This site uses cookies to provide you with a more responsive and personalized service. By using this site you agree to our use of cookies. Please read our cookie notice for more information on the cookies we use and how to delete or block them.

Bookmark Email Print page

Destruction of evidence

Computer Forensics

Background:
We were approached by a legal firm. The defendant in an employment case had been required to surrender his laptop computer because the device was believed to contain important evidence. However, when surrendered the hard drive was discovered to contain operating system files and nothing else.

 

Concern:
To demonstrate if and how evidence had been removed from the hard drive.

Deloitte’s Actions:
• Deloitte took the computer into custody and acquired a forensic image of the hard drive.
• Deloitte also inspected the hard drive and computer for signs of tampering.

Deloitte’s Findings:
• Deloitte quickly found that time stamps on the operating system indicated that it had been 'installed' in 2003. Deloitte quickly established that no other documents or applications had been installed on the computer.
• Deloitte decoded the manufacture date of the computer’s hard drive, and found out it had not been built until mid-2007. This demonstrated that the time stamps of the data on the hard drive were fake.
• Deloitte also examined the slack and unallocated spaces on the hard drive (unused areas of the disk where deleted and ephemeral data tends to accumulate over time) and found them to be completely clean. This indicated that the computer had not even been turned on after the operating system had been installed.

Results:
• Using an affidavit prepared by Deloitte, our client was able to demonstrate bad-faith by the counterparties in the case. The case was thrown out, with costs in our client’s favour.

 

Comment:
Evidence modification and deletion is quite common in the cases we investigate. Fortunately, it is very difficult to destroy or modify files without leaving telltale traces. Even specialised 'evidence elimination' software leaves clear traces of its operation. Nevertheless it is better to ensure that electronic evidence is acquired and secured as quickly as possible after it is identified as potentially relevant.

Page Last Updated

Material on this website is © 2013 Deloitte Global Services Limited, or a member firm of Deloitte Touche Tohmatsu Limited, or one of their affiliates. See Legal for copyright and other legal information.

Deloitte refers to one or more of Deloitte Touche Tohmatsu Limited, a private company limited by guarantee, and its network of member firms, each of which is a legally separate and independent entity. Please see www.deloitte.com/ie/about for a detailed description of the legal structure of Deloitte Touche Tohmatsu Limited and its member firms.

Get connected
Share your comments
More on Deloitte
Learn about our site