About Our Mobile Device Forensics Practice

Law & Forensics’ Mobile Device Forensics team has extensive experience performing forensics on mobile devices in a wide range of civil and criminal disputes, investigations, arbitrations, and administrative proceedings.

Whether data was deleted or hidden, intentionally or not, if it is present on the device – our Mobile Device Forensics team can identify, collect, and forensically preserve it.

Our Services

100s of years of collective experience doing forensics. And of course working out of the box and solving problems…

Conduct Forensic Investigations Involving Mobile Devices

  • Deliver a strategic, systematic, and economic approach to investigating and collecting a myriad of data sources including network, mobile devices, smartwatches, fitness trackers, and other mobile devices.
  • Identify, collect, and analyze custodians and document locations across multiple mobile devices using eDiscovery and forensics tools.
Mobile Device Forensics
Mobile Device Forensics

Preserve, Identify and Collect Data from Mobile Devices

  • Identify and analyze relevant files on mobile devices including smartphones, tablets, smartwatches, fitness trackers, and other mobile devices.
  • Collect electronically stored information (ESI) and data using forensic tools from a wide range of mobile devices including Samsung devices (Galaxy, Note, Gravity, S8530, Galaxy Tab), Apple iPhones, Google Pixel, Android devices, Apple devices (iPod, Apple TV, Apple Watch), Microsoft devices (Microsoft Surface tablet, Xbox), ZTE devices (Blade, nubia, Axon), Acer devices and phones, Dell devices and phones, LG phones and devices, Motorola devices and phones.
  • Cull, process, and search ESI using forensic and e-discovery tools.
  • Advise clients that are working with third-party vendors on best practices relating to processing and searching ESI from mobile devices.

Recover and Analyze Valid and Deleted Files from Mobile Devices

  • Examine and recover valid and deleted electronically stored information and data stored in mobile devices’ non-volatile (NAND) flash memory or associated cloud accounts, and even analyzing backups stored on other devices.
  • Examine deleted data, even if the deleted data on the device is unrecoverable because it has been overwritten, our team may still prove that it was deleted, which can still be considered key information for forensics cases.
  • Analyze data collected from all types of mobile devices using various forensic tools, including proprietary forensic hardware and software.
Mobile Device Forensics
Mobile Device Forensics

Author Expert Reports, Create and Review Forensic Collection Protocols, and Testify on Wide Range of Mobile Device Forensics Topics

  • Prepare reports on technical topics related to mobile devices and ESI.
  • Develop defensible collection plans, including tracking and documentation that demonstrate reasonable preservation of ESI and data from mobile devices, tablets, smartphones, tablets, fitness trackers, and other mobile devices.
  • Review opposing parties’ expert reports and preparing rebuttal reports on technical topics related to mobile devices and ESI.
  • Testify in depositions, civil and criminal trials, arbitrations, and administrative proceedings on the completeness of opposing party experts analysis or the results of Law & Forensics analysis in all types of cases including white-collar crime, fraud, intellectual property theft, breach of contract, partnership dissolutions, employee misconduct, workplace harassment, trade secret theft, copyright infringement, and failed transactions.

Case Studies by Industry

Industry/Sector: Software

Type of Case: Breach of Contract

Description: Hired by in-house counsel to perform a forensic investigation that resulted in a favorable outcome for the client, a software company with a complex breach of contract dispute. Efforts included:

    • Identified, collected, and preserved data from laptops, desktops, proprietary medical testing, and dozens of mobile devices.
    • Recovered ESI and responsive data, including deleted iPhone messages, emails and photographs, and information on proprietary medical testing devices.
    • Analyzed valid and deleted files and incorporated the evidence into a report that the company used to obtain a favorable settlement.
100s of Android Devices


100s of Thousands

of files recovered

1000s of Devices Scanned

with our software

50.3k Mailboxes

examined by L&F

50+ Collective Years

of relevant experience

100’s of Reports


 Mobile Forensics Practice Edge

Cyber Insurance for Law Firms: Understanding the Cyber Risk Policy and Key Considerations for Law Firm Policy Holders


Annual Review of Regulations of Bitcoin and Blockchain in the United States and Abroad

Competitive fees


Review of Alternative Dispute Resolution Case Law in 2018

Quality Control