Does copying data prove malicious intent?¶
The practical answer¶
No. Copying data does not by itself prove malicious intent.
The key evidential caution¶
The dangerous assumption is that any export, download or copy by an employee is theft.
Legitimate reasons may include:
Key points¶
- casework
- backup
- migration
- analysis
- reporting
- handover
- remote working
- approved disclosure
What investigators should establish¶
Investigators should establish:
Key points¶
- what data was copied
- where it was copied from and to
- which account and process acted
- what approval or business purpose existed
- whether the volume and timing were normal
- whether the data was later shared, sold, retained or deleted
A large export may be authorised.
A small selected copy may be highly significant.
The evidential value lies in the relationship between the data, purpose, destination and later use.
Evidential limits¶
Do not infer intent solely from file size or use of removable media.
Likewise, copying to a personal account or device may breach policy without proving a plan to harm the organisation.
Relevant evidence¶
Relevant evidence may include export logs, device records, cloud uploads, email, messaging, instructions, approvals and later access.
Copying may also occur automatically through synchronisation, backup or export tools after a user selects a folder or enables a service. Identify the initiating decision and the later automated transfers separately. The person may be responsible for the setup without manually copying each file.
Where copied data is later deleted, moved or concealed, preserve those actions as separate evidence. Concealment may support improper purpose, but legitimate cleanup or policy compliance may provide another explanation that must be tested.
Operational takeaway¶
Treat copying as an action requiring explanation, and prove malicious purpose from destination, concealment, later use, communications and surrounding context.