A departing employee, a laptop handed back suspiciously empty, and a business that needs to know what happened before it was wiped. Forensic recovery is data recovery with the burden of proof attached — and it's some of the most important work we do.
Free diagnostic on every forensic job. Fixed quote before any work — and no fix, no fee.
Every forensic job starts by matching the symptoms to the fault — these ten cover almost everything that reaches the bench.
The case we handle most — traces of the wipe, the tool used, and the activity before it can usually be reconstructed.
Windows records which USB devices connected and when; cross-referenced with file access, it shows what may have been copied.
Uploads to webmail, Dropbox, Google Drive or WeTransfer leave traces in history, logs and file remnants.
Deleted documents and emails carved back and presented with a defensible, hash-verified methodology.
When a file was really created, opened or changed — rebuilt from the file system, USN journal and logs.
Establishing what confidential material was accessed, copied or removed, and by which account.
Evidence-grade investigation of company equipment under company policy, often via solicitors.
Forensic recovery of footage and device data needed for a claim or case.
Documented, impartial findings for internal HR processes, insurers and tribunals.
Work carried out to directions agreed between the parties' legal teams.
It's a story we handle constantly for employers. An employee copies company data off their work laptop — to a USB stick, a personal email account or a cloud drive — and then wipes or resets the machine before handing it back, hoping to erase the trail. The employer is left with a laptop that looks empty and a strong suspicion that something left with the person. This is exactly what forensic recovery is built for. Even after a reset or a wiping tool has run, a great deal survives: which wiping tool was used and precisely when, which USB devices were connected in those final weeks and what was opened just before they were, what was uploaded to webmail or cloud services, and deleted files carved back from the drive. We turn those traces into a detailed, plain-English forensic report you can act on.
Our forensic bench runs OSForensics, the PassMark investigation suite, for the heavy lifting: recovering deleted files, indexing and searching the whole drive, reconstructing a minute-by-minute activity timeline from file-system timestamps and the Windows USN journal, and pulling the artefacts that matter — connected-USB history, browser and download history, webmail traces, wireless networks and recent-file lists. Alongside it we run Passware Kit Forensic to open any password-protected or encrypted files and BitLocker volumes that stand in the way, where doing so is lawful. Every step is done on a hardware write-blocked, hash-verified image of the original, so the source media is never altered and any party can prove the copy is exact.
What makes recovery forensic is procedure at every step: originals write-blocked from first contact, images verified by cryptographic hash (MD5, SHA-1, SHA-256), a documented chain of custody from your hands to ours, and reporting split into clear findings and a technical appendix so it holds up in a tribunal or court. We're happy to work to directions agreed between solicitors. One boundary, stated plainly: forensic work needs a lawful basis — your own devices, company equipment under company policy, or matters instructed through solicitors and insurers. We don't provide covert access to someone else's private device, however strong the suspicion; where there's a legitimate route, we'll take it properly.
Forensic work is evidence, not just data — so procedure and tooling matter at every step:
Our core investigation suite — deleted-file recovery, whole-drive indexing and search, and artefact extraction across hundreds of file formats with OCR.
A minute-by-minute reconstruction of file and system activity from timestamps, the USN change journal and system logs — what happened, and exactly when.
Which external devices were connected, when, and what was accessed around those times — the backbone of a data-theft investigation.
Opens password-protected and encrypted files and BitLocker volumes standing in the way of evidence, where lawful.
Every original is write-blocked from first contact and imaged to a hash-verified copy (MD5, SHA-1, SHA-256) that any party can prove is exact.
Documented custody from your hands to ours, and reports split into plain-English findings and a technical appendix built to stand up in a tribunal or court.
One boundary, stated plainly: forensic work needs a lawful basis — your own devices, company equipment under company policy, or matters instructed through solicitors and insurers. We never provide covert access to someone else's private device.
For a forensic case, preserve the device exactly as it is — powered off — and don't let anyone log in, 'have a look' or re-image it, as each of those overwrites recoverable evidence. Note the dates and names in question. Remove the drive and send it labelled; if the whole device must be preserved as evidence, call us first on 0800 689 0668 to arrange handling under a documented chain of custody.
Most customers post or courier their device to us — it arrives next morning, and the free diagnostic starts the day it lands.
Sending a drive from a computer, laptop, MacBook, iMac or server? Please remove the internal hard drive or SSD and send us just the drive — we don't provide an internal drive-removal service. If the storage is soldered in (e.g. Apple Silicon), call us first on 0800 689 0668.
↓ Print the booking-in & shipping form (PDF)
Mark the package for the attention of Leeds Data Recovery and we'll call you as soon as we diagnose your media.
Not sure what to send? Call 0800 689 0668 first or use the free online diagnostic.
Free diagnostic, fixed quote, no fix no fee — start now or call the freephone.