Last week I posted a poll on LinkedIn with the question:
What is a realistic expectation from a cell phone device forensic exam in litigation?
Here are the potential poll answers:
- Recovered deleted texts/app data
- Usage timeline without full content
- Limited by locks/encryption
- Little/no data after wipe or overwrite
All four can be correct under the right circumstances. That is the point. Device forensics is not a magic wand, and it is not a guarantee. It is a technical process constrained by the phone’s condition, the operating system, encryption, how long the device kept being used after the incident, and where the industry sits at any given moment in the ongoing contest between phone manufacturers hardening security and the tools available to examiners.
That last point matters more than most attorneys realize. Digital forensics lives in the middle of a permanent arms race. Manufacturers improve lock screens, encryption, secure enclaves, and anti-tamper protections because malicious hackers and thieves keep trying to break in. Those same improvements also limit what a lawful forensic extraction can obtain, even with a court order, consent, or a properly preserved device. What was routinely recoverable two years ago may be difficult or impossible today on a fully updated phone. What is difficult today may become available again when a new exploit, bootloader method, or tool update lands, and then get closed again in the next OS patch. The result is simple: what you can get from a phone extraction is constantly changing. Realistic case strategy has to account for that, not assume a static checklist of “always recoverable” evidence.
What follows walks through each poll answer the way it actually plays out in commercial vehicle crash litigation, other civil cases, and criminal defense, leaning hard into managing over-expectations, while still explaining what you can often still obtain when conditions are imperfect.
First, a quick review: device forensics is not the same as carrier records
Before the four answers, draw a bright line.
Carrier Call Detail Records (CDRs) are business records from the provider: call/SMS metadata, sometimes tower/sector data, sometimes data-session logs. They do not require the handset. They also usually do not give you message content, app usage, or proof the phone was unlocked in someone’s hand.
Device forensics means imaging and analyzing the phone itself (or a proper forensic image of it). In the best case, that can include:
- call logs and contacts
- SMS/MMS and some third-party messaging artifacts
- app data and databases
- photos/videos and media metadata
- location related artifacts
- browser history, notes, health data, and more
- deleted items still lingering in unallocated or residual space before the space is overwritten
In the real world, you often get some of that, not all of it. The comprehensive report states what was extracted, what could not be extracted, and why, without dressing limitations up as certainty.
1) Recovered deleted texts/app data
This is the outcome attorneys hope for, and sometimes it is exactly what happens.
When it is realistic:
Deleted data recovery is most plausible when:
- the device was preserved quickly after the incident
- it was not factory reset
- it was not heavily used for weeks afterward (overwriting unallocated space)
- the extraction method obtained a deep enough image (not merely a quick logical pull of what the user can see)
- the OS/app versions still leave recoverable remnants in databases, logs, or unallocated space
In that setting, examiners may recover deleted SMS threads, app chat fragments, deleted photos/videos, navigation history remnants, notification logs, or database records the user thought were gone.
Commercial vehicle / civil litigation:
Recovered deleted texts or app artifacts can show communication or phone interaction near a crash timeframe, dispatcher pressure, side work, or a cleanup effort after the crash. On the defense side, recovered content can undercut a plaintiff’s narrative, support comparative fault, or show the device activity does not match the story being told.
Criminal defense:
Deleted message and app recovery can corroborate an alibi, contradict a claimed communication pattern, or expose gaps in the government’s theory especially when paired with CDRs and other independent records.
Realistic expectation:
“Deleted” does not automatically mean “recoverable.” Modern apps encrypt local data. Some messengers are designed so content is not retained in a useful way. Secure delete, OS compaction, flash storage behavior, and continuous device use can destroy residual traces. A factory reset is often devastating. And even when fragments come back, they may be incomplete: pieces of a thread, timestamps without full bodies, or artifacts that require careful interpretation.
Imperfect but still useful:
Partial recovery still matters. A handful of deleted messages with solid timestamps, a recovered attachment, or app residue showing activity in a key window can become powerful when corroborated. The win is often not “we got everything.” It is “we got enough reliable artifacts to answer the question that matters.”
2) Usage timeline without full content
This may be the most underrated realistic outcome in modern examinations—and one of the healthiest expectations you can set.
When it is realistic:
Even when full message bodies, decrypted app contents, or deep deleted recovery are unavailable, many extractions still produce a defensible timeline of device activity, such as:
- lock/unlock patterns (when available)
- app open/usage residues
- notification and knowledge-center type artifacts
- connectivity events
- media creation times
- system logs and database timestamps
- evidence that the device was active, idle, charging, or interacting with specific apps around key times
You may not get the text of the conversation. You may still get evidence that the phone was in active use, that a particular app family was engaged, or that activity clustered in the minutes before a crash or alleged offense.
Commercial vehicle / civil litigation:
In distracted driving cases, attorneys often over-focus on “show me the text.” Jurors and adjusters also understand timelines. A clean exhibit showing device activity overlapping an established driving window, supported by ELD, telematics, dispatch, video, or other proof the vehicle was moving, can be highly persuasive even without content. It also strengthens the argument for broader discovery when the device shows activity the other side has not explained.
Criminal defense:
A usage timeline can support or undermine presence, opportunity, and narrative sequencing. It can show the phone was active somewhere inconsistent with the accusation, or that supposed “smoking gun” communications are not reflected in device activity the way the state implies. Just as important, it can prevent your own side from overclaiming.
Realistic expectation:
A timeline is not the same as proof of what was on the screen, who was holding the phone, or whether use was handheld versus hands-free. Background processes exist. Shared phones exist. Passengers exist. Credible reporting uses disciplined language: “artifacts consistent with activity,” not “the driver was texting,” unless other evidence closes that gap.
Imperfect but still useful:
When content is blocked by encryption or platform limits, timeline and metadata are often the best remaining value on the device—and they pair extremely well with CDRs, social media records, vehicle data, and testimony. Device forensics and carrier records are complementary, not interchangeable.
3) Limited by locks/encryption
This outcome is common, and it is easy to oversell. “We sent the phone to a forensics lab” does not mean “we obtained the contents of the phone.” When a device is passcode-locked and the forensic tools available for that make, model, and OS version cannot bypass the lock or access the encrypted user data, the realistic handset result is often no usable user content, not a reduced set of call logs and messages that somehow still come off a phone you cannot get into.
When this is the realistic expectation
Plan for little or nothing from the device itself when:
- the phone is locked and the passcode is unknown or will not be provided
- biometrics are unavailable (device rebooted, disabled, or not usable for the exam)
- there is no supported bypass, bootloader method, or exploit for that OS version with the tools on hand
- encryption keeps user data inaccessible without proper unlock/authentication
- legal authority exists to examine the phone, but authority alone does not decrypt a modern locked handset
That fact pattern shows up in civil cases (including commercial vehicle matters) when a phone is collected or produced without credentials, and in criminal cases when everyone assumes an “extraction” occurred but the lock stopped the exam at the gate.
What “limited by locks/encryption” actually means
Be precise in how you describe the result:
- Locked out / no supported access
If the tool chain cannot get past the passcode and encryption for that device state and OS, you should expect no reliable recovery of user content from the handset, not call history, not SMS/MMS, not app databases, not deleted items, not a full media set. The work product may still document identifying information visible without unlocking (where applicable), photos of the device, chain of custody, OS/version as determined, attempts made, tool/version limitations, and a clear statement that user data was not accessible. That is a real forensic result. It is not a partial content dump. - Access obtained, but scope is still limited
Separately, once a phone is unlocked or otherwise lawfully accessible, encryption architecture, OS protections, app security, and extraction type can still limit what categories are available. That is a different problem from “we never got in.” Do not conflate the two in pleadings, client emails, or expert outlines. - The security arms race sets the ceiling
Manufacturer hardening against thieves and attackers also limits lawful forensic access. A bypass that worked on an older build may fail after an update. Tool capability changes over time. What you can get is tied to this device, this OS, this lock state, and today’s methods, not to a generic promise that “forensics always gets something off the phone.”
What you should not expect
Do not build strategy on the idea that a locked phone with no bypass will still produce:
- call logs, SMS/MMS, or chat content from the handset
- deleted message recovery
- full or near-full app data
- a complete user file system
- the same evidence you would get from an unlocked device with a supported full extraction
If someone claims those categories were obtained while the device remained locked and unsupported for bypass, demand method detail. That claim needs to be squared with device state and tool capability—not accepted as normal.
What attorneys should do instead
- Ask early, before promising the client or the court: Is there a supported path to user data on this locked device/OS right now? If the answer is no, say so.
- Solve for credentials and legal process: consent, court orders, production obligations, and whether the passcode can lawfully be obtained matter as much as lab scheduling.
- Preserve the device correctly anyway: even when current tools cannot bypass the lock, poor handling can still worsen outcomes, and future tool capability or later-obtained credentials may change the picture. Do not factory reset, do not “just try passwords” endlessly, and do not allow the phone to be placed back in service.
- Shift proof to other sources when the handset is a brick: carrier CDRs, cloud accounts (with proper authority), vehicle systems (ECM/ELD), dashcam, app provider records, and witness evidence may carry the timeline issues the phone cannot. That is parallel proof, not content pulled from a locked handset.
- Use a no-access result deliberately: in civil matters, lockout can raise preservation, cooperation, and production issues if a party controlled the device and credentials. In criminal defense, it can undercut any narrative that “the phone was fully examined” when it was not. In both settings, the expert’s value is often explaining why nothing user-level was obtained, not dressing up an empty result as a partial success.
Bottom line for attorneys
If the phone is locked and there is no supported bypass for that OS/device state, the realistic expectation from device forensics is often no user data from the handset. Locks and encryption are not a soft filter that still lets call logs and texts through as a matter of course. They are frequently a hard stop.
A clear report that says “could not access user data because of lock state/encryption and current tool limits” is credible. A report, or a case plan, that assumes content will appear anyway is not. Engage someone who will tell you which of those two you are dealing with before the extraction is sold as a centerpiece of the case.
4) Little/no data after wipe or overwrite
Sometimes the honest result is sparse. That can still be a case-critical finding if you handle it correctly.
When it is realistic:
Little or no useful user data is a real outcome when:
- the phone was factory reset
- the phone continued in heavy daily use for a long period after the event, overwriting recoverable space
- secure wipe features, encryption + reset, or app-level secure deletion did their job
- only a severely limited extraction is possible and residual areas cannot be accessed
Commercial vehicle / civil litigation:
In trucking and other serious injury cases, the difference between “we examined the phone and recovered X” and “we examined the phone and it had been reset after the crash / after notice” can be enormous. The absence of data is not automatically proof of bad faith—but timing, litigation holds, preservation letters, carrier records showing communications the device no longer reflects, and testimony about who handled the phone can turn a barren extraction into a spoliation and credibility issue. On the other side, if your client’s phone is empty because it was reset for an ordinary trade-in before any duty to preserve attached, you need that chronology documented early.
Criminal defense:
A wipe can look like consciousness of guilt, or it can be routine, or it can be someone else’s act. Forensic documentation helps separate “no data obtained” from “evidence of intentional destruction at a particular time.” Defense counsel also needs realistic expectations when the government’s extraction is thin: thin does not always mean exculpatory, and it does not always mean incompetence. It may mean the device simply had nothing left to give.
Realistic expectation:
Attorneys sometimes hear “forensic exam” and assume something useful must come out. Not true. A competent exam can yield a well-supported negative or near-negative result. That is still information. It closes off weak theories, redirects budget to CDRs/cloud/other devices, and prevents surprise at deposition when everyone assumed a treasure trove was coming.
Imperfect but still useful:
Even when content is gone, examiners may still document device identifiers, reset indicators, setup dates, account remnants, proof of later use, or mismatches between carrier activity and device contents. Those scraps frequently matter more than clients expect, especially on preservation and authenticity issues. The timing of a factory reset, wipe, or deletion can support a spoliation claim.
The arms race problem: why your last case is a bad template for your next one
It is worth saying plainly for attorneys who handle these issues often.
Device forensics is caught between:
- malicious actors trying to defeat phone security, and
- manufacturers improving encryption, hardware security modules, lockout behavior, and exploit resistance in response.
Forensic capability rides that wave. It does not sit above it. That means:
- tool support lags behind new phone models and OS versions
- methods appear, disappear, and reappear
- two phones of different generations can produce radically different results under the same legal authority
- “We got it last time” is not a guarantee we will get it this time
- reports must be dated in their technical context, not written as eternal truths about “what phones show”
When you retain an expert, look for one who will tell you when the answer is “not with current tools on this device,” and who will distinguish best-case marketing from device-specific reality.
Tips for Attorneys
Cell phone device forensics is most useful when you treat it as part of case strategy, not as a last-minute request for “everything on the phone.” The tips below are practical steps you can take in civil matters (including commercial vehicle crashes) and criminal defense.
1. Engage a qualified expert early.
Do not wait until the eve of a deposition, mediation, or trial to bring in a mobile forensics expert. Early involvement helps you decide whether a device exam is worth pursuing, what legal process is needed, how to preserve the handset, what the likely yield is given make/model/OS and lock state, and how device findings should fit with carrier records, ECM/ELD data, dashcam video, and witness accounts. An early consult also helps you avoid spoliation risk and over-promising to the client or the court.
2. Issue preservation directives immediately.
As soon as a phone may matter, send clear written hold instructions. Direct the relevant parties cease using the phone immediately and preserve it until it can be examined. In CMV and other civil cases, include phones in litigation holds alongside trucks, dashcams, and electronic logs. In criminal matters, move quickly on return-of-property issues and defense access so evidence is not lost to continued use or a wipe. Contact me for copies of example preservation letters and language for subpoenas.
3. Secure the device the right way.
When you can control or influence custody of the phone: keep it powered off if that is the agreed protocol, or isolated from networks (Airplane Mode and/or Faraday bag) when power-on is required; do not guess passcodes repeatedly; do not pair it to a new computer “just to look”; and document chain of custody from the moment it comes into counsel’s or an agent’s control. Casual browsing by a well-meaning investigator or family member can alter timestamps, trigger sync, or destroy residual data.
4. Get the lock-state and consent/authority issues straight before extraction.
Know whether you have consent, a court order, warrant-based access, or another lawful path, and whether the passcode, biometrics, or cloud credentials will be available. Locks and encryption are often the difference between a useful extraction and a partial or failed one. Build that into your discovery plan and your client conversation before anyone assumes full content is coming.
5. Demand device forensics and carrier records when both matter—and know the difference.
Device extractions and carrier CDRs are not substitutes for each other. Ask for both when the case issues call for it and be prepared to explain to clients and co-counsel why tower/CDR data will not produce iMessage or app content, and why a locked phone may not produce the full message history they expect. Pairing both sources is often how you build a coherent timeline even when content is incomplete.
6. Preserve first; analyze with a purpose.
Do not treat the extraction as a fishing expedition with no theory of the case. Before or as soon as the forensic image is available, identify the questions that matter: distraction in the minutes before a crash, contact with a co-defendant, deletion after notice, location consistency with an alibi, or impeachment material. Purposeful review controls cost and produces testimony you can actually use.
7. Protect admissibility and defensibility, not just “findings.”
Insist on a documented methodology, tool/version notes where appropriate, hash verification, and a report that separates facts from opinions. If you may call the examiner, plan for cross on scope, limitations, and what was not found. A clean, limited report beats a dramatic over-read that collapses under scrutiny.
8. Coordinate phone evidence with the rest of the file.
In commercial vehicle cases, align phone timelines with ECM/ELD data, dashcam footage, dispatch records, and scene evidence. In criminal cases, align them with body-worn camera, tower dumps or CDRs, surveillance video, and statements. Device forensics rarely stands alone; it is strongest when it corroborates or challenges other proof.
9. Treat “no data” or “partial data” as a result, not a failure.
A wipe, overwrite, or encryption wall can still support arguments about timing of deletion, control of the device, failure to preserve, or the limits of the opposing narrative. Ask your expert to explain why the extraction was limited so you can decide whether the point is evidentiary, instructional for the jury, or primarily about spoliation and sanctions strategy.
Conclusion
A realistic expectation for cell phone device forensics in
civil litigation—especially commercial vehicle crashes—and in criminal defense
is not “we will get everything.” It is this: a proper exam will tell you
what this device, in this condition, at this moment in the security/tooling
arms race, can and cannot support.
Sometimes that means recovered deleted texts and app data.
Sometimes it means a solid usage timeline without full content.
Sometimes it means a partial extraction limited by locks and encryption.
Sometimes it means little or no user data after a wipe or overwrite.
All four outcomes are legitimate. The attorneys who get hurt
by device forensics are rarely the ones who received a limited report. They are
the ones who promised, or expected, an unlimited one.
If you treat device forensics as a disciplined search for
reliable artifacts, paired with carrier records and the rest of the case
evidence, you will make better preservation decisions, better spending
decisions, and better courtroom claims.
If you have questions about a specific device, preservation
timing, or what an extraction is likely to yield before you subpoena or
stipulate your way into a corner, contact me at ben@braveinvestigations.com
or through the contact form on this page.


