Skip to content
MEX-037 Mobile Extractions

What corroboration should I look for before attributing mobile evidence?


title: What corroboration should I look for before attributing mobile evidence? subtitle: Choose evidence that tests the weakest link between artefact, account, device, time and person. slug: what-corroboration-should-i-look-for-before-attributing-mobile-evidence series: mobile-extraction-and-reader-reports section: evidential-limits-corroboration-and-supervision card_type: question_card content_type: core-operational risk_level: high-risk pathway_order: 58 section_order: 8 status: draft owner: IF Digital last_updated: '2026-07-25' version: '0.1' review_gate: pending review_mode: ai-assisted review_timebox_mins: 60 qa_gate: pending qa_count: 0 pipeline_ref: PIPELINE_PRG_001 pipeline_version: '1.1' public_safe: true video_ready: true word_count: 464 estimated_read_time_seconds: 192 audiences: - investigator - supervisor - fraud and compliance practitioner tags: - mobile evidence - corroboration - attribution - independent evidence - alternative explanations sources: - title: SWGDE Best Practices for Mobile Device Forensic Analysis url: https://www.swgde.org/documents/published-complete-listing/20-f-005-swgde-best-practices-for-mobile-device-forensic-analysis/ - title: 'Forensic Science Regulator: Interpretation and Communication (FSR-GUI-0004)' url: https://www.gov.uk/government/publications/forensic-science-activities-interpretation-and-communication-fsr-gui-0004 - title: 'Forensic Science Regulator: Statutory Code of Practice, Version 2' url: https://www.gov.uk/government/publications/forensic-science-activities-statutory-code-of-practice-version-2 - title: 'NIST SP 800-101 Rev. 1: Guidelines on Mobile Device Forensics' url: https://csrc.nist.gov/pubs/sp/800/101/r1/final


What corroboration should I look for before attributing mobile evidence?

Choose evidence that tests the weakest link between artefact, account, device, time and person.

Script

Good corroboration begins with the proposition you are trying to establish.

Don't collect more mobile artefacts without deciding which link needs support.

The possible propositions include:

the artefact existed;

the account created or received it;

this handset was involved;

the handset was in a particular place;

a person controlled the handset;

the person knew about the content;

or the person authored or triggered the action.

Each requires different corroboration.

For the existence and content of the artefact, look for:

the active source record;

another parser view checked against the same source;

a participant’s device;

provider records;

a backup;

or a preserved attachment or file.

Remember that several views generated from one database are not independent sources.

For account attribution, look for:

verified email addresses or telephone numbers;

service-specific account IDs;

provider account records;

authentication events;

linked devices;

session identifiers;

and recovery details.

For handset involvement, look for:

device tokens;

local drafts;

files created on the handset;

application-use events;

notifications;

local network activity;

and source paths within the device extraction.

For possession and human control, look for:

seizure circumstances;

passcode or biometric access;

continuous personal activity;

CCTV;

witness evidence;

location;

Wi-Fi and Bluetooth associations;

payments;

vehicle use;

and the person’s later knowledge or conduct.

For authorship, look for:

local composition traces;

attachments created immediately beforehand;

content known to the person;

a coherent conversation;

related instructions;

admissions;

and actions consistent with the communication.

Test alternatives rather than merely listing them.

If shared use is suggested, identify the other user, access and opportunity.

If remote access is suggested, look for the mechanism and session.

If automation is possible, identify the trigger and configuration.

If cloud synchronisation is relevant, determine the originating client where possible.

Independent corroboration is more valuable than repetition.

A message, notification and search-index entry may all derive from one application event.

A provider record, recipient device and CCTV sequence are created by different systems for different purposes.

They may provide stronger independent support.

Also seek contradictory evidence.

A person may be elsewhere.

The account may show another device.

The application may have run automatically.

The source record may not support the friendly label.

Corroboration is a test, not a search only for confirmation.

The common mistake is:

“The report contains the same message in five places, so it is corroborated.”

Those may be duplicate traces from one source.

Another mistake is:

“There is no single perfect record, so attribution can't be made.”

Several independent and consistent links can create a strong overall inference.

A careful attribution explains the chain:

“This provider account created the event. Device-specific records link the session to this handset. Local activity and independent evidence link control of the handset to this person.”

Then state any remaining gap.

Corroboration should strengthen the weakest link and challenge the most realistic alternative.

Key takeaway

Corroboration should be independent and proposition-led, not a count of repeated artefacts from the same source.

Source notes


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.