What corroboration should I look for before attributing mobile evidence?¶
Start with the bit of the story that is weakest.
If the extraction clearly shows a WhatsApp message, you probably do not need three more copies of the same message. You may instead need evidence showing which account it belonged to, which device created the activity, or who was actually using that device at the time.
That is what useful corroboration is for.
Work out what you are actually trying to connect¶
Imagine the report contains:
That finding gives you several separate questions:
- Is this genuinely a WhatsApp artefact?
- Which account or participant does the number represent?
- Was this handset involved in creating or storing it?
- Was the activity local to the handset or from a linked client?
- Who was using or controlling the device at 19:41?
You may already have strong answers to some of those. Focus the next enquiry on the one that is still weak.
Look for evidence created somewhere else¶
Independent evidence is particularly useful because it is not just another view of the same underlying database row.
For example:
| Question | Useful corroboration |
|---|---|
| Did the message exist? | Recipient's device or provider/service record |
| Which account was involved? | Account records, participant identifiers, provider data |
| Was this handset involved? | Local app database, device/session identifiers, notifications, app use |
| Who had the handset? | CCTV, witnesses, access records, location, transactions |
| Was activity remote or linked? | Linked-device records, sessions, browser/client activity |
A message row, a notification and a search-index hit may all come from the same event. They are useful, but they are not necessarily three independent confirmations.
Use real-world activity when it helps¶
Suppose the message was sent at 19:41.
At 19:39, CCTV shows the suspect entering a shop holding the seized handset.
At 19:42, the same device makes a contactless payment or connects to the shop Wi-Fi.
Neither record proves who typed the message by itself. Together with the mobile artefact, however, they can make the relevant-time control picture much stronger.
This is often where corroboration becomes most useful: different systems converge on the same time, device and person.
Test realistic alternatives, not imaginary ones¶
If the account could realistically have been used from a linked desktop, check for that.
If the handset was shared, find out who else used it.
If the account may have been compromised, look for relevant session or security records.
You do not need to invent far-fetched explanations simply because attribution is important. Deal with the alternatives that genuinely fit the evidence.
Do not over-corroborate the easy bit¶
A common waste of effort is collecting more evidence for the part that is already solid.
If three independent records already establish that the phone was at a location, but the real uncertainty is who was using it, spend the next enquiry on user control, not on a fourth location source.
That matters for proportionality and investigative resources as much as it does for evidential quality.
What should a supervisor ask before relying on mobile-extraction evidence? deals with the management decision that follows.
The practical point is: corroboration should strengthen the weakest useful link. Ask what is still genuinely open, then find an independent source that can answer that question.