Can Law Enforcement Really Recover Files You’ve Deleted? (2024)

Can Law Enforcement Really Recover Files You’ve Deleted? (1)

When you delete a file from your computer’s hard drive, it’s never really gone. With enough effort and technical skill, it’s often possible to recover documents and photos previously thought obliterated. These computer forensics are a useful tool for law enforcement, but how do they really work?

Setting the Legal Groundwork

Before we get into the technical weeds, it’s worth discussing the boring procedural and legal aspects of computer forensics within the context of law enforcement.

First, let’s dispel with the old myth that a warrant is always required for a law enforcement officer to examine a digital device like a phone or a computer. While that’s often the case, plenty of “loopholes” (for lack of a better word) can be found within the fabric of the law.

Many jurisdictions, like the United Kingdom and the United States, permit customs and immigration officials to examine electronic devices without a warrant. American border officers can also examine the contents of devices without a warrant if there’s an imminent thread of evidence being destroyed, as affirmed by an 11th Circuit judgment from 2018.

When compared to their American counterparts, U.K. cops tend to have more leeway to seize the contents of devices without having to make their case to a judge or magistrate. They can, for example, download the contents of a phone by using a piece of legislation called the Police and Criminal Evidence Act (PACE), regardless of whether any charges are brought. However, if the police ultimately decide they wish to examine the contents, they need sign-off from the courts.

Legislationalso gives U.K. police the right to examine devices without a warrant in certain circ*mstances where there is an urgent need—such as in a terrorism case, or where there is a genuine fear that a child may be sexually exploited.

But ultimately, regardless of the “how,” when a computer is seized, it merely represents the start of a long process that begins with a laptop or phone being removed in a tamper-resistant plastic bag, and often concludes with evidence being presented in a courtroom.

The police must adhere to a set of rules and procedures to ensure the admissibility of evidence. Computer forensics teams document their every move so that, if necessary, they can repeat the same steps and achieve the same results. They use specific tools to ensure the integrity of files. One example is a “write blocker,” which is designed to allow forensic professionals to extract information without inadvertently modifying the evidence being examined.

It’s that legal basis and procedural rigor that determines whether a computer forensics investigation will be successful—not technical sophistication.

Moving Platters, Moving Cases

Can Law Enforcement Really Recover Files You’ve Deleted? (2)

Legal issues notwithstanding, it’s always interesting to note the many factors that can determine the ease in which deleted files can be recovered by law enforcement. These include the type of disk being used, whether encryption was in place, and the drive’s file system.

Take hard drives, for example. Although these have largely been surpassed by faster solid-state drives (SSDs), mechanical hard disk drives (HDDs) were the predominant storage mechanism for over 30 years.

HDDs used magnetic platters to store data. If you’ve ever disassembled a hard drive, you’ve probably observed how they look a bit like CDs. They’re circular and silver in color.

When in use, these platters spin at incredible speeds—usually either 5,400 or 7,200 RPM, and in some cases, as fast as 15,000 RPM. Connected to these platters are special “heads” that perform read and write operations. When you save a file to the drive, this “head” moves to a specific part of the platter and transforms an electrical current into a magnetic field, thereby changing the properties of the platter.

But how does it know where to go? Well, it looks at something called an allocation table, which contains a record of every file stored on a disk. But what happens when a file is deleted?

The short answer? Not much.

Here’s the long answer: The record for that file is deleted, allowing the space it occupied on the hard drive to be overwritten later. However, the data remains physically present on the magnetic platters and is only ever truly deleted when new data is added to that particular location on the platter.

After all, deleting it would require the magnetic head to physically move to that location on the platter and overwrite it. That could impede on other applications and slow the computer’s performance. As far as hard drives are concerned, it’s simpler to just pretend deleted files simply don’t exist.

That makes recovering deleted files much easier for law enforcement. They just have to recreate the missing parts within the allocation table, which is something that can be done with free tools, includingRecuva.

RELATED: How to Recover a Deleted File: The Ultimate Guide

Solid (State) as a Rock

Can Law Enforcement Really Recover Files You’ve Deleted? (3)

Of course, SSDs are different. They contain no moving parts. Instead, files are represented as electrons held by trillions of microscopic floating gate transistors. Collectively, these combine to form NAND flash chips.

SSDs bear some similarities to HDDs, insofar as files are only ever deleted when they’re overwritten. However, some key differences inevitably complicate the work of computer forensics professionals. And like HDDs, SSDs organize data in blocks, with the size varying wildly between manufacturers.

The key difference here is that for an SSD to write data, the block has to be completely empty of content. To ensure that the SSD has a constant stream of available blocks, the computer issues something called a “TRIM command,” which informs the SSD which blocks are no longer required.

For investigators, it means that when they try to find deleted files on an SSD, they may find that the drive has innocently put them far beyond their reach.

SSDs can also scatter files across multiple blocks across the drive to reduce the amount of wear and tear incurred by day-to-day use. Because SSDs can only withstand a finite number of writes, it’s important they’re distributed across the drive, rather than in a small location. This technology is called wear leveling, and has been known to make life hard for digital forensics professionals.

Then there’s the fact that SSDs are often harder to image, because you often physically can’t remove them from a device.

Whereas hard drives are almost always replaceable and connected via standard interfaces, like IDE or SATA, some laptop manufacturers choose to physically solder storage to the machine’s motherboard. It makes extracting the contents in a forensically sound way much harder for law enforcement professionals.

The Real Complications

So, in conclusion: Yes, law enforcement can retrieve files you’ve deleted. However, advances in storage technology and widespread encryption have complicated matters somewhat.

Yet, technical problems can often be overcome. When it comes to digital investigations, the biggest challenge facing law enforcement isn’t the mechanisms of SSD drives but rather their lack of resources.

There aren’t enough trained professionals to do the work. And the end result is, many police forces across the world are faced with a crushing backlog of unprocessed phones, laptops, and servers.

A Freedom of Information act request from the U.K. newspaper The Times showed that the 32 police forces across England and Wales have over 12,000 devices pending examination. The time to process a device there varies, from one month to over a year.

And that has consequences. The bedrock of any fair criminal justice system is that the accused are afforded a speedy trial. As the saying goes, justice delayed is justice denied. This principle is so fundamentally important, it’s even represented in the Sixth Amendment to the U.S. constitution.

Sadly, it’s not a problem that’s easily fixable without more money being spent by forces on recruitment and training. You can’t solve it with more technology.

READ NEXT

  • Should You Replace Your Laptop With a Mini PC?
  • Plex’s Lifetime Pass is Cheaper Than Ever Today
  • How to Watch the Marvel Movies in the Correct Order on Disney+
  • 10 iPhone Spotlight Search Features You Should Be Using
  • Does Your Xbox or PlayStation Need a Cooling Fan?
  • What Are Tracking Cookies, Really?
Can Law Enforcement Really Recover Files You’ve Deleted? (2024)

FAQs

Can Law Enforcement Really Recover Files You’ve Deleted? ›

So, in conclusion: Yes, law enforcement can retrieve files you've deleted. However, advances in storage technology and widespread encryption have complicated matters somewhat. Yet, technical problems can often be overcome.

Can police recover permanently deleted data? ›

Keeping Your Data Secure

So, can police recover deleted pictures, texts, and files from a phone? The answer is yes—by using special tools, they can find data that hasn't been overwritten yet.

Can police recover deleted files from computer? ›

In the case of HDD hard drives, the police and forensic entities can recover the data moved to unallocated space as long as it has not been overwritten. They will however be unable to both date and time stamp the data as this information, the metadata, would have been stripped out.

Can deleted files really be recovered? ›

If you can't find a file on your computer or you accidently modified or deleted a file, you can restore it from a backup (if you're using Windows backup) or you can try to restore it from a previous version. Previous versions are copies of files and folders that Windows automatically saves as part of a restore point.

How do investigators recover deleted files? ›

In addition to searching the file table, most data recovery and forensics programs can recover deleted files by searching the free space (also called unallocated space) on a hard drive for the header and footer values associated with different types of files. This technique is called "carving".

Is deleted data gone forever? ›

But just because you delete a file, doesn't mean that the data is gone forever. Traditional spinning hard drives store data on polished magnetic metal platters (or glass or ceramic with a thin metal layer) and the store data by magnetizing sectors.

How recover permanently deleted data? ›

Method 1: Check the Recycle Bin
  1. Double-click on the Recycle Bin to open it.
  2. Find and see the files to be recovered. You can use the Ctrl and Shift keys to choose multiple items at once.
  3. Right-click on the selection and choose Restore. ...
  4. Verify the files have indeed been restored to their original or new location.
Feb 7, 2023

Can forensics recover overwritten data? ›

Device Usage After Deletion

If new data overwrites that old data, the old data is no longer recoverable.

Where do permanently deleted files go in computers? ›

When you delete a file from your computer, it moves to the Windows Recycle Bin. You empty the Recycle Bin and the file is permanently erased from the hard drive. ...

Can police recover deleted Instagram messages? ›

Yes, if the police department has a search warrant, they can use advanced tools and experts to retrieve deleted Instagram chats.

How far back can deleted files be recovered? ›

You are not sure when a deleted file can be overwritten. So, there is no fixed answer to how long is too long before a deleted file is unrecoverable. You might discover that some files that were deleted years ago are still recoverable. But, some files that were deleted recently become unrecoverable.

Why files are not permanently deleted? ›

When you delete a file on your computer and empty the Recycle Bin, your data does not entirely disappear. Although the file is no longer visible in its original location and your operating system possesses it, a copy remains on your hard drive. The file will remain in the exact spot until another file replaces it.

What data recovery software do the police use? ›

IsoBuster is a well known and often used tool in the forensics world. Many police departments and other governmental institutions in law enforcement and forensic data gathering use IsoBuster extensively.

Can police recover deleted ring videos? ›

Since the Ring company doesn't come up with any recovery service for customers, even police having the warrant to access the videos won't be able to retrieve them.

How do I recover deleted files from cyber forensics? ›

Run MyRecover on your computer > Choose the exact partition or disk where your data is deleted > Click Start Scan. Step 2. Wait for the scan process to finish. The deleted and lost files will be scanned and listed in the Scanned files list during the process.

How old deleted data can be recovered? ›

Find the user who needs their Drive data restored. Restore data. Select the date range for the data that you want to restore. You can only restore data that was deleted within the last 25 days.

How far back can police recover text messages? ›

The police may obtain your opened and unopened messages that are 180 days old or older with a subpoena. But they have to let you know once they've requested this access from the provider. Law enforcement are allowed to access older, unread emails without telling you if they obtain a court order.

Can police recover after factory reset? ›

You don't need to worry about others accessing your data as long as you've got encryption enabled. Not backing up your data is one of the common mistakes, but it isn't the only one that Android users make. Yes, data can be recovered utilising a forensic data recovery process after a factory reset.

How far back can texts be recovered? ›

You can only recover messages and conversations that you deleted within the last 30 to 40 days.

Top Articles
Latest Posts
Article information

Author: Terence Hammes MD

Last Updated:

Views: 5933

Rating: 4.9 / 5 (49 voted)

Reviews: 80% of readers found this page helpful

Author information

Name: Terence Hammes MD

Birthday: 1992-04-11

Address: Suite 408 9446 Mercy Mews, West Roxie, CT 04904

Phone: +50312511349175

Job: Product Consulting Liaison

Hobby: Jogging, Motor sports, Nordic skating, Jigsaw puzzles, Bird watching, Nordic skating, Sculpting

Introduction: My name is Terence Hammes MD, I am a inexpensive, energetic, jolly, faithful, cheerful, proud, rich person who loves writing and wants to share my knowledge and understanding with you.