Corporate Information Leak: How to Identify Who Is Responsible
By Juan Jesús Merino Carretero, chartered computer engineer no. 89 (CPIIEX) information leak · company · internal investigation
When a company detects that confidential information has reached a competitor, a poached client or the press, the question is always the same: who took it out? Identifying who is responsible for an information leak is one of the most complex investigations in computer forensics because it combines technical analysis of multiple sources, knowledge of the corporate environment and, almost always, delicate labor and procedural implications. This guide explains how Forenlab approaches this type of case.
Common types of leak
Before investigating, it is worth classifying the type of leak because each has a different technical pattern:
| Type of leak | Typical vector | Indicators |
|---|---|---|
| Disgruntled employee leaving for a competitor | USB, personal cloud, email | Download spikes before the dismissal |
| Industrial espionage | Remote access, persistence | Unusual connections, malware |
| Accidental leak due to lack of training | Misaddressed email, public cloud | History of emails to external recipients |
| Leak to the press | Photos, screenshots | Screen-capture activity |
| Theft or loss of a device | Phone, laptop, USB | Missing device |
| Compromised credentials | Phishing, password reuse | Access from anomalous IPs |
Identifying the type guides the work plan and narrows the scope of the expert work.
Steps of the investigation
1. Scope analysis
The first step is to define, together with the company, what information has leaked, when it was detected, how it was detected and who could have had access (the perimeter of suspects). This avoids examining 200 computers when only 5 people had access to the material.
2. Securing the evidence
Before touching any device, the expert makes a forensic clone of:
- The devices of the employees with access.
- Servers where the leaked material was stored.
- Central logs: AD, firewall, proxy, DLP, EDR.
- Mailboxes (with management’s authorization).
- Cloud access (Microsoft 365, Google Workspace).
It is crucial not to alert the suspects during this phase to avoid destruction of evidence.
3. Activity analysis
On the clones, the expert looks for patterns that reveal the leak:
- USB connections: complete history of connected devices (the
USBSTORregistry key on Windows,IOUSBHostFamilyon macOS) with date-time and serial number. - Volumes of files copied to USB or private cloud.
- Emails sent to external addresses, especially with large attachments.
- Uploads to cloud services (Google Drive, Dropbox, personal OneDrive): the browser leaves traces.
- Screenshots of confidential material saved locally.
- Printing: print server history.
- Access to sensitive files: “last read” timestamps compared with legitimate activity.
- Searches on the computer for the competitor’s name or the name of the stolen file.
- Communications between suspect employees.
4. Cross-referencing and chronological reconstruction
The expert builds a timeline that cross-references events:
14:32 - Employee X connects USB serial XYZ123 14:33 - Reads file “estrategia-Q3.xlsx” 14:35 - Copies file to USB 14:36 - Disconnects USB 14:42 - Deletes file “estrategia-Q3.xlsx” from the desktop (attempt to conceal)
This kind of reconstruction is what turns indicators into a defensible technical conclusion.
5. Cross-confirmation
Before issuing conclusions, the expert looks for cross-confirmation in other sources:
- Does the time match the employee’s physical presence in the office?
- Are there physical access-control records?
- Are there later emails that reveal knowledge of the material?
- Does the activity coincide with the moment the employee announced their departure?
The more independent confirmations, the stronger the attribution.
Evidence that carries the most weight
From experience, the most solid evidence in this type of case is:
- USB connection with an identified serial number: if the company can show who the USB belongs to, attribution is direct.
- Upload to a personal cloud account with the employee’s email: complete traceability.
- Email sent to an outside party from the employee’s corporate mailbox: practically irrefutable evidence.
- Print log of the confidential document outside working hours: can be combined with physical access control.
- Prior searches for the file name or the competitor: indicates intent.
Labor and data protection considerations
Investigating an employee has legal limits. Forenlab always operates within:
- Policy on the use of company equipment signed by the employee in their contract.
- Privacy and monitoring policy communicated beforehand.
- Proportionality: the investigation is limited to what is necessary.
- Confidentiality: the information obtained is used only for the case and is not shared with third parties without authorization.
If the company has no clear usage policy, the investigation can be challenged and the dismissal may be declared unfair. Before investigating, the legal department should review the legal basis.
Fair vs. unfair dismissal
If the investigation clearly demonstrates the leak, dismissal for breach of contractual good faith (art. 54.2.d of the Estatuto de los Trabajadores, the Spanish Workers’ Statute) has a high likelihood of being declared fair. The keys are:
- Technical quality of the expert report.
- Compliance with the safeguards (prior policy, proportionality).
- Demonstration of the employee’s intent.
In proceedings where these safeguards are not met, courts have declared dismissals unfair even when there was a real leak.
When to escalate to a criminal complaint
If the leak involves:
- Violation of trade secrets (Ley 1/2019).
- Discovery and disclosure of secrets (arts. 197-201 of the Criminal Code).
- Unauthorized access to systems (art. 197 bis of the Criminal Code).
Then, in addition to dismissal, a criminal complaint can be filed. The expert report is key because it supports both the labor and the criminal action.
Mistakes that destroy the investigation
- Investigating without a signed usage policy.
- Alerting the suspect before cloning the evidence.
- Tampering with the suspect’s computer without prior cloning.
- Carrying out the investigation with internal technicians without forensic methodology.
- Not documenting the chain of custody.
Any of these mistakes can wreck the investigation and expose the company to a claim for unfair dismissal or violation of rights.
Frequently asked questions
How long does a leak investigation take?
Between 3 and 8 weeks depending on the scope. The first conclusions are usually available 1-2 weeks after cloning.
What does it cost?
Between €3,000 and €8,000 depending on the number of devices and depth. Forenlab gives a fixed quote after analyzing the scope.
Can the company investigate the employee’s personal phone?
No, unless it belongs to the company. A personal phone is protected by the employee’s right to privacy.
What if the suspect no longer works at the company?
The investigation focuses on the corporate device they used (which the company still has), the mailboxes, the central logs and the cloud records. The employee’s departure does not prevent the investigation.
Can the report also be used to claim damages?
Yes. If economic harm is proven (loss of a client, loss of intellectual property), it can support a parallel civil claim.
Conclusion
Investigating an information leak requires acting with speed, confidentiality and forensic methodology. Without prior cloning, without a chain of custody and without a prior policy, the investigation can destroy the case. At Forenlab we handle information leak cases for companies of all sizes with complete forensic analysis, timeline reconstruction and a report defensible in both labor and criminal jurisdictions. Contact us if you suspect a leak: we reply within 24 hours with confidentiality assured.