Email and Cloud Exfiltration Forensics

Material going out by mailbox or cloud account gets recorded twice. Once by the machine, once by the service. Any sound investigation reads the pair. Your tenancy supplies rules, attachment history and sign-in patterns. Your device supplies browser and sync traces. Both halves get lined up into a single dated account, for the professional and legal offices around Union Street and the energy consultancies instructing them.

Footing first. Bench time after. The free diagnostic opens the job, a written scope follows it, and forensic fees clear ahead of any examination. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// the patterns that start these cases

What a departure through the mailbox looks like

Every one of these has an innocent explanation of its own. Put together they make a pattern worth examining.

Large attachments heading to the same private address week after week
A forwarding rule turns up in a mailbox after the person has gone
Company accounts signed into at hours when the office was shut
A private Dropbox, OneDrive or Google Drive logged in on a work laptop
SharePoint or the shared drive downloaded in bulk before a leaving date
The mailbox was deleted before anybody had looked inside it

The way a mailbox behaves on its way out

A mailbox being used to shift material behaves in a way you can learn to recognise. Attachment sizes climb while the recipient list narrows to one private address. A rule appears and starts forwarding chosen mail with nobody watching. Searches read like hunting rather than working: client names, project codes, price lists. Access drifts into evenings and weekends. Mail platforms note every bit of that, and each item is pulled out and dated during the examination.

Personal cloud accounts on company kit

The device gives you the other half. Browser traces catch accounts being created, then signed into, at Dropbox, OneDrive or Google Drive from a work machine. Sync-client logs and folder layouts show which directories were set to mirror upward, and from which date. Upload residue, meaning cached pages, confirmation screens and recent-file lists, sits on the image well after someone has cleared their browsing history. A personal account appearing on work hardware during a final month is rarely there by accident.

The audit trail your tenancy already keeps

Microsoft 365 and Google Workspace hold evidence of their own, and it frequently decides matters. Message movement, sharing and downloads land in Microsoft Purview audit logs and eDiscovery exports. Google Vault retains mail and files. SharePoint and OneDrive logs record every share and bulk download with an account and an hour against it. Dropbox keeps version history and recoverable deletions. A deleted mailbox can often be recovered out of retention or from backup, though not for ever. That is the argument for ringing early.

Two records, one account of events

Findings persuade when they agree with themselves. The tenancy logs a 3.4 GB download at 22:38. Two minutes on, the same files show up inside a personal sync folder on the device. Browser history closes the loop. Service evidence and machine evidence get built into a single run, and where they disagree we flag it rather than paper over it. Everything, mailbox export and audit extract and the disk image, is hashed before any account gets suspended or any licence reclaimed.

Method underneath the whole practice sits at the forensic recovery hub. Credentials and server records continue on insider threat forensics. Employer casework is employee data theft. Holding material is legal hold and chain of custody. Figures are on the prices page.

// what you get back

Findings out of the tenancy and the machine

Service records and machine traces, checked against each other and set out as one run.

Attachments

What went out to private addresses, at what size, and on which dates.

Rules

Forwarding and deletion rules, their creation dates, and what they caught.

Access

Sign-in hours and locations, with out-of-hours clusters marked up.

Cloud residue

Personal accounts, sync folders and upload leftovers on work kit.

Audit extracts

Share, download and export events lifted from M365 and Workspace logs.

Mail restored

Messages and entire mailboxes brought back from retention or backup.

// the price, and who we may act for

Forensic fees, and the footing underneath them

The money, stated plainly

Each instruction opens on the free diagnostic. Allow 2 working days from the date a device reaches this bench. Forensic casework sits outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. Where a scope reaches across several accounts, or a whole tenancy, we quote in writing once the free diagnostic is done. You will find both figures repeated on the prices page, and we take nothing until a scope is agreed in writing.

The footing we need

Mailbox and cloud work runs on tenancies and devices the company owns, or on the written instruction of a solicitor. Three doors in, and we have never found a fourth. Kit the business itself owns. A written instruction out of a solicitor, an insurer or from the court. Or else a device that genuinely belongs to the client, which in a matrimonial matter takes in one held between the two of them. Nothing gets hacked at this bench. Live traffic is never intercepted. Where the instructing client holds no right to look inside a device, we hold none either.

// getting your device to us

Getting it to the bench — plainly done

Cloud material is frequently preserved by export rather than by parcel. Ring 0800 689 0668 and we will sort out which parts can be captured remotely and which must travel. We run no collection service, so anything physical comes to Edinburgh tracked and insured, or across the counter, and custody starts at the signature.

Still bolted into a laptop, desktop, MacBook, iMac, server or CCTV / DVR box? Get the hard drive or SSD out first. The bare drive travels on its own. Stripping machines down is not a job this lab takes on. Flash soldered to a motherboard, as on Apple Silicon Macs and a couple of very thin laptops, is our one flat no: if it will not unbolt, it cannot be worked on.

  • Bubble wrap, then a rigid box or padded envelope packed tight enough that nothing rattles. Keep the cables, caddies and power bricks at home.
  • Print the shipping & booking-in form (PDF). Name, mobile number, two lines on what went wrong. In the box with the drive.
  • Royal Mail Special Delivery is tracked and insured door to door. Your own courier account does the same job if you would rather use it.
  • Handing it over yourself instead? Reception takes drop-offs at the address below, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Edinburgh Data Recovery

4 Redheughs Rigg
Westpoint, South Gyle
Edinburgh, EH12 9DQ

↓ Print the shipping & booking-in form (PDF)

Address it for the attention of Edinburgh Data Recovery. From Aberdeen that is roughly 130 miles and two and a half hours down the A90, or next working day by tracked post if you would rather not make the run. You get a call the moment it is booked onto the bench.

Not sure what belongs in the box? Ring 0800 689 0668 before you tape it shut, or work through the free online diagnostic.

// email and cloud · asked before instruction

What IT managers ring about

Often, provided we hear early enough. A deleted mailbox normally sits in retention for a spell during which restoring it is still possible, and a litigation hold or a backup stretches that further. The window has an end, so preservation ought to start the day somebody first asks the question.
The configuration tells you what it was built to catch. What actually moved comes from message trace and audit records, for as long as those retain anything. Once that window has closed, the pattern sitting at the receiving end on the device normally covers the gap, and we are explicit in the report about which finding leans on which source.
No. A private account sits beyond what an employer may reach, and beyond us as well. We work the company half of the exchange: tenancy logs, machine traces, and anything recovered afterwards under a specification of documents. That half is normally enough.
Secure it, certainly, but preserve first. Export the mailbox. Pull the audit logs down. Image the device. Reclaim licences or purge the account after that. Running the sequence backwards has destroyed more email evidence than any departing employee ever managed, and we will walk your IT people through the order on the phone.

The tenancy remembers. For a while.

Retention windows shut on their own schedule and not on yours. Ring the freephone first.