not.
A police complaint. Impersonation to obtain something by deceit, extortion, and threatening harassment are criminal offences. The police have what we do not: the authority to obtain information from providers by order. An organised file shortens their road.
Interim relief. In severe cases, counsel can seek an injunction. Here too, the quality of the documentation decides whether the application succeeds.
What not to do
- Do not respond publicly to the post. The response widens the reach and hands the attacker new material.
- Do not contact the impersonating profile. It will vanish, with the evidence.
- Do not ask friends to “flood” positive reviews. The platforms detect it, and it looks exactly like what you are complaining about.
- Do not wait. Archives do not keep everything, and profiles get deleted.
What the file contains at the end
The file we deliver contains every preserved item with its fingerprint, a timeline of the attack, the infrastructure and attribution analysis with a confidence level for each finding, and an affidavit from whoever performed the documentation. It is written so counsel can attach it to a statement of claim, and the police can start from it rather than from zero. And what we could not establish is stated in it explicitly. A file that overstates is a file that falls apart under cross-examination.
This section is general information, not legal advice. Every case is examined on its own facts.


