What evidence helps identify who actually used the device?¶
Identifying the actual user of a mobile device usually requires several pieces of evidence working together.
What this means¶
No single artefact is guaranteed to answer the question.
Possession is relevant. So are ownership, subscription and account registration. But each can point to a different person.
Who knew the passcode?
Whose biometrics were enrolled?
Who carried, charged and maintained the device?
Which person’s accounts, contacts, photographs, messages and payment methods appear consistently?
Location patterns may show the device travelling between a person’s home, workplace and regular destinations.
Bluetooth pairings, vehicle connections, Wi-Fi networks and linked wearables may connect the phone to their routine.
Communications can help, especially where contacts address the user by name or refer to events only that person would understand.
Photographs, videos, calendar entries, notes and app activity may provide further context.
Biometrics may include more than one person. A saved account may be shared. A device may travel in a vehicle without its usual user. Messages may be automated, copied or sent remotely.
Build the attribution around the relevant period.
Combine technical records with witnesses, CCTV, transactions, travel, work records and other independent evidence.
Where alternatives remain plausible, record them honestly.
The operational takeaway is: identify the user through converging evidence of possession, access, behaviour, location and context. The stronger the conclusion, the more independent links should support it.
What to check or do next¶
- Look for evidence of practical control.
Evidential limits¶
But each source has limitations.
Timing is critical. Evidence that identifies the usual user does not automatically prove who used the device during one specific event.