Mobile Device Investigations

Mobile Device Investigations

Mobile Device Investigations

Mobile devices have become the most evidentially rich category of digital evidence available in most investigations. They carry a combination of communication records, location data, photographic evidence, application activity, and[…]

Mobile devices have become the most evidentially rich category of digital evidence available in most investigations. They carry a combination of communication records, location data, photographic evidence, application activity, and personal and professional data that desktop computers rarely replicate. An investigation that overlooks the mobile device overlooks the digital record that is most likely to contain the evidence it is looking for.

Mobile device forensics is also one of the more technically demanding areas of digital investigation. Manufacturers invest heavily in security features that prevent unauthorised access to device data, encryption is standard across modern devices, and the diversity of operating systems, device models, and application architectures requires specialist knowledge and specialist tools to navigate effectively.

Why Mobile Devices Matter

Mobile devices matter in investigations for several reasons that distinguish them from other evidence sources. They are almost always with the user, making them a continuous record of activity rather than a record limited to working hours or work locations. They carry communication records from multiple channels — SMS, WhatsApp, Signal, Telegram, iMessage, and any number of platform-specific messaging services — that may capture the evidence that email analysis would miss. And they carry location data from GPS, cell tower records, and application activity that can establish where a person was at a specific time.

In employment and commercial investigation contexts, mobile devices are particularly important where the investigation concerns conduct that occurred through personal communication channels: a departing employee who discussed data theft with a future employer through WhatsApp, a business partner who colluded with a competitor through Signal, or an employee who planned a fraudulent scheme through personal messaging applications that do not appear on their corporate email record.

Types of Recoverable Evidence

Call records: incoming and outgoing call records with timestamps, call duration, and contact identification. Where the device retains deleted call records, forensic analysis can recover them from the device’s database structures.

SMS and messaging application data: SMS messages, iMessages, WhatsApp conversations, Telegram messages, Signal messages, and the content and metadata of any other messaging application installed on the device. Different applications use different storage mechanisms and different encryption approaches, and the forensic approach must be tailored to each.

Location data: GPS location records, cell tower connection history, Wi-Fi connection history, and application-specific location data. Location evidence from a mobile device can establish where the device was — and by inference, where the user was — at specific points in time.

Photographs and videos: images and videos stored on the device, including deleted media recoverable from unallocated space, with embedded EXIF metadata that records the time, date, and location of capture for photographs taken with the device’s camera.

Application data: the data stored by applications installed on the device, which varies significantly between applications but may include browsing history, search history, purchase records, communication history, and any content created or stored within the application.

Email and calendar data: corporate and personal email accounts accessed through mobile email clients, and calendar records that establish the user’s scheduled activities during the relevant period.

Forensic Acquisition

Forensic acquisition of a mobile device differs from computer forensic acquisition because the mobile device’s architecture does not permit a simple bit-for-bit image in the same way as a hard drive. Mobile forensic acquisition tools use a range of extraction methods, each of which produces a different scope of data recovery:

Logical extraction: the simplest extraction method, which uses the device’s own interface to access data that is accessible through normal operation. This method produces the most limited evidence scope but is applicable to a wide range of devices and operating systems.

File system extraction: access to the device’s file system, providing access to a broader range of data than logical extraction, including application data and some deleted content.

Physical extraction: a bit-for-bit image of the device’s storage, equivalent to a hard drive forensic image, providing access to deleted data in unallocated space. Physical extraction requires specialist tools and may require bypassing the device’s security features, which is not always possible with modern encrypted devices.

Cloud extraction: where the device is linked to a cloud backup service — iCloud for iOS devices, Google Drive for Android devices — and cloud credentials are available, forensic tools can extract data from the cloud backup that may be more complete than what is available on the device itself.

Common Investigation Scenarios

Departing employee: examination of a departing employee’s mobile device for evidence of data exfiltration via messaging applications or personal email, communication with competitors, or discussions about intellectual property before departure.

Harassment and misconduct: examination of a device for evidence of messages that constitute harassment, discrimination, or bullying in the workplace, where the conduct occurred through personal communication channels.

Fraud and corruption: recovery of communication records and financial application data that evidence a fraudulent scheme, corrupt payment, or conflict of interest conducted through personal communication channels.

Accident and incident investigation: where a mobile device was in use at the time of an accident or incident, forensic analysis can establish whether the device was being used, what it was being used for, and whether that use was a contributing factor.

Reporting Evidence

Mobile device forensic findings are reported in the same structured format as computer forensic findings: scope, methodology, acquisition details, analysis, and conclusions. Where communication records are the primary evidence, the report presents them in chronological order with full context, and distinguishes between the data recovered and any interpretive analysis of what that data indicates.

The forensic investigator must be prepared to give expert evidence about the acquisition methodology and the analytical findings, and to address challenges about the reliability of the extraction method used and the accuracy of the data recovered. A well-documented forensic process, using validated specialist tools, is the most reliable defence against those challenges.

Need mobile device forensics for an investigation or legal matter? Contact iSpy Detectives for specialist mobile forensic examination services.

Related Services

I-Spy Detectives
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.