Employee and civil evidence guide

Does a USB Connection Prove Files Were Copied?

A recorded USB connection alone does not prove that files were copied. A copying allegation needs the connection history assessed alongside file activity, destination data where available and the surrounding events. Device use, transfer and the identity or intention of a person are separate questions.

By Alistair Ewing · Updated 7 September 2026

At a glance

  • Establish which device was recognised and what the recorded times mean.
  • Look for supported links between relevant files, computer activity and the destination device.
  • Explain missing sources and reasonable alternatives before attributing a transfer to a person.

For help with a live matter, see the employee data theft investigation service.

What does a USB connection record actually establish?

Was a device connected?

Records may identify a device, volume or period. Check timestamps and identifiers against the operating system and source condition.

Were relevant files accessed?

Recent-item, shortcut, application, file-system or server records may show interaction. Access is not necessarily a copy.

Were files written to the USB device?

The device, destination metadata, configured auditing or correlated artefacts may support copying. Strength depends on what survives.

Who acted, and why?

User-session, physical or business records may assist attribution. A device event does not establish the person, intent, authority or liability.

Which records may support a finding of file copying?

A review should start from the allegation and a defined file set, not treat one event as a complete narrative. Useful sources may include:

  • USB device, volume, installation and mount records from the computer.
  • Shortcuts, recent documents, application history and file-system metadata linked to the defined files or path.
  • The USB drive itself, preserved before inspection, including its file-system records.
  • File names, sizes, hashes and metadata compared between an authoritative source and authorised destination.
  • Security, removable-storage, EDR, DLP or process telemetry, if configured and retained at the relevant time.
  • File-server, cloud, email and network records that may show access or another transfer route.
  • Login, door-access, ticketing and business records used cautiously to test attribution and routine activity.

Microsoft describes events as observations whose meaning comes from context and correlation. Its removable-storage auditing can record access attempts when the policy is configured. The examiner must establish what logging was actually active.

What should be preserved after suspected USB copying?

  1. Record the allegation and period. Identify the files, repositories, people, devices and reason for concern.
  2. Hold routine IT changes. Do not reissue, reset, wipe or unnecessarily search the computer.
  3. Protect short-lived sources. Retain relevant cloud, server, identity, EDR and DLP records before they expire.
  4. Keep removable media separate. Do not plug it into an ordinary computer. Record its source and handling.
  5. Preserve known file information. Retain authoritative copies, repository records and a description of the confidential information.
  6. Confirm lawful scope. Legal, HR and data-protection advisers should define authority, proportionality, privilege and purpose.

Can copying be assessed without the USB drive?

The computer and company systems may still hold useful records. They may support connection, access or preparation without establishing destination content. A report should state the highest supported proposition, the next evidence gap and ordinary alternatives such as backup, authorised transfer, IT support or earlier use.

Common questions

Can an examiner identify the exact USB drive?

Sometimes system records contain a serial number or other identifiers that can be compared with the device. Some hardware does not expose a unique serial number, records can be incomplete and a volume may have been reformatted, so the confidence must be stated.

Can file timestamps prove a copy?

Timestamps can contribute to a conclusion but their meaning varies by file system, operation and software. They should be interpreted with other source and destination records, not treated as a self-explanatory audit trail.

Does deletion after a USB connection prove concealment?

No. Deletion may be relevant to the chronology, but neither the person responsible nor their purpose follows automatically. Normal clean-up, synchronisation, software and IT activity should be considered where supported.

Can the investigation prove that no files were copied?

Usually not as a universal proposition. It can report the sources examined, whether relevant evidence was found and the visibility gaps. Missing, disabled or expired logs and an unavailable destination may prevent exclusion of every possible route.

Concerned that company files were copied?

Send the party names, allegation, relevant period, source types, device state and deadline. A proportionate first stage and itemised estimate can then be considered.

Do not send evidence through the public form. A secure route is agreed after the initial checks.