Skip to content
MEX-003 Mobile Extractions

Could another person have used the handset?


title: Could another person have used the handset? subtitle: Yes. Test access, opportunity, device state and time-specific traces rather than treating shared use as either impossible or automatically decisive. slug: could-another-person-have-used-the-handset series: mobile-extraction-and-reader-reports section: evidential-limits-corroboration-and-supervision card_type: question_card content_type: core-operational risk_level: high-risk pathway_order: 53 section_order: 3 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 60 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 470 estimated_read_time_seconds: 194 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - shared device - alternative user - access - attribution sources: - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/ - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final - title: 'Forensic Science Regulator: Interpretation and Communication (FSR-GUI-0004)' url: https://www.gov.uk/government/publications/forensic-science-activities-interpretation-and-communication-fsr-gui-0004


Could another person have used the handset?

Yes. Test access, opportunity, device state and time-specific traces rather than treating shared use as either impossible or automatically decisive.

Script

Another person may have used the handset.

That possibility needs investigation, not a standard sentence added to every report.

Start with physical and account access.

Who possessed the phone during the relevant period?

Who lived or worked with the usual user?

Who knew the passcode?

Were additional fingerprints or faces enrolled?

Was the device regularly lent to another person?

Was it found unlocked?

Were application accounts protected separately?

Could somebody use a linked wearable or vehicle interface?

Then examine the time-specific activity.

Does the device show an unlock, application launch, call, message, photograph, search or movement at the relevant time?

Are there records showing which account or profile was active?

Does the content reflect the knowledge, language or relationships of a different user?

Was the usual owner elsewhere, asleep, in custody or otherwise unable to use it?

Is there independent evidence placing another person with the handset?

Look at the broader pattern.

A one-off message written in a different style may justify checking another user.

A continuous sequence of ordinary personal activity before and after the disputed event may support the normal user.

A second person’s accounts, photographs, contacts or browser activity on the handset may show genuine shared use.

But old or synchronised data should not be mistaken for time-specific control.

Device security is relevant.

A strong passcode and active biometric protection may reduce the likelihood of casual use.

They don't eliminate deliberate sharing, coercion, observation of the passcode or use while already unlocked.

Some applications can be accessed through notifications or linked devices without reopening the handset.

Ask whether the alternative explains the whole sequence.

Could the other person access the phone?

Were they present?

Would they have known the account credentials and content?

Does their proposed use fit the local files, timestamps and later behaviour?

A vague possibility is weaker than an evidenced alternative.

Also avoid assuming that the person in possession at seizure was the user weeks or months earlier.

Phones change hands.

They can be stolen, sold, passed between offenders or restored from backups.

Establish the relevant period.

The common mistake is:

“The handset was PIN-protected, so nobody else could have used it.”

The PIN may have been shared or the phone already unlocked.

Another mistake is:

“Someone else might have used it, so attribution is impossible.”

The alternative user still needs opportunity and consistency with the evidence.

A careful assessment might say:

“Two household members knew the passcode and used the handset. At the disputed time, application and location records form a continuous sequence linked to the second user’s account and workplace.”

Or:

“No evidence of shared use was identified, and the disputed activity sits within continuous personal use associated with the owner.”

Shared use is a factual hypothesis.

Test access, time and pattern rather than accepting or dismissing it in the abstract.

Key takeaway

A realistic alternative user should be assessed against access, timing and the pattern of activity.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.