Home / Forensic Recovery / Employee Data Theft

Employee Data Theft Evidence

The notice period ends, the laptop comes back factory-fresh, and a month later your quotes start losing to a familiar name. For employers around Swindon — from the units at Kembrey Park and Cheney Manor to professional practices in Old Town — we retrieve the evidence a reset machine still holds. Freephone advice and a free diagnostic come first.

Quiet, methodical, defensible. Nothing starts until the free diagnostic is finished and you have approved a written scope; forensic fees are then settled upfront.

// recognise any of this

The tells employers usually spot too late

Any one of these is a reason to lock the machine away, unused, until it has been imaged — whether your firm sits in Swindon, Chippenham or Royal Wootton Bassett.

A returned laptop restored to factory settings without anyone asking
A stick or portable drive seen plugged in during the final fortnight
Attachments drifting out to a personal address over the last month
A sync client - Dropbox, OneDrive, Google Drive - installed without IT's blessing
Server folders opened in bulk the weekend before the resignation landed
Long-standing customers now fielding calls from the leaver's new firm

The wipe is a confession, not a clean-up

A laptop that comes back reset tells you something before any examination starts: ordinary leavers do not scrub their machines. The reset clears the desktop and the visible folders, but it seldom reaches the deeper record — registry hives that survive, the footprint of the erasing tool and the minute it ran, and unallocated space still holding a good proportion of the deleted documents, waiting to be carved back out. Around Swindon we see the same rhythm again and again: a fortnight of quiet copying, then one loud deletion on the final day.

Serial numbers, shortcuts and the journal

Windows is an obsessive record-keeper. Each stick or portable drive ever attached is logged by make, model and serial number in the USBSTOR registry key; the setupapi log notes when it first appeared; MountPoints2 ties it to the user profile that mounted it. LNK shortcuts and jump lists then show named company documents being opened from a removable drive letter, shellbags keep the shape of the folders explored on the device, and Windows' change journal timestamps file operations minute by minute. Laid out in order, those artefacts read less like a suspicion and more like an itinerary.

The routes that never touch a USB port

Plenty of exfiltration happens in a browser tab instead. We reconstruct webmail sessions where attachments went to a private address, uploads pushed through transfer services, and folders synchronised into a personal OneDrive, Dropbox or Google Drive. Sync-client logs record what went up and when; deleted emails come back out of unallocated space. The finished timeline covers every exit the data could have taken, not just the one somebody happened to notice.

Prepared for a tribunal from the first hour

Everything is done on the assumption that the other side's expert will check it. The drive is imaged through a hardware write-blocker and the copy proven identical by MD5 and SHA-256 checksums; each handover of the exhibit is entered in the custody record. OSForensics carries the analysis, Passware Kit Forensic opens password-protected material where the law allows, and the report puts plain-English findings first with the technical workings in an appendix behind them. Directions agreed with your solicitor are followed to the letter.

The discipline underneath this page — write-blocked imaging, hash verification, logged custody — is walked through on our forensic data recovery hub. Fees on forensic cases are settled upfront: the standard investigation runs to £800 + VAT with its full written report, while the forensic binary-image and deleted-file option at £400 + VAT skips the report; the data recovery cost page lists the pair. Should the laptop come back encrypted, BitLocker recovery opens it first with the key your business holds.

// what the image yields

What a leaver's laptop can be made to say

Imaged properly, one company machine usually gives up all six of these threads at once.

Device register

Make, model and serial of every stick attached, with first and last dates.

Opened-from-stick traces

LNK and jump-list entries pinning documents to a removable letter.

Browsed folders

Shellbag records of the directories explored on the device.

Minute-by-minute journal

USN change-journal activity across the weeks that matter.

Webmail & sync history

Private-address sends, transfer uploads and cloud-client logs.

Carved deletions

Recovered documents plus the wiping tool's own footprint.

The boundary, and the first move to make

Equipment the company owns and issued is legitimate ground; a personal device needs a proper footing such as a signed acceptable-use policy or a solicitor's instruction; covert access to an ex-employee's own phone or home computer is work we refuse, every time. While you decide next steps, treat the laptop as an exhibit rather than a spare: power it down, lock it away, and tell IT it must not be rebuilt or handed to the next starter — a reinstall grinds away precisely the traces the case needs.

// getting your device to us

Post or courier your device — it's simple

An exhibit is not an ordinary parcel, so ring 0800 689 0668 before boxing anything up. We will agree the packaging and paperwork with you, and custody is recorded from the second the device is signed for at our Oxford location — under an hour up the A420, or next-day by tracked post.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Oxford Data Recovery

John Eccles House, Oxford Science Park
Robert Robinson Avenue, Littlemore
Oxford, OX4 4GP

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Oxford Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// employee data theft — asked and answered

Common questions

Usually not. A reset leaves its own dated footprint, the USB register and much of the journal survive, and a large share of deleted documents can still be carved from unallocated space. What destroys cases is reuse afterwards — keep the laptop powered off and away from IT's rebuild pile.
Often, yes. The stick's serial number sits in the Windows registry, and shortcut files, jump lists, shellbags and the USN journal can place specific documents on that lettered device at specific times — an itemised account rather than a hunch.
Normally, yes: kit the business owns and issued is examinable, and a signed acceptable-use or IT policy settles any doubt. We confirm the footing before starting and will work to your solicitor's instruction — covert access to someone's private device is the one thing we never touch.
They are built for it: write-blocked imaging proven by MD5 and SHA-256, a custody log covering every handover, an openly stated method, and a report a panel can follow without a translator. Where the parties' solicitors agree directions, we follow them exactly.
// the wider casebook

The other case files

Laptop back, data gone?

Lock the machine away and pick up the phone — imaging early is what keeps the evidence intact.