Email and Cloud Exfiltration Forensics

Anything leaving through a mailbox or a cloud account is written down twice, once by the machine and once by the service, and a sound investigation reads both. Rules, attachment history and sign-in patterns come from the tenancy. Browser and sync traces come from the device. The two are aligned into one dated account of what went where. For brokers, accountants and professional firms in the commercial district, and for the solicitors instructing on their behalf.

Scope first, then work. Diagnosis is free and comes at the beginning; the written scope follows, and the forensic fee is paid in full before an examiner opens the image. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. The whole price list sits on the data recovery cost page.

// what usually triggers the call

What an exit through a mailbox looks like

Every one of these has an innocent explanation. Together they form a pattern worth examining.

Large attachments going to a single private address over several weeks
A forwarding rule discovered on a mailbox after the person has left
Sign-ins to company accounts at hours when nobody was working
A personal Dropbox, OneDrive or Google Drive signed in on a work laptop
Bulk downloads from SharePoint or a shared drive before a departure
A leaver's mailbox deleted before anybody had looked inside it

How a mailbox behaves on the way out

A mailbox being used to move material has a recognisable manner. Attachments get larger while the recipients narrow to one private address. A rule appears and starts pushing selected mail outward unattended. The search history begins to look like hunting — customer names, project titles, price lists — rather than the day's work. Access drifts into evenings and weekends. The platform records every part of that, and each element is retrieved and dated in the examination.

Personal cloud accounts on company hardware

The device supplies the other half. Browser artefacts record accounts being created at and signed into Dropbox, OneDrive and Google Drive from a company machine. Sync-client logs and folder layouts show which directories were set to mirror upward, and from when. The residue of an upload — cached pages, confirmation screens, recent-file lists — remains on the image long after the browsing history has been cleared. A personal account appearing on work hardware during a final month is rarely there by accident.

Evidence the tenancy keeps by default

Microsoft 365 and Google Workspace hold evidence of their own, and it frequently decides the matter. Message movement, sharing and downloads appear in Purview audit logs and eDiscovery exports. Google Vault preserves mail and files. SharePoint and OneDrive logs attach an account and an hour to every share and bulk download. Dropbox retains version history and recoverable deletions. A deleted mailbox can often be restored from retention or backup, but the window is finite, which is the whole argument for telephoning early.

Two records, one account

A finding persuades when it agrees with itself. The tenancy logs a 2.1 GB download at 21:14. The same files appear in a personal sync folder on the device two minutes later. Browser history closes the loop. Service evidence and machine evidence are combined into a single sequence, any disagreement between them is flagged rather than tidied away, and everything — the mailbox export, the audit extract, the image — is hashed before an account is suspended or a licence recovered.

The method behind all of it is at the forensic recovery hub. Credentials and server records continue at insider threat forensics, the employer casework at employee data theft, and holding material at legal hold and chain of custody. What it costs is on the prices page.

// what the report contains

Findings from both sides of the exit

Service records and machine artefacts, read against one another and presented as a single sequence.

Attachments

What went to private addresses, at what size, and on which days.

Rules

Forwarding and deletion rules, their creation dates and what they captured.

Access

Sign-in times and locations, with out-of-hours clusters marked.

Cloud residue

Personal accounts, sync folders and upload leftovers on the work machine.

Audit extracts

Sharing, download and export events from M365 and Workspace logs.

Restored mail

Messages and entire mailboxes recovered from retention and backup.

// the fee, and who may instruct

The fee, and the basis we require

The price, without hedging

Diagnosis is free and takes 2 working days from the morning the parcel is opened. Nothing forensic runs under no fix, no fee. A forensic investigation ending in a written report is £800 + VAT, settled in full before the examination opens. Where no report is wanted, the binary image with deleted-file extraction stands on its own at £400 + VAT. Forensic work is paid for in advance, without exception. A scope covering several mailboxes, or an entire tenancy, is quoted in writing once the free diagnostic has finished. The same two figures appear on the prices page, and you are asked for nothing until the written scope has been agreed.

Who may instruct

Mailbox and cloud work runs on company tenancies and company devices, or on a solicitor's written instruction. Only three routes reach an examination and there is no fourth. Hardware the business itself bought. A written instruction from solicitors, from an insurer or from the court. Or a device belonging to the client, which in a family matter extends to a machine the couple own between them. Nothing is broken into on this bench. Live traffic is never intercepted: that power belongs to the agencies named in the Investigatory Powers Act 2016 and nowhere else. If a client may not lawfully look inside a device, the answer here is the same one.

// posting your device in

Sending it in — a padded box and a label

Cloud material is usually preserved by export rather than by parcel. Ring 0800 689 0668 and we will separate what can be captured remotely from what has to travel. Devices go by tracked, insured post to the Manchester laboratory, because nothing is collected, with custody recorded from arrival.

Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.

  • Wrap it well and use a box or padded envelope stiff enough that nothing rattles. Hold on to the cables, caddies and power supplies; they are no help at this end.
  • Fill in the shipping and booking-in form (PDF) — name, number, and a line or two about what went wrong — and drop it in the box beside the drive.
  • Royal Mail Special Delivery gets it here tracked and insured. Book your own courier instead if you prefer; either way the parcel is signed for.
  • Driving over instead? Reception at the Manchester address below accepts drop-offs, Mon–Fri 9:00am–5:30pm. What there is not, anywhere, is a Liverpool counter or a collection service.
// the address on the parcel

Manchester Data Recovery

Manchester Data Recovery
Peter House, Oxford Street
Manchester, M1 5AN

↓ Print the shipping & booking-in form (PDF)

Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.

Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.

// email and cloud — from IT departments

What IT managers telephone about

Often, if we are told early. A deleted mailbox usually remains in retention for a period during which it can be brought back, and a backup or a litigation hold extends that further. The window is finite, so preservation should begin on the day the question first arises.
Its configuration shows what it was set to capture, and message trace and audit records show what moved while those logs remain. Once that window has closed, the pattern at the receiving end on the device usually fills the gap, and the report identifies which conclusion rests on which source.
No. A private account is beyond an employer's reach and beyond ours. We work on the company's half of every exchange: tenancy logs, machine artefacts, and whatever the court subsequently orders to be disclosed. That half is usually enough.
Secure it, but preserve first. Export the mailbox, capture the audit logs, image the device, and only then recover licences or purge the account. Doing it in the wrong order has destroyed more email evidence than any departing employee ever managed, and we will walk your IT team through the sequence by telephone.

The tenancy remembers. Not indefinitely.

Retention windows close to their own timetable, not yours — ring the freephone before anything is purged.