The situation
A Mumbai-listed midcap company (we'll call them "TraderCo") had board-level concerns about procurement irregularities. Multiple vendor contracts had been awarded at above-market rates to firms with apparent connections to the procurement head. The audit committee engaged outside counsel; outside counsel engaged Bachao.AI for the forensic investigation.
Constraints:
- The procurement head was still employed and unaware
- Evidence had to be acquired without alerting the subject
- Findings would potentially be used in: (a) internal termination proceeding, (b) civil recovery suit, (c) potential criminal complaint
- Section 65B certified evidence was essential
- 6-week timeline before the board needed conclusions
Acquisition (Week 1)
Coordinated with counsel and HR, Bachao.AI's forensic team acquired:
On-site over a weekend (subject travelling):
- Company-issued laptop (full disk forensic image with write-blocker)
- Company-issued phone (full physical acquisition via Cellebrite)
- Backup tapes for the procurement department's shared drive
- Microsoft 365 mailbox (full export including deleted items)
- Slack workspace (subject's messages + DMs)
- Company VPN logs for the past 18 months
- Subject had voluntarily provided phone access to HR for an unrelated matter 4 months prior
- HR's prior phone backup contained pre-litigation snapshot
- Bachao.AI forensic team validated the prior backup against current state using hash comparison
Analysis (Weeks 2–4)
WhatsApp forensics on company phone:
- Full chat history recovered including 7 deleted conversations
- Counterparties identified through phone number-to-VPA-to-PAN correlation
- 4 conversations with vendor representatives showed pricing discussions inconsistent with the formal procurement record
- 2 conversations contained explicit references to "commission" and "share"
- 14 additional vendor conversations not visible on company phone
- Multiple conversations with one specific vendor mentioning amounts that correlated with bank transfer records (obtained separately via court process)
- 23 emails between subject and vendor representatives outside company email policy
- 8 emails containing pricing details that pre-dated formal vendor responses by 3–7 days (indicating leaked information)
- Auto-forwarding rule discovered on subject's mailbox redirecting procurement notifications to a personal email — set up 14 months before the investigation began
- Email + WhatsApp + Slack messages reconstructed into a unified chronological timeline
- Patterns showed coordinated vendor scoring (subject's emails timed to align with vendor proposal submissions)
- Total estimated procurement irregularity: ₹14.7 crore over 18 months
Know your vulnerabilities before attackers do
Run a free VAPT scan — takes 5 minutes, no signup required.
Book Your Free ScanReporting (Weeks 5–6)
The deliverables to outside counsel:
- 240-page forensic report with full methodology
- Section 65B certificates for every electronic record cited (23 certificates)
- Hash registry with verification commands for every artefact
- Chain-of-custody log (240 entries across the engagement)
- Forensic image of every device preserved in Bachao.AI evidence locker
- Expert witness availability declaration
What happened
The findings were presented to TraderCo's board with outside counsel. Decision: terminate subject with cause, refer matter to civil arbitration for recovery, file criminal complaint with EOW Mumbai.
Civil arbitration:
- TraderCo's case relied heavily on the Bachao.AI forensic evidence
- Counsel for the subject challenged the Section 65B certification
- Bachao.AI forensic lead testified as expert witness for 2 days
- Cross-examination focused on chain of custody and acquisition methodology
- Arbitrator accepted the evidence; awarded ₹9.2 crore recovery against subject
- EOW Mumbai accepted the forensic evidence under proper Section 65B
- Bachao.AI forensic team coordinated with EOW for evidence handover with full chain of custody
- Proceedings ongoing at the time of this case study publication
What it cost
| Line item | Cost |
|---|---|
| Bachao.AI forensic engagement (Complex case) | ₹15L |
| Expert witness testimony (2 days × ₹50K) | ₹1L |
| Total Bachao.AI cost | ₹16L |
What TraderCo's outside counsel said
"Forensic evidence is only as good as the chain of custody and the Section 65B certification. Bachao's methodology survived cross-examination from an experienced opposing counsel. The arbitrator's acceptance speaks for itself. The team understood not just the technology but the legal context — that's rare in cyber forensics."
Pattern this engagement followed
Common shape for Bachao.AI's cyber forensics engagements:
- Internal investigation triggered by board / audit committee
- Subject still employed; discreet acquisition required
- Evidence likely to be used in legal proceedings
- Section 65B certification essential
- Expert witness availability needed
Schedule the forensics scoping call →
Related: Cyber Forensics India Methodology · Digital Forensics for Indian Law Firms
