Data Guard
Case studies

Incident response and forensic work

Four engagements, described including what we could not establish. Client identities and identifying details are omitted.

Suspicion of Espionage on Family Devices

The challenge

A client undergoing a hostile divorce in New York City feared that their spouse had covertly installed spyware (stalkerware) on their iPhone and, more concerningly, on their children’s tablets. The client sought forensic confirmation that these devices had been compromised—potentially recording private communications or tracking their movements—to present as evidence in court.

Our approach

We conducted a comprehensive forensic examination of both the client’s and children’s mobile devices. Leveraging the low-level acquisition capabilities of Elcomsoft iOS Forensic Toolkit (EIFT), our team successfully performed a full file system extraction and keychain decryption on the client’s iPhone.

To provide a complete picture of the security incident, we also collected data from the client’s Apple devices with M-series processors using Sumuri RECON ITR—a tool specifically designed for imaging and extracting data from modern macOS systems, including those with Apple Silicon.

To analyze and correlate the recovered data sets across devices, we employed Sumuri RECON LAB, which enabled precise timeline reconstruction, pattern detection, and cross-device artifact comparison. This combination of tools allowed us to conduct an in-depth search for:

  1. Unauthorized location sharing and access logs
  2. Configuration profiles or applications matching known stalkerware signatures
  3. Hidden communication logs or remote access utilities installed on the children’s tablets

Through this methodology, we successfully recovered thousands of deleted messages, in-app transaction histories, and—most importantly—logs indicating remote access activity across multiple devices.

The outcome

All findings were compiled into a court-admissible forensic report.

Post-Ransomware Forensic Preservation and System Migration

The challenge

We were engaged by a small service-based company shortly after a ransomware attack had disrupted their operations. Although the encrypted data had already been successfully decrypted by the client’s contracted IT provider, the organization needed to ensure long-term protection of digital evidence in case further analysis or legal proceedings became necessary. In addition, they sought guidance on securely rebuilding their IT environment to prevent future incidents.

Our approach

Data Guard was brought in to handle the forensic preservation and secure reestablishment of business operations. Our primary objective was to create forensically sound disk images of all affected systems for potential future investigation. To achieve this, we used FTK Imagerand hardware Write Blocker, ensuring that all disk content was captured without any alteration to the original data.

Once preservation was complete, we focused on restoring essential services and helping the client transition to a more resilient IT infrastructure. This included migrating all recovered data to a new environment based on Microsoft 365, providing improved collaboration tools, secure cloud storage, and advanced access controls.

The outcome

The client’s data was preserved in a court-admissible format, ensuring the possibility of future forensic analysis. At the same time, their operations were swiftly restored on a more secure and modern platform. By acting quickly and comprehensively, Data Guard ensured both immediate business continuity and a solid foundation for future cybersecurity resilience.

Suspected Phone Tracking and Identity Spoofing During Divorce Proceedings

The challenge

Our client from Canada, a businessman in the midst of a contentious divorce, began to suspect he was being tracked via his mobile phone. Compounding these concerns, he started receiving suspicious text messages from individuals impersonating real people from his contact list—strongly indicating potential unauthorized access to his personal data and communications..

Our approach

Over a two-week forensic investigation, we conducted a thorough analysis of the client’s digital environment. This included a full review of his social media accounts, forensic imaging and analysis of his computers and iPhone, and a deep inspection of device logs. To ensure forensic soundness and preserve evidence integrity, especially in the event the findings needed to be presented in court, we utilized a hardware Write Blocker during data acquisition.

While log analysis revealed inconsistencies and unexplained gaps, we were unable to recover the missing system logs from the devices, which limited our ability to definitively identify the attacker or the exact method of intrusion. However, indicators strongly suggested prior unauthorized access had occurred.

Despite the limitations in log data, we successfully reclaimed full control over all of the client’s compromised accounts, systematically removing unauthorized devices and sessions.

Recognizing the broader security risks, our parent company, Arkadian Cybersecurity Inc., implemented a tailored cybersecurity solution designed specifically for the client’s home office environment. This included the deployment of a firewall with full logging capabilities, ensuring complete visibility of all inbound and outbound connections moving forward.

The outcome

Although the attacker’s identity and method remained undetermined due to incomplete system logs, the incident was fully contained. The client’s digital assets were secured, compromised accounts were restored, and long-term protection was put in place. The client now benefits from a hardened and monitored home office infrastructure that aligns with best practices for personal digital security.

Incident Response & Ransomware

The challenge

A medium size construction company in NYC was hit by a targeted ransomware attack. They paid the ransom, but their key focus shifted to compliance and liability. They urgently needed to know how the attackers gained entry and what data, if any, was compromised before encryption occurred, to comply with privacy regulations.

Our approach

We treated the compromised local server and workstations as a crime scene. Using forensic analysis and log correlation, we quickly identified the initial point of entry: a compromised email account on a single employee’s Windows workstation. We then traced the attacker’s lateral movement within the network and confirmed they only accessed specific, non-critical folders, minimizing the data breach notification scope required by regulators.

The outcome

The client gained regulatory confidence by accurately defining the breach scope and providing definitive evidence of the attack timeline, helping them avoid unnecessary penalties. Furthermore, our parent company, Arkadian Cybersecurity Inc., provided the client with detailed recommendations. These included implementing modern, attack-resistant backup systems and replacing network infrastructure. The new infrastructure was necessary to improve corporate network security at the Internet edge and enabled internal network segmentation, which allowed for the isolation of the most critical resources.

This strategic response enabled the client to move beyond incident recovery and toward long-term resilience.
To achieve the highest level of protection and incident preparedness, we encourage organizations to contact Arkadian Cybersecurity Inc. for a tailored, proactive cybersecurity strategy.

Thanks to their engagement with Data Guard NYC, the client received far more than just post-incident support—they gained a sustainable path to cybersecurity maturity.

Data Guard by Arkadian Cybersecurity Inc.

+1 (929) 535-3509

sales@dataguard.nyc

198 Huron St #1L, Brooklyn, NY 11222 / United States