Employee Data Theft Investigations

A sales manager resigns from a freight forwarder in Bootle; a buyer leaves a wholesaler on one of the estates off Speke Boulevard. Six weeks later a customer list nobody else could have built is being worked by a competitor. The returned laptop usually holds the answer, and holds it right up until somebody signs in and starts writing over it. Everything here is done on a verified copy, and the report claims only what that copy will support.

Scope first, then work. Diagnosis is free and comes at the beginning; the written scope follows, and the forensic fee is paid in full before an examiner opens the image. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. The whole price list sits on the data recovery cost page.

// stop before anybody signs in

Six reasons to take an image now

Any single one of these justifies pulling the device out of circulation and leaving it alone until a copy exists, whether the firm trades from the waterfront, from Speke or from the Wirral side of the river.

The laptop came back reinstalled and nobody in IT ordered it
A stick or portable drive started appearing during the notice period
Documents went out to a private address a few at a time
A personal Dropbox, OneDrive or Google Drive is signed in on company hardware
Entire shared folders were opened late at night before the resignation
Customers say they have been approached from the leaver's new employer

Do nothing at all for the first hour

Restraint decides these cases more often than effort does. Every login writes fresh data across the old. A helpful look round by the IT team alters exactly the dates that later matter. A rebuild for the next starter ends the enquiry outright. The routine is therefore short and unexciting: shut it down, label it, list everyone who has handled it, and leave it alone. Analysis then proceeds against a copy that verifies, and the machine itself stays sealed, so that an expert instructed by the other side can examine the same hardware and reach their own view of it.

The notes Windows keeps on its own account

An operating system makes a better witness than most people. USBSTOR holds an entry for every stick, card reader and portable drive ever attached, carrying manufacturer, model and serial, while setupapi.dev.log records the day each of them first appeared. LNK files and jump lists connect named documents to the drive letter the removable volume was given. Shellbags preserve the folders somebody browsed while it was mounted. $UsnJrnl timestamps the operations one by one across the weeks at issue. Assembled in order, that material turns a suspicion into something a solicitor can act on.

Copying that never goes near a port

The browser now carries most of it. On the copy we find webmail sessions with attachments addressed to a private account, mailbox rules quietly pushing selected mail outward, uploads to file-transfer sites, and a sync client mirroring folders into personal storage. Where the business runs Microsoft 365 or Google Workspace, the tenancy audit records are collected too, which allows the service's version of a given hour to be laid against the machine's version of the same hour.

Written for the panel

The intended reader is a tribunal panel with a technical assessor beside it. Findings lead, numbered and dated, each tied to its source artefact, and the technical reasoning goes to an appendix. Every image on the exhibit schedule carries its SHA-256 value. If the matter is instead bound for the High Court — an interim injunction, or a search order against a former employee — the same material supports the application, because it was captured early and documented as it was captured. Nothing is asserted beyond what the record carries, which is the reason the record tends to be accepted.

Imaging and custody across the practice are described at the forensic recovery hub. Connection history has its own page at USB device forensics, and preservation at legal hold and chain of custody. Every figure is on the prices page.

// the findings, itemised

What your case gets in writing

Each item below arrives as a numbered finding, dated, with the artefact it rests on named beside it, in a document a tribunal or a judge can work from.

// what a single machine yields

Six threads from one laptop

Imaged before it returns to service, a leaver's computer usually surrenders all six.

Device register

Every item ever attached, by manufacturer, model and serial, with first and last dates.

Transfer timings

Journal entries and destination timestamps placing named files on a device at stated hours.

Opened-from evidence

LNK files and jump lists connecting documents to the letter the removable volume held.

Routes outward

Webmail sends, mailbox rules and personal sync activity still resident on the machine.

Conduct in context

Repeat visits, late sessions and messages that speak to intention.

Preservation proof

Capture date against leaving date, carried by SHA-256 values that still verify.

// the fee, and who may instruct

The fee, and the basis we require

The price, without hedging

Diagnosis is free and takes 2 working days from the morning the parcel is opened. Nothing forensic runs under no fix, no fee. A forensic investigation ending in a written report is £800 + VAT, settled in full before the examination opens. Where no report is wanted, the binary image with deleted-file extraction stands on its own at £400 + VAT. Forensic work is paid for in advance, without exception. The same two figures appear on the prices page, and you are asked for nothing until the written scope has been agreed.

Who may instruct

Employee investigations run on hardware the business owns, with HR standing behind them or a solicitor instructing. Only three routes reach an examination and there is no fourth. Hardware the business itself bought. A written instruction from solicitors, from an insurer or from the court. Or a device belonging to the client, which in a family matter extends to a machine the couple own between them. Nothing is broken into on this bench. Live traffic is never intercepted: that power belongs to the agencies named in the Investigatory Powers Act 2016 and nowhere else. If a client may not lawfully look inside a device, the answer here is the same one.

// posting your device in

Sending it in — a padded box and a label

Once a machine is an exhibit it travels on terms agreed in advance. Ring 0800 689 0668 and we will settle packaging and paperwork. Nothing is collected and Liverpool has no counter, so it goes by tracked, insured post to the Manchester laboratory, and the custody record opens at booking-in.

Still screwed inside a laptop, tower, MacBook, iMac, server or a CCTV recorder? Take the drive out and post that on its own. We do not strip machines here, and any computer shop will do it in a few minutes. The one job nobody can take on is flash soldered straight to a logic board, as on Apple Silicon Macs and a handful of very slim laptops: if the storage will not unbolt, there is nothing to send.

  • Wrap it well and use a box or padded envelope stiff enough that nothing rattles. Hold on to the cables, caddies and power supplies; they are no help at this end.
  • Fill in the shipping and booking-in form (PDF) — name, number, and a line or two about what went wrong — and drop it in the box beside the drive.
  • Royal Mail Special Delivery gets it here tracked and insured. Book your own courier instead if you prefer; either way the parcel is signed for.
  • Driving over instead? Reception at the Manchester address below accepts drop-offs, Mon–Fri 9:00am–5:30pm. What there is not, anywhere, is a Liverpool counter or a collection service.
// the address on the parcel

Manchester Data Recovery

Manchester Data Recovery
Peter House, Oxford Street
Manchester, M1 5AN

↓ Print the shipping & booking-in form (PDF)

Address it to Manchester Data Recovery. It is roughly 35 miles from Liverpool along the M62 if you fancy the run, and next working day by tracked post if you do not. We ring or email the moment it is booked in, and the free diagnostic closes 2 working days after that.

Not sure what belongs in the parcel? Call 0800 689 0668 before you tape it shut, or step through the free online diagnostic first.

// employee data theft — the first telephone call

The questions employers open with

Nearly always. A reset is a loud event: it is dated, much of the registry and the journal come through it intact, and unallocated space keeps a share of whatever was deleted. A reset nobody authorised is itself a fact worth putting in a report. Keep the machine powered down and away from the rebuild queue.
Drawing that line is the examination. Attachment on its own proves very little, so LNK files, jump lists, shellbags, journal entries and the timestamps at the receiving end are read against each other until a named document sits on a named device at a stated hour. If the stick itself can be imaged, the picture tightens further.
On hardware the business bought and supplied, generally yes, and an acceptable-use or IT policy signed by the employee leaves very little room for argument. The basis is recorded in writing before anything starts, any instruction from your solicitor is followed, and property belonging to the former employee is not touched.
Numbered findings with their sources, a dated timeline, an exhibit schedule carrying SHA-256 values, a method appendix and the custody record, all prepared to evidential standards. Admissibility belongs to the panel. Leaving them nothing to hesitate over is the part we can do.

The answer is on the laptop. Stop using it.

Power it down, ring the freephone, and let a verified copy speak for you.