← All posts

Digital Forensic with AI 101 - Corporate Espionage by NS and DNS manipulation

Digital Forensic with AI 101 - Corporate Espionage by NS and DNS manipulation

Let's begin with something different! From the title you can probably tell this is going to be a rather technical post, but even if you are non-tech and you bear with me till TLDR at the end, you'll probably learn something new to protect your company's most prominent digital asset: the Domain name.

In this series, I'm sharing insights from one of my recent investigative cases involving corporate sabotage through DNS manipulation specifically, tampering with NS (Name Server) records. This tactic disrupted email communications and domain accessibility, raising serious questions about contract validity, liability, and preventive measures.

The twist? I'm no cybersecurity expert just a software guy who's been tinkering with digital forensics for over two decades. I first played with a Router's settings when I was 15, fast forward to today with AI tools accelerating investigations, the landscape is evolving rapidly and becoming even more fascinating. You can trust me, or not... 🙃

All events described in this article are made up events to illustrate the concepts, any similarities are coincidental.

🧨 The Sabotage Unfolds

Payment Promises and Delays

Payment Promises and Delays: The client had repeatedly promised payment on a specific date, let's say December 18th, but the day came and went without any transfer or response.

Communication Breakdown: I followed up via email on 20th, only to discover bounces back on 21st due to domain NS issues. This affected not just one domain but several under the client's control, suggesting that it is intentional (shown below).

Client's Evasive Response: On December 22nd, the client replied, claiming efforts to pay but providing no concrete timeline. Notably, they ignored the email failures, the domain downtime (which lasted several days), and even denied responsibility for payment on completed work, phrased it as charity help, not a contractual debt.

Unmentioned Downtime: The client never acknowledged the domain going "dark," which halted all email and web access temporarily.

This pattern screamed foul play, prompting a deeper dive!

🗃️ The Investigation

My curiosity led me to trace the timeline using reliable tools. Here's what DNS history revealed from dnshistory.org (extracted on December 23):

Red flags? The NS records shifted abruptly between Google Cloud clusters, correlating with gaps in domain functionality. Cross-checking with Google Cloud Platform (GCP) logs confirmed zero activity during those periods. Traffic to Cloud DNS halted abruptly around noon one day and resumed days later. This suggests deliberate deletion and re-addition of NS records, a classic sabotage tactic to disrupt services without permanent loss of control.

Google Cloud Check

Our access to the Cloud DNS, granted in July, remained intact.

Next, we check the Cloud DNS status. The Owner role in GCP (or similar in AWS/DO) assigned to us since July a few months prior, remained intact, along with the other account ___jsc@gmail which is controlled by our Client, linked to his mobile phone for 2FA. This personal gmail also suggests that this Google Billing Account belongs to another company of his, linking the 2 unrelated projects together in one context in the eye of the cyber security law!

And then when we look at the Billing Reports , the picture started to emerge clearly! The is a clear gap in December in our incoming traffic, which basically aligns with the blackout dates above.

Cloud DNS Billing Report Cloud DNS Billing Report showing a clear gap in traffic

🕵🏻 The Sherlock Toolkit

In digital forensics, the internet never forgets. While bad actors rely on erasure and gaslighting to evade contractual obligations, these tools help reconstruct the digital chain of custody and secure Electronic Evidence admissible under Vietnam’s Civil Code 2015 (Article 95). The law recognizes electronic data as valid if sourced reliably (e.g., timestamps, hashes).

DNSHistory (dnshistory.org): The Chain of Custody DNS records are the timestamped fingerprints of infrastructure control. They definitively establish when administrative rights were transferred, validating the existence of a verbal contract. On July 16 same year, Client transferred DNS control from their personal Google Cloud account to our team's control. This timestamp proves us, the Vendor, was the authorized administrator.

Wayback Machine (web.archive.org): The Internet never forgets When toxic partners attempt to rewrite history by deleting websites or denying involvement, web archives freeze their public commitments in time. You can use this tool to literally travel back in time to see the websites that are no longer accessible? They are still there, you just have to know where to find them. Perhaps you could also find your embarrassing MySpace or Yahoo360 pages there, still remember the username? oh I missed old those times.

Billing Reports & Logging Records: The Heartbeat Monitor Forensic billing reports act as a "proof of life" for digital assets. Even if a client ghosts, the infrastructure they ordered continues to generate logs and costs, proving the service was delivered and active. In my case, Cloud DNS Billing Report showing a clear gap in traffic for those exact matching dates in December and November, also confirming the Billing Account is under the Client's control, they are still paying for the infrastructure to run the development server last couple of months as expected.

🦾 The AI revolution "factor"

Notice that AI was not part of the toolkit? This is intentional because I'm not sharing with you an exact magical tool. What I'm presenting is a different mindset to leverage AI as a colleague, not a Tool.

By now, most of us who interacted with AI tools often would know that AI is excellent at pattern matching, making token/words predictions, it can spot linkages between seemingly several random paragraphs of text. So why not let AI do most of those tasks as a Cyber Security Expert, for free!

Here is one example of how I worked with my AI.

I spent a few hours on this kind of back and forth with the AI, to validate and sometimes refute my logics. For me and I'm pretty sure people who does similar work, I find it super efficient already. Compared to how it is done manually, which as you can imagine, could take days or weeks or any one person.

What exact tools I used? It doesn't really matter much but if you do have a favorite tool you can just use it (ChatGPT, Perplexity, Grok, Claude, Gemini, NotebookLM...), for me personally, I use NotebookLM for majority of the cross-checking from existing sources. And if you are curious, I also use more cutting-edge help from Advanced apps such as Warp.dev and Trae.AI for tracking and tracing of deep complex routings and tunnelings.

The point here is, you need to know what you are doing, the tools is secondary. You need to have a certain expertise in the given domain in order to craft the right questions or tasks for the AI. You don't become a master by speaking to a master.

At the end of the day, YOU are responsible for your work, not AI.

⚖️ Legal Implications Under Vietnam's Cybersecurity Law

So with the help of multiple AI colleagues, I was able to understand the implications of what just happened. Again, I'm not a cyber security expert, nor licensed lawyer, don't trust 100% what I and my AI found, do your own homework!

Vietnam's Cybersecurity Law (originally 2018, consolidated into the 2025 version effective July 1, 2026) addresses such acts under provisions on network sabotage and unauthorized interference. Key points are:

  • Prohibited Acts (Article on Prohibited Cybersecurity Violations): Manipulating DNS/NS records to disrupt services qualifies as "sabotage of information systems" or "unauthorized access/alteration," especially if intent is to evade obligations or cause harm. This includes high-tech cybercrimes like domain hijacking for corporate gain.
  • Corporate Liability: Businesses face fines (up to VND 200 million for individuals, higher for entities), suspension of operations, or data localization mandates. If tied to national IT systems (Level 3, where sabotage risks public safety), penalties escalate, enhanced audits, licensing for cybersecurity tools.
  • Data and Evidence: Electronic records (DNS logs) are admissible under Civil Procedure Code 2015 (Article 95) if verifiable. The law emphasizes user verification, blocking unlawful content, and reporting breaches.
  • Broader Impact: This violates contract law (Civil Code 2015, Articles 428-430 on breaches) and could trigger criminal probes under Penal Code for fraud or property damage.

You can ignore those technical jargon, and remember this:

Even if you are the rightful owner of a domain name! Under Vietnam's Civil Code 2015, contracts are binding; breaching by reclaiming handed-over DNS rights without fulfilling payment obligations constitutes liability.

A domain name is a very important Digital Asset of any businesses, and the Vietnam government is stepping up efforts in enforcing IP Protections and Violations. Right now the country's framework is still in its infancy compared to much established markets, but it is changing rapidly to attract more FDIs in the coming years.

Thank you for reading this far, follow me for more quirky uses of AI!

TLDR

  • The internet don't forget, even the changes you made 20 years back.
  • Sabotaging at the NS / DNS level is easily traceable, or broadly, any cybercrime left plenty of digital traces. With the help of AI Analysis, its a blink of an eye versus days or weeks of pattern-matching and cross-checking.
  • YOU are responsible for your work, not AI.