In July 2025, the Seventh Circuit affirmed the dismissal of a whistleblower case and left more than $149,000 in sanctions standing. Most of that money came out of the lawyer's pocket, not the client's. Part of what he was sanctioned for was telling the court, more than once, that he had ordered and produced a complete forensic image of his client's phone. He had not.

The case is Pable v. Chicago Transit Authority, No. 24-2572 (7th Cir. July 28, 2025). There is a lot in it, including intentional deletion of Signal messages by the client. But the word worth stopping on is the one the lawyer used about the extraction: complete.

That word gets used loosely, and it gets used by people who believe it. Usually the belief rests on something real. The hash matched. The verification passed. The report says the acquisition completed successfully. All of that can be true at the same time as the extraction being badly incomplete, and nothing in the report will tell you so.

What a hash actually proves

A hash value is a fingerprint of a specific sequence of bytes. Run the algorithm over the source, run it over the copy, compare the two values. If they match, the copy is byte-for-byte what the source was when you read it.

That is a genuinely strong guarantee, and it is worth saying so plainly, because the point here is not that hashing is weak. NIST's own review of the field notes that hash algorithms used to determine whether two files are identical "have an inherent false positive rate, but the rate is so small as to be essentially zero." When someone tells you the hashes matched, believe them.

Then notice what the sentence covers. A matching hash accounts for the bytes that were collected, and says nothing about whether anything else should have been.

Anyone who has worked a scene understands the distinction without needing the math. Sealing an evidence bag proves nobody opened it between the scene and the lab. It proves nothing at all about whether you picked up everything that was on the floor. Two different questions, two different answers, and only one of them is answered by the seal.

NIST lists incompleteness first

The standards body starts in the same place.

NIST IR 8354, the scientific foundation review of digital investigation techniques, sets out the primary types of error found in forensic tool implementations. The first one on the list is incompleteness, defined this way: "All relevant information has not been acquired or found by the tool. For example, an acquisition might be incomplete, or a search does not identify all existing relevant artifacts."

Inaccuracy comes second. Incompleteness comes first, and it is the failure mode that leaves no fingerprint. An inaccurate result can be contradicted by other evidence. A missing result just looks like absence.

Extraction is a set of choices

Here is why completeness is never automatic.

An extraction has a level. A logical extraction, a file system extraction, and a physical image reach different depths and return different amounts of data from the same handset. On current mobile operating systems, the deepest of those is often unavailable, which means the older physical-versus-logical framing in a lot of training material no longer describes what actually happened.

An extraction also has a scope. Somebody decided which data types to pull and which date range to cover. Somebody decided whether to include the cloud account or only the device in hand. Those decisions may have been sensible, proportionate, and made for good reasons. They were still decisions, and they were made by a person, before the tool ever ran.

Scope is exactly where Pable came apart. The vendor's instructions were limited to certain search terms and date ranges rather than a full image, and the production that resulted was about 0.2 GB. When a second image was later ordered without those limits, it returned roughly 25 GB. No hash failed and no tool malfunctioned. The first extraction was a faithful, verifiable copy of the narrow slice somebody had asked for.

And an extraction has gaps the tool itself created. When a parser does not support the version of an application installed on that phone, the application is present and its contents are not. The report is not lying. It is reporting what it could read.

Every one of those produces output that is internally consistent, hash verified, and short of the whole picture. The verification step cannot catch any of them, because verification was never pointed at that question.

The rule that moved

Since December 1, 2023, Rule 702 has required the proponent of expert testimony to demonstrate, more likely than not, four things. The fourth one is the one that matters here: "the expert's opinion reflects a reliable application of the principles and methods to the facts of the case."

Read that against the two questions. Hashing is a reliable principle and method, which lives in subsection (c). Whether this particular acquisition, scoped this particular way, on this particular device, supports the opinion being offered is subsection (d), and it is now an independent admissibility requirement carrying a preponderance burden rather than something to be argued to the jury as a matter of weight.

So when the answer to "how do we know this extraction is sound" is "the hashes matched," that answers (c) and leaves (d) untouched.

Do not ask for an error rate

Attorneys are often coached to ask a forensic examiner for the error rate of the technique. In digital forensics that question tends to produce either a bad answer or a blank look, and NIST explains why.

Key Takeaway #4.4 of IR 8354: "Digital processes tend to have systematic errors rather than random errors. Therefore, an error mitigation analysis provides more information and is the correct way to manage uncertainty. An error rate is only useful where there are random errors."

Commercial extraction tools do not publish error rates, and a demand for one is answerable with a shrug. Error mitigation is answerable, and the answer is diagnostic. What could have been missed on this device, and what did you do to find out?

The questions that get you there

If you are reading a report you did not make, these are the ones worth asking, in writing, early:

None of those are hostile questions. An examiner who scoped an extraction well will answer them easily and the answers will strengthen the report. An examiner who cannot answer them has told you where the report ends.

For the examiners reading this, the same list is a documentation standard. When I teach acquisition overseas through the State Department's ATA program, the module that reliably runs long is not the imaging step. It is the scoping conversation that happens before anyone touches the device, because that is the part a competent opponent will later ask about, and it is the part that is hardest to reconstruct after the fact. Write down what you decided not to collect and why, at the time you decide it.

A hash tells you the copy is honest. It does not tell you the copy is whole.

Take it further

Acquisition scoping, verification records, and the reporting that survives a Rule 702(d) challenge are what our online curriculum is built to teach, which is why every course ends in reporting and testimony rather than in a features tour.

That curriculum is available as a single enrollment. All-Access is all four online courses together: Computer Forensics Fundamentals, Mobile Device Forensics Fundamentals, Drone Forensics for Law Enforcement, and the Certified OSINT Investigator, Court-Ready Practitioner program. Four separately verifiable certificates, 86 CPE hours, and every template library we teach from, including the intake, chain of custody, and examination worksheets. Self-paced and online, twelve months of access per course.

All four are listed in the CISA National Initiative for Cybersecurity Careers and Studies (NICCS) Education and Training Catalog. A listing is not an endorsement, but it is often what an agency training officer needs to see before a course clears an approval process.

Purchased separately, the four courses total $4,488 through September 30, 2026, and $4,888 beginning October 1. All-Access is $2,997, and it stays $2,997 after the October 1 increase. Government purchase orders, net-30 invoicing, and agency licensing are available. If you already bought one of the four, your tuition credits in full toward the bundle for 90 days: email info@thewaldrepcompany.com from your enrollment address and we will send an upgrade link for the difference.

Details and enrollment: thewaldrepcompany.com/courses/all-access/

If this issue was useful, subscribe to Digital Forensics Today below and send it to the attorney who just received an extraction report, or to the examiner who is about to write one. Every issue is about doing OSINT and digital forensics that stands up when someone asks how you know.

Digital Forensics Mobile Device Forensics Digital Evidence Expert Witness Rule 702 eDiscovery

Sources and further reading

Eric L. Waldrep is a court-qualified digital forensic examiner and Magnet Certified Forensics Examiner with 19+ years in digital forensics, 27 years in law enforcement, and federal and state court casework. He has served as a U.S. Department of State Antiterrorism Assistance cyber mentor; that is professional background only and implies no endorsement of this newsletter or any product mentioned in it. Nothing here is legal advice, and nothing here reflects the position of any government or agency. Case patterns are generalized and no client matter is described.