Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Digital Forensics

IP Theft Investigation and Departing Employee Forensics

Find out what left with a departing employee, how it left and when, with examiner findings your attorney can use in a demand letter, an injunction motion or a trade secret case.

Veteran-LedSDVOSB
Chain of CustodyEvery Engagement
Court-ReadyBy Design
AZ DPS PI LicenseNo. 1759795
NationwideRemote Collection

When you need an IP theft investigation

An IP theft investigation answers a narrow, urgent question: did a current or former employee copy, send or sync company information they had no right to take? Most cases start with a hunch. A top salesperson resigns to join a competitor. A customer list shows up in a rival’s pitch. An engineer’s laptop comes back wiped. Before anyone sends a demand letter or files suit, someone has to look at the evidence the right way.

We run these matters as part of our digital forensics services practice. The work is a forensic examination of company-owned laptops, mailboxes and cloud accounts to find copying, external storage, uploads and forwarding. It also covers wider employee misconduct and fraud questions, where the issue is not one file but a pattern of behavior.

Common triggers we see:

  • A key employee gives notice and joins a competitor, or starts a competing business.
  • Large downloads, USB use or personal cloud uploads in the last weeks before departure.
  • Company files forwarded to a personal email address.
  • A returned laptop or phone that was reset, wiped or is missing.
  • Suspected expense fraud, side deals, or a manager steering work to a related company.

What we deliver

Every engagement is scoped in writing before work starts. These are the service packages we combine for departing-employee and misconduct matters:

IP theft investigation allowance

A fixed block of examiner hours agreed up front for analysis of file copying, external devices, cloud sync and other exfiltration indicators. Collection and a formal expert report are estimated separately.

Employee misconduct and fraud allowance

A fixed block of examiner hours for reviewing scoped communications and device artifacts. Collection, attorney review and any financial specialist work are separate.

User artifact reconstruction

Registry entries, event logs, LNK files, shellbags, jump lists and application traces, interpreted into what the user did and when, with limitations stated plainly.

Timeline and cross-device correlation

Time zones normalized and events lined up across the laptop, mailbox, cloud storage and phone, so the story reads in order. We agree an initial planning allowance first.

Targeted remote collection

One reachable company endpoint, agreed folders and artifacts up to a stated volume, in one session with validation. This is a targeted collection, not a full physical image.

Mailbox and cloud collection

Company Microsoft 365, Google Workspace or Exchange mailboxes, and defined OneDrive, SharePoint, Google Drive, Dropbox, Slack or Teams sources, each up to a stated volume.

When a full image is the better choice, for example a wiped laptop or a dispute that will likely reach trial, we use our computer and hard drive forensics or remote forensic extraction services instead. Phones are handled through mobile and tablet forensics.

What an examiner looks for in a departing employee case

The questions are usually the same: what was taken, how, when, and where it went. The table shows common evidence sources and what each can, and cannot, tell you.

Evidence source What it can show Common limits
Windows registry and event logs USB devices connected, with first and last connection times Shows a device was connected, not every file copied to it
LNK files, jump lists, shellbags Files and folders opened, including on external drives Can be overwritten by later activity or a reset
Browser history and cloud sync clients Uploads to personal cloud storage or webmail Private browsing and cleared history reduce what remains
Company mailbox Forwarding to personal addresses, attachments sent, rules created Depends on retention settings and deleted-item recovery windows
Microsoft 365 or Google audit logs File downloads, sharing changes and sign-ins Retention is limited and varies by license
Company-owned phone Messages, photos of screens, file transfers and app use Encryption and resets can limit extraction

Audit logs are a common blind spot. As of October 2026, Microsoft documents a default retention of 180 days for Audit (Standard) records. If you wait, the record of a mass download can age out before anyone looks.

How an engagement runs

  1. Request and conflict check. You submit the request online with the employee’s role, departure date and what you suspect. We confirm who owns the devices and accounts.
  2. Scope and preservation advice. We tell you what to hold, what not to touch, and which sources matter most. We confirm the scope and billing basis in writing.
  3. Collection. Targeted remote collection, a remote collection kit, or onsite imaging, each documented with hash values and chain of custody.
  4. Analysis. User artifacts, external devices, cloud and email activity, then a correlated timeline across sources.
  5. Findings. A plain-language summary of what the evidence shows and does not show. A formal expert report or declaration is available if counsel needs one.
  6. Follow-on support. Help with preservation letters, discovery requests for the employee’s own devices, and expert witness testimony if the case proceeds.

Authority, consent and legal limits

We examine only devices and accounts the client has the legal right to search. In practice that means company-owned computers, phones and company accounts, examined at the request of the company or its counsel. The employee’s personal phone, personal email and personal cloud storage are a different matter. Those usually require the employee’s consent, a court order or a discovery agreement negotiated by counsel.

We do not log in to a former employee’s personal accounts, even if a password was left behind. Accessing stored communications without authorization can violate the federal Stored Communications Act, 18 U.S.C. 2701. We do not install monitoring tools on anyone’s personal device, and we do not bypass authentication we are not authorized to bypass.

The legal framework matters for how evidence is gathered. The federal Defend Trade Secrets Act, 18 U.S.C. 1836, lets a trade secret owner bring a civil action, allows an ex parte seizure only in extraordinary circumstances, and sets a three-year limitations period from discovery. Arizona’s Uniform Trade Secrets Act, A.R.S. 44-401 et seq., defines a trade secret as information that has value from not being generally known and is the subject of reasonable efforts to keep it secret. Both allow exemplary damages of up to twice the award for willful and malicious misappropriation. Under 18 U.S.C. 1833(b), an employer that did not give the required whistleblower immunity notice in agreements signed or updated after May 11, 2016 may lose access to exemplary damages and attorney fees against that employee.

Preservation also has rules. Federal Rule of Civil Procedure 37(e) lets a court order curative measures when electronically stored information is lost because a party failed to take reasonable steps to preserve it, and allows harsher sanctions if the loss was intentional. That cuts both ways: your company must preserve its own evidence too. This is general information, not legal advice. Your attorney decides strategy and legal claims.

How it is priced

We quote IP theft and misconduct work in clear units so you know what you are approving:

  • Analysis allowances. The IP theft and misconduct packages are a fixed block of examiner hours agreed in advance. If the evidence points to more sources, we ask before we go past the allowance.
  • Hourly analysis. Artifact reconstruction and timeline work are billed hourly against an agreed allowance.
  • Collection. Quoted per endpoint, per mailbox and per cloud source, each with a stated volume cap. Volume above the cap is quoted separately.
  • Quoted separately. Full physical imaging, phone extraction, formal expert reports, deposition or trial time, attorney document review and financial specialist work.

Cost drivers are the number of devices and accounts, data volume, whether devices are encrypted or wiped, and how fast you need answers. Any change in scope is handled by written change order.

Mistakes to avoid before an IP theft investigation

  • Do not reissue the laptop. Reimaging a departed employee’s computer for a new hire destroys the best evidence you have.
  • Do not let IT browse it. Opening folders and files changes access dates and can blur the timeline.
  • Do not delete the account. Suspend the departing employee’s mailbox and cloud accounts instead. Deletion can start a short recovery clock.
  • Do not confront the employee first. Talk to counsel before any contact. A warning can prompt deletion on personal devices you cannot reach.
  • Do not log in to personal accounts. A saved password does not give you authority.
  • Do collect the agreements. Have the offer letter, confidentiality or non-disclosure agreement, and acceptable use policy ready.

Our guide to trade secret theft first steps covers the first 48 hours in more detail.

Who this is for

  • Law firms
  • Business owners and executives
  • HR and people leaders
  • In-house counsel
  • IT and security teams
  • Private equity and acquirers

Frequently asked questions

How much does an IP theft investigation cost?

It depends on how many devices and accounts are involved, the data volume and how quickly you need findings. Analysis is quoted as a fixed block of examiner hours, and collection is quoted per device, mailbox or cloud source. You receive the scope and billing basis in writing before any work begins.

Can you prove an employee copied files to a USB drive?

Often we can show that a specific USB device was connected and that files on it were opened, with dates and times. Proving exactly which files were copied depends on what artifacts remain. We state what the evidence supports and what it does not.

Can you search the employee’s personal phone or Gmail?

Only with lawful authority, such as the employee’s written consent, a court order or a discovery agreement worked out by counsel. We do not access personal devices or accounts without that authority.

How fast should we start after an employee resigns?

As soon as you suspect a problem. Audit logs, deleted-item folders and some device artifacts age out or get overwritten. Preserve the laptop and accounts first, then request service online so we can confirm what to hold.

The laptop was already wiped. Is there anything left?

Sometimes. Cloud audit logs, the mailbox, sync records and other devices can still show activity, and some traces survive a reset. No recovery is guaranteed, but the wipe itself can be relevant evidence.

Will your findings hold up in court?

We work to be court-ready: documented chain of custody, hash verification, repeatable methods and clear statements of limits. Whether evidence is admitted is decided by the court, so we cannot promise an outcome.

Do you handle employee fraud as well as data theft?

Yes. The employee misconduct and fraud package reviews scoped communications and device artifacts. When the money trail matters, we coordinate with our financial investigations team.

Related guides

We examine only company-owned devices and accounts, or personal sources with consent or a court order. Findings are general information, not legal advice.

Sources: 18 U.S.C. 1836 (DTSA), 18 U.S.C. 1833(b), A.R.S. 44-401, FRCP 37(e), CISA: Defining insider threats, Microsoft Purview audit retention.

Find out what left before the trail goes cold

Request this service online and pick IP theft or employee investigations on the form. Your request goes straight to our cyber and forensics lead, the specialist who handles this type of case, so there is no phone tag and we can tell you what to preserve the same day. If evidence is being destroyed right now, use our urgent intake form.