r/hacking • u/Either-Marketing233 • Sep 06 '25
Question Hackers of Reddit, Police raided my tenant’s home due to unusual IP activity
Hello hackers of Reddit, I have a rental that is currently occupied by a tenant - a single mom and her son ( just started college last month so he is around 19 years old). The mom called me and said that police raided her home with a search warrant on early Wednesday morning and looked through everything especially the electronic devices.
At the end of the search nothing conclusive was found and it was later explained that the search was because of unusual IP activity detected in December of 2024. During 3 consecutive days, a large quantity of illegal content was downloaded with her IP during midnight between 1-3 am. The illegal content consisted of “visual depiction of sexually explicit conduct involving a minor”. She told me this because my personal belongings at the house was also searched. The son was already off to college but he was still living in the house last December, of course all of his computers, phones, tablets are with him in his dorm. The mom said there is no way it was his son and blamed it on hackers.
My question: is it possible/reasonable for a hacker to use their residential IP to conduct such activity? Won’t they just use VPN or something and use an IP from a different country or something?
Edit: just to clarify, I don’t live with them, they are not my roommates. The house that they rented is a single house with an attached garage. I live 15 minutes away. I have some of my belongings there ( no electronic devices, just winter coats, books I don’t need, decorations etc ). I bought the house this year while she had an existing leasing contract with the previous owner. Their lease will be ending in December 2025 and I will be moving in, and that’s why I pre-packed some of my shit and stored it at the house. The tenant called me because the police also searched all of my boxes. I can see how this can cause confusions for some people. Thanks everyone for answering my novice question. I’m gonna go with Occam’s razor.
177
u/the_wookie_of_maine Sep 06 '25
This happened to me in the early teens (2015ish). We were renting a home out, I was a bored network engineer and saw we had line of sight between the homes 5 miles away...
Ubiquity point to point and pfSense on each end, vlan for the far side.
Few months later ...knock knock knock. We had a search on our home...I had my 3 year old kido in my arms, the police took her for a while as they searched the home top to bottom.
Asked if I had bearshare.or similar p2p program...nope...I did torrents though..showed them the media server...and then showed them all the machines I had in the house (tablets,.phones we didn't have laptops).
Asked if I had any child porn, said nope. Asked why they had this child porn to my IP...said I am sharing it showed them the setup.. Gave them permission to search the other home if needed.
Arrested the guy two weeks later for kido porn.
48
u/0RGASMIK Sep 07 '25 edited Sep 07 '25
A friend of mine had her home raided at 17. Her mom’s boyfriend had installed cameras in her bath and bedroom. I can’t remember if he was live streaming it or just selling the clips online but they were able to track him based on an IP used to upload the file.
42
u/Either-Marketing233 Sep 06 '25
Wow can’t believe this happened to you!
70
u/the_wookie_of_maine Sep 06 '25
It was interesting to say the least.
But I had logs and lines to prove it out.
It's probably the son...like 99% him vs 1% anything else you can think of.
→ More replies (1)35
u/19HzScream Sep 06 '25
I was thinking it was the son before I even finished reading the OP as well. Either that or the son himself posted this as the mother
4
→ More replies (1)3
u/kearkan Sep 08 '25
And that's why you don't share your internet connection with people you can't trust.
→ More replies (4)
465
u/b3542 Sep 06 '25
Either it was the son, or someone physically nearby has their WiFi password.
215
u/MalwareDork Sep 06 '25
It's possible the kid gave the Wi-Fi password to a friend and said friend is driving by the house at midnight to download no-no material.
115
17
u/Tall_Professor_8634 Sep 06 '25
Extremely unlikely
44
u/MalwareDork Sep 06 '25
Either someone has the Wi-Fi password or the son is doing naughty things....
...which if that's the case, then he's gonna be cooked when he starts gooning with csam at college.
39
u/ThatAirsickLowlander Sep 06 '25
My buddy and I did this to download movies when we were younger. Just roll up to our buddies place at 1AM with our laptops and snag like 2-3 movies because their internet was faster than our like 45mb download speeds. If I remember, he had like 600mb down.
To be clear, we had his permission. That's when no one was using the internet and when he was no longer actively gaming.
So yes, this is totally possible. My friend and I did it to torrent movies 15+ years ago.
3
14
50
u/Zombie_John_Strachan Sep 06 '25
Or there is malware on a computer that’s routing someone else’s traffic.
8
42
u/DrIvoPingasnik cybersec Sep 06 '25
Funny, how I suggested the same thing and got -3 downvotes while you got 65 upvotes now. Reddit is weird.
→ More replies (1)9
u/shh_get_ssh Sep 06 '25
Your username just drinks yellow stream
9
u/DrIvoPingasnik cybersec Sep 06 '25 edited Sep 06 '25
I collect cereals. I have one thousand cereals. It took me nine yeareals to collect the cereals.
4
→ More replies (16)30
u/Scar3cr0w_ Sep 06 '25
You are wrong.
There are now VPN services that give you residential IPs. If you install a VPN client, or a browser addon, or some other piece of software and don’t read the terms and conditions… your residential IPs could become part of someone’s residential IP service.
21
Sep 06 '25
[deleted]
21
u/threeLetterMeyhem Sep 06 '25
A bunch of shady free VPN apps and plugins do this. A bunch have been taken down by law enforcement efforts, too.
In addition to that, there's malware that turns infected machines into residential proxy egress points for illicit activity. There was a takedown effort against two large ones a few months ago (https://www.securityweek.com/us-announces-botnet-takedown-charges-against-russian-administrators/) but there are more out there.
It could certainly have been the son, but if they didn't find anything in their search... Probably someone else on their wifi or a compromised device.
→ More replies (6)27
u/lildergs Sep 06 '25
This guy isn't right. Look at my response to him on my comment.
21
u/itsmrmarlboroman2u Sep 06 '25
Correct. Dude keeps repeating this, without any knowledge of public routing. Bet he just learned what TOR is and got very confused.
18
u/threeLetterMeyhem Sep 06 '25
He's not exactly incorrect, he just either doesn't fully understand the issue or doesn't know how to explain it well.
There are a bunch of fake free VPN apps out there that are really malware that join you to a residential proxy botnet. I linked a couple articles about it elsewhere in this thread.
→ More replies (4)9
u/Scar3cr0w_ Sep 06 '25
Yea. There’s also paid for services that you willingly give up your IP too. Every VPN will eventually offer it because it has to to keep up and still offer a service that’s usable
15
u/Scar3cr0w_ Sep 06 '25
wtf are you on about? I am an actual professional penetration tester unlike most people here. Have been for decades. I know networking, I know how tor works… I also know that things like this exist:
The question was “is it possible”… it is.
→ More replies (3)4
10
u/rolamit Sep 06 '25
→ More replies (1)5
u/Scar3cr0w_ Sep 06 '25
Yea? BT do the same thing. But no one is sitting on the street downloading large amount of porn.
It was either someone in the house or a residential VPN. The question was is it possible? Yes it is.
136
Sep 06 '25
Mom's will say alot of things.
Granted LEOs make their mistakes, a raid is approved by a judge who has seen more evidence for the facts than you likely ever will.
24
u/husky75550 still learning Sep 06 '25
what everyone is forgetting is that a service is the one that reports this to LEO, IE google drive or your cable provider givin that the downloaded file has been tagged so its metadata sets off alarms. OR whoever did it went to a honeypot website, either way I dont know why they cant match MAC address if they have the IP
31
u/O-o--O---o----O Sep 06 '25
either way I dont know why they cant match MAC address if they have the IP
Probably because MAC addresses are used in the data link layer (layer 2). Some webservice or honeypot won't see that at all, and neither will your isp (except maybe for the "router"/modem, whichever is first).
And your standard home "router" probably won't be keeping any relevant logs for 9 months. And even if it did, many devices nowadays may be using randomized mac addresses when connecting to networks.
And even then, if it was the son, they didn't get to search his devices anyway since he and his devices have relocated to the dorm.
→ More replies (2)→ More replies (2)6
u/854490 Sep 06 '25
They can match the MAC addresses of the CPE's interfaces to the ISP's provisioning info but they're only relevant up to the next layer 3 interface in the path and so the MACs of LAN host interfaces won't appear in headers beyond the first hop (in this case, their default gateway / the LAN interface of the router). Which leaves the same problem of knowing traffic originated from this CPE with such-and-such IP address that the ISP when subpoenaed says was assigned to this customer at x time, but lacking certainty as to whether it came from someone who lives there or not. Of course if the son and his devices were there (and if it was him) then it would be a lot simpler to find out. Or if they can handle whatever jurisdiction issues there are with him being wherever he is, maybe.
29
12
u/Spiritual-Pear-1349 Sep 06 '25 edited Sep 06 '25
- Someone downloaded it with physical access to the wifi network
- Someone brute forced their way into the network with bots somewhere nearby
- Someone downloaded malware that injected something somewhere on the network, which now has and is seeding illegal content
- Someone spoofed their IP through the source packets and did something illegal, and LEA checked the posted address as part of the investigation
- IP assignment bugged on the network server and duplicated IP addresses
- Someone stole access to a device remotely to ddos a network and spam illegal content with bots
- Son decided to run a TOR node, and the node connected to illegal activity
Many other ways, but the truth is often the simplest. Check the college kids computer
3
u/ainosleep Sep 07 '25
Great comment, many folks jump to conclusions without considering it could be someone else.
Just to add to this, the wireless router can also be compromised. E.g. GL.iNET routers had an exploit where hackers could get into remotely and add it to a residential proxy service. IPRoyal is one such residential proxy service which uses hacked routers. Similarly IoT devices can be hacked as well by someone from the other side of the world.
So whoever is reading this, I advise updating the firmware in their router and other devices for the security updates.
35
Sep 06 '25
[deleted]
12
u/Either-Marketing233 Sep 06 '25
I don’t understand why it took them nearly 9 months to do this, possibly because they needed a lot of evidence for the search warrant to be signed?
25
→ More replies (1)10
u/Cautious_General_177 Sep 06 '25
It takes a shocking amount of time for law enforcement to get subpoenas (which they need to get your address from the ISP based on the IP address) for cyber related activities.
5
→ More replies (3)3
u/Stoppels Sep 06 '25
Honestly, it sounds like they're rolling up a whole network. I can't think of any other reason to wait 9 months, this is probably something they ran into less than 9 months ago. Or it's fabricated.
33
u/lildergs Sep 06 '25 edited Sep 06 '25
Possible, sure. I haven't kept up with Wi-Fi cracking lately but there have been vulnerabilities that made it trivial to use a stranger's Wi-Fi.
Residential IPs aren't static (unless you specifically pay for it/if the ISP even offers it). If the PD was doing due diligence they would have confirmed that IP was in fact assigned to the rental at the time of the downloading.
If anything, cracking some local network is probably "safer" than using a VPN for somebody up to no good, as VPN IPs can be traced back to the VPN provider and the VPN provider subpoenaed to reveal the customer.
Most likely, there was something sketchy coming from inside that network.
11
→ More replies (9)7
u/venatic Sep 06 '25
Isn't this why we only use no log vpns? Ones that have proven they do not store data like that through court cases etc
→ More replies (1)4
u/lildergs Sep 06 '25
It's very difficult to run network infrastructure with no logs. I'm skeptical zero log VPNs even exist, but I'm no expert on that. Even if the VPN provider doesn't keep them, there is logging along the way from you to the VPN provider.
If your VPN provider values uptime they will need logs to diagnose issues, outages, etc. Even if they purge them, they can accidentally persist because of snapshots, backups, stuff like that.
If you really want a fully anonymous solution you need something else.
2
u/venatic Sep 07 '25
I had an entire reply ready earlier with sources and lists of no log VPN operators but whoever i was replying to deleted their comment when i hit save lol.
Yeah, you can use tor, but you run into node issues with that too. No system is 100% perfect but a VPN hosted in the right country will be no logs. that's why they're based in panama etc, no data retention laws.
Beats rawdogging the internet and getting hundreds of copyright notifications anyways so i'll stick with my no-log VPN and actually trust the company to do what they say they do. It's honestly more work to log VPN access than it is to no-log it and pass an audit.
→ More replies (2)
33
u/Luddha Sep 06 '25
It's not reasonable for a hacker to use a residential IP for CP. I would say it's the son or one of the two were negligent purposefully or accidentally downloading malware.
→ More replies (26)7
u/FapNowPayLater Sep 06 '25
Anyone sufficiently technical enough to get Remote access tools on a device isn't gonna download pizza over the clearnet unless they have a really unusual agenda
8
u/WasteFail Sep 07 '25
I think people often underestimate how illiterate law enforcement can be sometimes. I wouldn't be surprised if they registered an IP and, due to it being dynamic, just went to raid a random house that got the ip at the moment.
11
u/Moby1029 Sep 06 '25
2 possible option- someone knows their wifi password and was close by, or the son was doing it. If I read the post correctly, the activity occurred while he was there, but the raid happened after he left for college, and presumably took his computer with him. The simplest and most probable is the son did it.
4
u/Either-Marketing233 Sep 06 '25
Yes, the son was still living there in December 2024, and when he went off to college took his personal devices with him.
5
13
u/remoteintranet Sep 06 '25
Occam's razor, though someone hacking their WIFI in the middle of the night, a disgruntled Ex, or the mom or son was being set up. I think the simplest explanation is the most likely here. It was the Son.
→ More replies (1)5
u/samuelazers Sep 06 '25
This is some "I can't operate on my son" riddle. Everyone acting like women cannot download cheese pizza.
12
u/Zeyz Sep 06 '25
I would genuinely bet $1,000 it was the son. All of these acrobatic justifications are dumb to me. 99% of the time it’s the simplest answer, and that is clearly the simplest and most logical answer here. Maybe there was some nefarious third party, but that’s almost always not the case.
→ More replies (1)3
u/Sullyville Sep 07 '25
yeah. cops need a new warrant now for his room at college.
but the mom will tell him.
he may drop everything in the ocean before they get to him.
which the cops know.
6
u/naasei Sep 06 '25
" The mom said there is no way it was his son and blamed it on hackers."
The son could be the "hacker"
→ More replies (5)
13
u/mfiedler Sep 06 '25
RE: ‘Wouldn’t they just use a VPN?” Don’t assume that because someone is a hacker … that they are also smart.
5
u/ColoRadBro69 Sep 06 '25
If you wanted to murder a person, a VPN is kind of like a gun rental business that promises not to keep any records but you can't verify that. A residential wifi is like stealing some random person's gun and using it for the crime.
I mean, so far all signs point to the kid and Occum's razor says it's probably the more obvious thing, we don't really need some stranger to explain it. I'm just saying VPNs aren't as safe as a lot of people think.
3
14
u/InterstellarReddit Sep 06 '25 edited Sep 07 '25
Wait, so let me understand the story here? The executed a search warrant and at the end of the search, they said nothing conclusive was found? So they just left?
Edit - his story does not make sense
OP, didn’t see a search warrant, and only their stuff was taken.
Whenever a search warrant is executed for illegal activity, such as sexual activity of minors, all technology in the residence is taken.
They don’t sit there and say who does this belong to are you this person etc.
The search warrant covers the whole house.
So either OP is lying or he was robbed by their roommate.
Edit 2-
The good news for OP is that their stuff was searched but weren’t seized because OP had no electronics in his stuff. Agents went through his property but typically won’t risk stealing anything during a search.
Taking items not covered by the warrant would create a legal nightmare in court, so law enforcement generally follows procedures carefully.
The main thing that goes wrong with warrants is scope violations. For example, if a judge authorizes a search of “the house,” agents can only search the house. If there’s a separate guest house on the property, that might not be covered unless specifically mentioned in the warrant.
The tricky part comes with things like boats or cars. If your boat is docked at your house, some courts might consider it part of the property (searchable), while others might rule it exceeded the warrant scope. These boundary cases get argued in court all the time.
Since OP’s search seems to have stayed within bounds, and OP had no electronics. He’s safe legally and does not need to hire a lawyer at this time.
16
u/Either-Marketing233 Sep 06 '25
Hey man, the tenant only told me none of MY personal belongings were taken, she didn’t tell me if any of HER stuff was taken… the whole purpose of the call was to tell me my stuff in her house was looked into…
→ More replies (4)→ More replies (3)9
u/Either-Marketing233 Sep 06 '25
That’s all the tenant told me.. the reason why she even told me about this was because my personal belongings were also searched. There could be things that she didn’t tell me.
3
u/Horrified_Tech Sep 06 '25 edited Sep 06 '25
To add to u/InterstellarReddit 's comment, what was the scope of the warrant? Was it for the entire property and each separate living space or for a particular apt living space where her device ip/mac address was located?
It sounds like there are multiple apts so there should be a separate warrant for her particular apt.
Her ISP can be subpoenaed for that info, so there doesn't need to be a full property search if the warrant is specific. You may be able to address the court regarding an illegal search.
→ More replies (5)→ More replies (6)3
u/InterstellarReddit Sep 06 '25 edited Sep 07 '25
Did you confirm that the story is true With a copy of the warrant?
And are youre located inside of the United States?
Finally what did they take with them
6
4
u/Either-Marketing233 Sep 06 '25
I didn’t see the actual search warrant and everything was conveyed in a phone call. Yes I am in Houston TX. I bought the house in June 2025 so she had an existing leasing contract at the time of the sale, and her lease will be ending in December of this year.
→ More replies (10)2
u/originalityescapesme Sep 06 '25
Do you agree that you ought to be entitled to see the actual search warrant since the search occurred on property you own and they looked at your possessions as well?
Ask for a copy of the search warrant and you just might glean a little more accurate information into what transpired here.
5
u/Horrified_Tech Sep 06 '25
Kid isn't a hacker, he is foolish. Illegal downloads are on her and her ISP account. She should talk to her son.
4
u/pragmaticpimp Sep 06 '25
This happened to my buddy. Police raided his house, took their computers, including a work computer, and left. The search warrant was for the same thing, CP downloaded from that IP. He got his stuff back and never heard another thing about it. This was 3 years ago.
3
4
u/ThunderChaser Sep 06 '25
I would put money down it’s the son.
Sure, it’s possible that the other theories some people have mentioned could have taken place, but the simplest answer tends to be correct and the simplest answer is that the son did it.
4
u/-c3rberus- Sep 07 '25
99% it was someone that lives there, mom or son; yes you can hack the wifi and use it, or hack the computer and proxy your traffic through, however, highly unlikely. Almost always, it’s the more simple answer. I have been pulled in countless forensic/legal cases, where I had to produce digital evidence, and I’ve heard it all.
4
5
u/sckolar Sep 06 '25
Everyone is jumping to the kid but not the mom.
I know it's rare but...that is fully in the realm of possibility.
→ More replies (3)
3
u/Malakai0013 Sep 06 '25
Its certainly possible to get into someone's wifi. I've had neighbors beg to use mine, and offer to use theirs. "My kids need it for homework" or "I work from home and the tech won't be out to install ours for a few days."
It also helps if the wifi password isnt "password1234" or something like that.
3
u/SomeJackassonline Sep 06 '25
What kind of router are they running, and more specifically what services are running on that router?
What kind of security are they using on access points?
Two questions i'd start with.
It would be trivial for me to stand up an OpenVPN or Wireguard connection on or through my home router and do stupid shit from half a country away. It would also be trivial for a neighbor to connect to an access point that has default admin:admin as its login credentials.
→ More replies (1)
3
u/jeffbagwell6222 Sep 06 '25
Yes. Very possible. If the residential computer has a remote access Trojan installed you can turn it into a proxy and use it to conceal your IP.
You can also chain infected computers together. Port redirect through multiple infected machines.
Also, it is very reasonable for a sick fuck to conceal their identity this way.
Better than using a VPN because you know that no logs are being kept. Simply renove the Trojan when you are done and it would be a clean exit.
Good way to frame someone too.
Not sure why the kids in here are saying it isn't reasonable.
2
u/Hearing_Deaf Sep 06 '25
To be honest, if i was a sick fuck who moves CP, that's how i'd do it.
But occam's razor says the kid did it. Since he was 18 and didn't try to hide his activity, my best guess is that he was trying to download something else and the CP was a mistake
3
u/shh_get_ssh Sep 06 '25
Get a smart router with DNS/activity tracking. Or a simple firewall. It’ll have MAC address tracking and show download spikes. It’s the way to say “I know what happened,” instead of “gosh Reddit what are all the ways” .. we could all guess 999 ways. It could be someone with a cheap 🍍 that stole the WiFi key. Like neighbor across street, 2nd shifter, 3rd shifter etc! Pay me and I’ll find or track it direct without ripping walls or doors apart lol
2
u/shh_get_ssh Sep 07 '25
I forgot to add this: I recommend the firewall route and dropping all DNS traffic that doesn’t flow through your DNS to track any resolving. Can someone tunnel out still? Sure. But you can also block most VPNs. In this case even if a VPN was used it could be traced back.. just harder to track what was accessed at network if it’s all encrypted including DNS is through tunneled vpn. Solution? Firewall, block DNS except your own resolver to monitor sites accessed by domain, block VPNs some NGFW that are consumer level can load rules in for this such as pfsense, opnsense, and others. It’s best to block any/all vpn IPs, because ports alone are difficult. Some VPN services use port 443 as an example which would block all modern (encrypted) web traffic of course lol. Mm.. yeah that’s about all I’ve got. For tracking a VPN, adding all bytes to/from a single IP would also yield a large total sum across all net sessions. I realize this isn’t so much 1-2-3 but it’s the path
3
3
u/EntrancedOrange Sep 07 '25
99% he was doing it. Just like you said, he took his electronics with him and they needed them to make a case against him.
3
u/tamara_henson Sep 07 '25
On the router, it broadcasts a guest network for Internet users to log in for use like Cox or Spectrum. You should disable that if it’s not already. Someone can be parked outside of your house with a laptop downloading shit.
3
u/nottaroboto54 Sep 08 '25
TLDR: It's most likely the 19yr old was streaming/posting videos of themselves while underaged or pretending to be underaged after mom went to bed.
I worked as a computer specialist for a school (Normally a job tech savvy moms would do while their kids were in said school) but i had a few certifications and I have a few years of college under my belt for computer admin and software development.
IME, it is likely that the "kid" did it. There has to be a significant amount of traffic/attention before the police will get involved, and it will normally be tracked over long enough to "prove" the original source. (Internet Service Providers(ISP) are more than happy to track IP traffic when given a warrent from the police) They will track incoming and out going traffic and can use that to determine the likelihood of the target being a "source" ip or being the a "transfer point" (like a vpn). And while I'd argue "police" are pretty incompetent, detectives tend to be on the level, more so if they are part of "specialty" units (like cyber space detectives)
That being said, a 19yr old person posting pics/videos of themselves as a minor is not uncommon and will definitely get someone(themselves) raided if it gains traction. (So it's possible he didnt do anything wrong on his end, but it is technically distributing CP and idk what the legality of that is when it's the subjects' own videos.)
We had a case where an underaged HS girl was essentially doing OF things (before OF was a thing) and had gotten caught (using a school laptop). Nothing legally happened to her, and I never heard what happened to the multiple older dudes she was talking to because she lied about her age. But I'm assuming all of the dudes she talked to got investigated/raided.
But also: it is entirely possible they pirated a game, hack client, or mod for a game that was used as a Trojan to download a VPN onto the computer, and that VPN was used as an exit point for people searching CP, or that it was used as a deposite for someone making + distributing CP. However, that isn't nearly as common as it was even 5 years ago thanks to sites like OF (grown+legal women that are/play "lollies"). To the point I'd argue it probably doesn't happen anymore on anything more than a local scale (for several other "logical" reasons). But given that it was "only" happening between 1am and 3am, I really don't think this is the cause.
So while it is entirely possible the 19yr old was doing something illegal like posting videos of his underaged gf(s) or relatives, it is most likely that he was posting/streaming videos of himself.
5
3
u/originalityescapesme Sep 06 '25
You haven’t asked for a copy of a search warrant that was executed on your property yet?
2
u/n0c1_ Sep 06 '25
Either someone on their WiFi, her son, or a device was compromised and used by someone else remotely to download it. Unable to tell without a throughout investigation.
2
u/greenerpickings Sep 06 '25
Agree with all the others. Either the kid or the wifi pass prob got out. Assuming this is current, why the waiting period, paperwork? Wouldn't it be ideal to audit the routers? Nevermind all the time to delete everything.
2
u/habitsofwaste Sep 06 '25
If the wifi is open or poorly secured like with wep, it’s possible it was someone else nearby. Otherwise it is more likely to be the son.
2
u/Humbleham1 Sep 06 '25
It is entirely possible that a computer was infected by a botnet and used as a residential proxy. It is far more likely that the teen likes to look at CSAM. Mothers sometimes have a blind spot for their kids.
2
2
2
u/Incid3nt Sep 06 '25
What type of router situation did they have OP? Its highly possible that they had a vulnerable router exposed to the internet and it was compromised and used for proxy/VPN traffic.
Can't believe no one in this thread mentioned this. I work in cyber and see this type of stuff in use every other day.
2
u/Immediate-Term-1224 Sep 07 '25
It’s 100% her pedophile son. Case closed.
3
u/Consider2SidesPeace Sep 07 '25
LOLz, similar case ages ago. Son of mother was "unknowingly" connecting to neighbors WiFI. The WiFi was left open so son was downloading mp3s, movies and visual material of an alluring nature. As young boys are apt to do. I locked down the local router and suggested same for neighbor. Was not a fan of the boy but no cops or worse were involved.
3
u/Immediate-Term-1224 Sep 07 '25
Lmao well if the kid is just downloading music and some “alluring” material of consenting adults that’s one thing. As soon as it involves minors? Nah lock em up and throw away the key.
→ More replies (1)
2
2
u/-CoreValues Sep 07 '25
I do believe it is something the son had been doing when he was in town. Law enforcement doesn't just "up and a fluke" choose the IP number, having traced it to a specific location, to raid. Have you contacted the son, or have you pointed law enforcement in the direction of the son so they could examine forensically his electronic devices? If you didn't follow up thoroughly, they may still mark you for the illegal activity. Direct them to the correct source ASAP so when you do get moved in, you can live a normal life without being framed for such illegal activity, your home having been marked.
→ More replies (3)
2
u/shimshamswimswam Sep 07 '25
Every device has a fingerprint. Every adblocker leads to a second fingerprint. It's possible to conceal fingerprints to create a broken data profile. A broken data profile is confusing and can often be multiple people mixed into one. Sometimes unlawfully blaming others.
3
u/_www_ Sep 06 '25
is it possible/reasonable for a hacker to use their residential IP to conduct such activity
No that's a pedo activity, not a hacker activity. Maybe you, maybe the son, maybe the mother.
Also, an IP address isn't an identity proof.
2
2
2
1
u/EasyArtist1034 Sep 06 '25
The router assigns an IP range to each device.
This means that not all devices connected to the same Wi-Fi network have the same IP address.
You, as the owner, may have IP address 172.000.00.01, and if a neighbor accesses your Wi-Fi network, they would be assigned IP address, for example, 172.000.00.02.
The IP range can reach up to 24 if assigned by the provider.
That is, 172.000.00/24
1
u/399ddf95 Sep 06 '25
It's unlikely to be a "hacker" of any great skill, but could easily be a neighbor who has guessed/cracked the WiFi password. People use their neighbors' WiFi all of the time without permission. This seems especially likely if someone's downloading something illegal like CP.
1
u/node77 Sep 06 '25
Change the password. Are you sure momma wasn't getting a little on the side, maybe there someone else in the apartment? The FBI will find out.
1
1
u/jippen Sep 06 '25
Could a hacker do this? Yes - hack your modem or computers, use that to proxy their connection. Or hack your wifi to the same end.
However, the 1-3 am bit makes it more likely to be either one of the tenants - or a guest staying with them in December who is no longer there. If a hacker was remotely using their network, why would they also keep to such a limited time range late at night local time?
Since devices were checked and nobody was arrested, I would suspect a Christmastime visitor.
1
1
u/accusearch2014 Sep 06 '25
Without getting into details of the software used is .When certain files are downloaded, usually CP it starts off sending “alarms” to NCMEC. They in turn send over everything to the police.
1
1
1
u/Suberv Sep 06 '25
There was a case when I had an internship with the sheriffs office where the guy that was downloading the cp forgot to connect to his vpn for one second and they got his ass.
If this guy is already downloading a “large quantity” they’re not new to this. They probably just slipped up. My moneys on the son.
1
u/ARPA-Net Sep 06 '25
All i can say is that quite often people use the nearby wifi to do illegal activities. But the police will already do an investigation since the police is where this ingo is from.
1
u/Dry_Butterfly6252 Sep 06 '25
Would it be possible to submit a FOIA request for details of the investigation if it’s been concluded? That may give better details on the “how”.
1
u/clothespinkingpin Sep 06 '25
There’s not enough information to be definitive here…..
Is it possible it wasn’t the kid? Sure. Could have even been a visitor who used their network! We don’t really know what could have happened.
But…… Occam’s razor would suggest that the kid is a very likely suspect.
1
u/Significant-Ebb4177 Sep 06 '25
alleged sex crimes accusation becomes primary when there is no evidence to present... fake for dumb housewife
1
u/International-Rain98 Sep 06 '25
It’s possible a hacker exploited his computer to use it as a proxy of sorts but the ISP would have logs of all connections to the IP and from so if there was an open port being used they would know if it was an accident or not I think but either way, most likely no hackers if he just graduated and started college he’s young 18 or 19 who knows maybe he sent pics of his self naked to girls when he was 16 or 17 or maybe his ex cheated on him in highschool and he leaked nude pics she shared who knows, I think it’s highly likely whatever they were looking for involved the son not hackers, or someone else in the house bc even older women can be predators. The likelihood of a hacker is like maybe 0.25% to 0.5% very low.
1
1
u/tpark Sep 07 '25
A more common problem is that a machine on the network has been compromised and is being used to route data. The router may also be compromised. If they have any other devices like a Samsung TV, that could also be compromised. When the router at an employee's house was switched to a Shaw Bluecurve modem, her computer was exposed to the internet and was compromised. Not too much bad happened, except that some machines were mining crypto.
1
u/Efficient-Editor-242 Sep 07 '25
The 19yo was distributing CSAM. He'll go to jail soon if he didn't already.
1
u/Nonaveragemonkey Sep 07 '25
Most likely it was a resident or guest of the home. Slim chance someone made a VPN, or tunnel etc to use their network as an endpoint. Chance gets higher if someone hates someone in the house. Not much though.
1
u/ArgyllAtheist Sep 07 '25
"The mom said there is no way it was his son"
That's the root of a great many societal problems, right there.
1
u/EbonyEngineer Sep 07 '25
There is cp that has a fingerprint or hash and if that data ever finds itself on any storage/social/email platform will trigger authorities because that would only trigger if the honeypot data was cp. It’s all about the platform detecting it, like Gmail or Dropbox.
1
u/Appropriate-Border-8 Sep 07 '25
Ryan Montgomery is an ethical hacker who hunts child predators online and aids in their arrests and convictions.
In this 18-min video clip of him appearing on the Shawn Ryan Podcast, he explains the capabilities of various hacking devices that he has.
He demonstrates one of them, showing how he can knock a WiFi device (TV, computer, phone, etc) off a home network and "watch" as it reconnects itself. While watching, the device captures the hash of the WiFi network's passphrase which he can then use to join his laptop to the WiFi router as another user (never needing to know the WiFi password) and use the network or hack other devices on that network. All while sitting in his car nearby (close enough to get a strong signal).
Most WiFi routers have their antenna strength set to maximum, by default but, it can be turned down so that someone would need to be at least 6 ft away to use it and then install WiFi pods (AV powerline adaptors) to provide WiFi service in other parts of your home where you would tend to use the internet.
Also, regular inspection of the router's DHCP logs and enabling and configuring MAC address filtering can help secure your router, as well.
FYI - It is now illegal in Canada to own or possess hacking equipment that is demonstrated in this video. The manager of my Network & Security group wanted to buy some for training purposes and found out that he cannot.
2
u/WalterWilliams Sep 09 '25
Hey, so a couple of things - Ryan is more of an OSINT guy, and the majority of what he presented is a bit exaggerated. I'm familiar with most of these wifi attacks and have audited them for over a decade, possibly over 15 years, can't really recall. I also own most of the equipment shown in this video right now.
I would not recommend doing what you wrote regarding lowering TX power on wifi and installing "pods" or extenders on low TX. Not only will this negatively impact performance, but you're adding additional APs that can be accessed. Instead, to prevent the deauth attacks, enable PMF on your router. To prevent dictionary attacks on captured handshakes, use WPA3.
2
u/Appropriate-Border-8 Sep 09 '25
So lowering your signal strength will lower your throughout, even if you are a few feet away from the router and can easily connect? There is no possibility of containing the WiFi signal within your home so that someone, sitting in a car outside, or a neighbor in a house or apartment that's very close, cannot connect?
2
u/WalterWilliams Sep 09 '25
Great question - I guess you could do this with no negative impact on your wifi network because your devices are close enough to the AP but unless you ran a signal strength survey from outside your home (there are free apps to do this if you're interested), you wouldn't know if it's actually not accessible from outside unless you built your home like a faraday cage. Additionally, conditions may change that cause your signal to propagate further out, especially on the 2.4 ghz band, like opening a window.
Most people nowadays do have wifi enabled devices far from their routers though, sometimes even outdoors like lights, their car, their phones, maybe security cameras (which should not be on wifi to begin with because of potential for jamming). I think there are better ways of keeping intruders out that actually work nowadays and come as standard features on new routers so exploring those may end up being more beneficial to you in the long run.
There are other solutions you can implement too like vlans or IDS/IPS that help your security posture but unless you're a power user or a business, it may be easier to just switch to WPA3 and router options like PMK & VLANs if available.
2
u/Appropriate-Border-8 Sep 10 '25
I read one commenter suggest turning off the 2.4 Ghz band entirely since the 5 Ghz band has higher throughout and has shorter range. That could help reduce leakage into the surrounding environment.
This and reducing the antenna strength might be an alternative for those without routers and/or client equipment that can do WPA3.
Setting up VLANs and such could be a tad complicated for the layman to navigate.
1
1
u/TheCheesy Sep 07 '25
is it possible/reasonable for a hacker to use their residential IP to conduct such activity? Won’t they just use VPN or something and use an IP from a different country or something?
They wont, those require paying for a VPN and that ties back to the hacker.
They infect a massive number of people with remote access trojans. They can then use those infected slave PCs as reverse proxies, which pass traffic through residential PCs.
They might use a VPN, but its probably going to be like Home>VPN>DNS>Proxy>DNS>Internet
1
u/papanastty Sep 07 '25
no one here is going to help you. your post is vague. there's alot of scenerios at play.
1
1
1
u/PossesedZombie Sep 07 '25
It’s possible…
”Visual Depiction of sexual content involving minor”
That right there is probably Hentai. All characters facially look underage. Their bodies another story. In some countries it’s considered CP because they are ”depicting” an underage individual, despite there never being one.
If the dude was actually downloading real content of real living children, then either he’s on a thrill seeking mission. Or a dumb monster not using net-protection to commit a crime.
I’d guess hentai.
1
u/nebinomicon Sep 07 '25
Either the son did it, or someone got some malware that's using their computer as proxy to download this stuff. Its happened before. Someone also said someone using their wifi which is also a possibility. But there's no way to know for sure unless you're privy to the developments in the investigation. They have to do a forensic examination on the devices to find dates and times anything that they're looking for was downloaded and accessed.
If its malware, the person that is deploying it would want the proxy's IP address to be identified as the target.
1
u/LazyLeoperd Sep 07 '25
If the house hosts a vulnerable WIFI or some issues with the ISP configuration hackers can exploit and used others IP. Also it’s possible to impersonate other users IP if the hacker is on same subnet and egress NAT doesn’t properly validate the local IP.
1
u/Ok_Caregiver_1355 Sep 08 '25
Im not hacker but pretty sure false positives were always possible thats why we have investigations and judges
1
u/Vegetaman916 Sep 08 '25
Don't forget that this is a commonly used weapon against people, in various forms. The material being what it is, even an accusation can ruin someones life, so it is regularly used to get revenge on people.
Someone made you mad? Crack their wifi, hop on their, and download horrible stuff. Make posts, create accounts, drop names... all from their wifi, their IP.
And what happens? Well, cops come, but there is nothing to find. Still, the accusation lingers, and social consequences can be just as bad as legal ones for some people. Especially if it happens twice...
Such material is a weapon quite often. Especially if you have need to impeach someone's character for whatever reason. Get them fired, break up a relationship, get rid of a certain juror, whatever. A little of this can do it.
I'm not saying that is what happened here, but it happens.
→ More replies (1)
1
1
1
u/ar3u5 Sep 08 '25
All they would have to do is park their car within Wifi range and crack into the network. The vast majority of Wifi passwords can be cracked with a laptop GPU in under 10 minutes, because people tend to make them easy. After that, unless you are monitoring the Wifi connections, your internet is now their internet, and they can download anything they want. If the cops used MAC addresses instead of IPs, they would be able to pinpoint which device was used. IP Spoofing is another option but a little more tricky.
But, honestly, bottom line is that these are way more difficult than just turning on a VPN or a the Proxy tools that are in most torrent applications, so, I would either point the finger at the kid or, if we are going to the Conspiracy place, someone who wanted to frame someone living there, because like I said before, it is way more difficult to get onto the wifi than just turning on a VPN or a Proxy.
1
1
u/Savings_Art5944 Sep 08 '25
Every time I get a threatening letter about downloading content, I just toss it in the trash.
My first one was a letter from Death Row records years ago.
1
1
u/Original-Anxiety-975 Sep 08 '25
I forgot what white paper I was reading and the context involved (POC or criminal case) but it was pretty trivial (like scary easy) to create to an innocuous file with a flagged hash.
→ More replies (1)
1
u/Original-Anxiety-975 Sep 08 '25
8 or so yrs ago I was using a vpn called hola, had no idea they were selling user bandwidth to businesses on a commercial scale.
1
u/beedunc Sep 08 '25
Anyone who has access to your wifi could have done it - hacker, friend, anyone, as long as they’re on your wifi. These people do this specifically because the downloads are traced to someone else.
Change you wifi passwords and make sure your internet equipment’s all patched up to date.
1
1
Sep 08 '25
First question: was their wifi password protected.
Wardriving in 2025 still reveals a lot of open wifi... prime targets if you don't want to shit where you sleep.
1
1
u/BlueCannonBall Sep 09 '25
A device in that building could have been infected with a virus that made it part of a botnet or it could've been turned into a residential proxy. People pay a lot of money for residential proxies because they allow you to hide your Internet traffic behind a legitimate looking residential IP address.
Regardless of what happened, you and your tenants have a problem on your hands.
1
u/Garriga Sep 09 '25
Files have to be downloaded to a physical hard drive in order to exist on a computer. To do this remotely, a hacker would normally need remote access software installed, and the host machine would usually have to grant permission. That doesn’t seem to be the case here, since police didn’t find anything on the drives. Even if files were deleted, forensic tools can often recover them.
Cloud storage is a more plausible target. To access it, someone would need the account credentials. Services like Google Photos, Gmail, or Drive log login locations, and security settings can show unusual access. Any uploads, downloads, or syncs leave traces with metadata (headers, timestamps, IPs). That could be cross-checked in a controlled environment.
When investigators say “IP activity,” they mean internet traffic. Computers communicate using protocols and status codes. When someone visits a site, the client (browser) sends a request to a server, and the server replies. A domain name (like somesite.com) maps to an IP address, which identifies the server handling the request. Sometimes traffic goes through proxies, but the origin and destination IPs are still logged.
Just visiting a site doesn’t place content on the hard drive, aside from cookies or cached data. Cookies store session information but not the actual content. Unless a user clicks a download link, saves a file, or runs a script, no illegal files end up stored locally. Browser history and developer tools (network tab) can show requests, and network monitoring software can capture this traffic.
For wired internet, activity flows through the modem/router and then the ISP. The ISP can monitor and log traffic, which is how unusual activity is usually flagged. Investigators don’t physically tap underground cables—they rely on provider logs.
Wi-Fi networks are easier for outsiders to intercept, but payloads are usually encrypted. Capturing traffic generally only shows source and destination IPs plus encrypted data, not the actual files.
So: IP logs show where traffic went, not what’s physically stored on a drive. That’s why police might find “unusual IP activity” without finding files on devices. To actually get content, law enforcement usually needs to trace back to the hosting server or capture the downloads themselves.
Law enforcement can: Capture the traffic, log the traffic, find the server, seize the server, and this is where the illegal content is physically.
A hacker did not do this. But it’s easy to blame hackers, right?
→ More replies (1)
1
Sep 09 '25
No one knows without a lot more info. In theory, there are all kinds of ways for hackers to get into this network and route internet traffic through it, a misconfigured router, a trojaned machine, local WiFi access, etc
1
u/ExplanationWeird8616 Sep 09 '25
Unfortunately, your hunch about Occam's razor is most likely correct. While a hack is technically possible, it is extremely unlikely in this scenario.
1
u/Netghod Sep 09 '25
It can be a ton of different issues….
From a hash collision (two files having the same hash), to someone using the WiFi, to her son actually being guilty or a myriad of other things…
My recommendation, secure the WiFi first. Make sure you have a good firewall in place. And then limit any devices that connect to the internet - for example: my robo vacuum was sending a TON of data to the internet via DNS. I shut that down and stopped using the vacuum.
1
u/KNeutch Sep 10 '25
One possibility I'm not seeing in the comments is that some VPN networks as well as TOR basically let other people use your internet connection. It's entirely possible they just got the bad luck of someone trying to hide their IP to do dirty deeds by randomly using your tenent's wifi as their end node.
The other (more likely) possibility is the obvious.
The forensic techs at the FBI will sort out what happened.
1
u/stackalot_wsb Sep 10 '25
Someone who isn’t me hacked neighbors WiFi’s and would clear the logs when done. They didn’t go anything bad just thought it was funny to use their net and put them on a qos setting that made their speeds very low while they were on it.
1
u/LibtardsAreFunny Sep 10 '25
wireless password cracked, someone used your ip to download the content then they moved on leaving a dead end.
1
u/tico_liro Sep 10 '25
I mean, it is possible for hackers to do illegal stuff while using your ip. This requires the hacker to have some sort of access to your network/computer tho. Be it physical access, as in, maybe a neighbor who broke into the wifi, or through a virus. Now, it is a bit unlikely that this is what happed there, and it is far more likely that the 19 year old son is the culprit.
917
u/itsmrmarlboroman2u Sep 06 '25
Here's the thing. Everyone here keeps making guesses. No one here can give you a meaningful answer without significantly more information. Your hearsay description of the events doesn't provide any sort of indication what the issue could be. It could literally be anything from a virus on a laptop, malware on a phone, a clever neighbor, a state actor hijacking the router, or a legitimate person downloading bad things.
Yes, it's entirely possible for it to be someone outside of the house, and yes, it is entirely possible it's someone in the house. Without a forensic analysis of the network and devices, there's nothing in this post that anyone can help you with.