LEAF-C

Law Enforcement Against

Financial Crimes

Cybercrime guidance

Preserving Digital Evidence After an Incident

First-hour actions that keep phones, laptops, CCTV, and cloud accounts usable as evidence after fraud, intrusion, or workplace misconduct.

19 September 2026 · 8 min read

The first hour decides what you can prove later

After a suspected fraud, data incident, or internal allegation, well-meaning staff often do the most damaging thing: they log in “just to check,” run antivirus, delete “junk,” or power equipment off and on. Each of those steps can alter timestamps, overwrite volatile data, or destroy a forensic image’s integrity.

Your job in the first hour is not to solve the case. It is to stop further harm and freeze the scene in a way a specialist can later explain.

Identify what might hold the story

Think in systems, not in a single laptop. Relevant material may sit on a phone, a desktop, a shared drive, email, messaging apps, CCTV, access-control logs, payment terminals, cloud admin consoles, and the router that logged the session.

Write a short inventory: device, owner, location, whether it is powered, and who last touched it. That list becomes the spine of your legal hold and of any later specialist instruction.

  • Endpoints: laptops, phones, USBs, workstations used by the people with opportunity.
  • Accounts: email, banking, cloud storage, admin panels, and password managers.
  • Environment: CCTV, badge logs, Wi-Fi logs, and server or firewall records.

What to do — and what not to do — with devices

If a computer is on and the suspected activity is live, photograph the screen, isolate it from the network if you can do so without destroying evidence, and call a specialist before you shut it down. If a device is off, leave it off. Do not attempt password guesses on a locked phone.

Do not run cleaner tools, “optimise disk,” restore from backup onto the same machine, or let IT reimage a laptop to get the user working again until a copy of the original has been taken. Business continuity matters; it should use a replacement device, not the exhibit.

Legal hold and cloud accounts

Issue a written hold to anyone who may hold relevant mail, chats, or files: do not delete, do not tidy folders, do not auto-archive. Suspend — do not wipe — accounts that may be involved. Preserve mailbox and drive data at the administrator level rather than asking the subject to forward “anything relevant.”

For banking and vendor portals, export available logs and statements immediately. Many platforms rotate logs in days, not months. Waiting for a Monday morning committee is how evidence expires.

Chain of custody in plain terms

Every exhibit needs a story: who collected it, when, from where, and where it went next. Use sealed bags or an evidence locker, restrict the number of handlers, and record transfers. Photographs of serial numbers and the scene help later identification.

If law enforcement may become involved, this paperwork is not bureaucracy. It is what allows a court or a disciplinary panel to trust that the laptop in the report is the laptop from the office.

When to bring in digital forensics

Call specialists when the potential loss is material, when you may need findings for a regulator, insurer, or court, or when staff lack a documented forensic process. A scoped engagement can image priority devices, extract cloud data, and give you a first briefing without boiling the ocean.

Tell the specialist what you already touched. An honest account of “IT logged in to check” is far more useful than a reconstructed narrative that pretends nobody did.

Key takeaways

  • Inventory devices and accounts, then stop casual login and reimaging.
  • Leave powered-off devices off; isolate live systems and photograph screens.
  • Issue a legal hold immediately — cloud and payment logs disappear faster than people expect.

This article is practical guidance for organisations. It is not legal advice and does not create a client relationship. For a live matter, request a confidential consultation.