CASE FILE

The Phone Was at the Crime Scene. Was Its Owner There Too?

The difference between the digital trace of a device and evidence of a particular person’s conduct. What do GPS, mobile networks, Wi-Fi, IP addresses, cloud accounts and application records actually prove?

The Phone Was at the Crime Scene. Was Its Owner There Too?
Jiný Kontext editorial illustrationIllustration accompanying this article.
Listen
00:00/00:00
1.00 ×
Ready

Analytical feature essay

At 2:13 a.m., the investigator has the first usable piece of information on the desk. A security camera captured only part of a figure and the lights of a departing car. A witness heard a bang but could not reliably identify anyone. Yet a phone number registered to a man who has already surfaced in the case communicated, at the critical time, through a base-station sector serving the area around the crime scene.

A phone icon appears beside the address in the mapping application. The time fits. The area fits. The subscriber says he was asleep at home. The first conclusion seems almost to draw itself: the phone was at the scene, the phone was his, therefore he was there too.

It is a natural inference. Often it is even correct. A phone is usually with the person who owns it, uses its number, is signed in to its accounts and replies through its applications. In everyday life, it is reasonable to compress all of that into one sentence: “That is his phone.” An investigation, however, does not begin where the shorthand works. It begins by asking what, exactly, has just been proved.

In this model scenario, we have not yet proved that a particular man stood in a particular street. We have proved that a mobile-network record linked a particular subscriber identity — and, depending on the data available, perhaps a particular device — to a particular cell or sector at a particular time. We also know that the service or number is registered to a particular person. Between those two propositions and the sentence “he was at the crime scene” lie several distinct evidential steps.

A digital value can be technically precise and still support a human conclusion only to a certain degree of confidence.

This is not an attack on digital forensics. After an extensive review of the field, NIST concluded that digital investigative methods rest on established computer-science principles and are reliable when used correctly. At the same time, it stresses that the meaning of an artefact depends on how it arose, how it was acquired, what its limitations are and whether it has been correctly understood.[1] Precision does not come from doubting every trace. It comes from refusing to make a trace say more than it actually contains.

01 / Chain of evidence

One sentence, at least five claims

“His phone was there” is not an atomic fact. It is a compressed story.

The sentence “his phone was at the crime scene” may look like a single conclusion, but it conceals several different claims. First, a particular record genuinely belongs to a particular physical device or subscriber identity. Second, that identity was in a particular geographic area at the relevant time. Third, the device belongs to person X. Fourth, person X was in fact using or at least carrying it at that moment. And fifth, if the device performed a particular action, it was person X who performed it.

The first two steps may be very well supported by technical records. The later ones require attribution. That attribution may itself be exceptionally strong — for example, if the phone had long been used exclusively by one person, was seized from that person shortly after the offence, repeatedly paired with their watch, unlocked in their presence, and if their movement is confirmed by camera footage while several independent systems record a continuous route. But the strength does not arise merely by renaming a device as a person. It arises only when the links are connected.

Time is a separate link in the chain. “At 2:13” may denote the moment when the device created an event, when an application wrote it to a database, when a server received it, or when a provider later entered it into an operational record. The phone may use a manually selected time zone, the server UTC, and the carrier its own reporting rules. Combining different timestamps into one timeline therefore first requires establishing their origin, resolution, time zone and relationship to the underlying event. For precisely this reason, the public draft of SWGDE methodology version 2.0 recommends documenting possible deviations in device time; for carrier records, the reporting of time zones must be verified separately.[2][5] The same number in a field labelled “time” does not necessarily denote the same instant in technical terms.

Device, account, user and action The chain-of-evidence diagram shows that the transitions between a device, an account, the actual user and a particular action are interpretive steps that must each be supported in their own right. ATTRIBUTION DIAGRAM Where does observation end and inference begin? 01 / DEVICE IMEI · serialnumber The physical object and itstechnical identifiers. 02 / ACCOUNT SIM · numberlogin Subscription, profile, sessionand the authenticated account. 03 / USER Who was holding it? The actual person at the exacttime, not merely the owner. 04 / ACTION Who acted — and with whatintent? Author of the message, pressing “send”,command, physical act, responsibility. IDENTITY LINK LINK TO THE PERSON LINK TO AUTHORSHIP A technical record may firmly prove one box. Moving into the next box requires further support, preferably from an independent source — not merely an intuitive shortcut.
Graphic 1 — The attribution chain. The farther a conclusion moves away from the directly observed artefact, the more important it becomes to state the additional premises. An arrow is not evidence by itself.
02 / Identity

“Phone” Can Mean Several Different Things

Hardware, a subscription, a number, an account and a person are not synonyms.

A physical device is a particular piece of hardware. It may have a serial number, an IMEI and other identifiers. A SIM or eSIM is another layer: it carries or provides access to the data needed to authenticate a subscriber identity to the mobile network. A conventional UICC can be moved between phones; with an eSIM, a profile is securely downloaded to an embedded element, and one device may support several carrier profiles.[3][4]

A telephone number, in turn, is an address for a service — not the manufacturing number of the phone or the identity of a person. It may survive a SIM replacement, a change of device or a change of carrier. One device may serve several numbers, and in some services one number may be accessible from several endpoints. A record containing a number therefore does not necessarily identify a particular piece of hardware; a record containing an IMEI, conversely, does not identify the person holding it at the time.

A user account — such as an operating-system, messaging-app or cloud-service account — adds another dimension. The account may be signed in on a phone, laptop, tablet and web client. A cloud event therefore often says reliably that the service received a request from a particular session, device, token or IP address. Without more, it does not say which human hand caused that request.

Physical deviceA particular piece of hardware

The phone as an object: its IMEI, serial number, storage, state and configuration.

SIM / eSIMSubscriber module or profile

Identity and keys used to access the mobile network. It is identical neither to the phone nor to a person.

Telephone numberService routing address

The identifier used to place calls or deliver messages; it may change independently of the hardware.

User accountDigital profile and session

It can be used simultaneously on multiple clients and mediate synchronisation or remote access.

OwnerWho bought or registered the device

A legal or administrative relationship to the object. It need not correspond to the everyday user.

Usual userWho normally uses the phone

A strong contextual link based on a long-term pattern, but not automatically valid for every moment.

Actual userWho was operating it at that moment

The decisive question for a particular time; it requires evidence that is temporally close and individualised.

Author of the actionWho created the particular content

The person who wrote, dictated or approved the message, or otherwise caused it to be sent.

In practice, the distinction between owner and user is not resolved by one “magic” artefact. The pattern may include contacts, accounts, photographs, language, habitual routes, known Wi-Fi networks, paired devices, payment cards, unlocking behaviour, the circumstances of seizure and testimony from people nearby. Some items point to long-term use; others to possession at a particular minute. Temporal proximity is what determines whether the evidence says “X generally uses this phone” or “X was very likely operating it at the critical moment”. The first proposition is an important foundation. The second is a separate conclusion.

The public draft update to SWGDE methodology version 2.0 expressly states that artefacts from a mobile device may help establish ownership, possession and use, and that device and subscriber identifiers should be correlated with carrier data and other findings.[2] The key word is “correlated”. A single identifier is one link in the chain, not the whole chain.

03 / Location

A map is not one technology

The same point on a screen can arise from entirely different mechanisms.

The greatest visual illusion in digital evidence arises when different kinds of data are drawn with the same symbol. A point then glows beside an address on the map whether it comes from a satellite calculation, a mobile cell, a Wi-Fi database, IP geolocation or a provider’s internal estimate. The graphical interface smooths over the differences. Yet those differences are precisely what determine the evidential meaning.

GPS—or, more precisely, GNSS —usually denotes a position estimate calculated by the device from radio measurements and, where applicable, other sensors or assistance data. A properly stored record contains more than latitude and longitude; the time, source and estimated uncertainty also matter. Android, for example, defines horizontal accuracy as a radius within which the true position is expected to lie with approximately 68% probability.[6] The number of decimal places in a coordinate is therefore not the same thing as accuracy. The result is affected by satellite geometry, signal obstruction, atmospheric conditions and receiver quality.[7]

Moreover, not every item labelled “location” comes directly from satellites. Mobile operating systems and applications may use a fused estimate that combines GNSS, Wi-Fi, the cellular network, inertial sensors or the last known position. The forensic meaning therefore lies not in the column heading but in which provider generated the value, whether it was a fresh measurement or an inherited state, and how the application stored it. A point on a map without those fields may look more precise than the data from which it was produced.

A mobile-network record answers a different question: which cell, and perhaps which sector, the device communicated with at the relevant time. Current SWGDE methodology describes it as a basis for placing a mobile device within an approximate geographic area. It also expressly states that CDRs alone do not persuasively identify who was using the device, and that ordinary cell or sector information cannot determine a precise intersection or address.[5] Timing Advance may narrow the area further, but it works with a band of derived distance, not with a single point.

Wi-Fi may mean a simple list of access points visible to the phone, a record of association with a particular access point, a log from an enterprise network controller, or specialised distance measurement. Android distinguishes an ordinary scan of nearby access points from Wi-Fi RTT, in which compatible devices measure signal round-trip time and, with several known points, can estimate location much more finely.[8] The sentence “the phone was on the Wi-Fi” is therefore incomplete until we know whether the record reflects only network visibility, an actual connection, a server log or ranging.

An IP address primarily describes a network path. A public IPv4 address may be shared by several devices in a household through NAT, and under carrier-grade NAT by several customers. The IETF therefore notes that an IP address and a time alone may not be enough to distinguish users; the source port and precise provider logs may also matter.[10] An IP address can reliably link an event to a network egress point or access session. By itself, it will usually not reveal a room, a device or a person.

A cloud account is not a location sensor in its own right. It is a place into which data from a phone, web client, server-side inference or synchronisation may flow. A cloud record may be more valuable than a local database because it was created outside the examined device and has its own timeline. At the same time, it inherits the meaning of the original mechanism: a coordinate synchronised from a phone remains a coordinate of the device; a login from an IP address remains a session event.

Bluetooth and other proximity artefacts may confirm that two radios detected, paired with or communicated with one another. This is especially powerful when one element has a fixed location and its log is acquired independently. RSSI signal strength, however, is not a universal ruler. NIST measurements showed that device orientation, the human body, walls and the surrounding environment substantially affect the relationship between RSSI and distance; outside idealised conditions, accuracy deteriorated sharply.[9]

Photograph metadata may contain time and geographic data under the Exif standard.[12] What this primarily proves, however, is that the particular file contains that metadata. A conclusion about where an image was captured requires an assessment of the file’s origin, continuity, exports, edits, time settings and consistency with other traces. The same applies to application records: a database may faithfully preserve a state created by a particular version of a program, but the investigator must understand the meaning of the fields, the time source, synchronisation, and the distinction between a user event and a system event. NIST and SWGDE both warn that the meaning of an artefact may change with the software version and that an automatically assembled timeline may not contain every event.[1][2]

Graphic 2 / Comparing traces

What question does the data actually answer?

GPS / GNSS

Where did the system estimate the device’s position?
A point with a time, source and uncertainty radius; quality depends on conditions and implementation.

By itself, it does not establish who was holding the phone or whether a person committed an act near the point.

Mobile network

Which cell or sector did the device use?
Typically an area of radio coverage; TA or other network data may narrow it.

It is not automatically a precise address, the nearest tower or the identity of the user.

Wi-Fi

What did the device see, or what did it connect to?
A scan, association, controller log and RTT are four distinct types of record.

Without verifying the AP’s location and the event type, a network name cannot be turned into an exact point.

An IP address

Through which network egress point did the session run?
Strong evidence for linking an event to a service or connection, especially when time, port and logs are available.

It usually does not identify a particular device, room or natural person.

Cloud

What did the service record about the account or session?
It may provide an independent server time, token, IP address, client and synchronised data.

An account may be shared or used from several clients; location inherits the source of the underlying data.

Bluetooth

Did two radios register one another within range?
Pairing, a beacon, a MAC address or an encounter log may support proximity and continuity.

RSSI alone is not a precise measure of distance, and a radio is not the same thing as a person.

EXIF photo

What metadata is embedded in the file?
Time, coordinates, device type and other fields may help reconstruct its origin.

Metadata alone does not establish the author, the integrity of the entire file or an unbroken history.

Application log

How did the application represent the event?
Meaning depends on the version, database schema, time source and synchronisation.

A database row need not be a direct user action or a complete picture of activity.

Precision is not a property of a technology’s name. It is a property of the particular record, its mechanism, the conditions under which it arose, its time synchronisation and its independent verification.
04 / An isolated data point

When a map permits more than one story

A single trace need not be weak. It may simply be less specific than it appears.

Return to the phone registered in the sector near the crime scene. This information is not worthless. If the time, identifiers and carrier data align, it increases the probability that the device or subscription was within the area served. It may contradict a claim that the phone was dozens of kilometres away. It may reveal a route, a repeated pattern or contact between two devices.

By itself, however, it does not resolve every alternative. The owner may have had the phone, but so may a member of the household, a colleague or an accomplice. It may have remained in a vehicle while the person went elsewhere. The SIM may have been in another device. The account may have generated the event from a linked client. Depending on the circumstances, some explanations will be highly plausible and others merely theoretical. Forensic honesty does not mean placing them all on the same level. It means identifying the question that the isolated data point has not yet closed.

The difference in one sentence

Trace: “The subscriber identity used sector S-17 at 2:13.”
Interpretation: “The device was probably within the coverage area.”
Attribution conclusion: “Person X was at the crime scene.”

The same discipline applies in reverse. The absence of a record does not necessarily prove that a person was absent: the device may have been switched off, may not have generated the relevant network event, or may fall outside the scope of the data obtained. A digital trace is generally an answer produced by a particular mechanism. It does not automatically answer every question we would like to ask of it.

05 / Convergence

Real strength comes from the convergence of independent traces

What matters is not the number of rows, but the number of independent paths to the same conclusion.

Five artefacts do not necessarily mean five pieces of evidence. A local database, a preview in a forensic tool and an export of that same database may be three views of a single event. A server record and a notification on the phone may likewise share one cause. When assessing convergence, the question is therefore not only whether the data agree, but whether they arose independently.

A stronger picture might look like this: the carrier records the device in a sector corresponding to the neighbourhood; an application on the phone stores a GNSS position with a reasonable uncertainty radius; the building’s Wi-Fi controller records an association with the same device; a camera captures a particular person arriving with the phone; a communications server receives a message from an authenticated session, and the same content appears on the recipient’s device. Each source answers a slightly different question. It is their overlap that narrows the space for alternative explanations.

Model timeline of converging digital traces Five relatively independent sources progressively support conclusions about the device’s presence, its possession by a particular person and the authorship of a particular message. GRAPHIC 3 / MODEL CASE How the strength of the conclusion changes The example is synthetic. It expresses neither a numerical probability nor universal technological accuracy. 21:48 CARRIER The device used the sectorcovering the neighbourhood. 21:51 PHONE A GNSS artefact placedthe device near the entrance. 21:52 WI-FI CONTROLLER An independent log recordedan association with the entrance AP. 21:54 CAMERA The image captured person Xwith a matching phone. 21:55 SERVER + RECIPIENT The service received a message from the session;the content was confirmed by the recipient’s phone. TIME SUPPORT FOR A MORE SPECIFIC CONCLUSION INCREASES
Graphic 3 — Timeline of the model case. The first record supports the device’s presence in the area. Only further traces from different sources connect the device to a person and a particular communication. In a real case, dependencies between sources must be examined.

Convergence does not mean that every additional point automatically multiplies certainty. If two traces share a source, or one arose from the other, their independence is limited. Even so, the principle is fundamental: an alternative explanation must gradually account not for one record alone, but for the entire set of concordant events. The more different mechanisms, data holders and timelines overlap, the harder it becomes to construct another explanation without adding further unsupported assumptions.

The strength of digital evidence does not lie in its most precise point. It lies in how many independent paths lead to the same story.

06 / Authorship

The message left the account. Who wrote it?

The technical authenticity of a communication does not always establish human authorship.

For a particular message, the evidential chain gains one more link. A local database may show an outgoing record. A server may confirm that it received the message from an authenticated session. The recipient’s phone may establish the content and delivery time. Together, that can prove very well that a particular account or client created or sent the message.

Attributing authorship to a particular person may nevertheless require further support. The account may have been open on a linked computer; someone else may briefly have controlled the device; the text may have been prepared earlier, sent by automation, dictated or inserted through remote access. NIST defines success in digital authentication primarily as demonstrating possession and control of an authenticator bound to the account.[11] That is a highly significant fact, but it is not the same as directly observing a person at the keyboard.

At the same time, not every theoretical possibility deserves equal weight. If the message appeared in an active session on the phone, the device was with person X, a camera captured X using it, the style continues the preceding conversation, and no linked client or remote access is evident, the attribution may be very strong. The correct proposition is not “authorship can never be proved”. It is: “A conclusion about authorship must be supported by traces that go beyond the mere existence of a message in an account.”

07 / Law and knowledge

A trace, an indication and a conclusion are not the same thing

Data integrity answers a different question from data meaning.

In a forensic report, it is useful to separate at least four layers. Observation states what was found: for example, a database row, a server log or a cell identifier. Technical interpretation explains how such an artefact typically arises. Indication describes its relationship to the investigative hypothesis. And a conclusion combines several indications into a claim about a past event.

Fact

The carrier file contains a record at time T of IMSI/IMEI and sector S.

Interpretation

The device or subscriber identity used the relevant part of the network at that time.

Correlation

The record overlaps with the crime-scene event in time and space.

Hypothesis

The device may have been carried by its usual user X at the critical time.

Conclusion

After adding further independent traces, it is — or is not — reasonably supported that X was present and acted.

A cryptographic hash can reliably show that acquired data has not changed since a particular point in time. It does not prove that the content was truthful when it arose before acquisition, that the device clock was correct or that a particular person created the record. The chain of custody protects the integrity of evidence. Attribution analysis addresses its meaning. Confusing those two questions is as mistaken as doubting a correct hash merely because the author of the file remains unknown.

It is similarly necessary to distinguish admissibility from evidential weight. A correctly acquired and authentic export may be an entirely proper item of evidence while still supporting only a limited claim — the presence of an account in a system, for example, rather than the identity of the author. Conversely, a substantively persuasive artefact may be weakened by uncertain provenance or an undocumented transformation. An honest expert opinion therefore states not only the finding, but the path by which it was reached, known limitations, and the degree to which it supports a particular hypothesis. NIST describes this transition as analysis that turns artefacts into a reconstruction of relevant events; the reconstruction is an expert result, not an automatic tool output.[1]

The Czech Constitutional Court has repeatedly emphasised that circumstantial evidence is not inferior to direct evidence. It may itself be sufficient to establish guilt if the individual pieces are interconnected and form a coherent chain that leaves no reasonable alternative.[13] Digital artefacts fit this logic exactly. Individually, they may prove partial circumstances. Taken together, they may create a highly persuasive reconstruction. The decisive question is whether a hidden gap remains between the observed data and the final conclusion.

08 / Counterargument

Caution must not end in absurd relativism

“Someone else might have been holding the phone” is not a magic formula that cancels all evidence.

Any evidence can be surrounded by hypothetical possibilities. The phone might have been lent out. The account might have been compromised. The camera might have captured a lookalike. The time might have been wrong. If the mere conceivability of an alternative were enough, almost nothing could be proved — digitally or otherwise.

A reasonable alternative must have support in the circumstances, explain the entire body of traces, and not require an ever-growing series of unsupported exceptions. Evidence that two people in a household routinely shared the phone carries a different weight from the purely theoretical statement that “anyone could have had it”. A documented active session on a laptop carries a different weight from the possibility that “perhaps somebody hacked the account” when the logs show nothing of the kind.

Forensic precision is therefore not an endless list of every imaginable scenario. It is a calibrated assessment: what a trace directly proves, what it strongly supports, what it merely permits, and which alternatives remain realistic. This approach does not weaken digital evidence. It strips away exaggerated claims that might collapse at the first serious expert challenge.

09 / A new sentence

The precision of the data and the precision of the story

The most honest conclusion is often longer. That is precisely why it is stronger.

At the start of the case, the proposition sounded simple: “His phone was near the crime scene.” Once context is added, an honest conclusion may sound less dramatic but be substantially more precise: “The subscriber identity registered to person X used, during the critical period, a sector covering the surrounding area. Further artefacts from a particular device, an independent Wi-Fi log and video footage support the conclusion that person X was holding the device at the time.”

That wording is not an evasion of a decision. On the contrary, it shows which parts of the conclusion rest on a direct technical record, which on a pattern of use, and which on the convergence of independent evidence. If a message sent from the account is later added, a different question must be asked again: are we proving session activity, control of the phone, or authorship by a particular person?

Digital technology has not created a world without uncertainty. It has created a world with an enormous quantity of traces — often more precise, more finely timed and more resistant to the failures of human memory than anything investigators had before. Their value is greatest precisely when we respect the boundaries of each mechanism and allow different sources to verify one another.

The greatest problem therefore often lies not in a shortage of data, but in language. In a single sentence, we can turn technically precise data into a human story more precise than the data permits. And the most dangerous forensic error need not occur when the trace is inaccurate. It may occur when the trace is precise — and our conclusion is more precise still.

Sources and literature

Sources and further reading

  1. NIST IR 8354 — Digital Investigation Techniques: A NIST Scientific Foundation Review. National Institute of Standards and Technology, 2022. Scientific review of the foundations of digital forensics, the reliability of its methods and known limitations in the interpretation of artefacts. DOI / document.
  2. SWGDE 20-F-005-2.0 — Best Practices for Mobile Device Forensic Analysis. Scientific Working Group on Digital Evidence, public draft version 2.0 released for comment on 23 June 2026. Current draft on the analysis of mobile artefacts, identifiers, time data and validation context; the document is not a final approved version. PDF.
  3. NIST SP 800-101 Rev. 1 — Guidelines on Mobile Device Forensics. NIST, 2014. Distinctions among a mobile device, UICC/SIM, subscriber and device identifiers, and types of mobile artefact. DOI / document.
  4. GSMA — eSIM. Technical overview of the role of SIMs and remotely downloaded profiles in a device’s secure element. Official GSMA page.
  5. SWGDE 17-F-001-5.0 — Best Practices for Historical Cell Site Analysis. Version 5.0, 9 July 2026. Defines CSLI as a basis for identifying an approximate geographic area and stresses the distinction among a cell/sector, a precise location and the identity of the user. PDF.
  6. Android Developers — android.location.Location. Documentation on the meaning of horizontal accuracy estimates, time data and the source of a location record. Technical documentation.
  7. GPS.gov — GPS Accuracy. Official explanation of the distinction between signal accuracy and user accuracy, and of factors such as satellite geometry, obstruction, the atmosphere and the receiver. Official overview.
  8. Android Developers — Wi-Fi scanning overview; Wi-Fi RTT. Distinguishes visible access points, scanning and active ranging by round-trip time. Wi-Fi scan; Wi-Fi RTT.
  9. NIST IR 8437 — On the Feasibility of COVID-19 Proximity Detection Using Bluetooth Low Energy Signals. NIST, 2022. Experimental analysis of the relationship among BLE RSSI, distance, orientation and environment. DOI / document.
  10. IETF RFC 6269 — Issues with IP Address Sharing. Description of the consequences of NAT and shared public IPv4 addresses for subscriber identification, and of the importance of precise times and ports. RFC Editor.
  11. NIST SP 800-63B-4 — Digital Identity Guidelines: Authentication and Authenticator Management. NIST, 2025. Defines authentication as demonstrating possession and control of an authenticator bound to an account. Technical standard.
  12. CIPA DC-008-Translation-2026 — Exchangeable image file format for digital still cameras: Exif Version 3.1. Camera & Imaging Products Association, 30 January 2026. Current edition of the standard for image metadata, including time and geographic fields. Overview of CIPA standards.
  13. Judgment of the Czech Constitutional Court, file no. IV. ÚS 1098/15, 22 March 2016. On the evidential force of circumstantial evidence and the requirement for an interconnected, coherent chain. NALUS.
Discussion

Comments

Have a view or an additional source? Add a comment.

Discussion is not active yet.