Could opening a payment application alter the evidence?¶
Yes. Opening a payment, banking, exchange or wallet application can alter both local and provider-held evidence.
Avoid the dangerous assumption¶
The dangerous assumption is that merely viewing the application is a passive action with no evidential effect.
The application may connect to the provider, refresh balances, synchronise transactions, update timestamps or register a new access event.
It may download new data, delete expired data, rotate tokens or change cached files.
The provider may record the device, IP address, session, location estimate and time of access.
Opening the application may also trigger biometric authentication, a passcode request, a security notification or an alert to another user.
A cryptocurrency wallet may synchronise with the blockchain or expose sensitive key material.
Some applications may log out another session, update the application database or require migration after an update.
Record the device state, screen, date, time, network connection and whether the application was already open before interacting.
Avoid unnecessary exploration.
Where evidence is important, seek forensic or specialist support and preserve the device using an approved process.
If urgent safeguarding requires access, record the reason, authority and every action taken.
Do not assume that later timestamps all relate to the suspect or account holder if investigator interaction occurred.
Provider logs should be interpreted against the action record.
When reporting, identify what changed or may have changed during examination.
Operational takeaway¶
Treat opening a payment application as an evidential action and record the device state and every interaction because access may change local data and provider logs.