Skip to content
FRP-123 Fraud & Financial Crime

Could another user delete cloud evidence remotely?

Yes. Another user with access may delete, move, overwrite or restrict cloud evidence from elsewhere.

Avoid this assumption: Material visible in the current session is safe because the investigator controls the local device. The actual data may remain under the control of account holders, collaborators, administrators or an attacker.

Deletion may occur through another browser, mobile application, synchronised device, administrator console or automated retention process.

Before changing anything, preserve the service, account, file or folder name, path, sharing status, owner, collaborators, timestamps and visible identifiers.

Capture the content or listing as found without opening more than necessary.

Consider whether provider preservation, organisational controls or specialist support should be requested urgently.

Isolation of the local device may not prevent deletion at the provider or through another session.

Changing passwords or permissions may reduce risk, but can also alert users, terminate sessions or create new records.

Where immediate loss is credible, use the least destructive effective protective action and record why delay was not reasonable.

Record any disappearance, access-denied message, permission change, recycle-bin movement or version update.

Do not assume that remote deletion proves who performed it. Provider and audit records may be needed.

Preserve any owner, administrator, collaborator and sharing-role information already visible. These details may show who had the capability to act, but not automatically who performed the deletion.

Operational takeaway

Assume cloud evidence may remain remotely controllable, preserve exact identifiers and access context quickly, and seek provider or specialist preservation where deletion risk is credible.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.