Employee Data Theft Investigations

Employee Data Theft Investigations

Employee Data Theft Investigations

Data theft by employees is one of the most consequential categories of business risk, and one that the digital environment has made dramatically easier to execute. A generation ago, an[…]

Data theft by employees is one of the most consequential categories of business risk, and one that the digital environment has made dramatically easier to execute. A generation ago, an employee who wanted to take company data needed physical access to paper records and a way to remove them from the premises. Today, a significant proportion of a company’s most valuable data can be sent to a personal email account, uploaded to personal cloud storage, or copied to a USB device in the time it takes to make a cup of tea.

The ease of exfiltration has not been matched by a proportionate improvement in detection capability in most organisations. Many data theft cases are discovered not by a monitoring system identifying anomalous activity but by a competitor having access to information they should not possess, by a customer alerting the company that they have been approached using confidential data, or by a chance observation during an IT support session. By the time the theft is discovered, it has typically been running for weeks or months.

What Constitutes Data Theft?

Data theft in an employment context is the unauthorised taking or copying of an organisation’s data by a person who has legitimate access to that data in the course of their employment. The ‘unauthorised’ element distinguishes data theft from the normal use of data in performing job duties: an employee who accesses, uses, and stores customer data in the ordinary course of their role is not committing data theft. An employee who takes that data for their own purposes — to take to a new employer, to sell to a competitor, or to use in establishing a competing business — is.

The legal characterisation depends on the circumstances. Under the Computer Misuse Act 1990, unauthorised access to computer material is an offence even where the individual has general authorisation to access the system. An employee who exceeds their access authorisation — accessing data outside the scope of their role — may commit a Computer Misuse Act offence in addition to any breach of their employment contract. Where the data constitutes a trade secret, the Trade Secrets (Enforcement, etc.) Regulations 2018 provide an additional civil remedy.

Common Scenarios

Departing employee: the most frequent scenario. An employee who is leaving, whether to a competitor or to establish their own business, copies data — customer lists, product specifications, pricing models, source code, strategic plans — before their access is revoked. The copying typically occurs in the final days of employment and is not always detected until after the employee has left.

Disgruntled employee: an employee who is under performance management, has been passed over for promotion, or has a grievance against the organisation may take data as an act of revenge or leverage. The motivation is different from the departing employee scenario but the technical activity — unauthorised copying or transfer of data — is often similar.

Employee in a conflict of interest: an employee who is simultaneously working for or establishing a competing business uses their access to take data that benefits that business. The data theft is a component of a broader conflict of interest that the investigation may need to address in parallel.

Employee acting on behalf of a third party: an employee who is being paid or otherwise incentivised by a competitor, a state actor, or another party to take specific data. This is the most serious category and may involve deliberate, systematic exfiltration over an extended period.

Warning Signs

  • Access to data categories not relevant to the employee’s current role, identified through access log review or DLP alerts.
  • Large-scale downloads of structured data — customer databases, product catalogues, pricing files — at unusual times or in volumes inconsistent with normal work activity.
  • File transfers to personal email accounts, personal cloud storage, or removable media.
  • Excessive printing of sensitive documents in the period before or after a resignation is submitted.
  • A new job at a competitor that is announced while the employee is still serving notice, combined with an increase in data access activity during the notice period.

Digital Forensic Techniques

Device imaging: a forensic, bit-for-bit copy of all relevant devices — the employee’s laptop, desktop, and any other company-issued device — taken before any investigative analysis is conducted. The image preserves the device’s state at the time of seizure and allows analysis to be conducted on the copy without risk of altering the original.

File system analysis: examination of the device’s file system for evidence of data access, copying, and deletion. This analysis can identify which files were accessed, when, and whether they were subsequently copied or deleted, even where the employee has attempted to erase the evidence.

Email and messaging analysis: review of the employee’s email account — including sent items, drafts, and deleted items — for evidence of data transfers to external accounts. Cloud-based email systems maintain logs that are not accessible to the employee and that preserve evidence of forwarding activity even after the employee has attempted to delete it.

Cloud storage forensics: analysis of access to personal cloud storage services — Dropbox, Google Drive, OneDrive personal, iCloud — identified through browser history, authentication logs, or network traffic analysis. Cloud storage is one of the most commonly used exfiltration channels and one that many organisations’ monitoring systems do not adequately cover.

Network log analysis: review of network traffic logs to identify large outbound transfers, connections to external storage services, or other anomalous network activity that may indicate exfiltration.

Legal Considerations

Data theft investigations in England and Wales engage several distinct legal frameworks, each of which creates obligations and opportunities for the employer. The Computer Misuse Act 1990 provides criminal remedies for unauthorised access to computer material. The Trade Secrets (Enforcement, etc.) Regulations 2018 provide civil remedies, including injunctions and damages, where the stolen data constitutes a trade secret. The employment contract may contain express restrictions on the use and retention of company data that support a breach of contract claim.

Where the data includes personal data about identifiable individuals, the data breach notification obligations under UK GDPR may be triggered, requiring assessment of the breach’s risk to those individuals and notification to the ICO and potentially to the data subjects if the risk is high.

Recovery Options

Civil injunction: an urgent application to the court for an injunction preventing the employee from using, disclosing, or retaining the data, and requiring them to return or destroy all copies. Where the threat is immediate and the evidence is sufficient, a without-notice injunction can be obtained swiftly.

Search order: a court order permitting the search and seizure of devices or storage media in the employee’s possession, to identify and recover exfiltrated data. Available in cases where there is a real risk that the employee will destroy or conceal evidence.

Damages and account of profits: civil claims for the financial loss caused by the data theft, or for an account of the profits made by the employee or a third party using the stolen data.

Criminal referral: where the conduct meets the threshold for a Computer Misuse Act or fraud offence, a referral to the police or NCA for criminal investigation.

Investigating suspected employee data theft? Contact iSpy Detectives for expert digital forensic investigation support. Our detectives have recently undertaken employee data theft investigations for corporate clients in London, Manchester, Swansea, Birmingham, Dundee, and Leeds.

Related Services

I-Spy Detectives
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.