Before the investigation begins
Connecting psychological responses to online scams, on-device behaviour and the quality of recoverable digital evidence.
Ongoing research project
Context: the person before the evidence
A scam is experienced by a person before it is examined by an investigator. Fear, shame, uncertainty and self-blame can shape what someone does next: deleting a chat, closing an account, clearing a history, saving a screenshot or delaying a report. This research examines the relationship between that human response and the evidence available for later investigation.
Aim
As an international student and cybersecurity practitioner, I have seen firsthand how online fraud and scams affect people who are unsure how to respond or preserve evidence. In this project, I want to examine how people’s psychological reactions and on-device behaviours during online scams affect the digital evidence later recoverable in a digital forensics lab, and to develop a psychologically informed evidence-capture approach that improves both investigations and victim experience.
Objectives
Four connected objectives take the project from understanding people’s responses to evaluating useful guidance.
- Identify psychological factors, including shame, fear and self-blame, that influence whether and how people respond to and report online scams.
- Describe which digital artefacts scam targets typically preserve or delete — emails, chats, screenshots and transaction records — and compare these with what digital forensics practitioners require.
- Simulate common scam scenarios in a controlled digital-forensics lab and measure how different user behaviours change the completeness and quality of recovered evidence.
- Use the findings to design and pilot a brief, user-centred evidence-capture guide that helps potential victims preserve key artefacts and seek timely help without increasing distress.
Originality: connecting three perspectives
The project’s central contribution is the experimental link between victim behaviour, forensic recoverability and user-centred guidance. It brings psychological responses to technology-related harm into the same framework as practical digital forensics. Rather than treating the emotional experience and artefact recovery as separate questions, it examines how one changes the other.
The research gap being investigated
The project starts from the observation that psychologically focused scam research and technical work on forensic recovery often examine different parts of the problem. It investigates the underexplored connection between real-time actions on a device and what can later be recovered in a lab. The extent of this gap is a question for the literature review, not a claim of established findings.
Research design
The research design combines literature review, surveys and semi-structured interviews with controlled scam scenarios and a usability pilot. These strands connect reported experiences with observable changes in evidence, then inform a guide that can be evaluated for clarity and emotional burden.
Inside the forensic lab
Controlled scenarios will compare preservation and deletion behaviours against a known starting record. The analysis will consider whether artefacts remain available, whether their original context survives, how clearly a timeline can be reconstructed and whether the recovered material is useful to a practitioner.
- Completeness and contextual coverage
- Integrity and source traceability
- Recoverability and timeline reconstruction
- Practical forensic usefulness
A psychologically informed evidence-capture guide
The intended practical output is a short, approachable guide that helps a person preserve key artefacts and seek timely support. The pilot will examine whether the guidance can be followed under stress without adding blame, confusion or unnecessary distress.
Current focus
This is an ongoing research project. The aims, research design and intended contributions describe the direction of the work; completed experiments, participant numbers and validated outcomes are not asserted.
A suspicious message. What happens next?
Explore how an immediate action could change the evidence available later.
Choose an action to explore a hypothetical effect. No messages, files or personal information are collected.