A forensic examiner extracting data from a mobile phone connected to a forensic workstation in a laboratory setting.

Service

Mobile Device Forensics

Your client’s phone went with them everywhere. It recorded nearly everything. Where they were, who they called, what they typed, what they searched, what apps were open and when, how many steps they took, what their heart rate was, what photos they took and where, what they deleted and when. The phone does not editorialize. It logs.

Cyber Agents, Inc. has conducted mobile device forensics in more than 400 cases spanning criminal defense, criminal prosecution, civil litigation, military courts-martial, and corporate investigations. The phone is the most important piece of evidence in the majority of the cases we work. What it contains is almost always more than either side initially expects.

Where they were

Location data from a mobile device is more granular and more reliable than most attorneys realize. iPhones and Android devices maintain detailed location histories drawn from GPS, Wi-Fi positioning, cell tower data, and motion sensors. That data persists in databases on the device and in cloud backups, often covering months or years of movement.

We have pulled GPS data from a defendant’s device to establish their position on the day of a murder. We have analyzed CDR and device location data in criminal matters where the data directly contradicted the client’s account of where they had been — leading to plea decisions that would not have been made without that analysis. We have placed victims at specific locations using device data in cases where no witness could do so. We have also placed defendants away from crime scenes, exonerating clients whose stories the digital record confirmed.

The question “was your client at the scene?” used to depend on witnesses. It increasingly depends on the device.

What they said, and what they deleted

Communications data from a mobile device covers every platform the user operated: native text messages, iMessage, WhatsApp, Snapchat, Telegram, Instagram, Facebook Messenger, Signal, and whatever else was installed. Each platform stores message data differently, and each leaves its own set of artifacts when messages are deleted.

We recover deleted messages routinely. Like a deleted file — gone to the user, still there to anyone who knows where to look — the content often remains in the device’s database well after the user believed it was gone. We have recovered messages at a client’s own request — after a client had deleted their messages and hoped those messages had been backed up somewhere, we were able to retrieve them. We have also recovered deletions that contradicted a client’s account of what they had or had not said.

Screenshots presented as evidence of a conversation are a specific area of concern. Screenshots can be fabricated, and screenshots from the other party’s screenshots frequently show gaps — missing message blocks in time windows where the actual device would show a continuous thread. We have identified those gaps in specific cases, comparing the timestamp sequences in a screenshot against what a real unmodified thread would contain. The gaps are visible and documentable.

How they met the other party

In assault, sexual assault, and exploitation cases, the question of how two parties came into contact is often central to the case. That origin is documented in the device. Dating app histories, social media direct messages, gaming platform communications, and third-party messaging apps all record the initial contact, the progression of the relationship, and the communications that predated the alleged incident. We have analyzed Snapchat returns, Facebook and Instagram data, and iCloud account histories in cases where how the parties connected determined which theory of the case was viable.

Social media platform returns — the records that come from the platform itself in response to a legal process — are frequently incomplete. We have worked cases where the platform return contained only part of a conversation. Cross-referencing the platform return against the device extraction surfaces the missing content.

Health data

The iPhone Health database records step counts, distance traveled, floors climbed, heart rate readings, sleep data, and workout sessions in a continuous log. That data is tied to timestamps and location in ways that place the device — and by extension the person carrying it — at specific locations, engaged in specific levels of physical activity, at specific times.

In a murder case we worked, the iPhone Health database was among the primary exhibits. In a wrongful death matter, health app data from a wearable device documented the subject’s biometric condition in the days before death, contradicting the clinical record. Activity data from a phone can establish whether someone was moving, resting, or physically exerting themselves at the time an event is alleged to have occurred.

Financial and personal data

Mobile banking apps, payment platforms, and financial applications store transaction histories, login timestamps, and in some cases location data associated with transactions. Notes applications contain personal observations that users often treat as private but that are forensically accessible. Search histories reflect what the user was thinking about and looking for, including searches that predated an alleged event by days or weeks. Browsing history and app usage logs establish what the user was doing and when, independent of anything they communicated to another person.

What the client is not telling you

Attorneys engage us for client control as often as they engage us for case strategy. The phone produces a more accurate account of a client’s conduct than the client does. When the device record and the client’s story diverge, the attorney finds out from us rather than from the opposing party at trial. That finding changes the advice the attorney can give, the positions they can defend, and the outcomes they can realistically pursue.

We have worked cases where the data confirmed the client’s account. We have worked cases where it contradicted it entirely. The value is not which result we find — the value is that you find out before the other side does.

Case types we handle

  • Criminal defense and prosecution matters requiring device extraction, location analysis, and communications review
  • Murder, assault, and violent crime cases where GPS and health data establish presence or alibi
  • Sexual assault matters requiring social media, messaging, and account history analysis
  • Child exploitation and ICAC cases requiring full platform and device examination
  • Civil litigation including personal injury, wrongful death, and insurance matters
  • Military courts-martial requiring device extraction and analysis across all branches
  • Corporate and employment matters requiring device examination for communications and activity history

Why you need an expert

Mobile device extraction is not a search. Connecting a phone to a computer and exporting its contents produces a data set that requires interpretation, cross-referencing, and verification against the platforms, backups, and carrier records that give it context. What the extraction shows and what it means are two different questions, and only the second one is useful in court.

According to Cyber Agents’ internal records, the firm has analyzed mobile devices in more than 420 matters and its examiners have not been disqualified in those matters We use industry-standard forensic tools — Cellebrite, GrayKey, Elcomsoft, and others — maintain chain of custody through every step of the examination, and produce reports that document our methodology and findings in terms that hold at deposition and at trial. When the phone has the answer, we find it.

Related services and litigation support

Contact Cyber Agents to discuss whether mobile forensics fits your matter.

Free consultation

Talk to an examiner before the evidence moves.

Digital evidence degrades, overwrites and expires. The earlier we are involved, the more of it survives to be examined.