Introduction
One of the most common questions asked during digital investigations is “If I delete a file, can the police recover it?”
The answer is often yes, sometimes, or no, depending on numerous technical factors including:
- The type of device.
- The operating system.
- The storage technology.
- How the file was deleted.
- Whether the storage has been reused.
- Whether encryption is present.
- The time elapsed since deletion.
Digital forensic specialists routinely examine deleted data during criminal, civil, corporate, and regulatory investigations.
What Happens When a File Is Deleted?
Deleting a file usually does not immediately erase its contents. Instead, the operating system typically:
- Removes the file’s directory entry.
- Marks the storage space as available.
- Leaves the underlying data intact until overwritten.
This means deleted files may remain recoverable.
For example:
- Windows removes references from the file system.
- Android and iOS remove database entries.
- Memory cards mark sectors as free.
- Cloud services may move items to a recycle bin.
Windows Computers
Files deleted normally are first moved to the Recycle Bin.
Investigators may recover:
- Original filename.
- Deletion date.
- Original location.
- User account information.
Artefacts include:
- $Recycle.Bin
- $I files.
- $R files.
- NTFS File System
When files are permanently deleted:
- The file entry within the Master File Table (MFT) may remain.
- Data clusters may still contain the file contents.
- Metadata can survive after deletion.
Forensic artefacts include:
- $MFT
- $LogFile
- $UsnJrnl
- Volume Shadow Copies.
Apple macOS
Deleted files may be recovered from:
- Trash.
- APFS snapshots.
- Time Machine backups.
- Local snapshots.
APFS copy-on-write technology can preserve historical data even after deletion.
Smartphones
iPhone
Modern iPhones employ:
- Full File Encryption.
- Hardware encryption keys.
- Secure Enclave protection.
Deleted files may survive temporarily in:
- Photo Recently Deleted folders.
- Application databases.
- Cloud synchronisation services.
- Backups.
However, modern versions of iOS aggressively remove encryption keys, making recovery significantly more difficult.
Android
Recovery depends upon:
- Android version.
- File-based encryption.
- Device manufacturer.
- Root access.
Deleted data may remain within:
- SQLite databases.
- Application caches.
- Thumbnail databases.
- Cloud backups.
Modern encrypted Android devices frequently render deleted files unrecoverable.
Solid State Drives (SSDs)
SSDs behave differently from traditional hard drives.
TRIM Command
TRIM informs the SSD that certain blocks are no longer needed.
Once TRIM executes:
- The controller may erase data internally.
- Deleted files become permanently unrecoverable.
- Traditional recovery techniques often fail.
This is one of the largest challenges facing modern digital forensics.
Hard Disk Drives (HDDs)
Traditional magnetic drives often provide better recovery opportunities.
Deleted sectors may survive for:
- Days.
- Months.
- Years.
Recovery depends on:
- System usage.
- Disk activity.
- Defragmentation.
- Overwriting.
Specialist forensic software can identify:
- File signatures.
- Fragmented files.
- Deleted directory entries.
USB Drives and Memory Cards
Recovery rates vary considerably.
Factors include:
- Wear levelling.
- TRIM support.
- Subsequent use.
- File system type.
Common file systems:
- FAT32
- exFAT
- NTFS
Deleted photographs and documents are frequently recoverable if the device has not been heavily reused.
Cloud Storage
Deleted files may remain within:
- Recycle bins.
- Version histories.
- Synchronisation databases.
- Account backups.
Examples include:
- Google Drive
- Microsoft OneDrive
- Apple iCloud
- Dropbox
Investigators may obtain:
- Cloud account records.
- Synchronisation logs.
- File version histories.
- Access logs.
Forensic Recovery Techniques
Digital forensic laboratories use various methods:
Logical Recovery
Examining:
- File system metadata.
- Recycle bins.
- Databases.
- Logs.
File Carving
Files can sometimes be reconstructed by identifying:
- JPEG headers.
- PDF signatures.
- ZIP structures.
- Video file markers.
This process is called file carving.
Shadow Copies and Snapshots
Previous versions may exist in:
- System backups.
- Snapshots.
- Restore points.
- Cloud archives.
Database Recovery
Applications often retain records after deletion.
Examples include:
- Messaging databases.
- Thumbnail caches.
- Browser history.
- Application logs.
Factors That Affect Recovery
Factor Effect
Time since deletion Longer periods reduce recovery chances
Continued device use Increases overwriting
SSD with TRIM Greatly reduces recovery
Encryption May prevent recovery entirely
Backups May preserve deleted files
Cloud synchronisation May create additional copies
File size Larger files are more prone to fragmentation
Can Police Recover Securely Deleted Files?
Secure deletion tools intentionally overwrite data.
Examples include:
- Multiple overwriting passes.
- Cryptographic erasure.
- Secure erase commands.
If correctly performed:
- Recovery may be impossible.
- Only metadata may remain.
- Evidence of deletion activity may still exist.
What Evidence May Still Remain?
Even if the actual file cannot be recovered, investigators may identify:
- Filename.
- Creation dates.
- Access dates.
- Application usage.
- Thumbnail images.
- Cloud synchronisation records.
- Recently opened documents.
- Search history.
- This is often called residual evidence.
Conclusion
Police and digital forensic investigators can frequently recover deleted files, particularly from traditional hard drives, memory cards, and older devices.
However, modern technologies such as encryption, SSD TRIM, secure deletion, and mobile operating system protections have significantly reduced recovery opportunities.
In many cases, even when the deleted file itself cannot be recovered, investigators may still discover metadata, backups, logs, cloud records, or other artefacts demonstrating that the file once existed.
From a digital forensic perspective, deletion does not necessarily mean destruction, but neither does it guarantee recoverability. The outcome depends entirely on the storage technology, operating system, and events occurring after the file was deleted.
About Athena Forensics
For information on our computer forensic expert services or if you require any advice or assistance please contact a member of our team on 0330 123 4448 or via email on enquiries@athenaforensics.co.uk, further details are available on our contact us page.
Our client’s confidentiality is of the utmost importance. All correspondence is treated with discretion, from initial contact to conclusion of the matter.
We are fully aware of the significance and importance of the information that they encounter and we have been accredited to ISO 9001 for 14 years.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies and we do not disclose personal information to other companies or suppliers.
Our team are all security cleared and we offer non-disclosure agreements if required.
Our premises along with our security procedures have been inspected and approved by law enforcement agencies.
Athena Forensics do not disclose personal information to other companies or suppliers.