Home / Forensic Recovery / Employee Data Theft

Employee Data Theft Investigation

A member of staff resigns or is dismissed, copies company data to a USB stick, personal email or cloud drive, then wipes the laptop before handing it back. We prove what left the business — for employers across Staines, Surrey and beyond. Free diagnostic, freephone advice.

Confidential and evidence-grade. A free diagnostic and a written scope come before any investigation begins.

// signs you may need this

Signs a departing employee took data

If any of these match what you are seeing in your Staines or Surrey business, the device should be preserved and examined before it is wiped or reissued.

A leaver's laptop handed back reset, wiped or suspiciously empty
USB sticks or external drives connected during the notice period
Company files emailed to a personal Gmail, Outlook or iCloud account
Documents synced to a personal Dropbox, OneDrive or Google Drive
A resignation followed by a burst of file access and downloads
A competitor or side business now using your client list or pricing

The classic case — copy, then wipe

It is the scenario Surrey employers ask us about most: a member of staff resigns or is dismissed, spends their final days quietly copying documents, contacts and pricing to a USB stick, a personal email account or a cloud drive, then factory-resets or runs a wiping tool on the laptop before handing it back. The machine looks clean; the suspicion is anything but. Forensic examination is built for exactly this. Even after a reset or a dedicated eraser has run, a great deal survives — including which wiping tool was used and the precise moment it ran, the burst of file activity in the notice period, and deleted documents themselves, carved back from the drive.

Proving what left on a USB stick

Windows keeps a surprisingly complete record of removable media. Every USB storage device that has been connected leaves its make, model and unique serial number in the USBSTOR registry key, with first-connection times in the setupapi log and last-connection times in the registry itself. We tie that device back to the user through MountedDevices and MountPoints2, then show which of your files were touched: shortcut (LNK) files and jump lists pointing at a document on the E: or F: drive prove it was opened from removable media, shellbags show which folders were browsed on the stick, and the NTFS USN change journal records the file operations around those dates. Cross-referenced, these artefacts turn 'we think they took something' into a documented list of what and when.

Email and cloud exfiltration

Data does not only leave on a stick. We examine webmail and browser history for company files sent to a personal Gmail, Outlook or iCloud account, attachments uploaded to WeTransfer, and folders synced to a personal Dropbox, OneDrive or Google Drive. Deleted emails are carved from unallocated space, download and browsing history is reconstructed, and cloud-client logs reveal what was synchronised and when — building a single, honest picture of every route the data may have taken out of the business.

Built for an employment tribunal

What makes this forensic rather than mere recovery is procedure. We work only from a hardware write-blocked image of the original drive, verified by MD5 and SHA-256 hash so anyone can prove the copy is identical and unaltered. Handling is logged as a documented chain of custody, our bench runs OSForensics from PassMark for the heavy lifting and Passware Kit Forensic where password-protected files stand in the way, and the report is split into plain-English findings and a technical appendix so it holds up before an employment tribunal or court. We are glad to work to directions agreed with your solicitor.

This is one of the scenarios covered by our wider forensic data recovery service — the hub page explains how write-blocked imaging, hashing and chain of custody underpin every case.

// what the examination covers

What the examination reconstructs

On a company laptop or PC, these are the artefacts that show whether data was copied — and where it went.

USB & removable-media history

Every stick's make, model and serial, with first- and last-connected times.

Opened-from-USB evidence

LNK files and jump lists that tie your documents to a drive letter.

Folder browsing on the drive

Shellbags showing which directories were opened on the removable media.

File-copy operations

USN change-journal activity around the dates data went missing.

Webmail & cloud uploads

Browser history and sync traces for personal email, Drive and Dropbox.

Deleted-file & wiper recovery

Carved documents and emails — and the eraser tool's own footprint.

The one boundary — and how to preserve the device

We examine company-owned equipment, or a personal device only where there is a lawful basis such as a signed company policy or a solicitor's instruction. We do not covertly access a former employee's private phone or home computer. Most important right now: preserve the laptop exactly as it is, powered off, and do not let IT re-image or reissue it — every reinstall overwrites the very evidence that proves what happened.

// getting your device to us

Post or courier your device — it's simple

Forensic cases are preserved, not probed. Before sending anything, call 0800 689 0668 and we will agree exactly what to submit and how to keep it evidentially sound. Chain of custody is documented from the moment your device reaches our secure Guildford location.

Sending a drive from a computer, laptop, MacBook, iMac, CCTV / DVR or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. We don't recover storage soldered to a motherboard (e.g. Apple Silicon Macs and some thin laptops) — only drives that can be removed and sent to us.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Guildford Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// employee data theft questions

Common questions

Usually a great deal. Even after a factory reset or a wiping tool, we can often establish which eraser ran and when, which USB devices were connected in the final weeks, what left by personal email or cloud, and which deleted files can be carved back — all assembled into a clear report. The key is to stop using the laptop and not let IT re-image it.
Often, yes. Windows records every USB storage device by serial number, and by combining that with shortcut files, jump lists, shellbags and the NTFS change journal we can show that specific documents were opened from — or copied to — a particular removable drive, with dates and times.
Company-owned equipment issued for work is normally yours to examine, particularly where an IT and acceptable-use policy is in place. We confirm the lawful basis with you at the outset and are happy to proceed under your solicitor's instruction. We do not access anyone's private personal device covertly.
It is built to. We work from write-blocked, hash-verified images, keep a documented chain of custody, state our methodology openly, and split the report into findings and a technical appendix. We can also work to directions agreed between the parties' solicitors.
// part of our forensic service

Related forensic work

Suspect a leaver took your data?

Preserve the laptop, then start a free diagnostic or call the freephone — the sooner it is imaged, the more survives.