IT Forensics · Private Individuals

How can I find out whether a chat history has been compiled or shortened retrospectively?

Selected messages may give a different impression to the full conversation history.

Enquire without obligation

Why this question is important for private individuals

Chats, photos, videos and screenshots can carry considerable weight in private, civil or criminal disputes. However, the fact that they are visible does not automatically answer questions regarding their origin, whether they have been altered, when they were created or who created them.

Technical investigative approach

We compare the exports or screenshots provided with the available original data, message sequences, IDs, time stamps and related correspondence.

Where the limits of what can be said lie

Missing messages may also result from deletion, retention or differences in synchronisation status, and do not automatically prove deliberate manipulation.

Why LanCologne?

To the untrained eye, digital evidence often appears more conclusive than it actually is from a technical point of view. A screenshot may look genuine yet still have been altered. Conversely, missing metadata or recompression may have entirely normal causes. A file may be present on a smartphone without having been created there.

LanCologne therefore breaks down the seemingly simple question „Is this genuine?“ into technically verifiable sub-questions: Is the original file available? From which application or data source does it originate? Are the internal structures and metadata consistent? Are there corresponding entries in databases, backups, cloud or system artefacts? Has the file been exported, converted or edited? Which of these processes can actually be verified?

It is particularly important to distinguish between authenticity and authorship. Even if a message was technically present in a particular account, this does not automatically prove which natural person entered it. Similarly, a camera model in EXIF data does not, without further verification, prove which specific physical device created a file.

We prefer primary data to mere representations. Original messages, databases and original files usually contain more technical context than screenshots, printouts or subsequent exports.

The outcome remains open. We document supporting, contradictory and inconclusive findings equally, and explain clearly the actual scope of any technical conclusion.

How we work

1Define the specific issue to be proved: content, origin, date, alteration or authorship.
2Obtain the original device or original file, where legally available.
3Create working copies and document the integrity of suitable data sets.
4Make a clear distinction between screenshots, exports and raw data.
5Examine file structures, metadata and application-specific artefacts.
6Interpret timestamps according to their respective technical significance.
7Check the relevant databases, backups, cloud data and system logs.
8Distinguish between normal conversion and platform processing on the one hand, and targeted manipulation on the other.
9Never allow automatic tampering or AI detectors to make decisions on their own.
10Do not equate authenticity with provenance, ownership and authorship.
11Document counter-hypotheses and gaps in the data.
12Present the results in a way that is clear and reproducible for technical verification.

Authenticity is not the same as authorship

Technically speaking, a message may be authentically stored in an account or on a device without this alone providing conclusive evidence as to which natural person authored it. This distinction prevents a correct technical finding from being conflated with an unsubstantiated claim regarding a person’s identity.

Original data is more important than the mere on-screen display

A screenshot can be valuable, particularly if content disappears later on. However, for a more in-depth investigation, we also try to obtain original files, app data, databases or other primary sources. These often contain context that is missing from the visible display.

Why use the LanCologne approach when examining digital evidence?

LanCologne does not treat digital content as true or false simply because it appears plausible. We examine the available technical evidence, document its origin and limitations, and present our findings in such a way that they are understandable to private clients whilst remaining verifiable by lawyers, investigating authorities, the courts or other qualified IT forensic experts.

Legal framework

In the case of tampered digital evidence, Section 269 of the German Criminal Code (StGB) may be relevant, depending on the specific circumstances. Subject to the conditions set out in the provision, this applies to the storage or alteration of data relevant to evidence with the intention to deceive, or the use of such stored or altered data. Whether a specific file or message fulfils all the elements of the offence is a legal question; a technical finding of manipulation alone does not answer this.

Section 371 of the Code of Civil Procedure (ZPO) is relevant to civil proceedings. Under this provision, evidence by inspection may also be adduced through the production or transmission of electronic documents. Section 371a of the ZPO contains specific provisions on the evidential value of electronic documents, in particular in the case of qualified electronic signatures and certain public electronic documents. Consequently, not every ordinary chat message or image file automatically possesses the specific evidential value set out in those provisions.

Sections 402 et seq. of the Code of Civil Procedure (ZPO) apply to expert evidence. A privately commissioned IT forensic report does not constitute a court expert report solely on the basis of its technical quality. However, its transparent methodology and the evidence on which it is based may be important for lawyers and for subsequent expert review.

Hash values are an important integrity tool, but they do not guarantee the authenticity of the original content. A hash records that a particular set of data has remained unchanged since the hash was generated, or that it matches a reference set bit by bit. It does not automatically indicate whether the content had been tampered with prior to being saved.

LanCologne assesses technical data and its significance. The legal evaluation of evidence, its classification under criminal law, and the decision as to what weight to give to which evidence during proceedings are the responsibility of solicitors, investigating authorities and the courts.

Frequently Asked Questions

How can I find out whether a chat history has been compiled or shortened retrospectively?
Chats, photos, videos and screenshots can carry considerable weight in private, civil or criminal disputes. However, the fact that they are visible does not automatically answer questions regarding their origin, whether they have been altered, when they were created or who created them.
How is such a technical investigation carried out in practice?
We compare the exports or screenshots provided with the available original data, message sequences, IDs, time stamps and related correspondence.
Can such an investigation always produce a clear result?
Missing messages may also result from deletion, retention or differences in synchronisation status, and do not automatically prove deliberate manipulation.
Is there a legal basis for this?
In the case of tampered digital evidence, Section 269 of the German Criminal Code (StGB) may be relevant, depending on the specific circumstances. Subject to its conditions, this provision concerns the storage or alteration of data relevant to the case with the intention to deceive, or the use of such stored or altered data. Whether a specific file or message fulfils all the elements of the offence is a legal question; a technical finding of manipulation alone does not answer this. Section 371 of the Code of Civil Procedure (ZPO) is relevant to civil proceedings. According to this provision, evidence by inspection may also be adduced through the production or transmission of electronic documents. Section 371a of the Code of Civil Procedure (ZPO) contains specific provisions on the probative value of electronic documents, in particular in the case of qualified electronic signatures and certain public electronic documents. Not every ordinary chat message or image file therefore automatically possesses the special evidential value set out therein. Sections 402 et seq. of the ZPO apply to expert evidence. A privately commissioned IT forensic report does not constitute a court-admitted expert report solely on the basis of its technical quality. However, its transparent methodology and the evidence on which it is based may be important for lawyers and for subsequent technical examination. Hash values are an important tool for verifying data integrity, but they do not guarantee the authenticity of the original content. A hash verifies that a specific data set has remained unchanged since the hash was generated, or that it matches a reference set bit by bit. It does not automatically answer the question of whether the content had been tampered with prior to being backed up. LanCologne assesses technical data and its evidential value. The legal assessment of evidence, its classification under criminal law and the decision as to which evidence is given what weight in proceedings are the responsibility of lawyers, investigating authorities and the courts.

LanCologne – IT Forensics for Private Individuals

Do you have a digital enquiry? LanCologne can assist you with an objective, unbiased IT forensic investigation.

Get in touch now