Employee Data Theft Investigations

An employee leaves a Clifton Moor distributor or a Monks Cross head office, the laptop comes back, and within a month a familiar customer list is being worked by somebody else. The machine can usually settle what happened — provided it is preserved before anyone signs in. We examine it methodically and report what the record supports, no more and no less.

Method before speed. The free assessment and a written scope come first; forensic fees are settled in full before any examination starts. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// grounds to preserve the machine now

Six observations that justify an examination

One of these alone is reason to take the device out of circulation, unused, until it has been imaged — whether the business sits in York, Malton or along the A64.

The laptop was handed back freshly reset, though nobody asked for that
A memory stick or portable drive appeared during the final weeks of notice
Work documents went to a personal email address, a few at a time
A personal Dropbox, OneDrive or Google Drive turned up on a company machine
Shared folders were opened in bulk, at odd hours, before the resignation
Customers report approaches from the leaver's new employer

Preserve first; conclusions can wait

The strongest employee-theft cases are decided in the first hour, by restraint. Every sign-in writes new data over old, every helpful look around by IT re-dates the folders that matter, and a reissue to the next starter can end the question for good. So the procedure is short: power the machine down, label it, record who has held it, and let it do nothing until it has been imaged. The examination then runs against the verified copy, and the laptop itself sits sealed — available, unchanged, ready for the other side's expert to check.

What the operating system already recorded

Windows keeps better notes than most witnesses. The USBSTOR registry key lists every removable device the machine has seen, by maker, model and serial number; setupapi.dev.log dates the first connection of each. Link files and jump lists then show company files opened from a removable volume's drive letter; shellbags hold the directory layout that was browsed on it; and the NTFS change journal fixes each file operation to the minute across the weeks in question. Read together, in sequence, these artefacts move a case from suspicion to record.

Exits that never used a USB port

A good proportion of copying happens in a browser instead. On the image we reconstruct webmail sessions with attachments addressed to personal accounts, auto-forwarding rules quietly applied to the mailbox, uploads through transfer sites, and sync clients pushing whole folders into a personal cloud account. Where the business runs Microsoft 365 or Google Workspace, the tenant's own audit records are collected alongside, so the device's story and the service's story can be compared line by line — and each corroborates the other.

Findings written for a panel

The report assumes an audience of non-specialists advised by a specialist. Findings come first, numbered and dated, each traceable to the artefact behind it; the technical workings sit in an appendix; the exhibit schedule carries SHA-256 hashes for every image. Where the parties' solicitors agree directions, the examination keeps to them exactly. Nothing is claimed beyond what the record supports — which is precisely why the record tends to be believed.

How imaging and custody run case-wide is covered at the forensic recovery hub; the connection-history detail lives on the USB device forensics page, and preservation practice under legal hold & chain of custody. Fees are on our prices page.

// the deliverables, itemised

What we document for your case

Each item below is delivered as a numbered, dated finding tied to the artefact that supports it — a record a tribunal or court can rely on.

// what one laptop typically yields

Six strands from a single machine

Imaged in time, a leaver's computer usually gives up all of these at once.

Removable-device register

Make, model and serial of each device connected, with first and last seen dates.

Copy-time evidence

Destination timestamps and journal entries placing files on the device at stated times.

Opened-from traces

Link files and jump lists tying named documents to the stick's drive letter.

Outbound channels

Webmail sends, forwarding rules and personal cloud sync recorded on the machine.

Intent indicators

After-hours patterns, repeated access and communications bearing on state of mind.

Preservation record

Imaging date and time against the departure date, verified by SHA-256.

// fees and footing

Forensic fees, and the lawful basis we require

What forensic work costs

The free diagnostic that opens every case is completed within 2 working days of arrival; forensic casework itself is not a no fix, no fee service. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Both figures are itemised on our prices page, and the written scope is agreed before payment is taken.

Who we can act for

Employee matters proceed on company-owned equipment, under HR oversight or a solicitor's instruction. Instructions are accepted on three footings only: equipment the company itself owns; the instruction of a solicitor, insurer or court; or devices that are genuinely the client's own — including jointly owned machines in matrimonial matters. We do not hack, we do not intercept live communications, and we do not examine a device the instructing client has no right to examine.

// getting your device to us

Sending it in — easier than you'd think

A machine that has become an exhibit should travel on agreed terms. Call 0800 689 0668 to settle packaging and paperwork; the custody record opens when the device is signed for at our Leeds location — next-day tracked from York, or by hand on Albion Street.

Is the drive still inside a computer, laptop, MacBook, iMac, CCTV / DVR or server? Take the hard drive or SSD out first and post the bare drive on its own — removing drives from machines isn't a service we offer. Storage that's soldered to a motherboard (Apple Silicon Macs, certain slim laptops) is the one thing we can't work on: if it doesn't come out, it can't come in.

  • Bubble wrap and a sturdy box or padded envelope will do nicely — cables, caddies and power bricks can stay at home.
  • Print off the booking-in & shipping form (PDF), add your name, number and a line or two on what happened, and tuck it in the parcel.
  • Royal Mail Special Delivery keeps it tracked and insured the whole way; your own courier does the same job if you'd sooner book one. There's no collection service at this end.
  • Happier handing it over in person? Reception at the address here takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Address the parcel for the attention of Leeds Data Recovery — about 40 minutes from York via the A64 and A1(M), or next working day by tracked post. You'll hear from us the moment it's booked onto the bench.

Not certain what to pack? Ring 0800 689 0668 first, or run the free online diagnostic.

// employee data theft — answered before instruction

Employers usually ask these first

Usually, yes. A reset is loud in the record: it carries its own date, much of the registry and journal survives it, and unallocated space still holds a recoverable share of the deleted documents. An unrequested reset is also itself a fact a tribunal may weigh. Keep the machine powered off and away from the rebuild queue.
That distinction is the whole examination. A connection alone proves little, so we correlate link files, jump lists, shellbags, journal entries and destination timestamps until named documents sit on a named device at a stated time. Where the stick itself is also available for imaging, the account strengthens further.
On equipment the business owns and issued, generally yes — and where the employee signed an IT or acceptable-use policy, the point is beyond argument. We confirm the footing in writing before starting, act on your solicitor's instruction where one exists, and never touch a former employee's personal devices.
A report with numbered findings tied to artefacts, a dated timeline, an exhibit schedule with SHA-256 hashes, a method appendix and the custody record — prepared to evidential standards. Whether it is admitted is always the panel's decision; our part is making that decision easy.

The record is still on the machine. Keep it that way.

Power it down, ring the freephone, and let the image settle the question.