Email and Cloud Exfiltration Forensics

Material leaving by mailbox or cloud account is recorded twice, once by the machine and once by the service, and a sound investigation reads both sides. Rules, attachment history and sign-in patterns come out of the tenancy; browser and sync traces come off the device; the two are lined up into one dated account of what went where. For insurers, brokers and professional firms in the city centre, and the advisers acting for them.

Scope first, then work. The free diagnostic comes at the start and the written scope follows it; forensic fees are paid in full before an examination begins. No fix, no fee all jobs except electronic and mechanical failures, chip level work, DVR and Forensic jobs. Full pricing is on the data recovery cost page.

// the patterns that start these cases

What an exit through the mailbox looks like

Each has an innocent explanation. Together they make a pattern worth looking at.

Sizeable attachments going to one private address over several weeks
A rule found on a mailbox after somebody has already left
Sign-ins to company accounts at hours when nobody was working
A personal Dropbox, OneDrive or Google Drive signed in on a work laptop
Downloads in bulk from SharePoint or a shared drive before a departure
A leaver's mailbox deleted before anyone had thought to look in it

How a mailbox behaves on the way out

A mailbox being used to move material behaves in ways you can recognise. Attachments grow while the recipients narrow to a single private address. A rule appears, sending selected mail outward without anybody watching. The search history looks like hunting — customers, project names, price lists — rather than the day's work. Access drifts into evenings and weekends. The mail platform notes all of it, and each item is retrieved and given its date during the examination.

Private cloud accounts on company kit

The device supplies the other side of it. Browser traces record accounts being created and signed into at Dropbox, OneDrive and Google Drive from a company machine. Sync-client logs and folder layouts reveal the directories that had been set to mirror upward, and from what date. The residue of an upload — cached pages, confirmations, recent-file lists — sits on the image long after somebody has cleared the browsing history. A private account appearing on work hardware in a final month is seldom there for nothing.

The audit trail the tenancy already keeps

Microsoft 365 and Google Workspace keep evidence of their own, and it often decides the matter. Message movement, sharing and downloads are recorded in Purview audit logs and eDiscovery exports. Mail and files are held under Google Vault. Every share and bulk download appears in the SharePoint and OneDrive logs with an account and an hour beside it. Dropbox keeps version histories and recoverable deletions. A mailbox that has been deleted can frequently be brought back out of retention or backup — but only for a while, which is the argument for ringing early.

Two records, one account of it

The finding that persuades is the one that agrees with itself. A 2.1 GB download is logged by the tenancy at 21:14. The same files appear in a private sync folder on the device two minutes afterwards. Browser history closes the circle. Service evidence and machine evidence are assembled into a single run of events, disagreements between them are flagged rather than smoothed over, and everything — mailbox export, audit extract, the image itself — is hashed before an account is suspended or a licence taken back.

The method behind all of it is at the forensic recovery hub. Logins and server records carry on at insider threat forensics, the employer casework at employee data theft, and holding material at legal hold and chain of custody. Costs are on the prices page.

// what you get back

Findings from the tenancy and the machine

Service records and machine traces, read against each other and presented as one sequence.

Attachments

What went to private addresses, at what size, on which days.

Rules

Forwarding and deletion rules, when they were made and what they caught.

Access

Sign-in hours and places, with the clusters outside working time marked.

Private-cloud residue

Accounts, sync folders and upload leftovers on the work machine.

Audit extracts

Sharing, download and export events out of M365 and Workspace logs.

Mail restored

Messages and whole mailboxes brought back from retention and backup.

// what it costs, and who we can act for

Forensic fees and the footing we work on

The fees, plainly

Each instruction opens with the free diagnostic, which takes 2 working days from the day a device reaches the bench. Forensic casework itself falls outside no fix, no fee. The full forensic investigation with report is £800 + VAT, payable 100% upfront. The less expensive Forensic binary image and deleted-file extraction service, without the report, is £400 + VAT. Any Forensic work required will be payable upfront. A scope covering several accounts, or a whole tenancy, is quoted in writing after the free diagnostic. Both figures also appear on the prices page, and no money is taken until a written scope has been agreed.

The footing we need

Mailbox and cloud work runs on company tenancies and on company devices, or on a solicitor's written instruction. Three footings open the door and there is no fourth: kit the company itself owns; a written instruction from solicitors, an insurer or the court; or a device that is genuinely the client's, which in a family matter means their own machine or one owned jointly. We do not hack. Live communications are not intercepted. Where a client has no right to look inside a device, neither have we.

// getting your device to us

Getting it here — no great performance

Cloud material is often preserved by export rather than by parcel. Call 0800 689 0668 and we will work through what can be captured remotely and what has to travel. Devices reach our Cambridge location by tracked, insured post or over the counter, with custody logged from the signature.

Is the drive still bolted inside a laptop, desktop, MacBook, iMac, server or CCTV / DVR recorder? The hard drive or SSD needs to come out first, and only the bare drive travels — taking drives out of machines is not something we do here. Storage soldered to a motherboard (Apple Silicon Macs, one or two very thin laptops) is the single thing beyond us: if it will not come out, it cannot come in.

  • Bubble wrap and a firm box or padded envelope, packed so nothing shifts about. Cables, caddies and power bricks are no use to us — keep them.
  • Print the shipping & booking-in form (PDF), write your name, your number and a couple of lines on what happened, and put it in with the drive.
  • Royal Mail Special Delivery covers it tracked and insured door to door; a courier of your own does the same job if that suits you better.
  • Rather hand it over yourself? Reception at the address below takes drop-offs, Mon–Fri 9:00am–5:30pm.
// where your device is headed

Cambridge Data Recovery

Compass House, Vision Park
Chivers Way
Cambridge, CB24 9AD

↓ Print the shipping & booking-in form (PDF)

Mark the parcel for the attention of Cambridge Data Recovery. From Norwich it is about an hour and twenty down the A11, then two minutes off the A14 at Junction 32 — or next working day by tracked post. You hear from us as soon as it is booked onto the bench.

Unsure what to put in the box? Ring 0800 689 0668 before you seal it, or run the free online diagnostic.

// email and cloud — asked before instruction

What IT managers ring about

Often, if we hear early enough. A deleted mailbox usually sits in retention for a period in which it can be restored, and a backup or a litigation hold stretches that further. The period is finite, so preservation ought to start the day the question is first asked.
Its configuration shows what it was set to catch, and message trace and audit records show what moved while those logs still hold. Where the window has closed, the pattern at the receiving end on the device commonly covers the gap, and the report says which part rests on which source.
No. A private account is beyond an employer's reach and beyond ours. What we work on is the company's half of each exchange: tenancy logs, machine traces, and whatever a court later orders to be disclosed. That half is usually sufficient.
Secure it, but preserve before you do. Take the mailbox export, capture the audit logs, image the device — then reclaim licences or purge the account. Suspending in the wrong order has cost more email evidence than any leaver ever managed, and we will take your IT team through the order on the telephone.

The tenancy remembers. For a while.

Retention windows close on their own schedule rather than yours — ring the freephone first.