Hacker News new | ask | show | jobs
by goles 788 days ago
As someone else mentions your first thought, set a canary trap. If the person is sending defamatory information pretend to leak several every so slightly different versions of things happening that the suspect is interested in.

https://www.canarytrap.com/what-is-a-canary-trap/

"Each summary paragraph has six different versions, and the mixture of those paragraphs is unique to each numbered copy of the paper. There are over a thousand possible permutations, but only ninety-six numbered copies of the actual document. The reason the summary paragraphs are so — well, lurid, I guess — is to entice a reporter to quote them verbatim in the public media. If he quotes something from two or three of those paragraphs, we know which copy he saw and, therefore, who leaked it ... You can do it by computer. You use a thesaurus program to shuffle through synonyms, and you make every copy of the document totally unique." - Patriot games https://www.businessinsider.com/nba-canary-trap-media-2014-1...

If any of the future emails include one detail over another it's likely it was that person. Repeat 3-4 times until you can establish a trend. If you send newsletters or weekly emails specifically start tweaking the emails your suspects receive. If/when LE can get a warrant signed on any of the used accounts they'll easily be able to find the person.

If you send out any images you could steganographically hide a watermark in an image if the person leaks it, even if its just your orgs icon or signature. Or modify one pixel then hash the image for each of your suspects.

"Here's our new classroom design (Please don't share!)" https://www.openstego.com/

You could also probably try to phish the person. If your school has Knowb4 or a similar software there are hundreds of convincing templates, if you don't contact a couple companies and ask for samples or take a real spam sample you've gotten. Replace the hyperlink with something you've hosted and just rip the files from the real website. Fake password has been changed, Complete survey to win $50 gift card, etc.

Best of luck!