September 20, 2026
Have a break (THM) Tryhackme Walkthrough
Description : Can you help us uncover the mystery behind the KitKat heist?

By Lawvye
3 min read
Difficulty : Medium
Note : All of the content and images are from https://tryhackme.com/
Room : https://tryhackme.com/room/haveabreak
Enjoy.
Walkthrough :
📧 Phase 1: Tracing the Whistleblower's Infrastructure
Question 1: Which VPN service was used to send the anonymous email from the .eml file?
- Steps: Open the provided
.emlemail file in the case directory. Analyze the email headers from bottom to top to identify the first origin IP hop. - Result: Performing an IP lookup on the sender's IP reveals that the IP block belongs to Mullvad VPN.
🗺️ Phase 2: Geolocation and Imagery Analysis
Question 2: What is the full street address of the petrol station where the missing vehicle was last seen?
- Steps: Analyze the attached image showing an Orlen branded petrol station. According to the internal memo found in the
transeuro-datafolder (Brno Logistics data), a dashcam SD card was recovered near the town of Hulín. Search for Orlen petrol stations near this area using Google Maps. - Result: The full address is Kroměřížská 1281, 768 24 Hulín, Czechia.
📊 Phase 3: Log Analysis and Identifying the Insider
Questions 3 & 5: Time of suspicious activity and the Employee ID of the insider leaking data
- Steps: Analyze the
Access.logsfile to search for unauthorized PDF exports of delivery route plans. Identify the exact timestamp and the employee ID that executed the command. - Result: The suspicious activity occurred at 22:14:09 and the insider threat's employee ID is BR0291.
Question 4: What is the employee ID of the person who sent the anonymous email?
- Steps: Check the logs for other active employee sessions around the same time (22:14:09) to uncover the whistleblower.
- Result: The whistleblower's employee ID is BR0312.
👤 Phase 4: Deanonymizing the Threat Actor
Question 6: What is the full name of the culprit?
- Steps: Analyze the activity history of user
BR0291where they failed a login attempt using a personal email address. Correlate this data with OSINT tracking of Google Maps reviews left at the Hulín Orlen petrol station. - Result: The full name of the culprit is Radovan Blšťák.
Task 1 Investigation
Disclaimer: This challenge is inspired by a real cargo theft that occurred in March 2026, in which a shipment of KitKat products was stolen in transit between Italy and Poland. All companies, agencies, individuals, documents, and investigative findings presented in this challenge are entirely fictional. No real employees, law enforcement personnel, or organisations are implicated. The real theft remains under investigation by the relevant authorities.
Background
On 26 March 2026, a refrigerated truck carrying over 400,000 units of KitKat product vanished somewhere between Central Italy and Poland. Nestlé confirmed the theft two days later. The vehicle has not been found.
The European Cargo Threat Assessment (ECTA) does not believe this was opportunistic. A shipment of this size, on a contracted route, does not disappear without someone helping it along.
An anonymous tip reached a journalist the following evening. ECTA obtained it under judicial authority. That is where your investigation begins.
Your Assignment
You are a CZ Node investigator on Project HAVEABREAK. Your goal is to identify the culprit behind the heist by using the following files:
FileDescriptionecta_memo.pdfYour briefing. Start here.exhibit_a.emlExhibit A — referenced in the memoexhibit_b.jpgExhibit B — referenced in the memotranseuro_data/employees.csvSubpoenaed from TransEuro Logistics ITtranseuro_data/access_log.csvSubpoenaed from TransEuro Logistics ITtranseuro_data/comms_export.txtSubpoenaed from TransEuro Logistics IT
You can download the files by clicking on the button below:
Download Task Files
Answer the questions below
Q1.) Which VPN service was used to send the anonymous email from the .eml file?
Answer : Mullvad
Q2.) What is the full street address of the petrol station where the missing vehicle was last seen?
Hint : Address as seen on Google Maps
Answer : Kroměřížská 1281, 768 24 Hulín, Czechia
Q3.) At what time did the suspicious action take place in the route planning system on March 25th, 2026? Format: HH:MM:SS
Answer : 22:14:09
Q4.) What is the employee ID of the person who sent the anonymous email?
Answer : BR-0312
Q5.) What is the employee ID of the employee responsible for leaking the shipment details?
Answer : BR-0291
Q6.) What is the leaker's full name?
Answer : Radovan Blšťák
I hope you enjoyed reading this post as much as I enjoyed writing it. Thanks for reading my blog sir ;) Lawvye