> Very few get caught that way.
Maybe, I haven't seen any numbers. (I've seen several cases from email is or cloud providers IDing specific content and tipping off law enforcement, but not aggregate stats.)
> Most of the major cases involve seizures of offline hardrives.
Are most cases major cases? Are even most of the individuals caught caught in major cases (I doubt it; the number of publicized major caelses and the number claimed caught in each, and the total number of cases don't seem to line up with that.)
And even for the major cases, how do they get the initial leads that they work back to?