Why My Cousin’s Recommendation Ruined My Career – Part 3

Story code: ST-001365

Part 3: The IP Trace

The logs from the security desk and internal network query records at Apex Consulting outline the events of October 14, between 2:00 PM and 3:45 PM. At 2:15 PM, Sarah Miller returned to the lobby, carrying her yellow legal pad and a silver USB drive containing encrypted PDF files. She sat on the leather bench, her posture rigid, her eyes fixed on the elevator doors. According to the guest network access log, Sarah requested connection credentials for the Apex Secure Transfer portal.

At 2:30 PM, Marcus Vance requested Sarah’s presence in Conference Room B once more. The room’s video feed shows Marcus sitting behind his laptop, surrounded by printed network packets. A flat-panel screen on the wall displayed a live video link to Todd Vance, who was seated in a cluttered home office, his camera capturing stacks of server towers and dual monitors flashing green status lights.

Marcus Vance began the session by introducing the IP Forensic Report, marked as Exhibit C. He read the primary finding in his flat, unhurried cadence: the reference email sent from the domain vance-node-betting.com at 11:14 PM on Tuesday had originated from a residential IP address in Arlington, Virginia. The ISP billing records for that IP address belonged exclusively to Todd Vance.

The video monitor recorded Todd’s immediate reaction. He tapped his foot rapidly against his desk leg, the sound picked up by his desk microphone. He leaned close to his camera, his eyes darting to a secondary screen off-camera. He spoke in a rapid, defensive tone, claiming that the IP address was a public node he had configured for Sarah’s remote use. He asserted that Sarah had VPN credentials to his home network and must have initiated the transmission herself to hide her location.

Marcus Vance turned his attention to the USB drive Sarah had placed on the conference table. The investigator logs show that at 2:50 PM, the compliance team uploaded Sarah’s submitted documents into the tracking system. These documents included verified Delta Air Lines boarding passes, a hotel receipt from the Chicago O’Hare Marriott, and cellular tower connection logs from her carrier. The logs placed Sarah’s mobile device and physical location in Chicago, Illinois, at the exact minute the email was routed from Todd’s Arlington residence. Furthermore, the hotel’s network logs showed Sarah was logged into their guest Wi-Fi, which did not resolve to any VPN signatures matching Todd’s residential server.

Todd Vance shifted in his chair, his hands disappearing below the camera frame. The audio log recorded him stating that the Chicago travel records could have been simulated or that she had scheduled the email delivery through a local cron job on his server. He insisted that he was merely an innocent host and that Sarah was the one running administrative commands on the vance-node-betting.com domain to bypass corporate screening.

Marcus Vance cleared his throat and adjusted his glasses. He pulled up the server administration log from the hosting provider, which the compliance division had subpoenaed twenty minutes prior under the firm’s emergency vendor-vetting clause. He pointed to the master login records. The logs showed that the administrator account, registered under Todd’s personal email, had accessed the routing table five minutes after Sarah’s morning interview had ended. The command line history indicated an attempt to scrub the outgoing email logs associated with Sarah’s name. The pressure of the digital footprint had forced the conflict to a critical bottleneck, leaving no room for Todd’s defensive deflections.


Leave a Comment