Suspicion of Espionage on Family Devices
The challenge
A client undergoing a hostile divorce in New York City feared that their spouse had covertly installed spyware (stalkerware) on their iPhone and, more concerningly, on their children’s tablets. The client sought forensic confirmation that these devices had been compromised—potentially recording private communications or tracking their movements—to present as evidence in court.
Our approach
We conducted a comprehensive forensic examination of both the client’s and children’s mobile devices. Leveraging the low-level acquisition capabilities of Elcomsoft iOS Forensic Toolkit (EIFT), our team successfully performed a full file system extraction and keychain decryption on the client’s iPhone.
To provide a complete picture of the security incident, we also collected data from the client’s Apple devices with M-series processors using Sumuri RECON ITR—a tool specifically designed for imaging and extracting data from modern macOS systems, including those with Apple Silicon.
To analyze and correlate the recovered data sets across devices, we employed Sumuri RECON LAB, which enabled precise timeline reconstruction, pattern detection, and cross-device artifact comparison. This combination of tools allowed us to conduct an in-depth search for:
- Unauthorized location sharing and access logs
- Configuration profiles or applications matching known stalkerware signatures
- Hidden communication logs or remote access utilities installed on the children’s tablets
Through this methodology, we successfully recovered thousands of deleted messages, in-app transaction histories, and—most importantly—logs indicating remote access activity across multiple devices.
The outcome
All findings were compiled into a court-admissible forensic report.
