WhatsApp
← Blog·Mobile forensics·27/09/2025
Flat-vector illustration: smartphone connected to a forensic extraction device with data waveforms and shield motif.

Mobile phone forensics: the core principles and how it works.

Over 95% of criminal investigations now involve digital evidence from mobile devices. The hard part is not unlocking a phone, it is preserving every digital trace so the evidence stands up in court.

What mobile phone forensics actually is

Mobile forensics is the disciplined extraction, preservation and analysis of data from smartphones and tablets so that what comes out of the device can be relied on in court. It is not data recovery, and it is not what a repair shop does. The difference is procedural: every step is recorded, every copy is hashed, and the original device is left in the state it was found.

A modern examination reaches messages and call logs, contacts, photographs and video, browsing history, location traces, application databases, health and sensor data, and a large volume of system artefacts that ordinary users never see.

Extraction methods, in plain terms

MethodWhat it doesWhen it is used
LogicalCopies visible user data through the phone's own interfacesLive records, quick preliminary reviews
File systemCopies the accessible file system, including some system dataFuller picture without full physical access
PhysicalBit for bit image of storage, including deleted materialSerious cases where deleted content matters
Chip offReads the memory chip directly after careful removalDamaged or otherwise unreadable devices

Why the method matters for solicitors

The choice of method sets the ceiling on what your report can say. A logical extraction can confirm the presence of a message; it usually cannot confirm the absence of one. A physical or file system extraction can, because it reaches the databases and journals that record deletions. If you are considering the value of digital evidence to a case, ask the examiner what depth of extraction the device supports before you commit to a strategy.

How the process runs

  1. 01
    Scoping. Agreeing what the court actually needs answered, and what the extraction must reach to answer it.
  2. 02
    Preservation. Isolating the device from the network, documenting its state, and taking a forensic image.
  3. 03
    Verification. Cryptographic hashes at every stage, so any later change to the copy is provable.
  4. 04
    Analysis. Reconstructing conversations, timelines, locations and app activity from the image, never from the live device.
  5. 05
    Reporting. A CPR Part 35 compliant report that a non technical reader can follow, and that will hold up under cross examination.

What we need from the instructing party

  • The specific questions in issue, framed for the tribunal.
  • The device, ideally powered off, with any PIN or passcode noted separately.
  • The relevant date range and the accounts or numbers of interest.
  • The court deadline and whether a preliminary opinion is needed first.

Do not let anyone have a quick look at the device. Every unlock, scroll and screenshot alters the very records the examination will rely on.

Frequently asked questions

Can deleted messages really be recovered?

Often yes, depending on the device, the operating system version and how long ago the deletion took place. The earlier the device is preserved, the more there is to recover.

Is the phone damaged during examination?

No. A properly conducted examination leaves the handset in the state it was received. All work is done on the forensic image.

How long does it take?

A focused examination on a single device usually takes days rather than weeks, once the device and instructions are with us. Urgent work can be prioritised.