This presentation will identify a number of UK based Local Internet Registries (LIRs) that have been fraudulently created in order to obtain IP resources from RIPE. In some cases, persons behind those LIRs have committed corporate identity theft. Those resources (controlled by individuals outside the UK) were then utilised to launch cyber attacks. The presentation will focus on the value of Open Source Intelligence in identifying involved individuals; also, how BGP tables and the RIPE Database can be used in such forensic work.