Call us — 01483 901310
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →
← All case files // case file · Forensic investigation

Did a leaving employee walk off with the data?

A resignation to a rival, a handed-back laptop, one question to answer: had company data gone with them? A forensically sound investigation in OSForensics.

DeviceWindows 10 laptop
FaultSuspected data exfiltration
Turnaround5 days
OutcomeEvidence secured
ToolsOSForensics · PC3000

The brief

When a salesperson quit a Guildford company to join a direct rival, the firm suspected the worst: that the client database and current price lists had been copied before the laptop came back. They couldn’t prove it, and they needed to — to a standard their solicitors could rely on. The question was narrow and specific: had data left the business, and by what means? Answering it, and evidencing the answer, was what they instructed us to do.

Securing the evidence

The soundness of the whole exercise depended on how the evidence was handled, so the laptop was never examined directly. Our first act was to make a forensic duplicate of the returned Windows 10 machine: a write-blocked, hash-checked .E01 acquisition — the PC3000 doing the job on any disk that isn’t fully stable. That done, the hardware was sealed in a bag and stored, and from there we only ever looked at a read-only mount of the duplicate. OSForensics ran the analysis with its audit log on, making every step we took reproducible and tamper-evident.

Following the trail

Everything hinged on the file-activity record, and it was unambiguous: on one evening — forty-eight hours before the resignation — the client database and a batch of price-list spreadsheets had been written out in quick succession. What device received them showed up when we lined that evening against the machine’s USB history, which OSForensics rebuilds from Windows event logs alongside the USBSTOR entries in the registry: a SanDisk stick, logged by serial number, connected just after the files were exported and unplugged a short time later. Email and web traffic filled in the motive and the second channel — the user’s OST mail store, once indexed, held two messages to a private address with a price list attached, and the browsing record from the same minutes captured a webmail login and a file sent up to personal cloud storage. A number of the exports had been deleted afterwards; those we recovered by carving them from the image.

The report

OSForensics produced the deliverable itself: a hash-verified report that drew every thread into one place — the exported files and when they were written, the SanDisk device and its timestamps, the two emails, the cloud upload, and the deletions we’d recovered — each anchored to the audit trail. That report went to the firm’s legal team to act on as they saw fit. Start to finish, five working days. Workplace investigations we undertake only for the owner of the equipment, and only on written instruction.

Tools used on this job

OSForensics · PC3000 — a write-blocked, hash-verified image examined read-only; USB history, file timeline, mailbox and recovered deletions drawn into an audit-trailed report. For the equipment’s owner only, on written instruction.

// sending your device in

Two simple steps.

Send us your device for a free diagnostic, and tell us a little about what happened — an engineer will review it and confirm your exact quote in writing before any work begins.

1

Send us your device

Getting your data back begins with getting the device to us. Pack it up safely, pop your contact details inside, and send it over — once we’ve run the free diagnostic, we’ll confirm your exact price in writing before any work starts.

How to pack it
  • Box the device up in a small, sturdy carton or a padded envelope.
  • You can leave out caddies, cables and power supplies — none of them are needed for the recovery.
  • Pop your details inside — name, address, phone and email, on a slip of paper or via our shipping form — and seal it up.
Post toGuildford Data Recovery
Building 2, Ground Floor, Guildford Business Park
Guildford GU2 8XH
Shipping formPDF · print & include with your devicePDF ↓

Posting it? A tracked, insured service is what we’d recommend. Rather drop it in? You’re welcome Monday to Friday, 9am to 5:30pm — just package the device up as above first.

2

Need more information?

Want a bit more detail first? Fill in the form with more about your issue and an engineer will review it and send you a custom quote.

An engineer reviews every enquiry personally — we usually reply within 30 minutes during the day. Prefer to call? 01483 901310.

Thanks — your message is in.

We’ll be in touch shortly. For anything urgent, call 01483 901310.

Common questions

Can you establish whether an employee took or deleted company data?

Yes. USB-device history, timelines of file activity, mailbox examination and recovery of deleted files together show what happened — all preserved to a standard that stands as evidence.

Would your forensic report stand up?

It’s built from a write-blocked, hash-verified image with a complete audit trail, and written to suit solicitors or a tribunal.

What does a forensic investigation cost?

From £800 plus VAT. These workplace investigations we take on for the equipment’s owner alone, on written instruction.

Related

// ready when you are

Facing something similar? Let's help.

Start with an instant online quote, or call and talk it through with us first. You'll have a clear, fixed price before any work begins.

Building 2, Ground Floor, Guildford GU2 8XH · Mon–Fri 9am–5:30pm · No fix, no fee on most jobs