Case Study 03 · OSINT Investigation

Mystery Box Supply Chain
— Investigative TV Documentary

Broadcast Journalism · Germany · Broadcast December 2025

Sector
Broadcast Journalism / Investigative Media
Client
Independent TV Production, Germany
Engagement
Vendor-neutral OSINT — digital infrastructure mapping & actor profiling
Duration
4–8 weeks · Delivered July–Dec 2025
The Brief

An investigative journalist at a German TV production company was developing a documentary on mystery boxes — the consumer trend of buying packages of unknown, returned e-commerce goods. The story needed to show the infrastructure: who controls the supply chains, where goods originate, how distribution networks are structured, and whether systematic consumer fraud could be documented.

Investigative intuition is not evidence. The documentary required verifiable, source-documented intelligence that could withstand editorial and legal scrutiny before broadcast. I was brought in to build that evidence base.

The investigation ran in two structured phases. Phase 1 used Shodan and Censys to identify server networks associated with mystery box operators. DNS analysis via crt.sh and DNSlytics traced relationships between domains sharing infrastructure, registrar patterns, or SSL certificate chains. Phase 2 used Sherlock, WhatsMyName, and OpenCorporates to correlate usernames and trace corporate relationships between operators, and TgStat and MaveKite to map the Telegram and TikTok influencer networks amplifying the ecosystem.

The investigation also incorporated physical intelligence: AirTag tracking to document actual product flows, and forensic address recovery — chemical treatment and specialised lighting to restore redacted shipping labels and reconstruct supply chain origin points operators had deliberately obscured. A whistleblower provided corroborating evidence of systematic fraud.

Findings
Mystery box articles in circulation annually 15+ million
CO₂ impact from returns logistics 240,000+ tonnes/year
Primary supply chain routing Polish warehouse network → German distribution
Operator structure Coordinated networks presenting as independent sellers
Consumer harm documented Systematic fraud: fake labels, adulterated contents
Physical verification AirTag tracking + forensic address recovery
Broadcast outcome Prime-time, major German public broadcaster ✓
Deliverables

PDF summary report with source verification · Technical annex with domain lists and infrastructure diagrams · Structured source archive (Excel/CSV) for editorial and legal review · Full OSINT dossier: actor networks, supply chain documentation, platform analysis · Methodology documentation to broadcast compliance standard · Visual assets and story frameworks for multiple publication formats.

"Super thanks — forwarding it. Results coming Friday."
— Lead Investigative Producer, German Television · Personal reference available upon request
Relevant for your organisation if
  • Investigative journalist or documentary producer needing OSINT to broadcast evidential standard
  • Law firm or legal team requiring open-source intelligence for litigation or regulatory proceedings
  • Need supply chain due diligence — mapping who is actually behind a distribution network
  • Require vendor-neutral intelligence with documented methodology and full source archives
  • Need digital infrastructure analysis combined with physical verification methods
Ready to Start
Your Investigation
Starts Here

Documented methodology. Verifiable sources. Evidence that withstands scrutiny.
Schedule a 30-minute scoping call to confirm fit and start date.

Schedule a Scoping Call meet@axelhoehnke.com