Digital Forensics

Recovering evidence from a factory-reset phone: what survives and what does not

"They reset the phone" is one of the most common sentences in a disputed matter, and one of the most misunderstood. A reset is rarely the end of the evidence, but it is often the end of the evidence nobody tried to preserve.

By the Editorial Team · September 2026 · 11 min read

When a phone is factory reset, the operating system removes user accounts, application data and the keys that unlock file-based encryption. On a modern iPhone or a current Android device with default settings, that last part is what matters most: the user data partition is encrypted, and the reset destroys the keys. The ciphertext may still sit in flash memory, but without the keys it is noise. Anyone who tells you they will "run recovery software" over a reset iPhone and pull the messages out is describing work that stopped being possible for consumer tools around 2014.

That is the honest headline, and it is where most explanations stop. In practice, several categories of material routinely survive a reset, and the difference between a hopeless wipe and a productive examination usually comes down to details that were fixed before the examiner was ever instructed.

What actually survives a reset

Unallocated flash content on older or unencrypted devices. Devices running Android versions before full-disk encryption became mandatory, cheap handsets, some tablets and a surprising number of work devices reset without encryption can still yield deleted photographs, message database fragments and app data from unallocated space. Recovery here is the classic carving work: signatures of JPEG or MP4 files, SQLite headers, orphaned WAL files that capture rows the main database never committed. A factory reset on these devices is often just a bulk delete, which leaves the same recoverable traces as ordinary deletion.

Everything already synchronised off the device. A reset wipes the phone, not the world. Backups in the vendor's cloud, message exports sitting in email, photographs auto-uploaded to a cloud album, chat histories held on a provider's servers under a preservation request, and data pulled onto a computer during a previous sync are all untouched by what happens on the handset. In a large share of matters, the productive examination after a reset is an examination of the backups, not the device.

The SIM and external storage. SIM cards carry their own records, and in disputes over numbers, contacts and message traces they can still be read independently of the phone's state. Removable microSD cards are frequently not wiped by a reset at all, depending on the option the user chose.

Wear-levelling remnants. Flash controllers write new data to fresh blocks and erase old ones lazily. On some devices, snapshots of older data can persist in blocks the reset never touched. This is unpredictable, method-dependent, and never something to promise a client in advance, but it is a reason a competent examiner still images a reset device rather than declaring it dead.

The reset that helps you

A curious inversion appears in some matters: the reset itself becomes evidence. A wipe performed days after proceedings became likely, minutes after a preservation warning, or in the gap between a request for disclosure and a deadline is an act with its own significance. The device logs the reset event, and on some platforms account activity shows when the handset was unlinked and re-linked. Judges are familiar with the pattern; the adverse inference available under the CPR from deliberate destruction of evidence can outweigh whatever the deleted material would have shown. Documenting when the reset happened is often more valuable than trying to undo it.

Why the examiner needs the device quickly

Two clocks run against recovery. The first is continued use: if the reset phone goes back into service, new writes consume the unallocated space where remnants lived. The second is remote erasure: a device still enrolled in a mobile device management platform or tied to a vendor account can be wiped again, remotely, at any moment. Airplane mode, a Faraday bag and a documented seizure time are not theatre; they are what keeps the position static until imaging can happen under proper chain of custody.

The imaging itself still matters even when encryption looks fatal. A verified forensic image taken now preserves the option to re-examine later with better techniques, and it records the device's true state at the point of seizure, which no amount of later work can reconstruct.

What to instruct, in what order

  1. Preserve the backups before anything else. Ask the client early for the phone's backup credentials, the computer it synchronised with, and any exported chats. This is where recovered evidence actually comes from in most reset matters, as we describe in our piece on chat exports as evidence.
  2. Isolate and do not power on. Keep the device off network, note its state on arrival, and get it to an examiner before anyone attempts the passcode.
  3. Fix the timeline. Collect whatever shows when the reset occurred: call records, account activity, MDM logs, witness accounts. If the timing is probative, it deserves the same rigor as the content.
  4. Expect an honest answer. A capable examiner will tell you within hours of triage whether the device is recoverable. What you should not accept is a refusal to look, because unencrypted remnants and wear-levelling artefacts are found only by people who image first and conclude second.

Practical guidance for instructing solicitors

Treat a reset device the way you would treat a shredded document: partly destroyed, partly duplicated elsewhere, and partly self-incriminating by the act of destruction. Frame the instruction around all three. Ask for backup preservation immediately, since providers delete stale data on their own schedules. Put the timing of the reset in evidence rather than leaving it as narrative. And resist any suggestion that a dead handset ends the enquiry; the same matter that produced the reset usually produced synchronised copies, and those copies rarely needed recovering at all, only locating.

SolveAssist examines reset, damaged and locked devices within the framework described on our services page, and the same discipline applies to vehicle and camera sources, including the recovery approaches in our article on deleted dashcam footage.

This article is general professional commentary, not legal advice. Case outcomes depend on the specific facts, the device involved and the stage of proceedings. Nothing here constitutes instruction for unqualified individuals. All work is conducted under professional indemnity insurance and is governed by the laws of England and Wales, the Civil Procedure Rules Part 35, and the ACPO/NPCC Principles of Digital Evidence.

© 2026 SolveAssist. All rights reserved.

← Back to journal SolveAssist →