<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Burgess Forensics</title>
	<atom:link href="https://burgessforensics.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://burgessforensics.com/</link>
	<description>Computer Forensics, Electronic Discovery &#38; Expert Witness</description>
	<lastBuildDate>Tue, 04 Aug 2026 21:10:04 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://burgessforensics.com/wp-content/uploads/2016/08/burgess-42x42.png</url>
	<title>Burgess Forensics</title>
	<link>https://burgessforensics.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Metadata You Didn&#8217;t Know You Were Sending</title>
		<link>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/</link>
					<comments>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 04 Aug 2026 21:10:04 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16161</guid>

					<description><![CDATA[<p>You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren&#8217;t looking. That paperwork is metadata — data about data. And it travels with your files whether or not you invited it along for the trip. [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/">The Metadata You Didn&#8217;t Know You Were Sending</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You thought you sent a one-page letter. What you actually sent was a one-page letter and a small pile of paperwork the letter filled out about itself when you weren&#8217;t looking.</p>
<p>That paperwork is metadata — data about data. And it travels with your files whether or not you invited it along for the trip.</p>
<p style="text-align: left;">Metadata is the stuff a document quietly jots down while you&#8217;re jotting down words. There’s a lot of potential information there: Who created it, when, and on what computer.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/stowaway.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16166 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/stowaway-300x225.jpg" alt="" width="300" height="225" /></a> Who edited it, and when they last saved it . Where a photo was taken, down to the GPS coordinates. What camera, what settings, what software. None of it shows up on the page. All of it comes along, like a stowaway.</p>
<p>&nbsp;</p>
<p>Most of the time this is harmless, but occasionally, it&#8217;s the whole story.</p>
<h4>A photo is a very talkative little file.</h4>
<p>Take a picture with your phone and you&#8217;ve created a small autobiography. The image, surely, but tucked inside is a section called EXIF data: the make and model of the phone, the date and time down to the second, and, if location services were on, the exact spot on Earth where you stood. Share that photo in its original form and you may be handing over your home address without meaning to.</p>
<p>The good news: most social platforms started stripping this out a few years ago when there was a public hue and cry about it. The bad news: &#8220;most&#8221; is not &#8220;all,&#8221; and emailing the original file, or dropping it in a shared folder, sends the whole talkative package along.</p>
<h4>Documents keep a diary too</h4>
<p>A Word document remembers more than the final draft. Depending on your settings, it can carry the author&#8217;s name, the company the software was registered to, how long the file was open, and sometimes, tracked changes and comments you thought you&#8217;d removed. Every &#8220;on second thought, delete that paragraph&#8221; can live on in the file&#8217;s memory.</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16162 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/genrating-metadata-300x225.jpg" alt="" width="300" height="225" />The internet is dotted with cautionary tales of press releases and legal filings that were sent out with the edits still readable underneath. The same is true with newsworthycongressional hearings. Most of us are not popular enough to warrant interest from the government. Still, the words on the page said one thing but the metadata said &#8220;here&#8217;s what we almost admitted.&#8221; Oopsie.</p>
<p>&nbsp;</p>
<h4>So, what to do?</h4>
<p>There&#8217;s no need to get paranoid about this. Depending on what you’re shipping for, your grocery list is not a national secret. But a few practical habits go a long way:</p>
<ul>
<li><strong>Before sending anything sensitive, look under the hood.</strong> In Word on Windows, &#8220;Inspect Document&#8221; should find and remove hidden data, comments, and tracked changes. Do it on the final version, not the draft.</li>
<li><strong>Turn off location tagging for your camera</strong> if you don&#8217;t need it — or scrub EXIF data from photos before sharing the originals. By the way, if litigation is foreseen that involves these photos, don’t scrub the EXIF metadata. It will be considered spoliation of data and will go poorly for you if and when it goes to court.</li>
<li><strong>Remember that &#8220;delete&#8221; inside a file often just means &#8220;hide.&#8221;</strong> Removing a comment from view is not always the same as removing it from the file.</li>
</ul>
<p>None of this requires becoming a hermit. It&#8217;s the digital equivalent of checking your pockets before you send the coat to the cleaners.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/hermit.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16163 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/hermit-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p>Metadata isn&#8217;t sinister. It&#8217;s just honest — sometimes more honest than we&#8217;d like. The trick is knowing it&#8217;s there, so you decide what to share instead of the file deciding for you.</p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … </strong></em><a href="https://burgessforensics.com/subscribe/"><em><strong>Subscribe now</strong></em></a><em><strong>!</strong></em></p>
<p>The post <a href="https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/">The Metadata You Didn&#8217;t Know You Were Sending</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-metadata-you-didnt-know-you-were-sending/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</title>
		<link>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/</link>
					<comments>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 21:43:33 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16150</guid>

					<description><![CDATA[<p>The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: &#8220;produce as PDF, that&#8217;s fine.&#8221; Maybe not so fine when that same attorney later pays me to explain why the file on my screen can&#8217;t [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/">Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The format language in a discovery request is easy to skip over. It looks like boilerplate. It reads like boilerplate. It is actually boilerplate. And so it gets waved through: &#8220;produce as PDF, that&#8217;s fine.&#8221; Maybe not so fine when that same attorney later pays me to explain why the file on my screen can&#8217;t answer the question the case now turns on.</p>
<p>Here&#8217;s the thing the other side already knows: whoever picks the format picks what you get to see. It&#8217;s just how the rules work. Under Federal Rule of Civil Procedure 34(b)(2)(E), the party asking for the documents gets to specify the form they arrive in. Don&#8217;t specify, and the choice falls to the producing side, with &#8220;reasonably usable&#8221; form as the only floor — and reasonably usable is a long way from native. Say nothing about format and you&#8217;ve handed them the pen.</p>
<p>Native files vs. PDFs sounds like an argument for the IT department, right? It isn&#8217;t. It&#8217;s one of the quietest, most consequential fights in the whole discovery process, and it&#8217;s worth having on purpose.</p>
<h4>A PDF is a photograph of a document, not the document</h4>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/PDF-vs-Word-doc.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-16154 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/PDF-vs-Word-doc-300x164.jpg" alt="" width="347" height="190" /></a>A native file is the thing itself &#8211; the spreadsheet with its formulas still doing math, the email with its full routing header, the Word file that still remembers every draft, the photo that quietly wrote down where and when it was taken. I have a paragraph in my engagement letter saying so, albeit a bit more succinctly. A PDF or a TIFF is a picture of that file after someone chose the pose.</p>
<p>What really gets me is when evidence is produced as a printout of a PDF of a scan of a PDF created from the actual original file. Happens all the time. But it’s several steps away from what really happened and far from the metadata that tells the real story.</p>
<p>Such “pictures” drop exactly the parts that tend to win cases. Most of the metadata, describing fields such as who made it, when, on what device, and sometimes where tends to get lost when a PDF is generated from it. This is the difference between &#8220;he says he wrote it in March&#8221; and knowing, to the minute, that he didn&#8217;t.<a href="https://burgessforensics.com/wp-content/uploads/2026/08/4-million.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class=" wp-image-16151 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/4-million-300x167.jpg" alt="" width="314" height="175" /></a></p>
<p>A spreadsheet may show you a very precise value of 4,203,722.46 in the flattened PDF version but hides the formulae and structure that generated a possibly different number. A document that previously contained all the things people put in a document before they remembered other people would read the tracked changes, comments, hidden rows? Native format keeps them. The flattened copy forgets them, conveniently.</p>
<p>Hash values and container data are integrity signals that may let you and me confirm that the document produced is the same as the original are casualties of a PDF export. It snaps that verification thread and asks you to just take everybody&#8217;s word for it instead.</p>
<p>None of it comes back, either. You can&#8217;t un-flatten a PDF into the original any more than you can un-fry a flapjack. Once it&#8217;s produced that way, the missing data isn&#8217;t hiding from you. It&#8217;s gone.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/08/unfrying-a-flapjack.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-16156 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/08/unfrying-a-flapjack-300x164.jpg" alt="" width="476" height="260" /></a></p>
<p>I had a case where the “date digitized” EXIF metadata from a series of photos supported one side’s story. However, deeper in the metadata, there was satellite data that cast real doubt on the story being told. Satellites and their atomic clocks don’t lie about the time or the day.</p>
<h4>Why the other side is so agreeable about it</h4>
<p>Producing in PDF usually isn&#8217;t laziness. It&#8217;s control wearing the costume of laziness. A flattened production is easier to redact, easier to Bates-stamp, and, in a happy coincidence, easier to sanitize. The timestamp that wrecks the timeline, the author who wasn&#8217;t supposed to be within a mile of that memo, the formula that shows how a number really got built: all of it vanishes in the conversion, and it vanishes wearing the respectable coat of &#8220;routine document handling&#8221; rather than the orange jumpsuit of spoliation.</p>
<p>To be fair, imaged production isn&#8217;t always a dodge. Sometimes there are honest reasons for it — privilege review, redacting personal or protected information, or real proportionality under Rule 26(b)(1) when native would cost more than the whole dispute is worth. Those reasons are legitimate. The trick is to make the other side say so out loud, in the protocol, so that &#8220;we imaged it&#8221; has to be justified rather than simply assumed.</p>
<p>I should be clear that &#8220;save as PDF&#8221; is also a genuinely lousy way to strip metadata even when someone&#8217;s trying to be honest. It leaves things behind and takes things it shouldn&#8217;t. But that&#8217;s a different article. For today: the party that controls the format controls the evidence, and they know it even if your side doesn&#8217;t.</p>
<h4>The fight is won in the ESI protocol, not in a motion six months later. <a href="https://burgessforensics.com/wp-content/uploads/2026/08/Stripping-metadata.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class=" wp-image-16155 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/08/Stripping-metadata-300x167.jpg" alt="" width="337" height="188" /></a></h4>
<p>This is the part I most want attorneys to hear. By the time you&#8217;re standing in front of a judge complaining about a bad production, you&#8217;re asking to redo work the other side has every incentive to slow-walk into the next fiscal year — and you&#8217;re explaining to your client why the schedule, and the bill, went sideways. Nobody enjoys that conversation. Least of all the person who once said &#8220;PDF is fine.&#8221;</p>
<p style="text-align: left;">So specify the format on the front end, in writing:</p>
<ul>
<li><strong>Ask for native formats, with metadata, by default</strong> for anything data-rich — spreadsheets, databases, structured exports — with load files that actually carry the field data. Boring to negotiate. Priceless to have.</li>
<li><strong>Name the metadata fields you want.</strong> Custodian, author, created and modified dates, an MD5 or SHA-1 hash, and parent/child relationships so attachments stay tied to their emails. &#8220;With metadata&#8221; is an invitation for the other side to read the phrase as generously as their conscience allows.</li>
<li><strong>Reserve the right to request native format</strong> for anything produced as an image, and say so up front — so when you invoke it, it&#8217;s a term of the deal and not an ambush they get to act wounded about.</li>
<li><strong>Bring your examiner in before the language is set, not after the production disappoints.</strong> Format specs written without technical input have a real talent for asking, very precisely, for the wrong thing.</li>
</ul>
<h4>The bottom line</h4>
<p>This is not enhance-the-reflection-in-the-sunglasses forensics. It&#8217;s plumbing. It&#8217;s unglamorous, it&#8217;s easy to skip, and it is very often the only thing standing between evidence you can build a case on and a tidy picture of evidence you have to take on faith.</p>
<p style="text-align: left;">Courts increasingly expect native production where format carries meaning, and (hopefully) increasingly treat &#8220;well, we already gave you a PDF&#8221; as the weak answer it is. But you don&#8217;t drift there by luck. You get there by treating format as a substantive term of the case — argued with the same seriousness as scope and custodians, and about a thousand times more attention than it usually gets. <a href="https://burgessforensics.com/wp-content/uploads/2026/08/checkbook.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16152 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/08/checkbook-300x167.jpg" alt="" width="300" height="167" /></a></p>
<p>Have the fight early. It&#8217;s a great deal cheaper than the one you&#8217;ll have later, in front of a judge, with your client and their checkbook watching.</p>
<p><em>What&#8217;s the worst production-format surprise you&#8217;ve run into — native you wish you&#8217;d demanded, a PDF that turned out to be hiding the whole case, or something else entirely?</em></p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><strong><em>Don’t miss a single issue of our informative newsletter … </em></strong><a class="uRHgOlUNgMoEOwgGoLxklVwtWfKTKfVqDQxSCg " tabindex="0" href="https://burgessforensics.com/subscribe/" target="_self" data-test-app-aware-link=""><strong><em>Subscribe now</em></strong></a><strong><em>!</em></strong></p>
<p>The post <a href="https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/">Native Files vs. PDFs: Why Discovery Format Fights Are Worth Having</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/native-files-vs-pdfs-why-discovery-format-fights-are-worth-having/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Why &#8220;He Deleted Everything&#8221; Is Usually Good News for Your Case</title>
		<link>https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/</link>
					<comments>https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Thu, 30 Jul 2026 19:49:28 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<category><![CDATA[CSI]]></category>
		<category><![CDATA[digital forensics]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[Mar-A-Lago]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[testimony]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16136</guid>

					<description><![CDATA[<p>When a client or opposing party says &#8220;he deleted everything,&#8221; attorneys often hear a dead end. I hear the opposite and you probably should as well. In digital forensics, deletion is rarely the end of the story. In fact, it may be the beginning of a better one. What most people don’t understand is that [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/">Why &#8220;He Deleted Everything&#8221; Is Usually Good News for Your Case</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>When a client or opposing party says &#8220;he deleted everything,&#8221; attorneys often hear a dead end. I hear the opposite and you probably should as well. In digital forensics, deletion is rarely the end of the story. In fact, it may be the beginning of a better one.</p>
<p>What most people don’t understand is that hitting delete doesn’t erase data. It tells the system that the space can be reused. Think of it less like shredding a document and more like taking the label off a file folder and telling the office it’s okay to reuse the drawer — the pages are still in there until someone actually needs the room and drops the pages in a shredder. Until something overwrites it, the underlying data often sits right where it always was. On phones, computers, and servers, deleted files, messages, and app data are frequently recoverable in whole or in part. While deleted phone data is somewhat more ephemeral and tends to become unrecoverable after a couple of months, other platforms are less so. In many cases, we have recovered them months or even years later.</p>
<p>Still, recoverability is only half of it. The more valuable half is what the act of deletion reveals.</p>
<p style="text-align: left;"><strong>Deletion leaves its own trail.</strong> Modern devices tend to be relentless record-keepers. They document nearly everything, often including their own attempted cover-ups. When someone deletes files, wipes an app, clears a chat, or runs &#8220;cleaner&#8221; or “wiping” software, those actions frequently generate their own artifacts: timestamps, log entries, system events, and traces in backups and cloud sync. In practice, you may be able to<a href="https://burgessforensics.com/wp-content/uploads/2026/07/Deleted-stuff-copy.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16138 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Deleted-stuff-copy-300x167.jpg" alt="" width="300" height="167" /></a> prove not just what existed, but when it was removed, and sometimes that a wiping tool was run at 2 a.m. the night before a device was handed over. We had a case where the inspection got stalled for a couple of days to give time for the IT guy to scrub away. However, the file-destroying tool kept a record of every single file it destroyed over the previous very busy nights.</p>
<p>Nothing says &#8220;nothing to hide&#8221; quite like a freshly installed disk-scrubbing utility. That timeline can be more persuasive to a fact-finder than the deleted content ever would have been.</p>
<p><strong>Intent is the story.</strong> A single deleted photo is a fact. A coordinated wipe — messages cleared, a drive reformatted, cloud backups switched off, all clustered around a key date — is a narrative unto itself. Courts have well-developed doctrine here. Spoliation of evidence can support sanctions and, in many jurisdictions, the dreaded adverse-inference instruction: the jury may be told they can assume the destroyed evidence would have hurt the party who destroyed it. The person trying to make the problem disappear might just be manufacturing a bigger one, wrapped up with a bow on top.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/07/guilty-guy-copy.jpg"><img loading="lazy" decoding="async" class="size-medium wp-image-16139 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/07/guilty-guy-copy-300x164.jpg" alt="" width="300" height="164" /></a></p>
<p><strong>The copies that survive.</strong> Data rarely lives in one place. A message deleted on a phone may survive in a backup, on the other party’s device, in a cloud account, or on a synced laptop nobody remembered was still logged in. Deleting the local copy does nothing to the dozen copies elsewhere. The modern device can be quite the bothersome gossip &#8211;  it tells your secrets to every other device it meets. Part of a competent forensic examination is simply knowing where those copies tend to hide.</p>
<p>Besides the potentially recoverable file being looked for, many programs, especially Microsoft Office, make invisible copies every time a file is open. Invisible to the user, that is – not to the examiner.</p>
<p><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-16137 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Bucket-o-coffee-copy-e1785439723662-300x205.jpg" alt="" width="294" height="201" />So, when the other side deletes everything, they may accomplish three things that help you: they leave recoverable data behind, they create adocumented record of the destruction, and they hand you a consciousness-of-guilt argument you didn’t have before. That’s a rough return on investment for a night or two filled with buckets of coffee and frantic clicking.</p>
<p style="text-align: left;"><strong>A few practical notes for counsel.</strong> Move fast. Recoverability drops as devices keep running and space gets overwritten, so preservation letters and litigation<a href="https://burgessforensics.com/wp-content/uploads/2026/07/Rushing-attorney-copy-e1785439849217.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class=" wp-image-16140 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Rushing-attorney-copy-e1785439849217-300x191.jpg" alt="" width="550" height="351" /></a> holds matter enormously.</p>
<p style="text-align: left;">Preserve the device itself, not just exports; a proper forensic image captures far more than a manual copy. And loop in an examiner early, before well-meaning IT staff or clients &#8220;poke around just to check&#8221; and overwrite the very evidence you’re trying to save. Curiosity has damaged more cases than it has solved.</p>
<p style="text-align: left;">&#8220;He deleted everything&#8221; isn’t the moment your case falls apart. More often, it’s the moment it gets interesting.</p>
<p><strong>A question for the litigators:</strong> what’s a situation you’ve had where deleted data actually strengthened your side of the case? I’d be curious to hear how it played out. The best forensic stories usually start with someone who was very sure they’d covered their tracks.</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe now</a>!</strong></em></p>
<p>&nbsp;</p>
<p>The post <a href="https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/">Why &#8220;He Deleted Everything&#8221; Is Usually Good News for Your Case</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/why-he-deleted-everything-is-usually-good-news-for-your-case/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Your Smart Home Is Testifying Against You</title>
		<link>https://burgessforensics.com/your-smart-home-is-testifying-against-you/</link>
					<comments>https://burgessforensics.com/your-smart-home-is-testifying-against-you/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 20:54:30 +0000</pubDate>
				<category><![CDATA[Attorneuys]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Forensic stories]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=16122</guid>

					<description><![CDATA[<p>A fitness tracker once told me the exact moment its wearer stopped moving. Not slowed down. Stopped. The device wasn&#8217;t built to establish a time of death. It was builtto count steps and nag its owner about standing up more often. But it kept a continuous record, and that record answered a question nobody had [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/your-smart-home-is-testifying-against-you/">Your Smart Home Is Testifying Against You</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: left;">A fitness tracker once told me the exact moment its wearer stopped moving. Not slowed down. Stopped. The device wasn&#8217;t built to establish a time of death. It was builtto count steps and nag its owner about standing up more often. But it kept a continuous record, and that record answered a question nobody had thought to ask it.</p>
<p>I can&#8217;t reveal much about the case. The survivors believed the facility had let conditions get too hot for too long with too little warning. The other side believed close to the opposite: that the tracker&#8217;s own history showed the deceased knew better than to push that hard through a changing but controlled environment. Both sides were arguing about the same person&#8217;s habits, and the tracker had a record of them. Dueling cardiologists reached differing conclusions about the fitness level of the deceased.</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-16127 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/heart-rate-300x164.png" alt="" width="300" height="164" />I did not expect a line chart to affect me. Heart rate climbing to a dangerous peak, dropping to zero, then flat and never moving again. Plain as any spreadsheet. Then I imagined what that jagged line meant on the floor of the event.</p>
<p>That case is the whole of digital forensics in one artifact. People imagine this work is about clever adversaries planting evidence. I hear that concern regularly, and it is rarely what actually happened. The real story is duller and much harder to argue with: an ordinary device did exactly what it was built to do, and nobody remembered that what it was built to do includes keeping a record.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/COnnected-house.png"><img loading="lazy" decoding="async" class="size-medium wp-image-16124 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/COnnected-house-300x167.png" alt="" width="300" height="167" /></a>Your house is full of these. A video doorbell logs every motion event with a timestamp, whether or not itsaved any video.A voice assistant logs when it woke up, and sometimes what it heard in the few seconds on either side, depending on a setting its owner has never opened or knew existed. A thermostat infers occupancy from temperature adjustments and motion, which turns out to be a decent proxy for whether anyone was home. A robot vacuum holds a floor plan of every room it has ever cleaned. A car knows where it went and how fast it got there. It is getting harder and harder to have a good ol&#8217; dumb home.</p>
<p>None of this was designed to be evidence,<img loading="lazy" decoding="async" class="size-medium wp-image-16126 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/dumb-house-300x164.png" alt="" width="300" height="164" /> which is one reason it can become powerful evidence when properly authenticated and interpreted. There may still be questions about reliability, chain of custody, retention settings, incomplete logs, and similar issues, but the device itself has no made-up story to keep straight. It is not shaped by human memory in the way witness recollection is, though it still has to be interpreted carefully. Someone can be careful about what they say out loud and still be wearing a watch that logged a heart rate spike at the moment in question.</p>
<p style="text-align: left;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/crook-in-the-themrostat.png"><img loading="lazy" decoding="async" class="size-medium wp-image-16125 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/crook-in-the-themrostat-300x164.png" alt="" width="300" height="164" /></a>The law is still catching up. Carpenter v. United States narrowed the old assumption that anything you hand to a company is fair game without a warrant, at least for cell site location records. Aside from preservation duties, discovery scope, and the need to meet and confer, there is a live question whether that reasoning will narrow access to data from a thermostat, a vacuum&#8217;s floor map, or a year of refrigerator door-open events. Those boundaries are being worked out one motion and one court at a time as we speak. I would not bet on the answers looking the same in five years as they do today.</p>
<p>For lawyers, the lesson is simple: ask early what connected devices were present, where the data is stored, how long it is retained, and who controls it.</p>
<p>In the meantime, the practical reality is simpler. Your home has more employees than you think, and all of them are taking notes. None of it is malicious. Much of it may be discoverable or obtainable, if someone thinks to ask.</p>
<p>What smart-device data point has surprised you most, in a case or in your own house? I&#8217;d love to hear about it.</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p>The post <a href="https://burgessforensics.com/your-smart-home-is-testifying-against-you/">Your Smart Home Is Testifying Against You</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/your-smart-home-is-testifying-against-you/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Future of Expert Testimony in a Digital World</title>
		<link>https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/</link>
					<comments>https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 14 Jul 2026 22:23:12 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15729</guid>

					<description><![CDATA[<p>Twenty years ago, a forensic report about a hard drive was mostly an argument about whether a file existed and when it was last touched. And of course, trying to recover deleted material. Today the same report might need to address whether a video is real, whether a document was generated by a language model, [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/">The Future of Expert Testimony in a Digital World</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Twenty years ago, a forensic report about a hard drive was mostly an argument about whether a file existed and when it was last touched. And of course, trying to recover deleted material. Today the same report might need to address whether a video is real, whether a document was generated by a language model, whether a &#8220;deleted&#8221; text message ever really existed on the device in the first place, and especially, whether the tool used to answer any of those questions is itself reliable enough to stand behind in front of a jury.</p>
<p style="text-align: left;">It doesn’t come up in every case, but when it does, we’d better be ready to answer. Digital forensics has always rested on the idea that a method can be explained, tested, and<img loading="lazy" decoding="async" class="size-medium wp-image-15730 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/Expert-in-the-future-300x168.jpeg" alt="" width="300" height="168" /> challenged — that&#8217;s pretty much the whole premise behind Daubert and Frye. AI-assisted analysis complicates that premise, because a growing number of detection and authentication tools now involve models whose internal reasoning isn&#8217;t fully visible even to the people who built them. Courts are already grappling with what that means for the right to confront the basis of evidence against you, and there isn&#8217;t yet a settled answer For instance, I’ve seen questions about whether Cellebrite might mis‑label a recovered file as‘deleted’ or treat an active file as if ithad been deleted, even though the platform is historically solid and time‑tested in most other respects. Still, that&#8217;s not a hypothetical academic question; it&#8217;s a live one working its way through appellate opinions right now and it&#8217;s going to shape how expert reports get written well into the future.</p>
<p>What&#8217;s changing on the ground, in the meantime, is the volume and variety of source data an expert has to account for. A phone used to mean <a href="https://burgessforensics.com/wp-content/uploads/2026/07/Update-permisisons.jpeg"><img loading="lazy" decoding="async" class="size-medium wp-image-15733 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/Update-permisisons-300x168.jpeg" alt="" width="300" height="168" /></a>call logs and texts. Now it means cloud-synced photo libraries, health data, smart-home integration logs, location history from a dozen apps that nobody remembers granting permission to (or maybe that an update changed the permissions you did or did not grant, and metadata trails that span devices the owner may not even still possess. The expert&#8217;s job isn&#8217;t just extraction anymore — it&#8217;s building a coherent, defensible narrative out of data that lives in more places than any one device.</p>
<p>The next several years will bring a few concrete shifts. Although there will certainly be changing laws for changing environments, standards bodies and courts will move, slowly and , toward requiring more explicit validation testimony for AI-assisted tools. Not just &#8220;the software said so,&#8221; but documented error rates, testing methodology, and version-specific behavior, the same rigor that&#8217;s long been expected of DNA analysis and toxicology. Authentication of video and audio is going to become its own specialized sub-field, distinct from general digital forensics, the</p>
<p><img loading="lazy" decoding="async" class="size-medium wp-image-15731 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/shifting-envrironment-300x168.jpeg" alt="" width="300" height="168" />way arson investigation split off from general fire science. And attorneys are going to need to get comfortable asking experts pointed questions about tool provenance — not because they distrust the expert, but because opposing counsel increasingly will.</p>
<p>None of this replaces the fundamentals. A well-documented chain of custody still matters. So does a methodology that can be explained in plain English to twelve people, a judge, and possibly an attorney who&#8217;ve never heard of a hash value, and an expert willing to say plainly what the evidence does and doesn&#8217;t show — that hasn&#8217;t changed and I don&#8217;t expect it to. What&#8217;s changing is the amount of homework required to get there, and how much of that homework now involves tools that didn&#8217;t exist five years ago.I&#8217;d like to makethis the first in a short series looking at where this field is actually headed, drawing on conversations with people building the tools and writing the standards rather than just my own two cents.</p>
<p style="text-align: left;">If there’s a specific angle—AI detection reliability, Confrontation Clause questions, how courts are handling deepfake authentication—you’d like covered first, I’m glad to hear it. Trial lawyers and judges who live with these issues every day are exactly who I’m hoping to hear from, so please let me know.</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p>The post <a href="https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/">The Future of Expert Testimony in a Digital World</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-future-of-expert-testimony-in-a-digital-world/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Metadata Your Client Is Accidentally Sending to Opposing Counsel</title>
		<link>https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/</link>
					<comments>https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 21:20:25 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cyber Investigations]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Electronic Discovery]]></category>
		<category><![CDATA[Evidence Preservation]]></category>
		<category><![CDATA[Expert Witness Insights]]></category>
		<category><![CDATA[Litigation Support]]></category>
		<category><![CDATA[Technology & Law]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15429</guid>

					<description><![CDATA[<p>Your client didn&#8217;t leak anything on purpose. That&#8217;s usually how it goes. The confidential settlement number, the internal complaint about a coworker, the photo that was supposed to prove they were out of town — all of it can arrive at opposing counsel&#8217;s desk wrapped in a bow, because nobody thought to ask what was [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/">The Metadata Your Client Is Accidentally Sending to Opposing Counsel</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Your client didn&#8217;t leak anything on purpose. That&#8217;s usually how it goes. The confidential settlement number, the internal complaint about a coworker, the photo that was supposed to prove they were out of town — all of it can arrive at opposing counsel&#8217;s desk wrapped in a bow, because nobody thought to ask what was riding along with the file.</p>
<p>Metadata is the paperwork a document fills out about itself. Every photo carries a record of when and where it was taken, and often what device took it.<a href="https://burgessforensics.com/wp-content/uploads/2026/07/metadata-forms.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class=" wp-image-15432 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/metadata-forms-300x169.jpg" alt="" width="279" height="157" /></a>Every Word document remembers who created it, who edited it, and sometimes what earlier drafts looked like — because &#8220;track changes&#8221; doesn&#8217;t always mean what people think it means. Every email carries routing information that shows exactly which server it passed through and when, which is a problem if someone&#8217;s story about when they &#8220;first learned&#8221; something doesn&#8217;t match the timestamps.</p>
<p>I&#8217;ve spent more hours than I&#8217;d like counting looking at metadata that a client&#8217;s own attorney didn&#8217;t know was there. A &#8220;final&#8221; contract whose revision history documented every negotiating position the client took before landing on the last one. A deposition exhibit — a screenshot, no less — whose EXIF data placed the photo three weeks earlier and 200 miles away from where the witness swore it was taken.</p>
<p>None of this requires opposing counsel to be Sam Spade. It requires them to right-click and select &#8220;Properties,&#8221; or open the file in a tool built for exactly this purpose. Metadata review is the price of admission in any competent discovery practice now, and if your side isn&#8217;t doing it, you can safely assume the other side is.</p>
<p style="text-align: left;">The fix isn&#8217;t complicated, but it does require actually doing it before production, not after a client calls you in a panic. Native files should be scrubbed of unnecessary metadata before they go out the door, using proper redaction and metadata-removal tools — not just &#8220;save as PDF&#8221; and hope for the best, because that conversion process is notoriously bad at actually stripping what needs stripping. Track changes and comments need to be resolved and cleared, not just hidden from the default view. <a href="https://burgessforensics.com/wp-content/uploads/2026/07/judge-grimm.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class=" wp-image-15430 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/07/judge-grimm-300x169.jpg" alt="" width="318" height="179" /></a>Photos being produced as exhibits should have their embedded location and device data reviewed before anyone decides whether that data helps or hurts the case — because sometimes it helps. You don&#8217;t want to accidentally destroy evidence (or let your client do it accidentally on purpose) when you’re just trying to be tidy. Frankly, destroying evidence when litigation is anticipated is a very large no-no at which a judge may frown deeply – sometimes with sanctions.</p>
<p style="text-align: left;">The flip side of all this, of course, is that the same sloppiness that burns your client can work in your favor against the other side. A produced document with intact metadata is a gift. It tells you who really wrote it, when, and whether the &#8220;contemporaneous&#8221; memo was actually drafted three days after the fact. I&#8217;ve had more than one case where a &#8220;Created&#8221; timestamp that didn&#8217;t match anyone&#8217;s testimony blew the case open.</p>
<p style="text-align: center;"><a href="https://burgessforensics.com/wp-content/uploads/2026/07/metadata_rail.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15433 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/07/metadata_rail-300x200.jpg" alt="" width="294" height="196" /></a></p>
<p style="text-align: left;">The broader point is that a document isn&#8217;t just what you can see on the screen. It&#8217;s a small forensic record of its own life, and that record travels with it whether anyone remembers to look or not. Attorneys who treat metadata review as a routine part of both production and receipt catch things that attorneys who don&#8217;t simply never see.</p>
<p style="text-align: left;">What&#8217;s the closest call you&#8217;ve had — metadata that almost went out the door, or metadata you caught on the other side that changed the case?</p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><strong><i>Don’t miss a single issue of our informative newsletter … <a title="https://burgessforensics.com/subscribe/" href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener" data-outlook-id="f80e5241-8c12-4ddf-9750-a82b56a522dd">Subscribe</a>!</i></strong></p>
<p>The post <a href="https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/">The Metadata Your Client Is Accidentally Sending to Opposing Counsel</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-metadata-your-client-is-accidentally-sending-to-opposing-counsel/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Text Messages as Evidence: Harder Than You Think</title>
		<link>https://burgessforensics.com/text-messages-as-evidence-harder-than-you-think/</link>
					<comments>https://burgessforensics.com/text-messages-as-evidence-harder-than-you-think/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Tue, 30 Jun 2026 22:35:26 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15418</guid>

					<description><![CDATA[<p>Copyright 2026, Steve Burgess Somewhere along the way, text messages became some of the most important evidence in litigation that nobody quite knows how to handle properly. A few years ago, that would have been an email thread, such as in the Case of the Computer That Got Lost. But in family law and other [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/text-messages-as-evidence-harder-than-you-think/">Text Messages as Evidence: Harder Than You Think</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Copyright 2026, Steve Burgess</em></p>
<p>Somewhere along the way, text messages became some of the most important evidence in litigation that nobody quite knows how to handle properly. A few years ago, that would have been an email thread, such as in the <a href="https://burgessforensics.com/csi-computer-forensics-real-cases-from-burgess-forensics-12-the-case-of-the-computer-that-got-lost/">Case of the Computer That Got Lost</a>.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/06/smoking-water-pistol.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15420 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/smoking-water-pistol-300x165.jpg" alt="" width="225" height="124" /></a>But in family law and other areas of law, the smoking gun is increasingly a text thread. In employment disputes, it&#8217;s a string of after-hours messages between a supervisor and a subordinate. In contract cases, it&#8217;s the informal &#8220;sounds good, let&#8217;s do it&#8221; exchange that may or may not constitute an agreement. And in criminal matters, text messages can place som<a href="https://burgessforensics.com/wp-content/uploads/2026/06/family-matters.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15419 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/family-matters-300x169.jpg" alt="" width="222" height="125" /></a>eone at a location, establish a relationship, or demonstrate intent in ways that no other evidence can match.</p>
<p>And yet, for something so central to so many cases, the process of getting text messages into evidence in a reliable, authenticated, defensible way remains surprisingly messy.</p>
<p>Let&#8217;s start with collection, because that&#8217;s where most of the problems begin. When a client tells you they have &#8220;all their text messages,&#8221; what they usually mean is that they can scroll through their phone and see the conversation. That&#8217;s not the same thing. What you&#8217;re looking at on the screen is a rendering &#8211; the phone&#8217;s software deciding how to display a conversation that&#8217;s actually stored in a database buried deep in the device&#8217;s file system. Screenshots of that rendering are easy to produce, easy to understand, and almost entirely useless from a forensic standpoint.<a href="https://burgessforensics.com/wp-content/uploads/2026/06/screenshot-hiding-data.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15422 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/screenshot-hiding-data-300x200.jpg" alt="" width="231" height="154" /></a></p>
<p>Why? Because screenshots don&#8217;t contain metadata. They don&#8217;t show you the underlying database records, the timestamps at the system level, the read receipts, the delivery confirmations, or the message identifiers that can establish when a message was actually sent versus when it appeared on the screen. They also don&#8217;t show you what&#8217;s been deleted. And they are pretty easy to fabricate. I could create a fake text message conversation in a minute that would be virtually indistinguishable from a real screenshot to the naked eye. People without any particularly special skill set can do the same. Opposing counsel knows this. The judge probably knows this. Your evidence needs to be better than a picture someone took of their own phone.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/06/Arrestee.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15423 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/Arrestee-300x200.jpg" alt="" width="228" height="152" /></a>Side note: it’s kind of shocking when I see that law enforcement has accepted a screenshot as evidence and arrested someone on that basis and the word of the accuser.</p>
<p>A proper forensic extraction pulls the actual database &#8211; on an iPhone, that&#8217;s the SMS database within the iTunes or Finder backup, or acquired through specialized tools like Cellebrite or GrayKey. On Android devices, the relevant database is typically stored in the device&#8217;s data partition. These extractions capture the complete message record: content, timestamps, phone numbers, group message identifiers, attachment references, and in many cases, deleted messages that the user thought were gone.</p>
<p>But here&#8217;s where it gets complicated. Not all extractions are created equal. A &#8220;logical&#8221; extraction is essentially a backup of what the phone makes available through its normal interfaces &#8211; it gets you active messages but usually not deleted ones. A &#8220;file system&#8221; extraction goes deeper, pulling the database files themselves. That difference matters: the deleted message your client swears they never sent, the timestamp that contradicts opposing counsel&#8217;s timeline, the metadata that proves a thread is complete &#8211; those often live only in the database files a file-system or physical extraction recovers, not in the tidy list a logical backup hands you.</p>
<p>Then there&#8217;s the carrier records problem. When forensic extraction of the device isn&#8217;t possible &#8211; because the phone has been lost, destroyed, wiped, or the owner won&#8217;t hand it over &#8211; attorneys sometimes turn to carrier records obtained through subpoena. Carrier records can confirm that a message was sent between two numbers at a particular time, but they generally don&#8217;t include the content of SMS messages (if a particular carrier retains that, they don&#8217;t retain it for long) and they handle MMS and iMessage differently depending on the carrier and the protocol. iMessages, for instance, don&#8217;t pass through the carrier&#8217;s SMS gateway at all &#8211; they travel over Apple&#8217;s encrypted servers &#8211; so they likely won&#8217;t appear in carrier records. If the key evidence is an iMessage thread and the phone is gone, you may have a serious hole in your case unless that message is in an iCloud account that you can access.</p>
<p>Group messages add another layer of complexity. The way group texts are stored and displayed varies between platforms and even between operating system versions. A group message that appears as a single coherent thread on one person&#8217;s phone may look completely different on another participant&#8217;s phone, depending on their device, their OS version, and whether the messages were sent as SMS, MMS, or through a proprietary protocol like iMessage or RCS. Establishing that everyone in the group saw the same thing requires more work than most people expect. On the other hand, though responsive data may not be found on one person&#8217;s device, we might have another crack at the data with the device from someone else in the group.<a href="https://burgessforensics.com/wp-content/uploads/2026/06/group-message.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15421 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/group-message-300x200.jpg" alt="" width="248" height="165" /></a></p>
<p>Authentication is the final hurdle, and it&#8217;s where everything we&#8217;ve discussed comes together. Under the Federal Rules of Evidence and their state equivalents, you need to establish that the text messages are what you say they are &#8211; that they came from the person you claim sent them, that they haven&#8217;t been altered, and that the record you&#8217;re presenting is complete and accurate. A forensic extraction with proper hash verification, reliable metadata, and chain of custody documentation gets you most of the way there. A screenshot from the client&#8217;s phone, standing alone, generally does not.</p>
<p>None of this is meant to suggest that text message evidence is hopeless &#8211; far from it. When properly collected, preserved, and authenticated, text messages can be devastating evidence. But the &#8220;properly&#8221; part requires more planning and technical awareness than many attorneys realize, especially early in the case when preservation decisions are being made and the phone is still in someone&#8217;s pocket, quietly syncing, updating, and auto-deleting per whatever settings the user configured and then forgot about.</p>
<p>If text messages matter to your case &#8211; and increasingly they do &#8211; get a forensic examiner involved early, before devices change hands, before carriers purge their logs, and before your client decides to &#8220;clean up&#8221; their phone. The evidence is there. You just have to get to it the right way.</p>
<p>What&#8217;s the trickiest text message evidence challenge you&#8217;ve faced in a case?</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p>The post <a href="https://burgessforensics.com/text-messages-as-evidence-harder-than-you-think/">Text Messages as Evidence: Harder Than You Think</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/text-messages-as-evidence-harder-than-you-think/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Digital Evidence 101: What Every Attorney Should Know Before Discovery</title>
		<link>https://burgessforensics.com/digital-evidence-101-what-every-attorney-should-know-before-discovery/</link>
					<comments>https://burgessforensics.com/digital-evidence-101-what-every-attorney-should-know-before-discovery/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Wed, 24 Jun 2026 19:51:23 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15409</guid>

					<description><![CDATA[<p>Digital Evidence 101: What Every Attorney Should Know Before Discovery  Copyright 2026, Steve Burgess I&#8217;ve sat across the table &#8211; or more recently, the Zoom &#8211; from a great many attorneys over the past forty years, and I&#8217;ve noticed a pattern. Litigators who can cross-examine a hostile witness into a confused puddle, who can recite [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/digital-evidence-101-what-every-attorney-should-know-before-discovery/">Digital Evidence 101: What Every Attorney Should Know Before Discovery</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Digital Evidence 101: What Every Attorney Should Know Before Discovery </strong></p>
<p>Copyright 2026, Steve Burgess</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/06/HArd-disk-on-the-stand.jpg"><img loading="lazy" decoding="async" class="alignnone size-medium wp-image-15410" src="https://burgessforensics.com/wp-content/uploads/2026/06/HArd-disk-on-the-stand-300x120.jpg" alt="" width="300" height="120" /></a></p>
<p>I&#8217;ve sat across the table &#8211; or more recently, the Zoom &#8211; from a great many attorneys over the past forty years, and I&#8217;ve noticed a pattern. Litigators who can cross-examine a hostile witness into a confused puddle, who can recite the rules of evidence from memory, and who can spot a hearsay problem from across the courtroom will sometimes look at a hard drive the way the rest of us look at a tax form: with suspicion, mild dread, and the blessed hope that someone else will handle it.</p>
<p>That&#8217;s understandable. Law school doesn&#8217;t teach this, and it shouldn&#8217;t have to. Digital forensics is its own discipline, just as forensic accounting or medical examination are their own disciplines. But discovery in 2026 runs through digital data so thoroughly that a basic working knowledge isn&#8217;t optional anymore. So, let&#8217;s cover a few fundamentals &#8211; the things many attorneys wish they knew before the discovery clock started running.</p>
<p>Digital evidence is broader than most people think. It&#8217;s not just emails and the obvious files on a work computer. It&#8217;s text messages, cloud storage, app data, metadata, browser history, location information, IoT (Internet of Things) device logs, and increasingly, AI-generated or AI-assisted content. If a device touches the internet or stores information electronically, it&#8217;s a potential evidence source.</p>
<p>I often suggest that clients assume something may be discoverable until proven otherwise, rather than the reverse. That approach occasionally results in collecting more information than you need. The opposite approach occasionally results in explaining things to your client, or worse, to a judge.</p>
<p>Speaking of common misconceptions, let&#8217;s talk about deleted data. When a file is deleted on most systems, the data itself usually isn&#8217;t immediately erased. Instead, the space it occupied is marked as available for reuse. Until something else overwrites it, some or all of that information may remain recoverable.</p>
<p>That&#8217;s often good news. It&#8217;s also not a guarantee. How long that recovery window remains open depends on the device, operating system, storage technology, and how much the device has been used since the deletion occurred. Anyone who tells you with complete certainty, as many a client will, that deleted data is &#8220;definitely still there&#8221; or &#8220;definitely gone forever&#8221; without examining the device is hand-waving.</p>
<p>Metadata matters more than content sometimes. A document&#8217;s content tells you what it says. Its metadata can tell you who created it, when it was created, what software was used, and what happened to it along the way. I&#8217;ve seen metadata reveal that a supposedly contemporaneous document was actually created weeks after the event it purported to describe &#8211; not a footnote – it can sometimes be the whole case.</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/06/CHain-of-custody.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15411 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/CHain-of-custody-300x300.jpg" alt="" width="191" height="191" /></a>Chain of custody sounds like bureaucratic box-checking until you’ve seen a case turn on it. It exists because digital evidence, unlike a paper document, can be altered without leaving an obvious trace if it isn&#8217;t handled correctly. A device examined by someone without proper forensic methodology &#8211; even with the best intentions &#8211; can have its evidentiary value compromised.</p>
<p>This is why &#8220;I&#8217;ll just have my IT guy take a look&#8221; is a sentence that makes me wince every time I hear it. Your IT person may be excellent at fixing printers, managing servers, and keeping everyone connected to Wi-Fi. <a href="https://burgessforensics.com/wp-content/uploads/2026/06/Accountant-printer.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class=" wp-image-15413 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/Accountant-printer-300x300.jpg" alt="" width="216" height="216" /></a>That&#8217;s a different skill set than preserving evidence for litigation. Nobody calls a forensic accountant to repair the office copier, either.</p>
<p>Timin<a href="https://burgessforensics.com/wp-content/uploads/2026/06/Timing.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15412 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/Timing-300x300.jpg" alt="" width="203" height="203" /></a>g changes everything. The earlier a forensic expert gets involved, the more options exist. Devices keep getting used. Cloud accounts keep syncing. Backups keep cycling and overwriting older versions. Evidence that&#8217;s recoverable today may not be recoverable in three months, and there&#8217;s rarely a reliable way to know in advance which evidence is on a fast clock and which isn&#8217;t. The cost of being wrong is usually much higher than the cost of an early consultation.</p>
<p>None of this requires you to become a forensic examiner yourself &#8211; that would be a strange use of your law degree, and frankly I&#8217;d be out of a job. What it does require is recognizing when a case has a digital evidence component &#8211; which, in 2026, is most of them &#8211; and bringing in the right expertise before discovery goes sideways.</p>
<p>The attorneys who get the best outcomes aren&#8217;t <a href="https://burgessforensics.com/wp-content/uploads/2026/06/fast-clock.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15414 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/fast-clock-300x300.jpg" alt="" width="194" height="194" /></a>the ones who know the most about digital forensics. They&#8217;re the ones who know enough to ask the right questions at the right time.</p>
<p>What are some things you’ve learned about digital evidence the hard way?</p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p>The post <a href="https://burgessforensics.com/digital-evidence-101-what-every-attorney-should-know-before-discovery/">Digital Evidence 101: What Every Attorney Should Know Before Discovery</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/digital-evidence-101-what-every-attorney-should-know-before-discovery/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Digital Privacy vs. Discovery: Where the Line Is Drawn</title>
		<link>https://burgessforensics.com/digital-privacy-vs-discovery-where-the-line-is-drawn/</link>
					<comments>https://burgessforensics.com/digital-privacy-vs-discovery-where-the-line-is-drawn/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Wed, 17 Jun 2026 23:46:06 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15401</guid>

					<description><![CDATA[<p>Copyright 2026, Steve Burgess Every so often I’ll sit across the Zoom from an attorney—or from a pro se litigant—who wants everything. Every text message the opposing party has ever sent. Every photo on their phone. Every search query. Every deleted file. Every app. Every cloud account. Of course, I’ve also had those calls where [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/digital-privacy-vs-discovery-where-the-line-is-drawn/">Digital Privacy vs. Discovery: Where the Line Is Drawn</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Copyright 2026, Steve Burgess</p>
<p>Every so often I’ll sit across the Zoom from an attorney—or from a pro se litigant—who wants everything. Every text message the opposing party has ever sent. Every photo on their phone. Every search query. Every deleted file. Every app. Every cloud account. Of course, I’ve also had those calls where I think they don’t want enough. But they’re the boss here.</p>
<p>In other words, they want the digital equivalent <a href="https://burgessforensics.com/wp-content/uploads/2026/06/Teen-bedroom-mess.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15403 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/Teen-bedroom-mess-300x214.jpg" alt="" width="229" height="163" /></a>of dumping every piece of dirty clothing on your teenager’s bed to find your missing sock. I understand the impulse. Somewhere in there might be the thing that wins the case.</p>
<p>But &#8220;it might be in there somewhere&#8221; is not how discovery is supposed to work. It&#8217;s also not how a forensic examination should work, because privacy doesn&#8217;t evaporate simply because someone becomes a party to a lawsuit.</p>
<p>This tension—between the legitimate need to discover relevant evidence and the very real privacy interests of the person whose device is being examined—sits at the center of much of the work I do. It&#8217;s worth understanding how courts actually navigate it, because the answer is more nuanced than either &#8220;produce everything&#8221; or &#8220;produce nothing.&#8221; Attorneys who understand that nuance generally get better results than those who don&#8217;t.</p>
<p>The starting principle in most jurisdictions is proportionality. Discovery requests, including requests for forensic examination of a device, are<a href="https://burgessforensics.com/wp-content/uploads/2026/06/scales.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15404 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/scales-300x200.jpg" alt="" width="251" height="167" /></a> generally supposed to be tailored to what&#8217;s relevant to the claims and defenses in the case—not a fishing expedition through someone&#8217;s entire digital existence.</p>
<p>Courts have increasingly pushed back on requests for complete forensic images of phones and computers, particularly when narrower methods can capture the relevant evidence without exposing unrelated personal material.</p>
<p>A request for &#8220;all text messages with this specific person during this specific time period&#8221; tends to fare much better than &#8220;give me the phone.&#8221;</p>
<p><a href="https://burgessforensics.com/wp-content/uploads/2026/06/Messy-garage.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class=" wp-image-15405 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/Messy-garage-300x200.jpg" alt="" width="287" height="191" /></a>After all, if someone sued you over a fender-bender, you probably wouldn&#8217;t give them your garage door opener and let them check every shelf and rag just in case they find something useful.</p>
<p>This is where forensic protocols come in, and they&#8217;re more sophisticated than most non-experts assume.</p>
<p>A forensic examination doesn&#8217;t have to mean someone reading every photo and message on a device. Searches can be scoped by date range, keyword, contact, application, file type, or a combination of all of these. Privileged or clearly irrelevant material can be filtered before opposing counsel ever sees the results.</p>
<p>Courts will sometimes appoint a neutral third-party examiner—someone retained by neither side—specifically to address privacy concerns. The examiner produces only responsive material under a protocol agreed upon in advance. I&#8217;ve worked within that structure many times, and it tends to satisfy both the legitimate discovery need and the legitimate privacy objection, which is no small trick. Getting two opposing attorneys to agree on anything is occasionally harder than recovering data from a damaged hard drive.</p>
<p>There&#8217;s also a category of information that receives special treatment regardless of relevance concerns: health information, financial account credentials, privileged attorney communications, and in some jurisdictions, location data tied to sensitive activities. Courts are generally more protective of these categories, and a request that sweeps them in without specific justification is likely to draw a motion to quash—and probably deserves to.</p>
<p>The practical lesson for attorneys on either side of this issue is the same: be specific.</p>
<p>If you&#8217;re requesting examination of a device, define the scope as narrowly as the case allows. You&#8217;ll encounter fewer objections, spend less time arguing, and generally get faster compliance.</p>
<p>If you&#8217;re objecting to a request, propose an alternative that addresses the actual relevance concern rather than simply saying no. &#8220;No&#8221; by itself rarely survives a motion to compel for very long. Unless of course, it’s that aforementioned teenager.</p>
<p>Privacy and discovery aren&#8217;t really opposites. They&#8217;re both trying to answer the same underlying question: What information is actually necessary to resolve this dispute fairly?</p>
<p>The cases that move most smoothly are usually the ones where both sides—and their experts—keep that question in view instead of treating discovery as an opportunity to rummage through someone&#8217;s entire digital sock drawer.<a href="https://burgessforensics.com/wp-content/uploads/2026/06/Digital-sock-drawer.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15402 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/Digital-sock-drawer-300x200.jpg" alt="" width="266" height="177" /></a></p>
<p>And trust me, after examining thousands of devices over the years, I can assure you that most digital sock drawers contain exactly what you&#8217;d expect: lots of clutter, a few surprises, a number of screenshots of questionable provenance whose purpose has been lost to history, and almost never the thing you were originally looking for.</p>
<p>So, as an attorney, where do you usually draw that line when negotiating the scope of a forensic examination?</p>
<p>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p>The post <a href="https://burgessforensics.com/digital-privacy-vs-discovery-where-the-line-is-drawn/">Digital Privacy vs. Discovery: Where the Line Is Drawn</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/digital-privacy-vs-discovery-where-the-line-is-drawn/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The 3 Phone Mistakes That Destroy Digital Evidence Before Trial</title>
		<link>https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/</link>
					<comments>https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/#respond</comments>
		
		<dc:creator><![CDATA[Steve Burgess]]></dc:creator>
		<pubDate>Mon, 15 Jun 2026 14:58:01 +0000</pubDate>
				<category><![CDATA[Attorneys]]></category>
		<category><![CDATA[Cell phones]]></category>
		<guid isPermaLink="false">https://burgessforensics.com/?p=15392</guid>

					<description><![CDATA[<p>Copyright 2026, Steve Burgess Smartphones are the single richest source of digital evidence in most litigation today. Text messages, call logs, photos, location history, app data, deleted files — it&#8217;s all there, sitting in a device that fits in a shirt pocket. Or in that back pocket that’s covered with bling. You&#8217;d think that because [&#8230;]</p>
<p>The post <a href="https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/">The 3 Phone Mistakes That Destroy Digital Evidence Before Trial</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Copyright 2026, Steve Burgess</em></p>
<p>Smartphones are the single richest source of digital evidence in most litigation today. Text messages, call logs, photos, location history, app data, deleted files — it&#8217;s all there, sitting in a device that fits in a shirt pocket. Or in that back pocket that’s covered with bling. You&#8217;d think that because phones are so ubiquitous and so central to how people communicate, attorneys and their clients would have developed good instincts about preserving them. You would be wrong, and I say that with forty years of forensic experience and genuine affection for the legal profession.</p>
<p><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15393 aligncenter" src="https://burgessforensics.com/wp-content/uploads/2026/06/Phone-police-line-300x200.png" alt="" width="311" height="207" /></p>
<p>The mistakes I see aren&#8217;t necessarily the result of bad intentions. They&#8217;re the result of people not knowing what they don&#8217;t know — which, in digi</p>
<p>tal forensics, turns out to be quite a lot. Here are the three that do the most damage.</p>
<p><strong>Mistake One: Letting the Client Keep Using the Phone.</strong></p>
<p>This one is so common that I&#8217;ve stopped being surprised by it, though I haven&#8217;t stopped being pained. The moment litigation is reasonably anticipated, a litigation hold applies to that phone. What it does not do, unfortunately, is apply itself. Unless someone explicitly tells the client to stop using the device normally, they will continue using it norma</p>
<p>lly — deleting old messages to free up space, backing up and syncing, downloading updates, letting apps purge their caches — all of which can overwrite the very data that might have been recoverable. The phone doesn&#8217;t know there&#8217;s a lawsuit. It&#8217;s just doing its job.<a href="https://burgessforensics.com/wp-content/uploads/2026/06/Cell-phone-hoarder.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15394 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/Cell-phone-hoarder-200x300.jpg" alt="" width="117" height="176" />.</a></p>
<p>Even using the phone abnormally, that is – at all – makes potentially important changes to data that</p>
<p>could be responsive, and can also make otherwise recoverable data gone from the planet.</p>
<p>The fix is straightforward but has to happen early: tell your client, in plain language, to stop deleting anything and to bring you the phone. Not a screenshot of the phone. The phone. Best to put it into airplane mode and then turn it off immediately. We&#8217;ll get to screenshots in a moment.</p>
<p><strong>Mistake Two: The Screenshot Problem.</strong></p>
<p>Attorneys receive screenshots of text message conversations constantly. Clients send them because they&#8217;re easy, because they <em>feel</em> like evidence, and because nobody told them otherwise. The problem is that a screenshot is a photograph of information, not the information itself. It shows you what someone wants you to see, cropped to whatever boundaries they chose, dating the evidence to the very time they took the screenshot, with none of the underlying data that makes digital evidence actually useful in court.</p>
<p>Even worse, we regularly get PDFs of screenshots of the evidence, two steps of creation removed from the genesis of the underlyi<a href="https://burgessforensics.com/wp-content/uploads/2026/06/Gemini_Generated_Image_1mtnyj1mtnyj1mtn.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15395 alignleft" src="https://burgessforensics.com/wp-content/uploads/2026/06/Gemini_Generated_Image_1mtnyj1mtnyj1mtn-300x164.jpg" alt="" width="220" height="120" /></a>ng evidence.</p>
<p>A proper extraction of text messages from a phone includes the full conversation thread, the phone numbers associated with each contact, timestamps that can be verified against carrier records, and in many cases deleted messages that the client may not even know still exist. A screenshot gives you none of that. It also gives opposing counsel a straightforward authenticity challenge, because a screenshot can be edited in about thirty seconds by anyone with a basic photo app and an agenda. Courts are increasingly skeptical of screenshots standing alone, and rightly so. If the text messages matter to your case, get the phone examined by someone who can extract the data forensically.</p>
<p><strong>Mistake Three: The Factory Reset.</strong></p>
<p>This is the one that occasionally crosses the line from mistake into something courts take a very dim view of, depending on the timing and the circumstances. People factory reset their phones for all kinds of innocent reasons — selling the device, switching carriers, trying to fix a software problem, general digital housekeeping, following the instructions of a tech support rep. Even just copying the data to a new phone. Hit the wrong button during the process and Poof! All the un-transferred stuff is gone. When it happens after litigation is anticipated and a litigation hold is in effect, innocent reasons tend not to matter as much as you&#8217;d hope.</p>
<p>What many people don&#8217;t realize is that a factory reset, once it happens, puts you in a very difficult position legally <a href="https://burgessforensics.com/wp-content/uploads/2026/06/Factory-reset.jpg"><img wpfc-lazyload-disable="true" loading="lazy" decoding="async" class="wp-image-15396 alignright" src="https://burgessforensics.com/wp-content/uploads/2026/06/Factory-reset-300x164.jpg" alt="" width="269" height="147" /></a>— regardless of what may or may not remain on the device. Which, with newer devices, is usually zilch. Courts don&#8217;t look kindly on resets that occur after a litigation hold is in effect, and the explanation of &#8216;I didn&#8217;t know&#8217; tends to land with a thud. The time to have this conversation with your client is before it happens, not after.&#8221;</p>
<p>The common thread in all three of these mistakes is timing. Digital evidence is not like paper evidence — it doesn&#8217;t just sit in a filing cabinet waiting patiently for someone to come find it. It&#8217;s dynamic, it&#8217;s fragile in ways that aren&#8217;t obvious, and the window for preserving it can close faster than anyone expects. The attorneys who understand this engage a forensic examiner early, preserve the device properly, and go into discovery knowing what the phone contains. The ones who don&#8217;t tend to find out what was on it the hard way.</p>
<p>If your client&#8217;s phone was examined today, would you know what&#8217;s on it — or would you find out the same time opposing counsel does?</p>
<p><em><strong>Don’t miss a single issue of our informative newsletter … <a href="https://burgessforensics.com/subscribe/" target="_blank" rel="noopener">Subscribe</a>!</strong></em></p>
<p><em>Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1984.</em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The post <a href="https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/">The 3 Phone Mistakes That Destroy Digital Evidence Before Trial</a> appeared first on <a href="https://burgessforensics.com">Burgess Forensics</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://burgessforensics.com/the-3-phone-mistakes-that-destroy-digital-evidence-before-trial/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
