Can Police Recover Deleted Files? ARS 13-3553 Forensics
Detectives seized your devices in an Arizona sexual exploitation case? Deleting a file rarely erases it. Under A.R.S. § 13-3553, each image can become its own count — and where the minor is under fifteen, those sentences run consecutively with no probation or parole. Call us before any interview.
As Seen On

Recognized By
Can Police Recover Deleted Files in an Arizona Case?
Usually, yes. Deleting a file normally erases only the pointer to it, not the underlying data, so examiners can recover deleted files from unallocated space, thumbnail caches, and backups. The harder question is not can police recover deleted files but who knowingly put them there — recovery is not attribution.
If detectives have taken your phone or computer in an Arizona sexual exploitation investigation, you are almost certainly asking one question first: is the stuff I deleted really gone? Usually it is not, and you should plan around that. But the answer people rarely hear matters more: whether a file can be recovered is not what these cases turn on. They turn on whether the state can prove that you, specifically, knowingly possessed it.
A.R.S. § 13-3553 covers a broad range of conduct involving a visual depiction of a minor engaged in exploitive exhibition or other sexual conduct, and it requires the state to prove a knowing mental state. That is the short version — our Arizona sexual exploitation defense page covers the charge in full. This article is about the other half: how digital forensics works, what an examiner’s report can and cannot establish, and where those conclusions are contestable.
In most cases, yes — and you should assume so. On ordinary phones and computers, “delete” almost never means “erase.” The operating system removes the entry that tells it where a file lives and marks that space as available for reuse. Until something else writes over that exact space, the underlying data is still physically present, and a trained examiner using standard forensic software can often locate and reassemble it.
Emptying a recycle bin, clearing a browser history, or uninstalling an app does not change that analysis the way most people expect. This is why the first advice any competent defense lawyer gives is the opposite of what panic suggests: do not touch the device. Altering it after you know about an investigation does not make evidence disappear, and it does create brand-new criminal exposure. We cover the search side of this in our guide to what happens when police search your phone in Arizona.
Where Does Deleted Data Actually Survive?
In more places than the average user has any reason to know about. These categories matter because several are created automatically by software rather than deliberately by a person — which is exactly where the defense argument starts.
- Unallocated space. The portion of a drive the system treats as free but which may still physically contain deleted file contents.
- File carving. A technique that scans raw storage for recognizable file structures and reassembles data even when the directory entry describing it is gone.
- Thumbnail caches. Operating systems and photo apps generate preview images automatically so folders load quickly, and those previews can persist after the original file is gone.
- File slack. Storage is allocated in fixed blocks. When a small file occupies a block once used by a larger one, remnants of the older data can remain.
- System restore points and shadow copies. Built-in backup features preserve older versions of data without any user action.
- Cloud-sync remnants. Sync services replicate content across devices and servers. Deleting on one device does not necessarily delete everywhere, and sync logs may outlive the files.
The same principles apply to digital evidence generally — we walk through them in a different context in our post on deleted evidence in Arizona image cases.
How Do Arizona Sexual Exploitation Investigations Begin?
Most start far from Arizona, long before anyone knocks on a door:
- Automated hash and PhotoDNA matching. Technology companies scan uploaded content against databases of known files and flag matches without a human reviewing the account.
- NCMEC CyberTipline report. The provider reports the flagged activity to the National Center for Missing & Exploited Children, which routes it to law enforcement by IP address.
- ICAC task force review. An Internet Crimes Against Children task force affiliate picks up the tip and begins building a case.
- Peer-to-peer monitoring. Investigators also run software that observes file-sharing networks and logs which addresses made particular files available.
- ISP subpoena. A subpoena converts the IP address into a subscriber name, billing address, and account history.
The defense challenge: every step in that chain identifies a connection or an account, not a human being. An IP address is assigned to a router, not a person. Households and businesses share networks, and networks can be accessed by people the subscriber never authorized. The name on the bill is simply the first place investigators look. Our overview of how Phoenix police investigate sex crimes covers what happens after that subpoena comes back.
How Does a Forensic Examination Work, and Where Can the Defense Push Back?
It runs in stages, and each stage has a documented standard that can be tested — what investigators can genuinely do, followed by where a defense team looks.
Seizure and warrant scope
Officers execute a search warrant and seize devices, storage media, and sometimes network hardware. The challenge: a warrant must describe what may be searched with particularity. Digital warrants are frequently broad enough that the search conducted exceeds what a judge actually authorized — an exam that began as a search for one thing and became an unrestricted tour of a person’s entire digital life is a suppression issue worth litigating.
Imaging with a write-blocker
Rather than examining the original, an examiner connects it through a write-blocker — hardware or software that permits reading while preventing anything from being written back — and creates a bit-for-bit forensic image. The challenge: whether a write-blocker was actually used and validated, and whether the original was powered on or browsed before imaging. Devices accessed before they were imaged raise real questions about what changed.
Hash verification
The examiner calculates a hash value — an MD5 or SHA digest — of the original and of the image. Matching values demonstrate the working copy is identical to what was seized. The challenge: that proves the copy is faithful and nothing more. A hash match to a database entry identifies a known file; it does not show who downloaded it, when, or whether any person ever viewed it.
The examiner’s report
The state’s examiner analyzes the image and issues a report identifying files, locations, and dates. The challenge: reports are summaries produced by software with settings, filters, and known limitations. The defense is entitled to look behind the summary — at the tools and versions used, the examiner’s training, what was excluded, and whether findings labeled as conclusions are actually assumptions.
Chain of custody
Every transfer of the device from seizure to lab to courtroom should be documented. The challenge: gaps, unlogged transfers, missing signatures, or a device that sat somewhere unaccounted for. Chain-of-custody failures go directly to whether the evidence a jury sees is what was actually taken from the defendant.
Why Is Attribution — Not Recovery — the Real Fight?
Because A.R.S. § 13-3553 does not criminalize the presence of data on a hard drive. It criminalizes knowingly possessing, receiving, transmitting, or exchanging a prohibited depiction, among other conduct. That mental state is an element the state must prove beyond a reasonable doubt, and a forensic report frequently does not address it at all.
Consider what a recovered file in unallocated space actually establishes: that data existed in that location at some point. It does not establish who caused it to be there, whether a human ever saw it, whether it arrived by deliberate download or automatic process, or whether the person now charged even owned the device at the time. Several ordinary realities break that chain:
- Automatic caching. Browsers, messaging apps, and media software write files to disk as a byproduct of loading a page or previewing a message. No user decision is required and no notification is given.
- Malware and remote access. Compromised machines can be used for storage or routing by someone the owner has never met. Establishing or excluding this requires examination, not assumption.
- Shared and multi-user devices. Family computers, shared logins, roommates, employees, and guests all mean “the device” and “the defendant” are not the same thing. Where multiple profiles exist, the state must tie files to one of them.
- Pre-owned hardware. Used phones and computers frequently arrive carrying a prior owner’s data in unallocated space — data the new owner has no way to see and never meaningfully possessed.
- Unreliable timestamps. Created, modified, and accessed dates are routinely rewritten by system processes, and a timeline built on them can be wrong in ways that matter enormously.
None of this is a magic escape hatch, and no lawyer can promise you an outcome. But it is the difference between a case where the state’s report goes unexamined and one where every inferential leap in it is tested.
What Are the Arizona Stakes Under A.R.S. § 13-3553?
They are as high as Arizona sentencing gets, and the single biggest variable is the age of the minor depicted.
Sentencing Exposure for Sexual Exploitation of a Minor
Statutes: A.R.S. § 13-3553 & A.R.S. § 13-705
In State v. Berger, 212 Ariz. 473 (2006), the Arizona Supreme Court affirmed a 200-year sentence — 10 years on each of 20 counts, served consecutively — holding 4-1 that it was not grossly disproportionate under the Eighth Amendment, applying Ewing v. California, and noting the 200-year term was the minimum available under Arizona law. Certiorari was denied February 26, 2007. That is why the number of counts, and the attribution evidence behind each one, matters as much as any single forensic finding.
What Does an Independent Defense Forensic Examiner Do?
Independent verification. A defense examiner does not simply read the state’s report and agree with it. Working under the constraints a court imposes on this category of evidence, an independent examiner can:
- Re-image the evidence under court-supervised conditions so the analysis begins from a verified copy rather than a summary;
- Recalculate the state’s hash values to confirm the working image genuinely matches what was seized;
- Audit methodology — which tools, versions, and settings, what was filtered out, and whether conclusions follow from the data or fill gaps with assumption;
- Test attribution by examining user profiles, login records, installed software, remote-access artifacts, and evidence of malware;
- Determine whether timestamps support the state’s timeline, and whether files were the product of automatic system processes rather than deliberate user action.
We explain how we select and work with these specialists on our page about a digital forensics expert in Phoenix.
What Should You Do in the First 72 Hours?
Do this
- Preserve everything. Leave every device exactly as it is — powered off if it is already off, untouched if it is on.
- Call a defense lawyer before any interview. Not after. Before.
- Write down, for your attorney only, who had access to each device and account, and when.
- Locate purchase records for any used device, and note any prior malware warnings or account compromises.
Do not do this
- Do not delete, reset, or alter anything. Altering devices after you know about an investigation creates separate felony exposure for evidence tampering, and it destroys the very artifacts your own expert would use to show someone or something else was responsible.
- Do not consent to a search without counsel. Declining consent is not evidence of guilt — it preserves your ability to challenge the scope of a warrant later.
- Do not talk to detectives without a lawyer present, no matter how much you want to explain.
- Do not discuss the case with family, friends, anyone online, or anyone who may be a witness.
The Experts We Bring to the Table
A digital case is won or lost on technical ground. These are the specialists we work with to test what the state’s report claims — and what it quietly assumes.
Digital Forensic Examiner
Re-Imaging And Verification
Obtains a forensic copy of the seized media, recalculates the state’s MD5 and SHA hash values, and confirms whether the image the prosecution relies on truly matches what was taken.
Computer & Network Forensics Analyst
Auditing The Examination
Reviews the tools, versions, filters, and settings behind the state’s report, then examines router logs, network activity, and remote-access artifacts the original exam may never have looked at.
Malware & Intrusion Analyst
Testing The Compromise Defense
Examines a device for remote-access tools, botnet activity, and unauthorized processes that can place or route data without the owner’s knowledge or any deliberate user action.
Metadata & Timestamp Specialist
Breaking The State’s Timeline
Analyzes created, modified, and accessed dates against system events to show where the prosecution’s chronology rests on values that software rewrote automatically.
Peer-to-Peer Network Expert
Challenging File-Sharing Logs
Explains what monitoring software on a file-sharing network actually captured, and what it did not, including whether any human ever selected, opened, or knew about a shared file.
False-Attribution & Device-Sharing Expert
Separating Device From Defendant
Maps user profiles, logins, household and workplace access, and prior ownership to test whether the state can tie a file to one specific person rather than one specific machine.
How Tamou Law Group Defends A.R.S. § 13-3553 Cases
We start before charges are filed whenever we can. In the pre-charge window — after devices are seized but before a prosecutor makes a filing decision — there is real room to work: presenting exculpatory technical context, raising attribution problems early, and making sure the charging decision is not made on an unexamined report. Once a case is filed, we push hard on disclosure: the full forensic image, the examiner’s notes and bench records, tool names and versions, chain-of-custody documentation, the underlying CyberTipline and ICAC materials, and the ISP subpoena returns — not just the summary the state prefers to hand over. Because the statute requires the court to seal this evidence at the conclusion of proceedings, we address the terms of expert access early rather than losing weeks to it later.
We also give clients an unvarnished plea-collateral analysis before any decision — sex-offender registration exposure, the consecutive-sentencing rules under A.R.S. § 13-705, the difference between a count involving a minor under fifteen and one involving a 15-to-17-year-old, and what a given count structure realistically means over a lifetime. Our team includes former prosecutors, law enforcement officers, and public defenders, working from our offices at 9375 E Shea Blvd in Scottsdale and 2390 E Camelback Rd in Phoenix. Call 623-321-4699 for a confidential consultation.
Awards & Recognition
Our recognition for Phoenix sex crime defense is independently verified, click any award to confirm it:
- National Trial Lawyers Top 100
- National Trial Lawyers Top 40 Under 40
- Elite Lawyer 2026 – Criminal Defense
- Super Lawyers – Southwest
- National College for DUI Defense (NCDD)
When you are looking for the best Phoenix sex crime lawyers, these are the independently verified credentials that matter, earned by Founding Attorney Michael Tamou and a full team of attorneys, including former prosecutors, public defenders, and law enforcement.
What Clients Say About Tamou Law
Real Google reviews from clients we have defended across Phoenix and Maricopa County. Every review is from a criminal defense client, never padded with non-legal work.
Frequently Asked Questions
Can police recover deleted files from a phone or computer?
Usually, yes. On most devices, deleting a file marks its space as reusable rather than erasing the underlying data, so a forensic examiner can often recover it until that space is overwritten. Copies also survive in caches, backups, and cloud-synced folders that a user never sees or manages.
Does recovering a deleted file prove I knowingly possessed it?
No. Recovery shows a file existed on a device. It does not show who put it there, whether anyone opened it, or whether the user knew it existed. A.R.S. 13-3553 requires the state to prove a knowing mental state, and that is a separate question from data recovery.
What is a hash value, and what does a hash match actually prove?
A hash is a digital fingerprint calculated from a file’s contents. A match tells you the file on a device is identical to a file already in a known database. It identifies the file. It says nothing about who downloaded it, when, or whether any person ever viewed it.
How do Arizona sexual exploitation investigations usually start?
Most begin outside Arizona. A provider files a CyberTipline report with NCMEC after automated hash or PhotoDNA matching, the tip is routed to an ICAC task force, and investigators subpoena an internet service provider to link an IP address to a subscriber account and a physical address.
Can malware or another person put files on a device I own?
Yes, and it happens. Shared computers, family accounts, roommates, guest Wi-Fi, remote-access malware, browser software that caches images automatically, and pre-owned hardware that was never wiped by its prior owner all create realistic paths for data to reach a device without the current user knowing.
Should I let detectives search my phone if I have nothing to hide?
Talk to a lawyer before consenting to anything. Consent waives search protections you may never get back, and a broad consent can hand over years of unrelated data. Declining to consent is not evidence of guilt. It preserves your ability to challenge the scope of any later search warrant.
Can I delete files or reset my device after police contact me?
No. Preserve everything exactly as it is. Deleting, resetting, or altering a device after you know about an investigation can create separate felony exposure for evidence tampering, and it destroys the very metadata your own expert would use to show that someone or something else put the files there.
What is the penalty for sexual exploitation of a minor in Arizona?
Sexual exploitation of a minor under A.R.S. 13-3553 is a class 2 felony. If the minor is under fifteen, it is punished under A.R.S. 13-705 as a dangerous crime against children, carrying a first-offense range of 10 years minimum, 17 years presumptive, and 24 years maximum.
Can my defense team hire its own forensic examiner?
Yes, and in a contested digital case it is often essential. An independent examiner can obtain a forensic copy, verify the state’s hash values, review the examiner’s methodology and tool settings, and test attribution questions the state’s report may never have asked, such as who else used the device.
What happens if the state’s forensic image does not verify?
It becomes a serious evidentiary problem for the prosecution. Hash verification exists to prove the working copy is identical to the seized original. If the values do not match, or the verification steps were never documented, the defense can challenge the integrity and admissibility of everything drawn from that image.
Two Arizona Offices, One Team
We serve all of Maricopa County and the surrounding area, with free, confidential consultations 24/7 by phone and in-person meetings at either office by appointment.
Case Results Disclaimer: The results described on this page are based on specific facts and circumstances and do not guarantee or predict a similar outcome in any future case. Every case is different. Past results do not guarantee future results. No attorney-client relationship is formed by viewing this page or submitting a contact form until a written fee agreement has been signed. Tamou Law Group, PLLC is licensed to practice law in the State of Arizona. This website is for informational purposes only and does not constitute legal advice.
(function() {
function customizeConsultForm() {
var form = document.querySelector('#consult-form');
if (!form) return false;
var fields = form.querySelectorAll('.gfield');
var emailField = null;
var didWork = false;
fields.forEach(function(field) {
var label = field.querySelector('.gfield_label, label');
if (!label) return;
var labelText = (label.textContent || '').trim().toLowerCase();
if (labelText.indexOf('best way to reply') !== -1 || labelText.indexOf('preferred contact') !== -1) {
field.classList.add('tlg-hide-field');
field.querySelectorAll('input').forEach(function(input) {
input.checked = false;
input.removeAttribute('required');
});
didWork = true;
}
if (labelText.indexOf('email') !== -1) {
emailField = field;
field.classList.add('tlg-email-required');
field.querySelectorAll('input[type="email"], input[type="text"]').forEach(function(input) {
input.setAttribute('required', 'required');
input.setAttribute('aria-required', 'true');
});
didWork = true;
}
});
var gform = form.tagName === 'FORM' ? form : (form.querySelector('form') || form.closest('form'));
if (!gform) gform = document.querySelector('#consult-form form, form[id^="gform_"]');
if (gform && !gform.dataset.tlgSourceBound) {
gform.dataset.tlgSourceBound = '1';
var pageUrl = window.location.href;
var pageTitle = document.title || 'Phoenix White Collar Defense Lawyers';
var pagePath = window.location.pathname;
var sourceTag = '[Source: ' + pageTitle.replace(/\s*[,|].*$/, '') + ' | ' + pagePath + ']';
['source_page', 'page_url', 'lander_url'].forEach(function(name) {
var h = document.createElement('input');
h.type = 'hidden';
h.name = name;
h.value = pageUrl;
gform.appendChild(h);
});
var hp = document.createElement('input');
hp.type = 'hidden';
hp.name = 'source_path';
hp.value = pagePath;
gform.appendChild(hp);
function findMessageField() {
var match = null;
form.querySelectorAll('.gfield').forEach(function(field) {
var label = field.querySelector('.gfield_label, label');
if (!label) return;
var t = (label.textContent || '').trim().toLowerCase();
if (t.indexOf('message') !== -1 || t.indexOf('comment') !== -1 || t.indexOf('detail') !== -1 || t.indexOf('describe') !== -1 || t.indexOf('tell us') !== -1 || t.indexOf('your story') !== -1) {
match = field.querySelector('textarea, input[type="text"]');
}
});
if (!match) match = form.querySelector('textarea');
return match;
}
function prependSource() {
var textarea = findMessageField();
if (textarea && textarea.value.indexOf('[Source:') === -1) {
textarea.value = sourceTag + '\n\n' + (textarea.value || '');
}
}
gform.addEventListener('submit', prependSource, true);
var submitBtns = gform.querySelectorAll('input[type="submit"], button[type="submit"], .gform_button');
submitBtns.forEach(function(btn) {
btn.addEventListener('click', function() {
setTimeout(prependSource, 0);
prependSource();
}, true);
});
}
var submitBtn = form.querySelector('input[type="submit"], button[type="submit"]');
if (submitBtn && emailField && !submitBtn.dataset.tlgBound) {
submitBtn.dataset.tlgBound = '1';
submitBtn.addEventListener('click', function(e) {
var emailInput = emailField.querySelector('input[type="email"], input[type="text"]');
if (emailInput && !emailInput.value.trim()) {
e.preventDefault();
emailInput.focus();
emailInput.style.borderColor = '#c62828';
emailInput.style.boxShadow = '0 0 0 3px rgba(198,40,40,.15)';
}
});
}
return didWork;
}
if (document.readyState === 'loading') {
document.addEventListener('DOMContentLoaded', customizeConsultForm);
} else {
customizeConsultForm();
}
var attempts = 0;
var interval = setInterval(function() {
attempts++;
var done = customizeConsultForm();
if (done || attempts > 10) clearInterval(interval);
}, 500);
})();






