Taking instructions now — the first conversation is freeExhibits posted in from anywhere in the UK, or handed in at ten drop-off pointsQuicker still, give us a ring:0800 6890668
FDRForensic Data Recovery 0800 6890668 Price my job
FDR / Services / Departing employee data theft

Departing employee · USB history · cloud uploads · webmail · deletions · company device

Departing employee data theft. The laptop remembers the USB stick, the upload and the last-minute deletions, long after the person has gone.

When an employee leaves under a cloud, the question is almost always the same: did they take anything with them. A Windows computer keeps a surprisingly complete record of the answer, and it survives long after the person has handed the laptop back. It remembers every USB storage device ever connected, with its make, serial and the dates; it records, in jump lists, shortcut files and shellbags, which files and folders were opened from those removable drives; it logs when a personal cloud client was installed and how much it uploaded; it keeps browser history to webmail and file-transfer sites; and its journal records files deleted in the final days and whether the Recycle Bin was emptied. The standard forensic report gathers all of this into a factual account with a timeline of the final week. It is examined only on the authority of the employer, whose device it is, on a lawful basis, and the report is honest about the one thing the artefacts cannot settle: which person was at the keyboard.

Owner-only, authority requiredFree first conversationStandard report £800 + VATWe say what it cannot prove

Rather talk it through? An engineer answers the bench line
0800 6890668

Before anything else: stop using the device, and do not let anyone have a look at it. Every time a computer is switched on and used, the very artefacts an examination relies on, the timeline, the recently-opened lists, the deleted-file space, are overwritten a little more. Do not reinstall, do not run recovery software, do not let IT open it to check, and keep it powered off. Preserve it as it is, record who has held it, and send it with the authority documents we ask for. If proceedings are contemplated, the duty to preserve evidence has already begun.

Who instructs us, and the authority we need.

The instructing party is the employer, and the device must be company property. We ask for a letter from a director, HR or the company's solicitor confirming that the laptop is the company's, the lawful basis for the examination (usually legitimate interests in protecting confidential information), and the company's IT and monitoring policy that staff were given, together with the scope, the period and the categories of interest. That lets the examination proceed lawfully and proportionately.

Personal material on a work device needs care. The employee may have personal email, banking or family photographs on the laptop, and the ICO's guidance on monitoring workers expects an investigation to be proportionate and scoped. We examine the artefacts relevant to the allegation and the period, and we filter out personal material that falls outside the scope rather than reproduce it.

We do not log in to the employee's personal cloud, webmail or other accounts; that would be a different matter requiring the account owner's authority. We examine what the device itself records, which is a great deal.

What the standard report typically contains.

Removable storage, with serials and datesThe computer's registry and logs record every USB storage device connected, with its make, model, serial number and the first and last connection times. The report lists them, flags any first connected in the final days, and shows how often each was used.
Files opened from the removable drivesJump lists, shortcut (LNK) files and shellbags record which files and folders were opened from a removable volume, tied to that volume's serial. Where the folder names match the company's own client, pricing or project folders, the report sets that out, with the times.
Cloud and webmail activityThe report records when a personal cloud client (a personal Dropbox, Google Drive or similar) was installed and how much its logs show was uploaded, and it lists browser visits to webmail and file-transfer sites. It is clear that upload volume and timing are recorded, not the contents of what was sent.
Deletions on the way outThe USN journal records files deleted in the final days, and whether the Recycle Bin was emptied. The report shows the deletion events with their times, lists what was recovered, and notes where recovery was limited by an SSD's TRIM.

The questions it can answer, and what it cannot.

Describe your situation →
What you want to know What the examination shows What it cannot prove on its own
Which USB devices were connected, and whenMake, model, serial, first and last connection, from the registry and logsThat a particular person connected them, rather than the account being used
Whether company files were opened from a USB driveJump lists, LNK and shellbags tied to the device's volume serialThat the files were then copied, used or sent; Windows does not log copies
Whether a personal cloud client was installed and usedInstall time and upload volume from the client's logsWhat was uploaded; the log records volume, not content
What was deleted in the final daysThe USN journal and recovered filesWho deleted them, beyond the account that was logged on

From the exhibit arriving to the report.

Work we have closed →
01

The first conversation, and the authority check Free

Tell us the situation, who owns the device, and what you need to know. We tell you whether it is a job we can take on, what authority we will need, and whether the standard report answers your questions or an expert report is called for. That conversation is free, and some enquiries end there, because we will not take work we cannot lawfully or honestly do.

FreeOwner-only; authority established firstThe honest answer about what is possible
02

Imaging behind a write blocker, and the hashes

When the exhibit arrives, your authority is checked, the device is logged and photographed, and the drive is connected through a hardware write blocker and imaged bit for bit. MD5 and SHA-256 hashes of the source and the image are computed and verified, so the copy is provably identical. Nothing is examined on the original; every later step is done on the verified image.

Bit-for-bit, behind a write blockerMD5 and SHA-256, verifiedThe original never altered
03

The examination, on the image

The image is examined for the artefacts your questions turn on: USB device history, files opened from removable media, cloud and webmail activity, deleted files and the Recycle Bin, the USN journal, program execution, email, document metadata, shadow copies, and a timeline. Findings that matter are confirmed in a second tool. The work is scoped to what you asked; material outside the scope is not reproduced.

Scoped to your questionsConfirmed in a second toolPrivate material filtered out
04

The report

The standard forensic report sets out the exhibit and its condition, the integrity record, the tools and method, and the findings by category, with a timeline, the limitations, and factual conclusions, as a self-contained report with its chain-of-custody and case-log reports. It is written in plain terms, keeps fact separate from any comment, and is suitable for internal decisions, HR processes, negotiations and solicitors. Where you need opinion evidence for court, an expert report is quoted.

Factual, tool-generated, self-containedChain-of-custody and case-log reports5–10 working days

Before you send the exhibit

  • Act quickly and preserve the laptop. Do not let IT examine it first; each logon overwrites the artefacts the examination relies on.
  • Have the authority ready: a director's or HR letter confirming company ownership, the lawful basis and the IT policy, with the scope and period.
  • Consider a preservation image straight away if the matter may go to court, so the evidence is secured before anyone examines it.

Every USB storage device ever connected to a Windows computer is recorded in the registry, with its serial and connection dates, and the record survives the device being removed.

One examination, in outline.

UK · FDR-2026-0401JOB LOGGED ✓

A company laptop examined for Northgate Fittings Ltd on the managing director's authority, after a director left to set up in competition

On the employer's written authority and lawful basis, the laptop was imaged behind a write blocker and examined. The report set out two removable drives first connected in the final four days, company client and pricing folders opened from them, a personal cloud client installed and used to upload around 1.8 GB over two evenings, visits to a file-transfer site, and 412 file deletions with the Recycle Bin emptied on the final afternoon, of which 58 files were recovered. It stated plainly that the artefacts did not establish who was at the keyboard. The director's solicitor used the report in correspondence.

Factual findings the company could act onIllustrative synthetic example
Illustrative example — replace with a genuine case

What helps, and what harms.

Do this much first

  • Stop using the device and keep it powered off
  • Preserve it as it is; record who has held it
  • Gather your proof of ownership or authority
  • Tell us the questions you need answered

What sets us back

  • Letting IT or anyone open it to have a look
  • Reinstalling, wiping or running recovery software
  • Carrying on using the device
  • Assuming artefacts prove who was at the keyboard
We examine devices only for the people and organisations with lawful authority over them. Before any work begins we ask for proof that the device is yours, or documented authority to have it examined: proof of ownership, a director's or HR letter for a company device with the lawful basis, a solicitor's instruction, a court order, or an executor's grant. It is a condition of the work, not a formality, and it is what keeps the examination on the right side of the Computer Misuse Act 1990. We will not access another adult's device or accounts without their consent or a court order, we will not install monitoring software or bypass anyone's security, and we do not undertake covert surveillance. A device with no proof of authority is returned unexamined.

Questions answered before you instruct.

Can you prove the employee stole our data?

We can show, factually, what the device records: which USB devices were connected and when, which company files were opened from them, whether a personal cloud client was installed and used, and what was deleted. We cannot prove who was physically at the keyboard, or what was in an upload. That combination is often enough to act on, and a solicitor can advise on its use.

Is it lawful to examine a former employee's work laptop?

Yes, where the laptop is company property and the examination is on a lawful basis and proportionate to the allegation. We ask for the company's confirmation of ownership, the lawful basis and the monitoring policy, and we scope the work to the matter and filter out unrelated personal material.

Can you get into their personal Dropbox or Gmail to see what they took?

No. Those are the employee's accounts, and accessing them would need the account owner's authority or a court order. We examine what the company's device records, which includes that a personal cloud client was installed and how much it uploaded.

Will this stand up if we take it to a tribunal?

The standard report is a factual, tool-generated examination with a full integrity record, which is suitable for an HR process and for a solicitor's assessment, and its author can give evidence of fact about what was done and found. Where a tribunal needs contested opinion evidence, an expert report is quoted; most matters do not reach that point.

What does it cost?

The standard forensic report for the one laptop is £800 + VAT, with a second disk quoted as extra. The first conversation is free, and an expert report, if the matter needs one, is quoted separately.

The device holds the answer; preserve it first.

The first conversation is free, and it starts with who owns the device and what you need to know. Tell us the situation and we will tell you whether we can take it on, what authority we need, and whether the standard report or an expert report fits. Until then, stop using the device and preserve it as it is.

0800 6890668