Skip to content
MDA-123 Mobile Devices & Apps

How do I build a mobile-device attribution investigation?

Start by separating the elements that need to be proved.

What this means

A device is not a person.

A telephone number is not a person.

An account is not a person.

The investigation must connect the relevant device, SIM, number, account, session and human user at the relevant time.

Begin with the physical handset.

Then map the external records.

Which network provider served the number?

Which device-account and app providers were involved?

What linked devices, backups and sessions existed?

Build a timeline.

Include possession, device unlocks, account logins, calls, messages, location, app use, security changes and provider events.

Was the device shared, lost, replaced or remotely accessed?

Was the account compromised?

Was the SIM swapped or number ported?

Corroborate across independent sources.

CCTV, witnesses, transactions, travel, workplace records and communications may connect the technical activity to the person.

Subscriber details, device ownership or account registration are starting points, not final attribution.

The operational takeaway is: mobile attribution is a chain linking device, network, account, session and person across time. Build each link separately and corroborate it before attributing the activity.

What to check or do next

  • Record the make, model, operating system, identifiers, power state, lock state, SIM or eSIM and apparent accounts.
  • Look for changes in control.
  • Do not rely on one identifier.
  • Use precise conclusions.

Evidential limits

State what the evidence links, and identify any remaining alternative explanations.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.