SKIP TO CONTENT
MATTER TYPE / FAMILY LAW

Family law: shared devices, shared accounts, and the attribution problem they create

A marital household runs on equipment nobody separated in advance. One laptop, one login, a tablet the children use, a cloud account with both spouses signed in. That arrangement removes the single assumption most forensic attribution rests on, and it does so before any question about the evidence is reached — the authorisation question having usually arrived first.

QUESTION
Who used the device, and was access lawful
CORE ARTIFACTS
Per-user profiles · browser · sync
CLOCK
Devices are wiped, sold and reset fast
USUAL POSTURE
State court · often expedited
DELIVERABLE
Report or affidavit, then testimony
ROLES
Testifying · Consulting · Neutral
IN SHORT

In a family law matter the forensic record normally establishes what a device or account was used for and when, and how that activity is distributed across user profiles. Where the spouses used separate accounts, most of it attributes cleanly. Where they shared one login, the machine holds no basis for distinguishing them and neither does an examiner — and no examination can establish that a device is free of monitoring software.

What is actually in dispute

The evidence questions in a matrimonial case are ordinary; the ownership of the evidence is not, because the parties held the devices and the accounts jointly right up to the moment they became adverse.

Four subjects recur. Assets, where the question is what a party has and has not disclosed. Conduct, where messages, browsing or photographs bear on the issues the forum treats as relevant. Monitoring, where one party alleges the other installed software or kept access to accounts after separation. And the evidence itself, where a party has already gone through a shared machine and produced what they found.

Underneath all four sits a problem this matter type has and the others largely do not. In a corporate case the account belongs to an employer, the permissions were configured by somebody, and there is a written policy to read against. Here the device is chattel that both parties owned, the password was on a note by the monitor, and the legal basis on which one spouse now reaches the other’s data is genuinely contested. Counsel resolves that before an examiner is instructed. An examiner who takes an instruction that skips it produces work product that may not be usable and may be worse than useless.

What a shared login does to attribution

Windows and macOS record most of the useful activity per user profile: shell history, document lists, browser data, application launch counts, and the folders each account browsed. Two profiles means two separable records, and in that configuration attribution is no harder than in a corporate matter. One profile used by two people means the operating system was never distinguishing them, so the examination produces a record of the household rather than of a person. That is not a limitation that better tooling overcomes; it is a fact about what was written at the time.

The same applies to shared cloud accounts, a shared password manager, a family plan with one Apple or Google identity across several devices, and a browser signed in on both spouses’ machines with history syncing between them. In each case the record names a credential that two people were entitled to use.

Which artifacts bear on it

The examination is a standard host examination. What changes is how each finding has to be qualified once the device turns out to have been shared.

Per-user activity

Logon events establish which local account was active in a session and whether it was at the console. RecentDocs, jump lists and shellbags record the documents and folders an account opened; UserAssist counts programs launched through the shell; and browser history, downloads and saved form data are frequently the most probative material on the machine, because they name institutions, services and search terms. On Apple hardware KnowledgeC records device and application usage over time in a form that supports a usage pattern rather than a single event.

Deletion, storage and what left

The Recycle Bin retains the original path and deletion time of items sent to it per user, and volume shadow copies often hold a version of a document or a database from before it was altered. Removable device history and sync client records show where material was moved, which matters when a party has been preparing for a proceeding for some time.

Signs of monitoring

Where the allegation is surveillance, the examination looks at installed applications and their execution records via Prefetch and Amcache, at configuration profiles and the permissions granted to them, at accessibility and screen-recording entitlements on macOS, and at the account’s own list of active sessions and trusted devices. A positive finding here is often decisive. A negative one carries very little, and should be written that way.

Limits of proof

What this evidence cannot establish

  • Which spouse did it, on a shared account. The system recorded a credential both parties were entitled to use. Where one login served the household, activity cannot be separated by profile, and attribution has to come from outside the machine or not at all.
  • That a device is free of monitoring software. Commercial products are built to avoid notice, some run from the account rather than the device, and an examination reports what was searched for and what was found. “Nothing detected” is a description of the search, not a clean bill of health.
  • What a party owns, or what it is worth. Local traces point at institutions and accounts. They do not establish balances, ownership, current existence, or that the trace is not a closed account from years ago. Valuation is someone else’s discipline.
  • That a document or message is genuine, from a screenshot. A screenshot carries the metadata of the screenshot. It shows neither the surrounding conversation nor whether anything was deleted or edited before the picture was taken.
  • Fault, credibility, or anything about parenting. Browsing history, message content and application use are facts on a device. What they say about a person, a marriage or a child’s interests is argument, and an expert who supplies it will be cross-examined on it rather than on the forensics.

Most of the message traffic in these matters lives on phones rather than computers, and phone extraction is a separate acquisition discipline covered at mobileforensicexpertwitness.com. The tool at can this artifact prove that? maps a proposition onto the records that bear on it and shows where the inference runs out.

The expert’s role and the deliverable

  1. Settle the basis for access first. Whose device, whose account, on what authority, and under which order — recorded in writing before anything is imaged. This step is counsel’s to resolve, and it is the one that determines whether the resulting examination is usable.
  2. Preserve before the household separates further. Devices in a divorce get factory reset, sold, given to children and replaced, and accounts get password-changed out from under the other party. The preservation deadline calculator sets out how quickly the common sources age out.
  3. Acquire under write-block, with a custody record. A forensic image taken through a write blocker, hashed at acquisition and again at verification, with a chain of custodyform that becomes an exhibit. Where a device must be examined at a neutral’s office rather than removed, that arrangement is recorded too.
  4. Map the profiles before reading the activity. Which accounts existed on the machine, when each was created and last used, whether any had a password, and whether the browser was signed in and syncing. That map decides how every subsequent finding has to be qualified, so it belongs at the front of the report rather than in a caveat at the end.
  5. Examine to the scope, and record what was excluded. Family matters draw narrow, negotiated scopes — a date range, a custodian, named categories — and often a court-appointed neutral rather than a party expert. What was searched, what was found and what was deliberately not examined all go in the report.
  6. Report, affidavit and testimony. State practice varies on the form; the discipline does not. Each assertion traces to a named artifact, the qualifications on shared-device attribution are stated as findings rather than buried, and another examiner working from the same image can reproduce the result.

The underlying examination is described on the computer forensics page, and the neutral and testifying roles on the expert witness testimony page.

Where the admissibility pressure falls here

Family matters are state-court matters, and the reliability standard depends on the forum: some states apply the federal framework as amended in December 2023, others the older general-acceptance test, and several apply a local hybrid. The Daubert or Frye lookup shows which standard a given jurisdiction applies. Whichever it is, the attacks in this matter type are consistent.

  • Attribution asserted on a shared machine. The most common defect, and the easiest to avoid. If the report does not state the profile structure and what it permits, the cross-examination will establish it instead.
  • How the evidence was obtained. Where access to an account or device is disputed, the argument often reaches the examination before it reaches the findings. Documenting authority at the point of collection is what keeps that argument about admissibility rather than about the examiner.
  • Self-collected material presented as forensic. Files a party copied themselves have lost their original file system metadata and carry no custody record. They can still be examined and are frequently all there is, but the difference has to be disclosed rather than smoothed over.
  • A clean scan offered as proof of no monitoring. Reporting that no monitoring software was identified is accurate. Reporting that the device was not monitored is not, and the distance between those two sentences is the whole opinion.
  • Scope creep.A narrow instruction that becomes a general trawl through a household’s data produces both an admissibility problem and a relevance objection, and in a matter with children and third parties on the same device it produces a privacy problem as well.
RECORDWHAT IT ESTABLISHESWHAT IT DOES NOT ESTABLISH
User profile structureWhich accounts existed on the device, when each was created and last used, and whether any was password protectedWhether the person named on a profile was the only person using it
Browser history, downloads and saved form dataWhich sites and services an account reached, what it retrieved, and what was typed into searchWho typed it, on a shared profile — and a synced browser mixes activity from every signed-in device
RecentDocs, jump lists and shellbagsThat a named document or folder was opened by a given profileWhether it was read, changed or copied; absence does not show a file was never opened
Recycle BinThe original path and deletion time of items sent to it, per userWhat happened to files deleted by other means, or emptied before imaging
Volume shadow copiesAn earlier state of a document, database or registry hive from before it was alteredThat any particular version was the one relied on, or that copies exist for the dates you need
Installed applications and execution recordsThat monitoring or anti-forensic software was present, and where enabled, that it ranThat no such software is present. Absence of detection is not absence of monitoring
Cloud account session and device listsWhich devices held live sessions on an account and when they last connectedWho was operating them, on an account both parties were entitled to use
The right-hand column is the one that decides admissibility fights in this matter type. Each record above has its own page under /artifacts setting out retention, failure modes, and how a finding drawn from it is attacked.

Questions counsel ask

The computer is in both names and we both used it. Can you still tell who did what?

It depends entirely on whether the two of you used separate accounts. Where each spouse had their own profile, most Windows and macOS artifacts are recorded per user, and activity separates cleanly. Where a single account was shared — one login, one password, no lock screen — the operating system has no basis on which to distinguish you, and neither does an examiner. In that situation the honest report describes the activity, states that the machine records no user distinction, and identifies which non-forensic corroboration would be needed to attribute any of it.

My client has the password to the other spouse's email. Can we just look?

That is a question for counsel and the forum, and it has to be answered before an examiner is instructed rather than after. Federal wiretap and stored-communications statutes, state eavesdropping and computer-misuse statutes, and the court's own orders all bear on access to another person's accounts and devices, and marriage does not by itself resolve them. What a forensic engagement can offer is a structure that keeps the question answerable: work from what a court has ordered produced, or from devices the client owns and controls, and document the basis for access at the point it happens.

Can you tell whether my client's phone or laptop is being monitored?

An examination can look for the signs monitoring software leaves — installed applications and their launch records, profiles and permissions granted, accessibility and screen-recording entitlements, unexpected network destinations, and account sessions from devices the owner does not recognise. Findings there can be strong. The reverse is much weaker: no examination can establish that a device is clean, because commercial monitoring products are designed to be inconspicuous and some operate from the account rather than the device. The finding is what was found, and the report says what was searched for and not seen.

We have screenshots of the messages. Is that enough?

It is a starting point that opposing counsel will test. A screenshot is a picture of a rendering, carrying the metadata of the screenshot rather than of the message, and it shows nothing about the surrounding conversation, deletions, or edits. Where the underlying account or device can be preserved and examined, the messages can be produced with their own records around them. Where it cannot, the screenshots are what there is, and the report should be explicit about what that form of evidence does and does not support.

Can forensics find hidden accounts and assets?

It can find the traces of them on the devices examined — browser history and saved credentials pointing at institutions, statements and tax documents in local folders or cloud storage, application installs for brokerages or exchanges, and search terms. Those traces support targeted discovery, subpoenas and deposition questions. They are not a picture of anyone's finances: an account can exist with no local trace at all, and a trace can survive long after an account is closed.

Is this the same standard as a federal case?

The reliability enquiry is similar and the label may not be. Family law is state-court work, and states divide between the federal reliability framework and the older general-acceptance test, with local variations on both. What travels regardless is the discipline: a sound acquisition, a documented custody record, an examination another examiner can repeat, and an opinion that stops where the evidence does.
  • Computer forensics

    Write-blocked acquisition, the artifacts an operating system keeps, and the three distinctions that keep an opinion inside what the evidence supports.

  • Daubert or Frye?

    Which reliability standard a given state applies to expert evidence, and what that changes about how an opinion is presented.

  • Browser history and downloads

    What the record actually contains, how syncing mixes devices together, and how a finding drawn from it is attacked.

  • How to hire and vet a forensic expert

    Party expert versus court-appointed neutral, what to demand before retention, conflicts, timing, and cost.

ENGAGE AN EXPERT ON A FAMILY LAW MATTER

Devices in a separating household are reset, sold and handed on within weeks, and account passwords change without notice. Send the matter, the county and court, the separation date, and whose devices and accounts are in issue — a conflicts check and a scoping call follow.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

Attorney advertising / expert services. This page describes forensic practice and the procedural rules that govern expert evidence in general terms. It is not legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum. Prior results do not guarantee a similar outcome.