When a client or opposing party says “he deleted everything,” attorneys often hear a dead end. I hear the opposite and you probably should as well. In digital forensics, deletion is rarely the end of the story. In fact, it may be the beginning of a better one.
What most people don’t understand is that hitting delete doesn’t erase data. It tells the system that the space can be reused. Think of it less like shredding a document and more like taking the label off a file folder and telling the office it’s okay to reuse the drawer — the pages are still in there until someone actually needs the room and drops the pages in a shredder. Until something overwrites it, the underlying data often sits right where it always was. On phones, computers, and servers, deleted files, messages, and app data are frequently recoverable in whole or in part. While deleted phone data is somewhat more ephemeral and tends to become unrecoverable after a couple of months, other platforms are less so. In many cases, we have recovered them months or even years later.
Still, recoverability is only half of it. The more valuable half is what the act of deletion reveals.
Deletion leaves its own trail. Modern devices tend to be relentless record-keepers. They document nearly everything, often including their own attempted cover-ups. When someone deletes files, wipes an app, clears a chat, or runs “cleaner” or “wiping” software, those actions frequently generate their own artifacts: timestamps, log entries, system events, and traces in backups and cloud sync. In practice, you may be able to
prove not just what existed, but when it was removed, and sometimes that a wiping tool was run at 2 a.m. the night before a device was handed over. We had a case where the inspection got stalled for a couple of days to give time for the IT guy to scrub away. However, the file-destroying tool kept a record of every single file it destroyed over the previous very busy nights.
Nothing says “nothing to hide” quite like a freshly installed disk-scrubbing utility. That timeline can be more persuasive to a fact-finder than the deleted content ever would have been.
Intent is the story. A single deleted photo is a fact. A coordinated wipe — messages cleared, a drive reformatted, cloud backups switched off, all clustered around a key date — is a narrative unto itself. Courts have well-developed doctrine here. Spoliation of evidence can support sanctions and, in many jurisdictions, the dreaded adverse-inference instruction: the jury may be told they can assume the destroyed evidence would have hurt the party who destroyed it. The person trying to make the problem disappear might just be manufacturing a bigger one, wrapped up with a bow on top.
The copies that survive. Data rarely lives in one place. A message deleted on a phone may survive in a backup, on the other party’s device, in a cloud account, or on a synced laptop nobody remembered was still logged in. Deleting the local copy does nothing to the dozen copies elsewhere. The modern device can be quite the bothersome gossip – it tells your secrets to every other device it meets. Part of a competent forensic examination is simply knowing where those copies tend to hide.
Besides the potentially recoverable file being looked for, many programs, especially Microsoft Office, make invisible copies every time a file is open. Invisible to the user, that is – not to the examiner.
So, when the other side deletes everything, they may accomplish three things that help you: they leave recoverable data behind, they create adocumented record of the destruction, and they hand you a consciousness-of-guilt argument you didn’t have before. That’s a rough return on investment for a night or two filled with buckets of coffee and frantic clicking.
A few practical notes for counsel. Move fast. Recoverability drops as devices keep running and space gets overwritten, so preservation letters and litigation
holds matter enormously.
Preserve the device itself, not just exports; a proper forensic image captures far more than a manual copy. And loop in an examiner early, before well-meaning IT staff or clients “poke around just to check” and overwrite the very evidence you’re trying to save. Curiosity has damaged more cases than it has solved.
“He deleted everything” isn’t the moment your case falls apart. More often, it’s the moment it gets interesting.
A question for the litigators: what’s a situation you’ve had where deleted data actually strengthened your side of the case? I’d be curious to hear how it played out. The best forensic stories usually start with someone who was very sure they’d covered their tracks.
Steve Burgess is a digital forensics expert witness with more than 40 years of experience and over 20,000 devices and digital media examined. He is the principal of Burgess Forensics, founded in 1985.
Don’t miss a single issue of our informative newsletter … Subscribe now!

