Read the relevant page, build a recovery brief, call an engineer, or send the case securely, without opening a second popup.
Problem, device and brand cards are normal page links. The assessment button builds a saved recovery brief.
Choose the closest description. If you arrived from a problem card, this step is already complete.
Brand, model family, exact model and capacity improve the handoff to the correct engineer.
Tick everything that applies. “Other” fields are available where the usual choices do not fit.
This is an intake guide, not a remote diagnosis or guarantee. The laboratory confirms the method, quote and limitations after assessment.
Read the recovery method, limitations and intake process for this device or issue.
Read the relevant pageBest for uncertainty, dangerous batteries, active incidents, legal deadlines and Emergency 24/7.
Call 1300 806 557Keep the menu open and load Wildfire’s secure submission form in this same full-screen panel.
Save the structured summary for a call, email, internal approval or later submission.
Real laboratory. Evidence handled properly.
The evidence may be on the device.
Let’s preserve it before anything changes.
Deleted messages. Copied company files. Tracking and spyware. Tell our Brisbane digital forensics laboratory what happened and what you need to prove or rule out. We preserve available data, acquire it using a method suited to the device, verify the resulting copies and answer the questions agreed in writing, including what the data cannot show.
ON THE WILDFIRE BENCH

The 20-second answer
Digital forensics is the preservation, acquisition and examination of data from electronic devices in a way another examiner could repeat and check. In practice, we minimise and document changes to the source, verify acquired copies and trace findings to their source records. A phone extraction may contain only some available data; the report explains what the method captured and what it did not. It answers questions such as what was deleted, what was copied, which account was used and when, and it reports the limits as plainly as the findings.
Start with the question
Select a matter for the specialist guide. We provide digital forensics Australia-wide from one Brisbane laboratory, and the scope we agree in writing is what we actually examine.
Damaged or unreadable devices that still need documented evidence handling.
Open the specialist guide → ↗File activity, USB history and deleted documents on PCs and Macs.
Open the specialist guide → ↗Messages, photos and app data from iPhone and Android.
Open the specialist guide → ↗Tracking, spyware and account intrusion, with the limits stated.
Open the specialist guide → ↗BitLocker, FileVault and VeraCrypt: assess available keys and lawful access options.
Open the specialist guide → ↗Surviving deleted or inaccessible recorder footage, subject to overwrite limits.
Open the specialist guide → ↗Servers, NAS and RAID storage that hold the evidence.
Open the specialist guide → ↗Deleted chats, media and backups on iPhone and Android.
Read the guide →About to reset, update, repair or hand the device to IT? Stop. Leave it as it is, write down who has held it, and call us before anything changes.
Evidence router
Choose what holds the evidence and what you need to find out. The router points you to the right specialist page, tells you what that kind of device can usually show and what limits it, and gives you the one thing to do right now.
The router needs JavaScript. Every route it can suggest is listed in Find your matter above, or call us on 1300 806 557.
Choose an answer to both questions to see where to start.
Fees
Our digital forensics services are charged in stages. Each stage is a fixed fee quoted in writing before it starts, and you pay for a stage before it begins. You always know the price of the next step before you decide whether to take it.
A fixed fee per device, quoted before collection. Covers sealed intake, the chain of custody record, acquisition, hash verification and a short note on what the image contains.
A fixed fee for each question in your scope, quoted once Stage 1 shows what the extraction holds. You choose which questions go ahead.
More devices or questions, a conference with your lawyer, a supplementary report or secure deletion of data. Each is quoted separately before it starts.
Your next step
Your choices in the evidence router carry into this enquiry. A short, general outline is enough; we agree a secure intake method before you send evidence.
Who instructs us
The method is the same for everyone: authority first, then a written scope, a sealed chain of custody and a report that can be checked. What changes is the question, and what you need to give us at the start.
We take written instructions from solicitors, agree the questions and the devices in scope, and keep a chain of custody record from collection to return. Reports are examiner-signed, separate located data from recovered data, and set out the method and its limitations. An examiner CV is available on request.
Whether evidence is admitted is a matter for the court. We control the quality of the work, and we do not promise outcomes.
When someone leaves with company files, the questions are simple to ask and careful to answer: what was taken, when, and where it went. We examine the work computer and any USB or external drive together, because each holds half of the evidence. Computer forensics can show when a drive was connected and which files were opened; the drive itself can show when files arrived on it.
Where a matter calls for it, company data can be removed from returned devices under a signed authority once the examination is complete, quoted as a separate stage.
Tracking, spyware, harassing messages or a dispute over what was said. In a free first call we explain what your kind of device can and cannot usually show, before you pay for any stage. Start with domestic violence digital forensics.
Access to a late family member's computer or phone needs authority, such as a grant of probate or letters of administration. Bring it to the first conversation and we will tell you what is possible on that device.
Company-owned devices, workplace investigations and misconduct allegations. We work to the questions in your scope, and we report anything outside it only when you instruct us to look.
★ 4.8 from 95 Google reviews
★★★★★“Wildfire Data Recovery were fantastic to deal with from start to finish. Extremely responsive to any customer requests and we able to perform data recovery and phone repair where Samsung official repairer advised they would not likely be able to preserve the data. Very satisfied with Viktor and his team. Highly recommend 👌”
★★★★★“Viktor is an absolute legend! I hit the worst-case scenario with BitLocker locking me out completely a problem that could’ve cost thousands. Viktor stepped in and had it fixed in mere minutes. He didn’t just fix it; he guided me step‑by‑step exactly what to do. Thanks to his clear, expert directions, everything was sorted quickly and stress‑free. Massive thanks to Viktor.”
★★★★★“Excellent Data Recovery and re set up. Viktor goes above and beyond to explain everything regardless of how long it takes. After disasters through the years gone by with other so-called experts, it was stessfree and a relief to discover Wildfire. Excellent pricing and communication. ☆☆☆☆☆ Highly recommend 👌”
Forensic data recovery
A phone that will not turn on or a drive that clicks cannot be examined until it can be read. Forensic data recovery is the repair-to-read work that comes first, done under the same rules as the examination: photographed, logged and explained in the report, so the findings that follow can still be checked.

The device is opened on the bench and its condition is recorded before anything is changed: corrosion, impact damage, swollen batteries and earlier repairs.

Liquid leaves corrosion that keeps spreading. Cleaning is selected for the affected components after assessment; compatible circuit boards may undergo ultrasonic cleaning. The method and any resulting changes are recorded.

A failed component on the logic board is replaced at the bench so the phone can start long enough to be extracted. A repair or boot can change device state. Each intervention is logged, and its possible effect on the evidence is considered in the report.
Then the same forensic process as any working device: acquisition, hash verification and examination to scope. See the chain of custody for what is recorded at each stop.
Repair does not always succeed, and some damage cannot be reversed, such as a crushed memory chip or a phone that was reset before it broke. For phones, assessment often cannot confirm what data survives until the phone is running and extracted. We tell you what we found at each step, before the next fee.
Live demo
A SHA-256 hash is a 64-character fingerprint calculated from the bytes being checked. Matching hashes provide strong evidence that two copies of those bytes match. They do not prove that an extraction captured the entire device, that the source was authentic before collection, or who created it. Acquisition notes and examination remain essential.
a64d5c55c2ef3c122a1110a3cfb3f6c964697348e281534f53c1868a76ef7afa
The same text, one character different
80a17797d8e1f873822452dae894b9ada792f962b5f7ef7aa1c4d10ea3252116
62 of 64 hash characters changed after one character of text changed.
Choose a file to see its SHA-256 hash. The file stays on your device: the hash is calculated in your browser.
Chain of custody
Chain of custody is the written history of who held a device, when, and what was done to it. It is what lets a lawyer, a court or another examiner check our work. Step through the seven stops and what we record at each one.
Before anything is collected, we confirm who is instructing us and their authority over the device, the devices in scope, the questions to be answered, how the results will be used and any deadline. The scope is agreed in writing, and it is the only thing we examine.
Devices travel sealed in a tamper-evident bag, by tracked Australia Post Express from anywhere in Australia or by direct collection in the Brisbane area. We send sealing instructions first, so the seal number can be checked at both ends.
The seal is checked before it is opened. The device is photographed, its identifiers recorded and its condition noted, including damage, power state and anything attached. If a passcode is supplied, the record notes only that it was supplied in writing and when, never the passcode itself.
The device is imaged or extracted with a method suited to it: write-blocked imaging for computer and drive storage, and a supported extraction for phones and tablets. A damaged device first goes through repair-to-read work, and every step that touches it is logged.
Hash values are calculated for the acquired data and checked against the copy. Examination uses verified working copies where practicable. Any necessary live-device access, incomplete acquisition or repair is documented so another examiner can understand its limits.
Only the agreed questions are examined. Each finding is labelled located (live data the user already had) or recovered (deleted data restored), and traced to where it sits on the device, so nobody has to take our word for it.
An examiner-signed report sets out the method, the findings question by question, what was not found and the limitations. The device is returned sealed. How long the forensic image is kept is agreed in writing, and it is destroyed on instruction with a certificate of destruction.
Choose the right service
Both start with the same device. They answer different questions, follow different rules and are charged differently. Pick the one that matches what the data is for.
| Data recovery | Digital forensics | |
|---|---|---|
| The question | Can I have my files back? | What does the data show, and can someone else check it? |
| Who instructs us | The owner of the device | The instructing party with established lawful authority for the agreed devices, accounts and scope |
| Handling | Careful laboratory records, focused on getting your files back | Chain of custody from collection to return, with sealed transit |
| The copy | Recovered files delivered on new media | Verified acquired material, with acquisition limits recorded, plus the items exported for the questions |
| Deleted and live data | Returned together as your files | Every item labelled located or recovered |
| What you receive | Your files and a file list to check | An examiner-signed report with method, findings and limitations |
| How it is charged | Fees depend on the recovery level. Hard-drive Levels 1–2 have no upfront recovery fee; Levels 3–5 include agreed upfront fees. See the written quote and policy. | A fixed fee for each stage, paid before the stage starts, because it pays for the forensic work whatever the data shows |
Need your files back and nobody needs a report? Start a data recovery under our No Data, No Fee policy. Broken device and evidence rules? That is forensic data recovery, the overlap of the two.
Honest limits
Overclaimed evidence helps the other side. These are the lines we hold in every report, and the lines any reliable examiner in Australia should hold too.
Choosing an examiner
Six questions to ask any forensic examiner before you hand over a device, including us. A good examiner answers all six without hesitating.
Executive Data Engineer/Owner, Wildfire Data Recovery
Viktor wrote this page and reviews it against the source standards listed here. He holds the IACIS Certified Forensic Computer Examiner (CFCE) credential, is trained on Cellebrite UFED, and holds further credentials with ACE Lab, ADISA and IACRB. Bench work at Wildfire began in Brisbane in 2016, and we have served more than 15,000 clients since. Read more about Wildfire.
Clear answers before you decide
Courts, costs, locked phones and deleted data. Search the answers, or open the group that fits.
An examiner preserves the device, makes a verified copy, examines only the questions agreed in writing, and reports what the data shows with the method and the limits stated. Most of the work is careful recording: every finding has to be traceable to where it sits on the device, so a second examiner can check it.
No. Cybersecurity prevents and responds to attacks while they are happening. Digital forensics looks back at what a device holds and what happened on it. If a network is under active attack or ransomware is still spreading, contain it with an incident response provider first. Forensic preservation comes next.
A forensic disk image copies the readable sectors acquired from storage; a mobile extraction may instead capture a supported subset of files or records. Hashes verify the acquired material and its copies, not completeness. The report records unreadable areas, acquisition limits and any changes to the source. You can see how the hash check works in the hash demo on this page.
Computer forensics is digital forensics applied to Windows PCs, Macs, laptops and their drives. It covers file activity, USB connection history, user accounts, browser history and deleted documents. Our computer forensics page explains the questions it can answer.
Mobile phone forensics is the extraction and examination of data from iPhones, Android phones and tablets: messages, photos, call logs, locations and app data. How much can be extracted depends on the model, the software version and whether the passcode is known. See mobile phone forensics.
Forensic data recovery combines documented repair-to-read or reconstruction work with evidence preservation when a device is damaged or data is inaccessible. It cannot restore overwritten content or encryption keys destroyed by a completed secure erase. See forensic data recovery.
Look for a named examiner with a recognised certification, a written scope, hash-verified copies, reports that separate located from recovered data, fixed fees per stage, and someone willing to tell you what cannot be done. Our six checks set out the questions to ask any digital forensics expert, including us.
We establish the instructing party’s lawful authority and agree the devices, accounts and questions in writing. Possession or ownership of a device does not automatically authorise access to every account or another person’s information. Where authority is disputed or unclear, obtain appropriate legal advice before examination.
Courts decide what evidence is admitted, under the Evidence Act 1995 (Cth), the Evidence Act 1977 (Qld) and the equivalent laws of each state. What we control is the work: a chain of custody record, hash-verified images, an examiner-signed report that sets out method and limitations, and an examiner CV on request. Tell us the intended use at the start, so the scope and the report suit it. We do not promise outcomes.
Yes. Our laboratory is in Brisbane and we take matters from across Australia. Devices travel sealed by tracked Australia Post Express, or we collect in the Brisbane area. Instructions, scope meetings and report walk-throughs can be done by phone or video.
It depends on the number of devices, their condition and the number of questions. We give an expected timeframe with each stage quote, and we tell you straight away if a deadline is at risk, so you can decide what to prioritise.
Each stage is a fixed fee quoted in writing before it starts: forensic access and imaging per device first, then examination and report for each question you choose to go ahead with. The fee depends on the device, its condition and the scope. How our forensic fees work explains the stages.
Sometimes. It depends on the model, the software version, the security patch level and the lawful options available. We do not promise access before assessment. If you know the passcode, give it to us through the secure method we agree at intake, never in an ordinary email or text.
No. Results depend on the storage technology, encryption, how much the device was used afterwards and its physical condition. Deleted data that has been overwritten, or that sat on a phone that was later factory reset, cannot be recovered by anyone. Nobody can know what survived until the device is imaged and examined.
Not from the phone itself. A reset on a modern iPhone or encrypted Android phone destroys the keys, so the old data cannot be read. Copies may still exist in a backup, on another device or in an account. Our guide to deleted messages after a factory reset explains where to look.
Only for as long as agreed in writing at intake. Forensic images and working copies stay in our custody in Brisbane, and are destroyed when you instruct us, with a certificate of destruction on request. We handle personal information under the Australian Privacy Principles.
Glossary
The words you will see in our reports, and in most forensic reports in Australia.
Everything else we do
If you only need your files back and nobody needs a report, ordinary data recovery is faster and starts with a free standard diagnostic. The same Brisbane laboratory handles every device below.
Inside the laboratory
Three published data-recovery cases from our bench, showing acquisition, reconstruction and validation work. These are not forensic litigation cases or proof of admissibility; each case explains the work, the result and its limits.
A 64 GB SanDisk card showed an empty folder after a format and earlier recovery-software attempts. Reads stalled near the 30 GB mark, so we paused and reassessed, then took a full image before rebuilding any footage.
27 complete videos from the latest session, each with its 4K file and preview, plus 28 photos. We also explained why some dates were misleading, and why 44 videos could not all be tied to the requested day.
It fell while it was running. By the time it reached us it clicked on power-up and Windows could not see it. We fitted compatible donor heads, kept the original electronics, and imaged the healthy platter regions first.
The three project folders the client nominated came back, opened, and were verified against their list.
Past outcomes do not set the price or guarantee the result of a new matter. Assessment and your written quote govern the work. More case files are on our blog.
Before you do anything else
Preserve the current state before making changes. A reset, an update, a well-meant IT reimage or a repair shop can destroy what you need. Call or email first, and we will tell you how to preserve the device and send it to us sealed.
Only need your files back? Start a data recovery instead.