← back to threat intelligence

⚖️Disclaimer & Methodology

How these investigations are produced · what they are and are not · effective 2026-06-20

1. Nature of publications

The threat intelligence dossiers published on this site are analytical assessments and opinions — not legal findings, not judicial determinations, and not accusations of criminal conduct.

Conclusions presented herein may be wrong. They represent the best interpretation of available evidence at the time of publication and may be revised, retracted, or superseded as new information becomes available.

Confidence levels (HIGH, MEDIUM, LOW) are explicitly stated for each major claim. Where sources disagree, the disagreement is documented rather than hidden.

2. Personal-capacity disclaimer

The research, views, and opinions expressed on shuffle-on.com are entirely my own. They do not reflect the official policies, positions, or opinions of my employer, Digital Science, or any of its affiliates.

Everything on this site is published in my personal capacity, on my own time, on my own infrastructure. No employer resources, data, or systems are used or referenced.

3. Data collection pipeline

All investigations follow a consistent 6-step pipeline:

4. AI-assisted research

This research uses large language models (LLMs) as research assistants. Specifically:

Every factual claim in a published dossier traces back to a verifiable source (captured traffic, public record, OSINT platform). The AI assists in finding and organizing evidence — it does not fabricate it.

All editorial decisions, conclusions, and responsibility for accuracy rest solely with the human author.

5. Source hierarchy

Evidence is weighted by reliability tier:

6. Limitations acknowledged

7. Factual corrections

If you identify a factual error in any published material — a misattributed IP, an incorrect organization name, a wrong date — please contact me at lisneanucristian@gmail.com for correction.

Documented corrections will be applied promptly and will leave a visible audit trail in the affected post or dossier. Corrections strengthen the work; they are welcome.

8. Named-entity policy

Where commercial entities or threat actors are named, the naming is supported by publicly verifiable evidence (registration records, captured traffic, signed documents, court filings, regulatory disclosures).

Such material is published under the standard journalistic principle of accurate reporting in the public interest. The purpose is to document observable patterns in internet infrastructure — not to defame individuals or organizations.

Subjects of any publication who believe the material is materially incorrect are encouraged to contact the corrections email above. Good-faith factual corrections will be applied regardless of the source.

9. Data protection & GDPR legal basis

This research processes IP addresses (personal data under GDPR) and, in some cases, names of individuals associated with corporate registrations or public records. The legal bases for this processing are:

10. Data subject rights

If you believe your personal data (e.g., an IP address registered to you) appears in a published investigation, you may contact lisneanucristian@gmail.com to:

However, please note that the right to erasure (Art. 17) is limited where processing is necessary for exercising the right of freedom of expression and information (Art. 17(3)(a)), for reasons of public interest in the area of public health and security, or for archiving purposes in the public interest / scientific research (Art. 17(3)(d)).

Each request will be assessed individually. Legitimate corrections are always applied; requests to suppress accurate, publicly-sourced information about malicious infrastructure will generally be declined.

11. Active reconnaissance disclosure

In some cases, IP addresses that have attacked this infrastructure are subsequently scanned to determine what services they expose. This counter-reconnaissance is:

No exploitation, data extraction, denial of service, or modification of remote systems is performed. This is analogous to checking if a burglar's vehicle has visible license plates — observational, not interventional.

12. Non-commercial purpose

This research is published without any commercial purpose. Specifically:

The sole purpose is contribution to public knowledge about internet security threats. This non-commercial nature is relevant to both GDPR legitimate interest balancing and to defamation law assessments of intent.

13. Jurisdiction & governing law

This website is operated from Iași, Romania, within the European Union. Any dispute arising from or relating to the content published on this site shall be governed by Romanian law and subject to the exclusive jurisdiction of the courts of Iași, Romania.

The author is a natural person domiciled in Romania and benefits from the protections afforded by:

14. Quotation & fair use

Published investigations may quote or reference material from third-party sources (news articles, court filings, corporate disclosures, academic papers). Such use is made under:

All quoted material is attributed to its source. No full reproduction of copyrighted works is made. Quotation is limited to what is necessary to support the analytical point being made.

15. External links & third-party content

This site contains links to external websites and resources (OSINT platforms, news outlets, public registries, academic papers). These links are provided for source verification purposes.

The author:

Effective 2026-06-20 · Last updated 2026-06-21 · Lișneanu Dumitru-Cristian · Iași, Romania
shuffle-on.com · Threat Intelligence