WhatsApp
← Blog·WhatsApp forensics·2025
Flat-vector illustration: chat bubbles above a smartphone with a magnifying glass revealing hidden database metadata.

WhatsApp forensics: tools, challenges and evidence recovery.

With over two billion users, WhatsApp is one of the richest sources of evidence in criminal investigations and civil disputes. Despite end to end encryption, examiners can often recover deleted messages, call logs, media and location data from devices or cloud backups.

Why WhatsApp evidence is decisive

WhatsApp has quietly replaced email as the medium of choice for arrangements people would not put in writing anywhere else. In criminal defence, in the Family Court, in employment and shareholder disputes, the messages people sent on WhatsApp are frequently the difference between a case that runs and a case that settles.

How the examination actually works

  1. 01
    Logical acquisition. Readily available data through the operating system, including local and cloud backups where credentials are held.
  2. 02
    Full file system or physical acquisition. Reaching the WhatsApp databases where deleted messages, media references and metadata live.
  3. 03
    Cloud backup review. iCloud and Google Drive backups, where legally authorised and where decryption keys can be produced.
  4. 04
    Reconstruction. Parsing the databases so conversations, group activity and timelines are reassembled with sender attribution and timestamps intact.
  5. 05
    Reporting. A single, hash verified exhibit that answers the questions in the case.

What can be recovered

Text and deleted messages

Deleted chats leave traces in databases, caches and backups, often recoverable with timestamps and identifiers.

Call logs and media

Voice and video call records with participants and duration; images, video and voice notes even when removed from chat view.

Location data

Shared pins and live location updates stored in WhatsApp records help build a movement picture.

Contacts, groups and device info

Contact lists, group memberships and admin activity, plus device level identifiers.

Screenshots are not evidence

Solicitors are routinely handed screenshots by clients. As exhibits they are fragile. A screenshot carries no database record, no message identifier, no delivery receipt, and nothing to show whether messages were edited, selectively omitted or fabricated. Modern image tools can produce a convincing fake chat in minutes.

A forensic extraction answers differently. Each message is produced with its database identifiers, timestamps in the device's own clock context, sender attribution, delivery and read state, and the surrounding conversation intact. The whole exhibit is hash verified back to the source device. Where both sides of the conversation are available, they can be reconciled message by message, which usually ends any allegation of tampering.

Working with disappearing messages

Disappearing message settings quietly erase material week by week. If a matter is contemplated, the preservation clock starts the day the device is identified, not the day proceedings are issued. A short letter to the client asking them to stop using the account and hand the device over is often the single most valuable step in the case.

Frequently asked questions

Can deleted WhatsApp messages be recovered?

Often yes, from device databases, caches or cloud backups. Recovery rates fall sharply once the account continues to be used.

Is WhatsApp forensics lawful?

Yes, when conducted with proper authorisation, a court order, or the account holder's consent.

Will the extraction be admissible?

Yes, when the method, the chain of custody and the hash verification are properly documented.