Home / Forensic Recovery / Employee Data Theft

Employee Data Theft Investigations

Staff hand in their notice, quietly move the customer base onto a memory stick or a private cloud account, then reset the laptop on the way out. We put the evidence back together for employers across Swansea, Llanelli, Neath and the wider South Wales area — free diagnostic and freephone advice first.

Discreet, documented, defensible. A free diagnostic and an agreed written scope come first; forensic work is payable upfront.

// does this look familiar

Signs a leaver has helped themselves

If your Swansea Bay business recognises any of these, set the machine aside and have it examined before anyone wipes or reissues it.

A returned laptop that has been factory-reset or is oddly empty
External drives or memory sticks plugged in during the final weeks
Work documents forwarded to a private email address
Company folders appearing in a personal cloud account
Bulk downloads from the file server just before a resignation
An ex-employee's new venture quoting against your price list

Copy first, wipe second — the pattern we see

Ask any employment solicitor in Swansea or Cardiff and they will recognise the sequence: an employee about to leave spends the notice period harvesting documents, contact lists and pricing, moves them onto a stick or into a private cloud account, then hands the laptop back freshly reset. To the eye there is nothing left; to a forensic examiner there is plenty. A reset rarely destroys the deeper traces — the record of the wiping tool itself and the minute it ran, the flurry of file activity before departure, and a large share of the deleted documents, which can be carved straight back off the disk.

The USB trail Windows leaves behind

Few people realise how much Windows remembers about removable media. The registry's USBSTOR key logs the make, model and serial number of every stick and external drive ever attached; the setupapi log records when each was first plugged in; MountedDevices and MountPoints2 tie a device to the profile that used it. Around that sit shortcut (LNK) files and jump lists showing your documents being opened from a lettered removable drive, shellbags recording which folders on the stick were browsed, and the NTFS USN change journal noting file operations minute by minute. Stitched together, those artefacts convert a hunch into a dated, itemised account of what was taken.

When the data leaves by email or cloud instead

Not every exfiltration involves hardware. We also reconstruct browser and webmail activity — attachments sent to private addresses, files pushed through transfer sites, and folders synchronised out to a personal OneDrive, Dropbox or Google Drive. Deleted messages are recovered from unallocated space and sync-client logs show what went up and when, so the report covers every route out of the business, not just the obvious one.

Evidence a tribunal can rely on

Procedure is what separates evidence from anecdote. The suspect drive is imaged behind a hardware write-blocker and the image verified against MD5 and SHA-256 hashes, so nobody can suggest it was altered. Every movement of the exhibit goes into a chain-of-custody log, the examination runs on OSForensics with Passware Kit Forensic brought in for password-protected material, and the finished report pairs plain-English findings with a technical appendix. It is written to survive cross-examination at an employment tribunal, and we are happy to follow directions agreed with your solicitor.

The imaging, hashing and custody discipline behind this page is set out on our forensic data recovery hub. Forensic work is payable upfront: a standard investigation with a detailed report is £800 + VAT, and a leaner £400 + VAT forensic binary-image and deleted-file extraction is available without the report — both appear on the data recovery cost page. If the returned laptop is encrypted, our BitLocker recovery service decrypts it with the recovery key before analysis begins.

// inside the examination

What we can reconstruct from the laptop

From a company machine, these are the strands of evidence an examination typically pulls together.

Removable-media record

Serial numbers and connection times for every stick and drive attached.

Documents opened from USB

LNK and jump-list traces tying files to a removable drive letter.

Folders browsed on the stick

Shellbag entries for directories opened on the device.

The change journal

NTFS USN activity around the dates in question, minute by minute.

Personal email & cloud sync

Webmail sends, transfer-site uploads and sync-client logs.

Deleted files & wiper traces

Carved documents plus the footprint of any erasing tool.

Where we draw the line — and what to do right now

Company equipment is fair ground, as is a personal device where a signed policy or a solicitor's instruction provides the lawful basis; covert access to an ex-employee's private phone or home computer is something we will never undertake. In the meantime, treat the laptop as an exhibit: power it off, put it somewhere safe, and make sure IT does not rebuild or reissue it — a reinstall grinds away the very traces the case depends on.

// getting your device to us

Post or courier your device — it's simple

Treat the device as an exhibit rather than a computer. Call 0800 689 0668 before sending anything and we will agree what to submit and how to package it — the chain of custody is logged from the moment it reaches our secure Bristol location.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Bristol Data Recovery

Castlemead
Lower Castle Street
Bristol, BS1 3AG

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Bristol Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// employee data theft — your questions

Common questions

Almost always more than people expect. A reset or eraser leaves its own fingerprint — which tool, and exactly when — while USB history, cloud-sync logs and a good proportion of the deleted files survive to be recovered. The essential step is to stop using the machine and keep IT from rebuilding it.
In many cases, yes. Windows logs each removable device by serial number, and LNK shortcuts, jump lists, shellbags and the USN change journal can place named documents on that device with dates and times attached.
Equipment the company owns and issued for work can normally be examined, and a signed IT or acceptable-use policy puts the position beyond doubt. We confirm the lawful basis before starting and can act on your solicitor's instruction — what we never do is covertly access someone's private personal device.
That is the standard they are prepared to: write-blocked, hash-verified imaging, a logged chain of custody, an openly stated method, and a report with findings up front and the technical detail in an appendix. Directions agreed between the parties' solicitors are welcome.
// more forensic case types

Other case types we cover

Think data left with a leaver?

Set the laptop aside and call the freephone — the earlier it is imaged, the more the evidence shows.