The Army Lawyer


The Spoof Is in the Evidence:


Obtaining Electronic Records to Corroborate Text Message Screenshots

“Don’t like your buddy’s girlfriend? Well, break them up. Just send a fake text message! www.spoofmytextmessage.com”1

Most modern courts-martial include text/chat message evidence from a cell phone. Digital evidence, like all evidence, is susceptible to fraud, alteration, and fabrication. A common method of fabricating text messages is “spoofing.”2 Using a spoofing application (app), an individual can falsify a text message and send the message from any phone number they choose. Thus, an alleged victim can enter the accused’s phone number and send a message—in which the accused appears to admit his guilt—to the alleged victim’s phone. Or, a witness could use a spoofing app to create an entire fake conversation on the user’s phone, allowing the user to take a screenshot of the spoofed conversation and represent it as a genuine conversation.

Access to spoofing has become so prolific that law enforcement should no longer assume the genuineness of a screenshot depicting a digital communication.3 Using the search term “spoof” in the Apple App store, the author scrolled through over 100 spoofing apps that enable the spoofing of text messages, phone calls, Global Positioning System location, email, and/or social media messages.4

Recognizing that electronic communications are susceptible to “spoofing” or fraud, courts have found it is insufficient to merely argue that, on its face, a message purports to be from a person’s messaging system.5 The availability and ease of modern spoofing technology makes such an assumption naive.

Fraudulent text message services are becoming increasingly prevalent. It is important for military justice practitioners to understand the primary ways to fabricate a text message, how to authenticate text message evidence using the “digital footprint” of electronic communications, and how recent changes to the Stored Communications Act (SCA)6 make compelling disclosure of the “digital footprint” from service providers much easier for military investigators. In response to the SCA changes, law enforcement should obtain SCA court orders or warrants7 for data recovery as a matter of course in all cases involving text/chat message digital evidence. Even when the physical communication device is secured and forensically analyzed, investigators should still secure the SCA records to ensure the forensic examination collected all the messages on the phone.8 Taking the steps to secure this data creates a minimal burden on law enforcement. However, obtaining this data provides corroboration when authenticating digital evidence at trial and may be the difference between obtaining a conviction or a not guilty finding. A blueprint for law enforcement to gather and litigators to analyze text or chat message evidence, placing particular importance on situations in which the cell phone is unavailable for forensic examination, will be helpful to judge advocates navigating this realm.

Spoofing Services Are Abundant, Affordable, and Easy to Use

As mentioned above, there are hundreds of companies providing spoofing services for relatively low costs. There are two main ways to spoof a text message. This article will refer to the first spoofing technique as the Fake-Text Transmission method. In this method, a user (the spoofer) accesses a spoofing website or app to send an actual text message to the recipient’s phone (spoofing recipient), appearing as though the message originated from a phone number of the spoofer’s choosing. The spoofer creates the content of the text message and chooses the phone number of the “sender” of the text message.9 The website or app then sends the text message to the spoofing recipient, appearing to originate from the “sender” selected by the spoofer.10 If the spoofing recipient takes a screenshot of the spoofed text message that they received, the screenshot would depict a picture of an actual text message received by the spoofing recipient, even though the “sender” identified on the screenshot had never actually sent that message to the spoofing recipient from their own phone.

This article will refer to the second spoofing technique as the No Transmission, Fake Conversation method. Here, the spoofer accesses a spoofing website or app and creates either a single fake text message11 or an entire fake conversation between any two (real or fictional) individuals on the spoofer’s own phone.12 No actual communication is sent or received by either phone. The spoofer inputs the names (or phone numbers) of both the sender and recipient of the spoofed message and creates the content of the messages. The spoofer inputs the date and time of each message.13 Using this method, the spoofer can take a screenshot of the fake text message conversation on their phone. That screenshot looks identical to the screenshot of an authentic text message conversation taken from a phone.14 This technology allows the presenter of the screenshot to present this spoofed text message conversation to law enforcement, even though the conversation never occurred.15

Both of these spoofing methods are user-friendly and readily available to anyone with access to internet websites16 or digital apps.17 Anyone with the smallest amount of comfort using cell phone apps could effectively use this spoofing technology. Law enforcement and litigators must be aware of this new technological reality to accurately investigate and litigate cases that include digital evidence of electronic communications. An accurate investigation requires pursuing a method to verify the genuineness of the text message.

Methods to Authenticate a Text/Chat Message

Traditional methods of authenticating digital evidence include testimony from the sender or recipient asserting the text messages are genuine or from a witness who saw the message being sent. When the purported “sender” denies sending the message and there were no witness to the transmission, the best evidence that a text message is what it purports to be is the “digital footprint” found through data recovery on the cell phone itself or in records stored by the service provider.

Text/chat messages, like all electronic communications, leave a digital footprint that is tracked in the records maintained by the service provider. Text messages produce transactional records18 that memorialize the date/time of when a text message was sent or received by a user’s account.19 Of note, some telecommunication service providers keep records of the content of text messages for a short period of time.20

Ideally, in a case involving text/chat message evidence, law enforcement will secure the physical device from the alleged victim and the accused and conduct forensic analysis to obtain the digital footprint of the messages. However, there are situations where the cell phone is unavailable.21 In these situations, it is crucial for law enforcement to obtain information regarding the witnesses’ smartphone or tablet brand, cellular service provider (e.g., Verizon, Sprint), and chat application service provider (e.g., Apple iMessage, Facebook Messenger); that information informs law enforcement of which service providers to contact.

Even when a cell phone is available for forensic examination, obtaining data from the service provider will corroborate the authenticity of the digital evidence and ensure the forensic examination captured all the message history associated with the phone’s user. As discussed in the next section, military investigators and litigators can easily request this data pursuant to a SCA search warrant or court order.

Military Judges Are Now Competent Authorities to Issue SCA Warrants/Orders

Prior to 1 January 2019, military investigators were limited in their ability to use the SCA to compel disclosure of electronic records from service providers. Since the SCA did not include military courts in its definition of a “court of competent jurisdiction,” military judges did not have the power to compel civilian service providers to disclose electronic communication records. Rather, law enforcement had to go through a lengthy process of working with a United States Attorney’s office to request a SCA order or warrant from a Federal Magistrate.22

As of 1 January 2019,23 military judges24 gained the authority to issue SCA court orders and warrants,25 compelling civilian service providers to produce these electronic records to military law enforcement.26 This removes a major hurdle for military investigators and supports the argument that trial counsel should obtain a SCA order or warrant for data recovery as a matter of course in all cases involving text/chat message digital evidence. The following section describes the consequences for litigators at trial should a SCA court order or warrant not be obtained.

Consequences of Spoofing for Litigators at Trial

As discussed above, law enforcement should be taking the additional investigative steps to pursue corroboration for screenshots of electronic communications. Trial counsel need the digital records to help prove their case27 and authenticate a screenshot at trial.28 Even if the military judge admits the screenshot into evidence without the SCA records, once they learn from the defense counsel how easy it is to spoof a text message, the finder of fact may determine the screenshot is unpersuasive evidence.29

Defense counsel need to understand the technology to properly evaluate the case and to make the proper arguments at trial. Defense counsel should highlight the shortcomings of the investigation by showing that law enforcement could have easily secured electronic records that would have verified the genuineness of the messages and corroborated the alleged victim’s claim, but they chose not to collect that evidence.30

Special victim counsel (SVCs) also need to understand this spoofing issue in order to effectively advise their clients. An alleged victim may want to report a crime but does not want to turn over their phone to law enforcement for forensic examination. The SVC could help preserve their client’s privacy interests by advising law enforcement to seek the SCA records for corroboration of the screenshot, thereby reducing the likelihood that Criminal Investigation Command (CID) would need to seize the client’s phone for corroboration. Additionally, the SVC should advise their client about CID’s investigative capabilities, to deter a client who may have considered spoofing a communication. The final section below provides a blueprint for military law enforcement and trial counsel to request electronic communication records from service providers.

Steps to Follow to Secure SCA Records

Freeze the Evidence Immediately by Sending Preservation Letters.

As soon as the allegation arrives, the CID agent should ask the alleged victim how she communicated with the accused,31 then send preservation letters32 to the appropriate service providers33 as a way to freeze the evidence and prevent its destruction. Service providers will preserve the requested content and transactional records for ninety days. Under the SCA, CID may ask for an additional ninety days of preservation, but no more than the total of 180 days.34 If the defense counsel is aware of potential exculpatory evidence, they may send the trial counsel a request for law enforcement to send preservation letters to service providers. Now that the data is preserved, the next step is to categorize the desired information.

Categorize the Information to Determine Scope of Judicial Process Request.

Law enforcement must categorize the information sought as either content records, transactional records, or basic subscriber information. Content records are less frequently available, whereas transactional records and basic subscriber information is readily available and require a much lower standard of proof.

Content records (i.e., the text of the written message) are only available from a cellular service provider, not a chat application service provider.35 Not all cellular service providers store content records and, if they do store content records, they do so usually only for three to five days before deleting the records.36 Courts require a showing of probable cause to obtain a search warrant for content records.37 So, if law enforcement is seeking the content of the text message on the screenshot, they will need a SCA search warrant based upon probable cause.

Transactional records (date/time of when messages were sent, the internet protocol (IP) addresses the request was made from, etc.,38) and records of a user’s basic subscriber information39 are available from any service provider— both cellular providers and chat application providers.40 For transactional records (not including historic cell site location information41), and basic subscriber information, a petitioner must secure a court order from a judge after demonstrating the desired records were relevant and material to an ongoing criminal investigation.42

Obtain the Proper Process in a Pre-Referral Judicial Hearing.

Once law enforcement has categorized the information it seeks and determined which provider to get it from, they must seek an audience from a judge for the appropriate judicial process. Law enforcement may seek this hearing as soon as the investigation begins. Hearings will usually be conducted ex parte,43 and the military judge may review the evidence in camera.44 Trial counsel request the pre-referral hearing with the military judge.45 The ideal process is to send the affidavit and administer the entire process over email, culminating in the military judge signing the warrant or court order and emailing the process back to the trial counsel. A hearing with the military judge is available, if necessary; in this case, a court reporter would record the hearing. Trial counsel is responsible to keep the records of the proceedings and must attach the entire correspondence to the record of trial if the case is eventually referred to court-martial.46

To obtain basic subscriber info or transactional records, petition the military judge for a SCA court order.47 To obtain content records or historic cell site location information, petition the military judge for a warrant. Despite the plain language in SCA and Rule for Court-Martial 703A, a warrant based upon probable cause is required for content, regardless of the length or location of storage.48 Law enforcement may also seek SCA warrants for items located in “the cloud.”49

Seek Non-Disclosure Orders, If Appropriate, and Follow Notification Requirements.

The Government may request non-disclosure orders (NDO) for court orders that prohibit the service provider from notifying the subscriber that the Government requested electronic records.50 Judges will issue NDOs when the Government demonstrates that one or more of five adverse results (set out in the statute) may occur due to notification of the judicial process.51 NDOs may last for up to ninety days and extensions are permissible.52 Neither the Government, nor the service provider, is required to notify the subscriber of process seeking basic subscriber info. However, the service provider may choose to notify the subscriber. To prevent or delay that notification, law enforcement may obtain an NDO in the court order. Once the NDO notification delay period expires, the Government serves or mails the subscriber a copy of the process.53


Given the proliferation of spoofing, courts may no longer accept screenshots of text messages as trustworthy evidence. Investigators and litigators must understand the capabilities of spoofing technologies and have a basic understanding of the digital footprint found in these records.

As of 1 January 2019, the SCA provides an efficient method for obtaining the digital records of communications conducted through civilian service providers, like Verizon or Facebook. Due diligence should include pursuing these records (or exploiting at trial the lack of these records). These investigative actions, or lack thereof, provide arguments for the litigators at court-martial that may be the difference between a conviction and a not guilty finding. TAL


LtCol Catto is currently assigned as an associate professor of criminal law at TJAGLCS.


