The report almost always reaches the legal department with the same phrase: the data leaked, we need to find out who broke in. In a significant share of cases, nobody broke in. The information walked out the front door, with a badge, a valid login, and its own password. The Ponemon Institute's Cost of Insider Risks report estimated in 2025 an average annual cost of US$ 17.4 million per organization to manage incidents of internal origin. Verizon's Data Breach Investigations Report indicates that roughly 60% of data breaches involve the human element. The numbers confirm what forensic practice has observed for years: the insider is not the exception, it is a mandatory hypothesis. Every serious leak investigation must methodically test the possibility that the source is inside the house before pointing outward.
The law has already mapped the consequences: LGPD, termination for cause, civil liability, notification to the authority. All of them depend on a demonstrated fact. And in a digital environment, facts are demonstrated through traces. This is where legal work meets technical work.
The traces the employee leaves behind
Every access leaves a record. Authentication logs show who logged in, when, from which machine, and through which network. Audit trails in management systems record queries, exports, and generated reports. The workstation's operating system keeps artifacts of every USB device ever connected: model, serial number, date and time of connection, along with traces of the files handled. Email servers record forwards to personal accounts; network logs document uploads to cloud services; print servers keep the history of everything sent to paper.
There is a limit that forensic honesty requires us to state: a photograph of the screen taken with a personal phone generates no record in the corporate environment. In those cases, the examination shifts from the act of capture to the behavior around it. Queries in atypical volume, access to records unrelated to the employee's role, sessions at unusual hours, and sequential browsing through customer records form, when correlated in time, the circumstantial evidence that the isolated capture tried to hide.
How a trace becomes evidence
A trace only converts into evidence when it is preserved with method, and preservation must happen before any confrontation with the suspect. The procedure begins with a forensic image of the workstation and a copy of the relevant logs, both authenticated by hash values that prove integrity. Working on the preserved material, the examination reconstructs the timeline: what was accessed, exported, connected, sent, and deleted, event by event. The strength of the result lies in the correlation of independent sources: when the system log, the workstation artifact, and the network record all point to the same event, the conclusion withstands adversarial scrutiny.
"The evidence of an internal leak is born in the first minutes of suspicion. What the company does before the confrontation defines what it can prove afterward."
Proof through identical errors
One recurring technique in unfair competition cases deserves attention. Every customer database carries imperfections: a misspelled surname, an outdated address, a transposed digit. When the leaked database reappears at a competitor, whoever received it rarely redoes the work, and the same errors reappear, in the same positions. The coincidence of identical errors between the source database and the database found at the destination demonstrates reuse with a very high degree of technical certainty. Mature companies go further and plant deliberate seeds: fictitious records created to track copies. If the customer who does not exist receives a proposal from the competitor, the leak's route is exposed.
The insider recruitment method has also evolved. Recent high-profile cases in the delivery app market exposed the scheme of fake paid surveys: consulting firms approach managers and directors through professional networks offering payment for interviews about the market, asking nothing about the company. The amounts grow with each round, the questions become specific, and when the interviewee resists, there are records of threats to send the recordings to the employer. What looked like consulting was structured collection of trade secrets, with cases that escalated into extortion.
The classic mistake: IT investigates first
The script repeats itself across companies. Suspicion arises, the IT team powers on the employee's computer, opens the files, prints emails, and assembles a dossier. The gesture looks diligent and destroys the case. Every file opened alters metadata; every login on the machine overwrites traces; a copy without hash values proves no integrity. Under adversarial scrutiny, the defense does not need to prove innocence: it only needs to show that the evidence was handled without a chain of custody. The well-known result is the termination for cause reversed in the Labor Courts, with severance pay and possible damages, in a case whose underlying fact was true.
The first minutes of suspicion
What HR and the legal department do in the first minutes is worth more than months of subsequent investigation:
- Do not confront the suspect or alter their routine before the evidence is preserved;
- Prevent use of the workstation involved; if it is powered off, keep it powered off;
- Suspend automatic purge routines for logs and backups covering the period under analysis;
- Record in writing who learned of the suspicion, when, and through which channel;
- Engage the legal department and a forensic expert before any internal technical measure.
Prevention and the role of the expert report
Prevention is less technological than it seems. Legitimate monitoring, provided for in internal policy and clearly communicated to the employee, sustains the validity of the evidence and discourages misconduct. Explicit notices that the corporate environment is auditable eliminate the gray zone the insider exploits. And culture matters: a team that understands the value of information and knows the consequences of a leak is the first layer of defense.
When prevention fails, the outcome depends on the expert report. The report documents the method, proves the chain of custody, states the limitations of the examination, and presents conclusions reproducible by another expert. It is this document that sustains termination for cause in the Labor Courts, grounds the civil action for damages, and supports the criminal complaint when the conduct constitutes a criminal offense. Internal leaks are resolved with demonstrated facts. And in a digital environment, a fact is a trace preserved in time.
