Home / Devices / forensic

Forensic Data Recovery Sheffield

A departing employee, a laptop handed back suspiciously empty, and a business that needs to know what happened before it was wiped. Forensic recovery is data recovery with the burden of proof attached — and it's some of the most important work we do.

Free diagnostic on every forensic job. Fixed quote before any work — and no fix, no fee.

// top 10 faults we recover from

The ten ways they fail

Every forensic job starts by matching the symptoms to the fault — these ten cover almost everything that reaches the bench.

Employee wiped their laptop before leaving

The case we handle most — traces of the wipe, the tool used, and the activity before it can usually be reconstructed.

Suspected USB data theft

Windows records which USB devices connected and when; cross-referenced with file access, it shows what may have been copied.

Data leaked by personal email or cloud

Uploads to webmail, Dropbox, Google Drive or WeTransfer leave traces in history, logs and file remnants.

Mass file deletion

Deleted documents and emails carved back and presented with a defensible, hash-verified methodology.

Tampered or disputed timestamps

When a file was really created, opened or changed — rebuilt from the file system, USN journal and logs.

IP or document theft

Establishing what confidential material was accessed, copied or removed, and by which account.

Departing-director / partner disputes

Evidence-grade investigation of company equipment under company policy, often via solicitors.

Deleted or wiped CCTV / device evidence

Forensic recovery of footage and device data needed for a claim or case.

Insurance or HR investigations

Documented, impartial findings for internal HR processes, insurers and tribunals.

Solicitor-instructed recovery

Work carried out to directions agreed between the parties' legal teams.

The case we're sent most: the wiped laptop

It's a story we handle constantly for employers. An employee copies company data off their work laptop — to a USB stick, a personal email account or a cloud drive — and then wipes or resets the machine before handing it back, hoping to erase the trail. The employer is left with a laptop that looks empty and a strong suspicion that something left with the person. This is exactly what forensic recovery is built for. Even after a reset or a wiping tool has run, a great deal survives: which wiping tool was used and precisely when, which USB devices were connected in those final weeks and what was opened just before they were, what was uploaded to webmail or cloud services, and deleted files carved back from the drive. We turn those traces into a detailed, plain-English forensic report you can act on.

The tools behind the report — OSForensics and Passware

Our forensic bench runs OSForensics, the PassMark investigation suite, for the heavy lifting: recovering deleted files, indexing and searching the whole drive, reconstructing a minute-by-minute activity timeline from file-system timestamps and the Windows USN journal, and pulling the artefacts that matter — connected-USB history, browser and download history, webmail traces, wireless networks and recent-file lists. Alongside it we run Passware Kit Forensic to open any password-protected or encrypted files and BitLocker volumes that stand in the way, where doing so is lawful. Every step is done on a hardware write-blocked, hash-verified image of the original, so the source media is never altered and any party can prove the copy is exact.

Evidence that stands up — and one clear boundary

What makes recovery forensic is procedure at every step: originals write-blocked from first contact, images verified by cryptographic hash (MD5, SHA-1, SHA-256), a documented chain of custody from your hands to ours, and reporting split into clear findings and a technical appendix so it holds up in a tribunal or court. We're happy to work to directions agreed between solicitors. One boundary, stated plainly: forensic work needs a lawful basis — your own devices, company equipment under company policy, or matters instructed through solicitors and insurers. We don't provide covert access to someone else's private device, however strong the suspicion; where there's a legitimate route, we'll take it properly.

// the equipment we use

A professional lab, not software guesswork

Forensic work is evidence, not just data — so procedure and tooling matter at every step:

OSForensics (PassMark)

Our core investigation suite — deleted-file recovery, whole-drive indexing and search, and artefact extraction across hundreds of file formats with OCR.

Activity timeline & USN journal

A minute-by-minute reconstruction of file and system activity from timestamps, the USN change journal and system logs — what happened, and exactly when.

USB & device-history analysis

Which external devices were connected, when, and what was accessed around those times — the backbone of a data-theft investigation.

Passware Kit Forensic

Opens password-protected and encrypted files and BitLocker volumes standing in the way of evidence, where lawful.

Write-blockers & hash verification

Every original is write-blocked from first contact and imaged to a hash-verified copy (MD5, SHA-1, SHA-256) that any party can prove is exact.

Chain-of-custody & reporting

Documented custody from your hands to ours, and reports split into plain-English findings and a technical appendix built to stand up in a tribunal or court.

// manufacturers & models

Cases we handle

Departing-employee data theftWiped-laptop reconstructionUSB exfiltrationEmail & cloud data leaksDeleted-evidence recoveryIP & document theftTimestamp / timeline disputesHR & disciplinary mattersInsurance investigationsSolicitor-instructed cases

What a forensic report can establish

One boundary, stated plainly: forensic work needs a lawful basis — your own devices, company equipment under company policy, or matters instructed through solicitors and insurers. We never provide covert access to someone else's private device.

// before you post it

Sending it in — remove the drive if you can

For a forensic case, preserve the device exactly as it is — powered off — and don't let anyone log in, 'have a look' or re-image it, as each of those overwrites recoverable evidence. Note the dates and names in question. Remove the drive and send it labelled; if the whole device must be preserved as evidence, call us first on 0800 689 0668 to arrange handling under a documented chain of custody.

// getting your device to us

Post or courier your device — it's simple

Most customers post or courier their device to us — it arrives next morning, and the free diagnostic starts the day it lands.

Sending a drive from a computer, laptop, MacBook, iMac or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. If the storage is soldered in (e.g. Apple Silicon), call us first on 0800 689 0668.

  • Wrap the device in bubble wrap or a padded envelope — no need to include cables or power supplies.
  • Print and enclose the booking-in & shipping form (PDF) with your name, phone number and a brief description of what happened.
  • Send by Royal Mail Special Delivery or any tracked courier for full insurance in transit.
  • Prefer to hand it over in person? You can drop it in at reception at the address shown, Mon–Fri 9:00am–5:30pm.
// send your device to your nearest location

Leeds Data Recovery

17th Floor, The Pinnacle
Albion Street
Leeds, LS1 5AA

↓ Print the booking-in & shipping form (PDF)

Mark the package for the attention of Leeds Data Recovery and we'll call you as soon as we diagnose your media.

Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.

// forensic recovery questions

Common questions

Usually a great deal. Even after a wipe or reset we can often establish which wiping tool ran and when, which USB devices were connected in the final weeks, what left by personal email or cloud, and which deleted files can be carved back — assembled into a clear forensic report. Stop using the laptop and don't let IT re-image it.
They're built to: hash-verified images, a documented chain of custody, an openly stated methodology, and reporting split into findings and a technical appendix. We can also work to directions agreed between the parties' solicitors.
Often, yes. Deleted files are carved from the drive and, using file-system timestamps, the USN journal and system logs, we can reconstruct a timeline of when files were created, opened, changed and removed — presented defensibly.
No — covert access to someone else's private device sits outside both the law and our terms, however strong the suspicion. Where there's a lawful route — your own devices, joint business equipment, or a matter via a solicitor — we'll handle it properly.
// related services

Also recovered here

Ready when you are.

Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.