Tracing criminals from CCTV, phones and online chats
Indian investigations now combine device data with WhatsApp chats, CCTV, CDRs, metadata, witness accounts and records held by technology companies, but each source has limits and must be interpreted before responsibility can be attributed reliably.
On 26th November 2008, ten Pakistani terrorists attacked Mumbai. In the aftermath of the attack, the investigating agencies had crime scenes spread across the city. The digital trail, however, extended much further.
Agencies intercepted telephonic conversations that linked the terrorists in Mumbai with the handlers sitting in Pakistan. Mobile phones were recovered from attack sites. Investigators traced calls to a Voice over Internet Protocol (VoIP) service in the United States. Payment records led elsewhere. Recovered GPS devices carried navigational data. Internet Protocol addresses provided another set of clues to the investigators.
The Supreme Court’s judgment in the Ajmal Kasab case mentioned how the terrorists used the US-based Callphonex service. Calls from three mobile phones used by the terrorists went to a single number associated with the provider. Evidence from the company included account information, call records and other material that helped the investigators reconstruct the communications network behind the attack.
The investigation was not limited to one electronic record that explained the operation. Investigators examined calls, recovered devices, provider records, internet connections, payment information, GPS data and other evidence.
While the scale of the investigation may differ, similar examinations of digital evidence happen in cases ranging from murder and kidnapping to riots, financial crimes and terrorism. A phone can contain a trail that can provide clues, but recovering it is only the beginning. Investigators still have to establish where the data came from, whether it remained intact, what activity it records and who was responsible for that activity.
The digital crime scene is larger than the phone
When investigators find or seize a handset, it may contain messages, photographs, documents, application databases, call information, location-related info and traces left by other activity. Another person’s phone may contain the other half of the conversation. A laptop may hold a synchronised copy, a blueprint and incriminating material. CCTV may show who was carrying the device. A telecom company may have call or connection records. An online platform may separately hold subscriber details or login information.
The curriculum of the National Cybercrime Training Centre (NCTC) explores the range of material investigators now encounter. NCRB training covers digital evidence, chain of custody, CDR and IPDR analysis, CCTV evidence collection, internet investigations and social-media analysis. Its forensic courses separately cover hashing, imaging, metadata, logs and encryption.
The investigation into the April 2025 Pahalgam terror attack extended beyond material recovered directly from suspects. NIA sought photographs, videos and other information from people who had been present in the area. By June 2025, the agency said it was examining eyewitness accounts, video footage, technical evidence and police sketches while working to establish the identities of the attackers. At that stage, NIA also cautioned that it had not reached conclusions on all the identities then being circulated publicly.
A tourist’s phone can consequently become part of a terrorism investigation without the tourist being an accused. A photograph taken shortly before an attack may preserve a person in the background. A video may capture a vehicle, clothing or movement. Its timestamp may assist a timeline. Another recording taken minutes later may add more information to the evidence board. None of those fragments has to solve the case on its own, but every piece has its own crucial role.
The first job is to preserve what already exists
Digital evidence can change while it is being handled. A recovered phone may be switched on, locked, connected to a mobile network or Wi-Fi, damaged or displaying information that may later disappear. Applications can continue receiving data. Routine interaction with the phone can generate new artefacts. A CCTV recorder can overwrite old footage while investigators are still deciding which cameras matter.
Opening applications and scrolling through a handset is therefore not equivalent to examining an ordinary physical exhibit. Bureau of Police Research & Development’s (BPR&D) standard operating procedures cover the handling, preview and imaging of computers and digital media, along with hashing and the use of forensic tools. The procedures recognise the need to control what happens to the source evidence while material is being acquired.
The condition in which a device is found also changes how the material on it is recovered and handled. An unlocked phone that is already running presents different choices from a locked phone recovered in a switched-off state. Network connectivity, security mechanisms and the possibility of losing access can affect how specialists handle it.
There is no useful rule that every seized phone should immediately be switched off. There is no equally useful rule that every device should be left running. Investigators have to document its condition and choose the method appropriate to the circumstances.
Chain of custody continues after seizure. With digital evidence, the record must account not only for who possessed the exhibit but also for what was done to the device and the data during examination.
A forensic extraction does not reveal everything
Once a phone or storage device reaches the laboratory, three different processes can follow: acquisition, examination and interpretation.
Acquisition obtains the material available through the chosen forensic method. Examination searches that material for relevant artefacts. Interpretation connects those artefacts with the investigative question.
Delhi’s Forensic Science Laboratory (DFSL) lists forensic imaging of storage media, retrieval of stored and deleted data, and extraction of data and deleted data from mobile phones and SIM cards among the functions of its Cyber Forensic Division. The resulting extraction should not be mistaken for a complete history of everything that ever existed on the phone.
Access can vary between devices. The operating system, hardware security, encryption, passcode state, damage and the forensic tools available can affect what an examiner can acquire. One method may recover categories of information that another cannot. An extraction may also be partial.
Absence from a forensic extraction does not automatically prove that a file, message or activity never existed. The examiner first has to know what the method was capable of reaching.
The Red Fort-area car bomb investigation provides a recent example of the volume involved in a major terror probe. In March 2026, NIA said searches at several locations in Jammu and Kashmir had resulted in the seizure of digital devices that were sent for forensic examination.
In May, NIA filed a 7,500-page charge-sheet against ten accused. The agency said its investigation had covered several states and Delhi-NCR and involved 588 oral testimonies, more than 395 documents and over 200 material exhibits. The allegations in the charge-sheet remain prosecution claims subject to judicial scrutiny, but the scale gives an indication of what investigators may have to process before a digital finding becomes useful evidence.
A seized device can contain thousands of chats, photographs, documents and application records. Several devices can multiply that volume. Investigators then face a second problem after extraction, that is, finding the few artefacts relevant to the offence and placing them in the correct context.
From a seized phone to foensic evidence
Hashing can test integrity, not authorship
A forensic copy needs a way of being checked against the material from which it was acquired. Hashing provides one such mechanism. A mathematical function processes digital data and produces a hash value. If the data changes, the resulting value should also change. Comparing hash values can therefore help an examiner demonstrate that particular material remained unchanged between specified stages of handling.
BPR&D’s procedures include hashing and forensic imaging as part of digital-evidence handling. NCRB also teaches hashing and imaging as dedicated components of forensic examination.
A matching hash answers only a part of the question. It can help show that the digital material being examined is unchanged from the material against which it was compared. It cannot identify who created a file. It cannot prove that the statements inside a message are true. It cannot establish that the owner of the phone personally performed the activity recorded in it.
Deleted does not necessarily mean recoverable
Deletion is often described at two opposite extremes. One assumes that pressing delete destroys the evidence permanently. The other assumes forensic laboratories can recover anything. Neither is a safe assumption.
Delhi FSL expressly lists retrieval of deleted data from storage devices and extraction of deleted data from mobile phones among its cyber-forensic functions. Recovery is therefore a recognised part of forensic examination. Success depends on what remains available on the particular device.
Investigators may have to determine whether data survives in recoverable storage, whether it has been overwritten, whether an application database contains residual information or whether another copy exists elsewhere.
The second copy may be more important than the deleted original. A recipient may still possess a message. A photograph may have been synchronised to another device. A CCTV clip may have been exported before the recorder overwrote the original period. A service provider may retain account or connection information even when content is no longer present on the handset.
Security can stop the examination before recovery is even attempted. NCRB’s forensic curriculum includes encryption and decryption as a separate module because physical possession of a device does not guarantee access to all of its contents.
The useful questions are consequently specific. What survived? Where did it survive? Can it be recovered? Is it complete? How confidently can the examiner explain what the recovered fragment represents?
Metadata can change the timeline
A photograph contains an image, but the file may carry information beyond what is visible in that image. An email contains text, but its headers can record how it moved through systems. A document can contain dates and other properties created by the software that handled it.
Metadata can help reconstruct events, provided the investigator knows what each field represents. NCRB’s cyber-forensic training separates metadata analysis from hashing, imaging, CDR/IPDR examination and log analysis.
Time is one of the easiest fields to misread. A timestamp may refer to creation, modification, receipt, access, export or another event. The device clock may have been wrong. Two systems involved in the same communication may record time in different time zones. A file copied to another system may acquire information that did not exist in the same form on the original device.
An apparent contradiction between two times cannot be resolved merely by choosing the one that fits the theory of the case. The examiner has to establish what each timestamp records, which clock produced it and whether another independent source supports the interpretation. Hence, precision on the screen does not guarantee precision in the conclusion.
WhatsApp, CCTV and the digital trail in the 2020 Delhi riots
The investigation into the February 2020 Delhi riots produced a digital trail running through WhatsApp groups, mobile phones, call-detail records and CCTV cameras. In FIR 59/2020, the larger conspiracy case, investigators sought to reconstruct not merely what happened during the violence, but the communication and coordination that preceded it.
Umar Khalid, Sharjeel Imam, Khalid Saifi, Gulfisha Fatima, Athar Khan, Shadab Ahmed, Saleem Khan and others were among those accused in different parts of the larger conspiracy case. The prosecution alleged that anti-CAA protest sites and chakka jaams were coordinated through meetings and digital groups and were ultimately linked to the violence. The accused have disputed those allegations, and the Delhi High Court has expressly stated that its observations in the bail proceedings should not be treated as findings on the merits of the criminal case.
WhatsApp records gave investigators a chronology extending back before the riots. The Delhi High Court recorded the prosecution case that the Delhi Protest Support Group, or DPSG, was created on 28th December 2019 after a meeting at the Indian Social Institute. The prosecution described DPSG as an umbrella WhatsApp group coordinating mobilisation, fundraising, legal assistance and the activities of smaller groups including JCC and JACT. The same court record says the prosecution attributed the propagation of the alleged strategy to Sharjeel Imam and Umar Khalid.
The messages were relevant for more than identifying who belonged to a group. Investigators examined what members were discussing and when they discussed it. On 3rd February 2020, according to the prosecution case recorded by the Delhi High Court, Khalid Saifi was alleged to have posted a message in DPSG instructing people to cover police CCTV cameras with black tape.
Messages presented during Umar Khalid’s bail proceedings added another layer. OpIndia reported the prosecution’s February 2022 submissions that DPSG member Owais Sultan Khan had posted objections on 16th and 17th February to what he described as a proposal to incite violence. One message cited in court said, “Aag lagwane ki poori tayyari hai”, while the prosecution argued that Owais was warning that local residents possessed evidence about what was being planned.
OpIndia’s detailed account of the subsequent bail order records that Owais was objecting to alleged plans involving violence and chakka jam and that the DPSG became unusually silent between 18th and 21st February. According to the material discussed before the court, no rebuttal was posted in the group to his accusations during that period.
Delhi riots: WhatsApp trail timeline
The WhatsApp evidence recovered in the wider Delhi riots investigations was not confined to DPSG. In the Jafrabad case, OpIndia reported from the police charge-sheet that investigators recovered messages from an accused person’s phone instructing recipients to keep boiling water and oil ready, store bottles of acid, extract petrol from vehicles, accumulate bricks and stones on terraces and arrange for electric current to be passed through metal gates. These messages came from a separate charge-sheet and should not be presented as messages written by Umar Khalid or as DPSG messages. Their forensic significance lies in what investigators said they recovered from the device in that particular riot case.
The distinction between different WhatsApp groups and different accused is important. A screenshot of a violent instruction can establish that a message existed on a particular device or in a particular conversation. It does not automatically establish who devised the wider plan, who acted upon the instruction or whether every member of the group agreed with it.
The DPSG conversations themselves contained dissent. OpIndia’s account of the bail proceedings says that when violence erupted, lawyer Anas Tanvir wrote in the group that he was disturbed by developments, believed what was happening appeared to be a concerted plan and wanted those responsible for instigating violence to be identified. He called for de-escalation. Owais Sultan Khan also questioned why messages concerning chakka jam had disappeared from the group.
Those objections became part of the chronology constructed by the prosecution. The Delhi High Court recorded the allegation that on 24th February, some DPSG members threatened to expose the people they considered responsible for the violence. According to the prosecution, a flurry of telephone calls then took place between Umar Khalid and other accused around 5 pm.
The digital trail did not end when the violence subsided. It continued into what investigators alleged were attempts to remove the record.
The Delhi High Court’s September 2025 judgment records the prosecution case that Owais Sultan Khan repeatedly posted messages showing reluctance to be associated with the violence before leaving DPSG. The prosecution further alleged that members were subsequently asked to delete DPSG chats from their phones and that some accused and other members were removed from the group before or after arrests.
OpIndia later reported more granular details from the material concerning the group. According to its March 2025 investigation, after details of an arrest in the conspiracy case became public on 11th March 2020, Mariya Salim posted a message asking that the group be deleted and chats cleared, with the group potentially reconvening on Signal. OpIndia reported that Rahul Roy subsequently asked members to delete their messages individually and that Athar Khan and Sachin Rao were removed from the group the following day. The article identified Sachin Rao as a Congress office-bearer but did not describe him as an accused in FIR 59 merely because he had been a member of the group.
Deletion itself creates a forensic problem rather than necessarily ending the investigation. Removing a chat from one handset does not mean every copy has disappeared. Another group member may retain the conversation. Screenshots may survive. Device databases can contain recoverable artefacts. Messages already extracted from another phone can be compared with what survives elsewhere.
The Delhi riots case also connected WhatsApp evidence with physical surveillance. The Delhi High Court recorded the prosecution allegation that, on the night of 23rd February, Athar Khan, Shadab Ahmed and others attended a meeting in Chand Bagh at which CCTV cameras were discussed. According to the prosecution, Athar Khan instructed Saleem Khan and Salim Malik alias Munna to destroy or dislocate cameras, while Shadab Ahmed agreed that his team would carry it out.
The prosecution further alleged that nearly 30 government-installed CCTV cameras spread over four to five kilometres in Chand Bagh and adjoining areas were sequentially disabled between approximately 12.05 pm and 12.45 pm on 24th February. Another CCTV camera allegedly captured Saleem Khan dislocating one of the cameras. The prosecution case was that large-scale mobilisation and violence followed after the cameras had been disabled or covered.
That allegation also sits alongside the earlier WhatsApp message attributed by the prosecution to Khalid Saifi directing people to cover police CCTV cameras with black tape. A message recovered from a digital conversation and the subsequent physical condition of cameras could therefore be examined against each other rather than treated as independent pieces of evidence.
The accused challenged precisely this method of connecting digital associations with criminal responsibility. Lawyers for Athar Khan, Shadab Ahmed and other appellants argued before the Delhi High Court that membership of a WhatsApp group or attendance at a meeting could not by itself establish participation in a criminal conspiracy. Athar Khan and Shadab Ahmed also argued that although they had been added to DPSG on 22nd January, they had not themselves posted messages demonstrating an intention to block roads or cause riots.
That argument identifies one of the central attribution problems in digital forensics. Group membership is evidence of membership. It is not automatically evidence that every member authored, endorsed or acted upon every message in the group.
Delhi riots: From group member to accused
The prosecution therefore relied on more than the presence of phone numbers inside WhatsApp groups. The court record contains allegations involving group messages, meetings, call-detail records, CCTV footage, movement between protest sites, witness accounts and activity attributed to individual accused persons. For Meeran Haider, for example, the prosecution alleged regular WhatsApp appeals for mobilisation and chakka jam and relied on telephone contacts with other accused. In other parts of the case, CCTV was used to place individuals at particular locations.
Delhi riots: How the digital trail was reconstructed
Umar Khalid presented a particularly important attribution question because his defence argued that he was not physically present at the north-east Delhi riot sites during the principal violence. The prosecution case sought instead to establish his alleged role through earlier meetings, speeches, WhatsApp groups, contacts with other accused and witness statements. OpIndia’s reporting on his bail proceedings details how prosecutors asked the court to consider these pieces cumulatively rather than look for a video showing Khalid himself participating in street violence.
The Delhi riots investigation therefore offers a useful example of what digital attribution actually involves. Investigators had the contents of messages, the identities and telephone numbers associated with groups, timestamps showing when communications occurred, CDRs showing contacts, CCTV footage showing activity at physical locations and witness accounts linking some of those digital records with meetings and events outside the phone.
They also encountered the weaknesses inherent in each category. A person could belong to a WhatsApp group without agreeing with its discussions. A message could exist without proving that every member acted on it. CCTV could establish presence without revealing what was discussed. A phone call could establish communication without recording what was said.
The forensic question was therefore not whether WhatsApp contained something incriminating. It was whether messages recovered from devices, the structure of the groups, their chronology, call records, CCTV footage and events on the ground could be connected strongly enough to attribute particular actions to particular accused.
CCTV can look convincing and still fail the evidentiary test
CCTV becomes especially persuasive outside court because people can watch it with their own eyes. The legal questions begin before the video is played. In Chandrabhan Sudam Sanap v State of Maharashtra, decided in January 2025, the Supreme Court examined CCTV footage relied upon in a murder prosecution. The case involved footage from Lokmanya Tilak Terminus that the prosecution used for its claim that the accused had been last seen with the victim.
The Court examined the manner in which the footage had been retrieved, the questions surrounding the recording and the absence of the certificate required under Section 65B of the Indian Evidence Act, which governed the proceedings. It declined to rely upon the footage for the asserted last-seen circumstance.
The acquittal involved wider weaknesses in the prosecution’s circumstantial case, so the judgment cannot be reduced to a proposition that one missing electronic-evidence certificate automatically destroys a prosecution.
The CCTV issue is nevertheless instructive. A recording may exist and may appear relevant, yet the court can still have to examine its source, retrieval, integrity, timing, identification and the legal route through which it was produced.
A call record does not record the conversation
Call-detail records are frequently referred to in criminal investigations as technical evidence. The label can conceal the limitations of the record. A CDR can document events associated with a telecom connection. Subscriber records can establish whose name appears against a connection. Handset and SIM identifiers can help distinguish devices and connections. IPDRs relate to internet activity and connections.
None of these is automatically a recording of what two people said to one another. NCRB teaches CDR, IPDR and tower-dump analysis as dedicated investigative subjects. Network information can also assist with location analysis, but it should not be described as though every telecom record were a GPS coordinate proving that a person stood at an exact spot. The evidentiary value depends on what the record actually measures and how it fits with other information.
A CDR can support a CCTV timeline. A witness can establish who possessed a phone. Another device can contain the corresponding communication. A transaction can coincide with the same period. Several independent records may then support a reconstruction that none could establish alone.
What different digital records can actually prove
ISIS investigations moved the trail onto internet platforms
Indian ISIS investigations show how quickly the relevant evidence moved beyond ordinary telephone calls.
An NIA case registered in 2016 began after intelligence concerning the user of a particular mobile number. According to the agency’s case summary, the user was suspected of being in internet-based contact with a foreign ISIS handler and of conspiring to carry out terrorist activity in Delhi-NCR and during the Ardh Kumbh at Haridwar. The information was an investigative lead that developed into a criminal case, rather than proof by itself of every allegation subsequently examined.
Later cases involved social-media and messaging platforms more directly. In a 2025 Tamil Nadu ISIS radicalisation case, NIA alleged in its charge-sheet that ISIS-related videos, documents and images had been circulated through social media and that WhatsApp and Telegram groups were created for the activity under investigation.
A separate Tamil Nadu case arising from the investigation into the Coimbatore car bombing involved allegations that radical sermons were disseminated through Zoom, WhatsApp and Telegram as well as through physical classes. These remain prosecution allegations unless and until determined by the competent court.
Such cases create attribution questions that a conventional phone bill cannot answer. Investigators may need to establish who created or administered an account, which device accessed it, who participated in a group, what information was distributed and whether the digital activity corresponds with conduct outside the platform. An account bearing a person’s name does not dispose of all those questions.
Ownership of the phone is not authorship of every message
A phone can have an owner. A SIM can have a registered subscriber. An email address can have an account holder. The person responsible for a particular digital act still has to be identified. Four different questions may arise in the same investigation.
Who had the documented relationship with the device, SIM or account? Who possessed or controlled it during the relevant period? What evidence connects the specific message, login, search, upload or transaction with that person? What does that activity establish about the alleged offence?
Indian evidence law expressly recognises part of the problem. Section 90 of the Bharatiya Sakshya Adhiniyam deals with electronic messages. The provision allows a court, in specified circumstances, to presume that an electronic message forwarded through an email server corresponds with the message fed into the computer for transmission. It does not allow the court to presume the identity of the person who sent it.
A genuine message can therefore exist while authorship remains disputed. Phones can be borrowed. Computers can be shared. Accounts can remain logged in on more than one device. Credentials can be shared or compromised. Several people may have physical access to the same handset.
Those possibilities are not automatic explanations for an accused person, but neither can ownership alone be used as a substitute for attribution. Recovery circumstances, witness evidence, CCTV, transactions, activity on other devices and independently established movements can help close that gap.
Pahalgam required more than one form of identification
NIA’s June 2025 statement on the Pahalgam attack provides an unusually clear description of multi-source identification. The agency said the material under examination included eyewitness accounts from victims, video footage, technical evidence and sketches issued by Jammu and Kashmir Police. It was analysing them together while trying to establish the terrorists’ identities.
A video can provide information about appearance. A witness can describe the person seen at the location. Technical records can add another part of the timeline. Other evidence can either corroborate or weaken the identification. No forensic principle requires investigators to force one source to answer every question. The more difficult task is deciding whether independent pieces actually point to the same person and the same sequence of events.
Sometimes the evidence is sitting on somebody else’s server
A seized phone gives investigators physical possession of a device. Online evidence can be controlled by an organisation thousands of kilometres away. Email providers, cloud companies, social-media platforms, telecom companies and other services can hold information relevant to an Indian investigation. The records may include subscriber information, connection data, transactional records or stored content.
Obtaining them can be a separate investigation within the investigation. The Ministry of Home Affairs’ guidelines on mutual legal assistance state that digital information held by internet service providers can disappear quickly and call for expeditious preservation. The guidelines provide mechanisms through which Indian agencies can seek preservation while formal legal processes for obtaining the records continue.
Preserving data and obtaining it are different steps. A preservation request can prevent available information from being deleted according to ordinary retention processes. It does not automatically hand that information to the investigator.
The MHA guidelines also distinguish subscriber information, transactional information and content. The required justification becomes more demanding depending on what is sought. For foreign requests, investigators need to explain how the particular account or record is connected with the crime. Merely saying that an accused possessed an email account is not enough.
The guidelines were drafted under the previous criminal-procedure framework, but the practical problem continues under the current law: the investigator may know that relevant information exists without having immediate access to the system that holds it.
Technology companies cannot always supply what police seek
The assumption that a technology company has a complete archive of every user’s activity can send an investigation in the wrong direction. A provider may never have collected the required information. Logs may have expired under its retention policy. The user may have deleted material.
The provider may hold subscriber details but not content. Encryption may prevent it from supplying some information in readable form. The company may also be subject to another country’s legal requirements before disclosure can take place. Indian agencies have repeatedly had to work with technology companies on these problems.
In October 2018, the Union Home Secretary met representatives of Facebook, Google, Twitter, WhatsApp, YouTube and Instagram. MHA said the companies were asked to develop mechanisms for prompt sharing of information sought by law-enforcement agencies and that the platforms assured cooperation. Cooperation does not remove technical or legal disagreements.
The dispute over WhatsApp traceability made that visible in 2021. WhatsApp challenged provisions requiring identification of the first originator of certain messages. The Government defended the requirement, while WhatsApp’s objection included concerns related to end-to-end encryption and privacy.
The dispute does not mean encrypted services leave investigators with nothing. A seized handset may contain messages visible to the user. Another participant can have a copy. Subscriber information, connection data, transactions, CCTV and other records may survive independently of message content.
It also does not mean investigators possess a universal method for obtaining every encrypted conversation.
There are several questions that need to be answered in order to get information from the company. What does the particular provider retain? For how long? In which jurisdiction? Can the company access the requested information itself? What legal process governs disclosure?
The digital evidence trail in a criminal case
Digital evidence can disappear while paperwork is moving
Retention creates a race that does not exist with many physical exhibits. The MHA mutual legal assistance guidelines warn that digital evidence can disappear quickly. They provide for urgent preservation because formal international requests can take longer than the period for which a provider ordinarily retains particular information.
Investigators may therefore have to identify the relevant account and period before they possess the complete evidence required to interpret it.
During such investigations, delay can have permanent consequences. A CCTV system may overwrite footage. Connection logs may expire. An account can be removed. A service may retain one category of information for longer than another. A foreign provider can require a form of legal process that takes time to obtain. No forensic tool can recover a provider record that was never retained or that disappeared before preservation.
Technology changes faster than investigative manuals
A forensic method that works on one phone may fail on the next model. Operating-system updates change security architecture. Applications alter how they store information. Hardware manufacturers introduce new protection. A forensic tool may support one version of a device but obtain less data after a software update.
NCRB’s curriculum itself spans encryption, metadata, network analysis, mobile evidence, CCTV, logs and internet investigations, reflecting the number of technical environments investigators can encounter.
Volume can be as serious a problem as access. One investigation can involve several phones, thousands of photographs, months of CCTV, multiple cloud accounts, chats, emails and telecom records. Extracting the information creates a dataset. It does not identify the relevant evidence automatically.
Software can index and organise material. The examiner still has to understand what the artefact records, check the assumptions made by the tool and determine whether different sources really describe the same event. A failed extraction, uncertain timestamp or ambiguous result remains a limitation and has to be reported as one.
The courtroom separates integrity, admissibility and meaning
Three questions arise when electronic evidence reaches court. Has the material remained intact? Has it been introduced according to the applicable law? What does it prove? Hash values and documented handling can assist the integrity inquiry. Statutory certification and testimony can affect admissibility. Attribution, context and corroboration determine how much weight the court can place on the material.
The current framework is contained in the Bharatiya Sakshya Adhiniyam, which came into force on 1st July 2024. Section 63 deals with electronic records produced as computer output, and its certificate schedule requires information concerning the electronic record, the device and the hash value, among other particulars. Older proceedings were governed by Section 65B of the Indian Evidence Act.
In Arjun Panditrao Khotkar v Kailash Kushanrao Gorantyal, the Supreme Court reaffirmed in 2020 the certification requirement applicable to computer output under the previous law while distinguishing circumstances in which the original electronic record itself was produced before the court.
The rule concerns the legal production of electronic evidence. It does not transform a record into proof of every fact alleged by the prosecution. An authentic CDR may leave unanswered who had the phone. Properly produced CCTV may be too unclear for identification. A genuine email can still leave authorship disputed. An intact document can contain false information.
Admissibility permits a court to consider evidence. The court must still decide what the evidence establishes.
Forensic software does not replace the examiner
The machinery of digital forensics can make the process look automated. NCRB’s training programme places considerable emphasis on the people operating it. Its courses cover identification and preservation of evidence, imaging, hashing, metadata analysis, CDR and IPDR examination, CCTV collection, network investigations and legal challenges.
An examiner may have to compare a mobile extraction with telecom records, reconcile different clocks, examine whether a CCTV export is complete, distinguish a deleted artefact from a surviving copy and explain why some portions of a phone could not be accessed.
The report also has to record what did not work. Failure to recover a file is a forensic result. A partial extraction is a limitation. A software-generated identification requires scrutiny. An uncertain timestamp should not become a precise time merely because precision would make the chronology neater.
Another examiner, the investigating officer and eventually the court should be able to understand what was examined, what method was used, what was found and where the conclusions stop.
From a device to a person
The VoIP records examined after 26th November 2008, the huge volume of CCTV material collected during the Delhi riots, online accounts investigated in ISIS cases, videos sought after the Pahalgam terror attack and devices seized during the Red Fort-area blast investigation belong to very different cases. The forensic questions repeat every time an investigation reaches the point when electronic evidence is to be examined.
Where did the record come from? Was it preserved? What does it actually record? Was the entire relevant dataset available? Can the activity be linked to a particular device or account? Who controlled that device or account at the relevant time? What independent evidence supports the attribution?
A phone is not a confession. A telecom record is not automatically an exact map of a person’s movement. A registered account does not prove authorship of every post. Facial recognition can produce an investigative lead without deciding criminal liability. Deletion does not guarantee destruction, but neither does forensic examination guarantee recovery. A technology company may possess useful records, yet jurisdiction, retention, encryption or law can affect what investigators ultimately obtain.
Digital evidence becomes persuasive when those gaps are closed with evidence rather than assumption. The phone may now be a crime scene, but the task remains the same as it was with physical evidence: recover what survives, preserve it properly, understand what it can prove and connect it to the person responsible in a form that can withstand challenge in court.
The remaining question is whether India has enough trained investigators, examiners, laboratories and equipment to do that routinely across the criminal justice system. That is where the forensic revolution moves next.
Anurag has over 22 years of professional experience, including more than six years in journalism. He is known for deep dive, research driven reporting on national security, terrorism cases, judiciary and governance, backed by RTIs, court records and on-ground evidence. He also writes hard hitting op-eds that challenge distorted narratives. Beyond investigations, he explores history, fiction and visual storytelling. Email: [email protected]
India’s expanding fingerprint and DNA systems now connect laboratories, national databases and family reference samples, but every match still depends on sample quality, scientific comparison and the wider evidence surrounding an investigation or identification process.
The journey from a recovered exhibit to courtroom evidence involves documentation, packing, sealing, dispatch, scientific examination and legal scrutiny, with delays often hidden between police custody, laboratory receipt, reporting and collection of the final report.
India’s expanding fingerprint and DNA systems now connect laboratories, national databases and family reference samples, but every match still depends on sample quality, scientific comparison and the wider evidence surrounding an investigation or identification process.
At ONGC’s August 2026 AGM, Chairman A.K. Singh said the company will invest about ₹1 lakh crore in cash over five years to drill 87 deepwater wells by March 2031, roughly ₹20,000 crore a year. They’ll start slow with just four wells in FY26, but plan to crank it up to 27 in the final year. Singh didn’t mince words about why they’re in such a mad dash, either: India’s crude output has been sliding downhill for eleven straight years.
The journey from a recovered exhibit to courtroom evidence involves documentation, packing, sealing, dispatch, scientific examination and legal scrutiny, with delays often hidden between police custody, laboratory receipt, reporting and collection of the final report.