Screenshots as Criminal Evidence: Italian Supreme Court Ruling and Forensic Acquisition

Most stalking and cyberharassment cases today live on screens. WhatsApp messages, social media posts, emails, video calls: the victim's story is told through digital artefacts, and the evidentiary weight of those artefacts depends on how they are captured. Screenshots feel like the natural solution: press a key, save the image, move on. From that moment, however, the evidentiary ground becomes unstable.

In February 2026 the Italian Supreme Court (Corte di Cassazione, Criminal Section V) filed ruling 6024/2026, dismissing the appeal of a man convicted of stalking his former wife. The defence argued that the WhatsApp screenshots produced by the complainant were selectively chosen material and that a technical examination of the phone was needed to establish who wrote the messages. The Court held that a screenshot is a document under art. 234 of the Italian Code of Criminal Procedure and that, when the complainant hands it over, neither a seizure of correspondence nor the acquisition of the whole device is required, as long as nothing casts doubt on her credibility.

The short answer is this: in Italian stalking proceedings a screenshot handed over by the complainant is usable as documentary evidence, and its weight depends on the credibility of the person who produces it. When that credibility can be challenged, or when the chat carries the prosecution on its own, an acquisition that documents the integrity, origin and date of the capture leaves less room for objections. This article explains what ruling 6024/2026 decided, where the room for challenges remains, which technical requirements make a screenshot more defensible under international standards, and how TrueScreen captures screenshots at the source.

Italian Supreme Court Ruling 6024/2026: what it says about screenshots in stalking cases

The ruling addresses the use of screenshots in criminal proceedings for persecutory acts. The Court classified a screenshot of a WhatsApp conversation as a document under art. 234 of the Code of Criminal Procedure, a reproduction of facts and things, and ruled out the seizure provided for by art. 254 when one of the participants in the conversation provides it. Assessing the evidence remains the judge's task: the Court found the screenshots sufficient because nothing called the complainant's credibility into question. A summary of the ruling in Italian is available from Studio Legale Grici Testa and Studio Cataldi.

Facts and decision

The case concerned a man convicted of stalking his former wife. The complainant had produced a DVD containing screenshots of WhatsApp written and voice messages. The defence argued that the material had been deliberately selected and was therefore potentially misleading, and that a technical examination of the original device was needed to establish who wrote the messages. The Court dismissed the appeal: a screenshot is a document under art. 234 of the Code of Criminal Procedure, and acquiring part of the messages handed over by the complainant does not require a seizure of correspondence, as long as nothing casts doubt on her credibility.

System screenshot vs forensic acquisition

For anyone who has to produce a chat, the practical difference lies between two ways of acquiring it. A system screenshot, produced by the device's print-screen function or native shortcut, is a photograph of the display with no subsequent integrity constraints: it can be modified, renamed and re-saved without leaving univocal technical traces. A forensic acquisition, by contrast, is a structured process where the screen is captured with a sealed technical chain that binds the image to a qualified timestamp, a cryptographic hash and a signed certification record. Ruling 6024/2026 does not draw this distinction: practice does, because only in the second case can the integrity and date of the capture be demonstrated without the phone.

Why a traditional screenshot is contested in court

The direct answer is that a traditional screenshot does not carry the technical elements criminal proceedings require to exclude manipulation. There is no seal linking the image to its capture date, no cryptographic fingerprint certifying immutability, no independent record attesting from which device, when and by whom it was produced. Without those elements, any defence challenge is legitimate and, in most cases, decisive. These weaknesses have been documented in international forensic literature, including NIST Special Publication 800-86 on integrating forensic techniques into incident response.

Missing metadata: hash, timestamp, device

When a screenshot is saved to the device gallery, it retains only the metadata that the operating system decides to preserve. No SHA-256 hash is computed at capture, because the print-screen function has no cryptographic role. The timestamp is the one written by the file system, easily rewritten when the image is transferred from one device to another. The device identifier is not signed by any independent authority. In a criminal proceeding those absences do not prevent the screenshot from being used, but they become openings for the defence when it challenges its reliability, and the SWGDE Best Practices for Digital Evidence ask for evidence that allows verification of origin and integrity.

Federal Rule of Evidence 901 and international standards

Under Federal Rule of Evidence 901, the proponent of digital evidence must produce sufficient evidence to support a finding that the item is what the proponent claims it is. In Italian proceedings, the analogous requirement is articulated around reproducibility and the absence of reasoned disconnection. Both frameworks converge on the same practical point: the party introducing the screenshot must be able to show how the capture happened. Without a sealed forensic acquisition upstream, that burden is difficult to discharge, as explored in our guide to authenticating digital evidence under FRE 901.

Why screenshots get challenged

In practice, defence counsel often challenge screenshots on technical grounds: selected messages, inconsistent dates, the absence of the device. When the challenge is specific, the court can order a technical examination, which lengthens the proceedings. The issue is not judicial scepticism towards the victim: without tools that document the integrity and date of the capture, the discussion shifts to the credibility of whoever produced the image.

Admissibility requirements: ISO 27037, eIDAS, chain of custody

Ruling 6024/2026 does not set technical requirements for screenshots. When the reliability of a chat is challenged, however, forensic practice relies on well-known frameworks. The reference technical norm is ISO/IEC 27037, which governs the identification, collection, acquisition and preservation of digital evidence. The EU eIDAS Regulation regulates qualified timestamps and qualified electronic seals, which confer a presumption of authenticity on signatures and attestations. The chain of custody traces every step of the evidence from capture to courtroom.

Requirement Reference standard Evidentiary function
Qualified timestamp eIDAS, Art. 42 Opposable temporal placement
SHA-256 cryptographic hash ISO/IEC 27037 Immutability and integrity
QTSP digital signature eIDAS QTSP framework Authorship and non-repudiation
Acquisition record ISO/IEC 27037 Reconstructible chain
Identified and attested device ISO/IEC 27037 Technical provenance

Qualified timestamp under eIDAS

A qualified timestamp is an electronic attestation issued by a Qualified Trust Service Provider that binds a sequence of data to a precise moment in time. Unlike the date recorded by the operating system, a qualified timestamp under eIDAS benefits from a presumption of the accuracy of the date and time and of the integrity of the data (Article 41, Regulation EU No 910/2014). For a stalking screenshot, it means being able to demonstrate in court that the image existed in that exact form on a specific date and time, and that no later modification is possible without invalidating the timestamp.

SHA-256 hash and integrity

SHA-256 is a cryptographic function that generates a 256-bit string uniquely associated with binary data. Changing a single pixel produces a completely different hash. In the forensic process, the hash is computed at the moment of acquisition and recorded in the acquisition document: in court, anyone can recompute the hash of the produced file and verify that it matches the original. This excludes subsequent manipulation with mathematical certainty and keeps the screenshot technically defensible even years after capture. The same mechanism underpins the digital chain of custody across forensic toolchains.

Certified acquisition record

The acquisition record describes step by step how the screenshot was captured, on which device, with which tool, at what time, over which network, resulting in which hash. When the record is digitally signed by an accredited Qualified Trust Service Provider, it becomes a document with a presumption of authenticity equivalent, in evidentiary terms, to a notarised attestation in digital form. For the criminal judge, this is not a photo of a screen: it is a structured technical act, with a weight that a raw screenshot cannot match.

TrueScreen: screenshots captured at source for criminal proceedings

What is a source-captured screenshot and how does it work

A source-captured screenshot is an acquisition in which the forensic chain closes at the very moment of capture, before the image leaves the controlled environment. TrueScreen acquires the device screen while simultaneously applying a qualified eIDAS timestamp, computing the SHA-256 hash and digitally signing the certification record. The user does not need to perform any technical step: starts the acquisition, TrueScreen records the screen as required, and at the end produces a package with the sealed evidence and a signed certification record. The difference compared to a system screenshot is structural: it is not an image to which a timestamp is added later; it is an image born inside the forensic methodology, with integrity guaranteed from the origin. We analyse the full workflow in our guide to screenshot admissibility in court.

Features: app, web portal, chain of custody

Acquisition happens through the mobile app, which captures the phone screen directly, and through the web portal, which acquires web pages, desktop chats and browser-based workflows. Each piece of evidence is stored in a certified data room with a tracked chain of custody: every access, download and share is logged and digitally signed. The certification record, signed as QTSP, is generated automatically and contains all the elements required by ISO/IEC 27037: device identification, acquisition tool, hash, qualified timestamp and contextual metadata.

Use cases: stalking, cyberharassment, workplace harassment

In stalking proceedings, the captured screenshot preserves WhatsApp, Telegram and Instagram DM conversations, along with account and thread identifiers. In cyberharassment cases, the app is used directly by the victim or by a parent to capture social posts and feed interactions before they are removed. In workplace harassment cases, the acquisition covers corporate emails, Teams and Slack exchanges and shared documents, always with a reconstructible chain of custody. In every scenario, the complainant reaches the hearing with evidence that does not require a court-appointed expert to be discussed on the merits.

What changes for criminal defence lawyers and complainants

After ruling 6024/2026, a lawyer assisting a complainant in Italian stalking proceedings knows that screenshots handed over by the victim can enter the trial without a seizure. The risk moves to credibility: if the defence brings specific elements to question it, such as missing messages or inconsistent dates, it can ask for a technical examination. For this reason, when messages are criminally relevant, it is worth acquiring them with a forensic methodology from the start: it narrows the room for challenges and avoids later expert reports, which take time and cost money. This logic mirrors international guidance on the admissibility of digital evidence.

FAQ: screenshots and criminal evidence in stalking cases

Can a print-screen screenshot be used as evidence in court?
Yes, as a document under art. 234 of the Italian Code of Criminal Procedure: under ruling 6024/2026 a screenshot handed over by the complainant is admitted without a seizure. If the defence challenges its reliability with specific elements, the court has to assess how it was acquired: without a qualified timestamp, a cryptographic hash and a chain of custody, a forensic expert may be needed, which is costly and not always conclusive.
How do you prove a screenshot has not been altered?
With three combined elements: a SHA-256 cryptographic hash computed at acquisition and recorded in the acquisition document, a qualified eIDAS timestamp binding the image to a precise, immutable moment, and the qualified electronic seal of a third-party trust service provider on the record. Changing a single pixel produces a different hash, and a qualified timestamp prevents backdating. Ruling 6024/2026 does not require these elements, but they are what a technical expert checks when the authenticity of a screenshot is challenged.
Is the 6024/2026 ruling binding across all Italian courts?
In the Italian legal system, Supreme Court rulings are not binding precedents in the common-law sense, but they carry authoritative persuasive weight. In practice, after a ruling by Criminal Section V, lower courts tend to align their approach: screenshots handed over by the complainant are admitted without a seizure, unless specific elements cast doubt on her credibility.
How long does a forensic screenshot acquisition take?
Acquisition through a certified application takes the capture time itself plus a few seconds for the record signing. For a chat thread or a post, that means between 30 seconds and a few minutes, depending on the length of the sequence. By contrast, a court-appointed forensic report can take weeks or months: capturing at source moves the technical effort to the cheapest moment in the workflow.
What is the difference between a TrueScreen screenshot and a timestamp applied to an existing file?
A timestamp applied later to an existing file certifies that the file existed in that form on a specific date: it says nothing about how the file was generated or whether manipulation occurred before the timestamp. A TrueScreen screenshot is born inside the forensic methodology: timestamp, hash and acquisition record are all applied at the moment of capture, within a controlled environment. In a criminal proceeding, the second configuration is structurally more defensible.

Seal screenshots at source, ready for court

With TrueScreen you capture chats, posts and web pages with a forensic methodology: qualified eIDAS timestamp, SHA-256 hash and QTSP-signed acquisition record, defensible in criminal proceedings.

mockup app
TS

TrueScreen editorial team

Published on · Updated on

This section is edited by the TrueScreen editorial team, which brings together expertise in digital forensics, the law of digital evidence and regulatory compliance. Every article is checked against primary sources: legislation, published rulings, technical standards and official documentation, always cited in the text.