Does file access prove data theft?¶
The practical answer¶
No. File access does not by itself prove data theft.
The key evidential caution¶
The dangerous assumption is that opening, reading or listing a file means it was copied or removed.
A file may be accessed by:
Key points¶
- the user
- an application
- search indexing
- backup software
- antivirus
- synchronisation
- administrative tools
- malware
- a remote operator
What investigators should establish¶
Investigators should establish:
Key points¶
- which file was accessed
- which account and process accessed it
- what type of access occurred
- whether the full content was read
- whether it was copied, exported or archived
- whether a later transfer followed
File metadata and access logs may be incomplete or altered by normal system behaviour.
A recent-access record may show that an application referenced the file without proving the user viewed all its content.
Evidential limits¶
Likewise, opening a document may create temporary copies, cache files or thumbnails.
Do not infer theft from access alone.
But do not dismiss access where it forms part of a wider sequence involving targeted searches, archive creation and outbound transfer.
The account holder may also be different from the person controlling the session.
Where access records are generated by synchronisation or preview services, establish whether the user or process actively requested the file. The same document may be opened locally, cached automatically and scanned by security software, producing several events from one interaction.
Also preserve any audit field describing read, preview, download, export or synchronisation. Product terminology may distinguish actions more precisely than a generic access event.
Operational takeaway¶
Treat file access as evidence of interaction with data, and require separate evidence of copying, staging or transfer before concluding theft.