Back to case studies

Deleted files in an employee-theft prosecution: what the artifacts proved, and what they couldn't

Criminal Defense
Updated Jul 27, 2026
8 min read

The situation

A company discovered roughly $185,000 had moved over eight months to a vendor account management didn't recognize, approved through the financial controller's user account. Shortly after questions started, spreadsheets, PDF invoices, and emails disappeared from the controller's work laptop. Charges followed for theft, computer crime, and falsification of business records.

What the other side said the evidence showed

The prosecution's theory was clean and intuitive: the defendant created a fictitious vendor, approved payments to it, deleted the supporting records, and concealed the theft. The deletions themselves were offered as evidence of consciousness of guilt.

Deletion is an event on a device. It is not, by itself, an act by a person.

The single most common overreach in digital evidence is collapsing four separate findings into one conclusion. A competent examination keeps them apart: a file was deleted; a user account performed an action; a device recorded an action; a specific human being performed that action. Those are four different claims requiring four different kinds of proof, and forensic artifacts routinely establish the first three while saying nothing at all about the fourth.

The other half of this case is preservation. Before the laptop ever reached an examiner, the company's own IT employee had opened it, signed into the defendant's account, run antivirus software, and copied folders. That does not destroy a case, but it means some portion of the timeline now reflects the company's activity rather than the defendant's — and if nobody documents which is which, the whole timeline is contestable.

This is why counsel on either side should ask, early, who touched the device before the examiner did. The answer frequently changes what the evidence can support.

What the examination involved

1

Documented chain of custody, including what happened before intake

Who seized the laptop, when it was handled, whether it was powered on, what software was run, and when it reached the lab — plus a written statement from the IT employee describing every pre-intake action. That statement is what makes it possible to separate the defendant's activity from the company's from the examiner's.

2

Imaged the drive through a hardware write blocker

A bit-for-bit forensic image with SHA-256 hashes calculated on both the source and the image. Matching values establish the copy accurately represents the drive. All analysis then happens on the copy; the original is never worked on.

3

Examined deleted NTFS Master File Table records

The deleted files' MFT records survived, preserving original names, paths, sizes, creation and modification timestamps, and file-system deletion status. One spreadsheet was recovered intact from unallocated space.

4

Analyzed document metadata

The recovered spreadsheet carried authorship metadata, creation on that laptop, saves under the defendant's Windows profile, and six months of revisions. It also contained a hidden worksheet listing vendor payment amounts and bank account details.

5

Correlated USB, Registry, LNK, and Jump List artifacts

Registry entries recorded a USB device by serial number connecting on specific dates. LNK shortcut files referenced documents opened from that device, and a Jump List showed the spreadsheet opened repeatedly in Excel. The serial number matched the drive found in the defendant's desk.

6

Checked the email deletions against the mailbox audit log

Microsoft 365 audit records showed the vendor emails were deleted — but after the company had already suspended the account, and by an administrator account rather than the defendant's.

What the examination found

  • The vendor spreadsheet existed on the laptop, was associated with the defendant's user profile, and matched the disputed transactions
  • Independent artifacts — Registry, LNK, Jump List, and the physical USB drive — corroborated each other rather than resting on a single source
  • The relevant files were deleted before the laptop was seized
  • The email deletions attributed to the defendant were actually performed by an administrator account after the account was suspended
  • Remote-login activity from another employee's workstation appeared during one disputed transaction
  • Pre-intake activity by company IT had altered part of the timeline

Outcome

The forensic record supported significant parts of the prosecution's theory while eliminating one of its assumptions outright. A defensible expert conclusion in a matter like this reads: the artifacts are consistent with the spreadsheet being created, stored, accessed, and deleted within that Windows user environment; the evidence does not independently establish who was physically operating the laptop at each relevant time.

Takeaways for counsel

  • Ask who handled the device before the examiner did, and get it in writing. Pre-intake activity by internal IT is extremely common and rarely documented on its own.
  • Treat "the account did it" and "my client did it" as separate propositions, and make the expert say which one the artifacts actually support.
  • Audit logs frequently contradict the narrative built around them — the mailbox deletion in this case was assumed to be the defendant's and wasn't.
  • Corroboration across independent artifact types is what makes digital evidence durable. A single artifact standing alone is the one to attack.
  • Shared credentials, administrator access, and remote sessions are the standard avenues for reasonable doubt about exclusive access. Ask for the logs that would show them.

Related questions

If a file was deleted, can it still be recovered?

Often, at least in part. On NTFS the Master File Table record commonly survives deletion, preserving the file's name, path, size, and timestamps even when the contents are gone — and the contents themselves are frequently recoverable from unallocated space if the storage hasn't been reused. Whether recovery succeeds depends on the file system, how much the device was used afterward, and whether it's an SSD with TRIM active.

Does metadata prove who created a document?

No. Metadata establishes the user profile and system involved, which is not the same as identifying the human at the keyboard. Shared credentials, administrator access, and remote sessions all produce artifacts identical to the account owner's. An examiner who testifies past that distinction is exceeding what the evidence supports.

Have a case that turns on digital evidence?

Tell us the case, the device, and your deadline. The scoping call is free, and we'll tell you honestly whether an examination is worth it.

Appointed counsel: see our Colorado public defender program.

This case study is illustrative. It is written to show how digital evidence is examined, challenged, and presented in court; it is not an account of any client matter, and any resemblance to a specific case is unintended. The techniques and failure modes described are real. Nothing on this page is legal advice, and no result is a prediction or guarantee of the outcome of any other matter.