Trade Secret Theft Investigations
Forensic investigation of trade-secret misappropriation and departing-employee matters — establishing what left, how it left, and who moved it, on a record that holds up at the preliminary-injunction stage and beyond.
Trade Secret Theft Investigations capabilities
Departing-employee examination
Reconstructing the final weeks of access from workstation, mobile, cloud, and email artifacts — USB attachment history, mass downloads, personal-cloud syncing, forwarding to personal accounts, and file access immediately preceding resignation.
Exfiltration reconstruction
Establishing the path data actually took, and distinguishing deliberate removal from routine business use. The distinction usually decides the motion, and it is a question about artifacts rather than intent.
Rapid preservation
Forensically sound imaging of departing-employee devices and accounts before they are reissued, wiped, or reassigned — the window that most often determines whether the evidence survives at all.
Source code and technical comparison
Structured comparison of code, designs, and technical documents to identify copying, derivation, and the fingerprints that survive superficial modification.
Injunction and testimony support
Methodology reports and declarations built for the compressed preliminary-injunction timeline, with the same examiner available to testify to the findings.
Trade Secret Theft Investigations — matters we are engaged for
Resignation to a direct competitor
The pattern is familiar: a resignation, a short notice period, and a new role at a rival. We examine the weeks before departure for the activity that does not fit an ordinary handover — bulk access to files outside the person's role, archives assembled and deleted, sync clients installed late.
Mass download before departure
Volume alone is rarely enough; what matters is what was taken relative to what the person legitimately touched. We baseline normal activity for the role, then show the departure-window activity against it so the anomaly is demonstrable rather than asserted.
Personal cloud, webmail, and removable media
Data usually leaves through consumer channels — a personal Dropbox, a Gmail draft, a USB stick. We reconstruct device connection history, sync logs, and webmail artifacts to establish the route out, and what travelled along it.
Source code and design files
Where the asset is code or CAD, the question is whether what the competitor now holds derives from what the employee had. We compare artifacts, build history, and commit records, and document the method so an opposing expert can reproduce it.
Contractors, vendors, and joint ventures
Misappropriation is not only an employee problem. Where a counterparty had authorized access, the analysis turns on scope — what the agreement permitted versus what the logs show was actually taken, and when.
Trade Secret Theft Investigations — frequently asked questions
How do you prove trade-secret misappropriation forensically?
Forensic proof generally rests on three linked showings: that the protected material existed and was treated as confidential, that the accused party accessed or removed it, and that the removal falls outside ordinary business use. The artifacts that carry those showings are things like USB device history, cloud-sync and upload logs, email forwarding to personal accounts, mass file access shortly before departure, and the presence of the material on a destination system. No single artifact is usually decisive; the pattern across several is.
What digital evidence shows data exfiltration by a departing employee?
Common indicators include registry and system records of external storage attachment, anomalous volumes of file access or copying in the days before resignation, personal cloud-storage clients installed or synced late in employment, documents emailed or forwarded to personal accounts, printing spikes, and deletion or wiping activity after notice was given. Each has innocent explanations in isolation, which is why the examination looks at sequence and volume rather than treating any one artifact as proof.
How quickly does forensic preservation need to happen?
Immediately, and ideally before the device is reissued. Departing-employee laptops are frequently wiped and redeployed within days, and cloud and endpoint logs commonly age out on retention windows measured in weeks. Every day of delay narrows what can be recovered, and a preservation gap becomes the other side's argument. The duty to preserve attaches when litigation is reasonably anticipated, which is generally earlier than a filed complaint.
What is the role of forensics in a DTSA claim?
The Defend Trade Secrets Act creates a federal civil cause of action for misappropriation of a trade secret related to interstate commerce. A plaintiff must show the information qualifies as a trade secret, that reasonable measures were taken to keep it secret, and that it was acquired, disclosed, or used improperly. Forensics supplies the evidentiary basis for the second and third elements — demonstrating both the access controls actually in place and the mechanics of how the information moved.
Can deleted files be recovered as evidence of theft?
Often, yes — and just as importantly, the act of deletion itself is frequently recoverable even when the content is not. File system records, journal entries, shellbags, link files, and thumbnail caches can establish that a file existed, was accessed, and was removed, along with when. Evidence of targeted deletion after a preservation duty attached is independently significant, since it can support a spoliation argument regardless of whether the underlying content is restored.
Do you work for both plaintiffs and defendants in these matters?
Yes. The same examination that establishes misappropriation can also demonstrate its absence — that files were accessed in the ordinary course, that a device shows no exfiltration path, or that an accusation rests on artifacts that do not support the inference drawn from them. We run conflicts before any engagement, and we do not take a matter where we are serving as a court-appointed neutral.
Trade Secret Theft Investigations — questions, terms and comparisons
Questions answered
Terms defined
Investigations experts who testify to this work
Full expert panel →
Jeremy Desor
Senior Consultant
Complex Financial Crime · Securities Fraud Investigation · Money Laundering & Asset Tracing

George Pierce
Expert Consultant
Regulatory Compliance · Internal Investigations
Our experts serve as court-appointed special masters, forensic neutrals, and arbitrators — 40 appointments are listed by matter and citation.
Trade Secret Theft Investigations case results
Electric Utility / Power Generation
Forensic Attribution Halts a Departing Engineer's Theft of Grid Design Data at an Electric Utility
Energy / Oil & Gas Developer
Forensic FCPA Investigation for an International Energy Developer
Logistics & Freight
Insider Theft of Proprietary Routing and Pricing Models Traced and Proven at a National Logistics Carrier

