Skip to main content

Anton Piller Acquisitions

digital forensics

Anton Piller orders often require the urgent identification, preservation, and forensic acquisition of digital evidence, including computers, mobile devices, servers, and cloud accounts, to prevent deletion, alteration, concealment, or destruction.

Our digital forensic investigators assist attorneys, independent supervising attorneys, Sheriffs, and other court-authorised parties with identifying, acquiring, preserving, and documenting electronic evidence during the execution of an Anton Piller order.

We conduct on-site acquisitions across South Africa, acting independently and objectively. We follow court orders and accepted forensic procedures to preserve the integrity of evidence.

What Is An Anton Piller Order?

An Anton Piller order is a court-authorised procedure designed to preserve specific evidence that may otherwise be hidden, altered, deleted, or destroyed before legal proceedings.
In digital environments, relevant evidence may be distributed across multiple devices and locations, such as computers, mobile devices, servers, external storage, email accounts, and cloud systems.
Executing an Anton Piller order involving electronic evidence requires an experienced digital forensic practitioner to identify, acquire, and preserve evidence without altering or compromising original data.
We do not determine the legal scope of the order. We act in accordance with the orders and instructions from authorised supervising parties to acquire and preserve electronic evidence within the terms of those orders and instructions.

Digital Evidence We Can Acquire And Preserve

Depending on the wording and scope of the Anton Piller order, we can assist with the forensic acquisition and preservation of data from:
  • Desktop and laptop computers.
  • Windows, macOS and Linux systems.
  • Internal and external hard disk drives.
  • Solid-state drives (SSD).
  • USB flash drives and memory cards.
  • Cell phones and tablets.
  • Servers.
  • RAID and NAS storage systems.
  • Virtual machines.
  • Email accounts and mailboxes.
  • Microsoft 365 and Exchange Online.
  • OneDrive and SharePoint.
  • Google Workspace, Gmail and Google Drive.
  • Dropbox and other cloud storage.
  • Network shares and business file servers.
  • Backup media.
  • Databases.
  • Other digital storage devices and locations identified in the order.
If a device is damaged, inaccessible, encrypted, or partially failed, our data recovery capabilities enable us to acquire evidence that might otherwise be difficult or impossible to preserve.

Before The Anton Piller Acquisition

Thorough preparation is essential.
When permitted, we assist the legal team in identifying technical requirements for the planned acquisition before executing the order.
This may include establishing:
  • The anticipated number and type of devices.
  • The likely operating systems and storage configurations.
  • Whether servers or RAID systems may be present.
  • Whether mobile devices are included.
  • Whether cloud-hosted information must be preserved.
  • The approximate volume of data involved.
  • What forensic equipment and storage capacity will be required.
  • Whether specialised data recovery equipment may be necessary.
  • Whether additional forensic personnel may be required.
Careful planning reduces delays and helps ensure evidence is acquired with minimal disruption to business operations.

On-Site Forensic Acquisition

During execution, our investigators attend the specified premises with the necessary forensic acquisition equipment.
The procedure depends on the court order, the devices encountered, and instructions from the independent supervising attorney or other authorised person.
Where authorised, our investigators can:
  • Identify relevant computers and digital storage devices.
  • Photograph and document devices prior to acquisition.
  • Record identifying information such as make, model and serial number.
  • Identify storage media installed within computers or servers.
  • Forensically acquire data using appropriate acquisition methods.
  • Create forensic images of storage devices.
  • Acquire logical or physical data from mobile devices where technically possible.
  • Preserve relevant cloud-hosted information.
  • Calculate cryptographic hash values where appropriate.
  • Document the acquisition process.
  • Securely store the resulting forensic evidence.
Where possible, we use forensic write-blocking technology to prevent changes to original storage media during acquisition.

Forensic Imaging

Where appropriate, we can create a forensic image of a computer hard drive, SSD, external drive or other storage device.
A forensic image preserves data from the source media for later examination, eliminating the need to repeatedly analyse the original device.
Depending on the acquisition method, this may include:
  • Existing files.
  • File system metadata.
  • Deleted data.
  • Unallocated space.
  • System artefacts.
  • Application data.
  • User activity artefacts.
  • Internet and browser information.
  • Email data.
  • Relevant metadata and timestamps.
We calculate and record cryptographic hash values to verify that the acquired forensic image remains unchanged.

Cell Phone And Mobile Device Acquisition

Cell phones and tablets can contain critical evidence, including communications, photographs, documents, application data, internet activity and cloud account information.
Where authorised by the order and technically possible, we can assist with forensic acquisition from devices including:
  • Apple iPhone and iPad.
  • Samsung.
  • Huawei.
  • Xiaomi.
  • Oppo.
  • Vivo.
  • Other Android devices.
The type and amount of data acquired depend on the device, operating system, security settings, encryption, available credentials, and supported acquisition methods.

Server, RAID And NAS Acquisitions

Business environments frequently contain evidence on servers, RAID arrays, network-attached storage systems and shared network locations rather than individual computers.
Removing drives or copying data without understanding the storage configuration may compromise evidence or cause unnecessary downtime.
Our experience in both digital forensics and complex data recovery enables us to assist with acquisitions from:
  • Physical servers.
  • RAID arrays.
  • NAS systems.
  • File servers.
  • Virtual servers.
  • Virtual machines.
  • Database servers.
  • Shared network storage.
Where appropriate, we select acquisition strategies that balance evidentiary requirements with the need to minimise disruption to operational systems.

Cloud And Email Acquisitions

Important evidence may not physically exist on any of the devices located at the premises.
Modern businesses frequently store information in Microsoft 365, Google Workspace, OneDrive, SharePoint, Dropbox and other cloud-hosted systems.
Where the court order authorises the acquisition of such information and the necessary access is available, we can assist with preserving relevant cloud-hosted evidence.
This may include:
  • Email.
  • Attachments.
  • Cloud-hosted documents.
  • File metadata.
  • Shared folders.
  • Audit records.
  • User account information.
  • File-access and sharing information.
  • Other available cloud artefacts relevant to the order.
Cloud evidence should be identified early, as retention periods and available audit information vary by service and subscription level.

Damaged Or Inaccessible Devices

An Anton Piller acquisition does not always involve working devices.
A computer may have been damaged, a hard drive may have failed, or a storage device may no longer be recognised by the operating system.
Our laboratory combines digital forensic investigation with advanced data recovery to acquire evidence from faulty or difficult-to-access storage media.

Preservation Of Evidentiary Integrity

Preserving the integrity of digital evidence is central to every Anton Piller acquisition.
Depending on the circumstances and the wording of the court order, our acquisition procedure may include:
  • Documenting the condition of the device.
  • Recording identifying information.
  • Photographing the evidence.
  • Using forensic write blockers where appropriate.
  • Creating forensic images using accepted forensic procedures.
  • Calculating and recording hash values.
  • Recording dates, times and acquisition methods.
  • Labelling acquired evidence.
  • Maintaining chain-of-custody documentation.
  • Securely storing acquired forensic images.
The goal is to create a documented, repeatable record of how electronic evidence is obtained and preserved.

We Do Not Conduct A Fishing Expedition

The purpose of an Anton Piller acquisition is to preserve evidence identified within the scope of the court order.
Our investigators do not use the acquisition to search indiscriminately through a respondent's private or business information.
We work within the technical and legal parameters provided and acquire only the devices, data, or categories of information authorised by the order.
If there is uncertainty about whether a device or information source falls within the order, we refer the matter to the independent supervising attorney or another authorised person instead of making a unilateral decision.

Acquisition Versus Investigation

Forensic acquisition and forensic investigation are separate processes.
Creating a forensic copy does not necessarily mean its contents can be examined immediately by the applicant or legal representatives.
Any subsequent searching, examination, filtering, disclosure, or forensic analysis of acquired data must comply with the court order and any further directions or agreements governing access to the preserved evidence.
Where subsequent forensic examination is authorised, our investigators can assist with searching, analysis, data recovery, timeline reconstruction and forensic reporting.

Keyword And Targeted Data Searching

Where specifically authorised, it may be necessary to identify data falling within defined categories contained in the order.
This can include searches based on:
  • File names.
  • Folder names.
  • Email addresses.
  • Named individuals or companies.
  • Project names.
  • Product names.
  • Relevant keywords.
  • Date ranges.
  • File types.
  • Document contents.
  • Email communications.
  • Other criteria specified in the order.
Large data sets can be processed using forensic and e-discovery techniques to identify information responsive to authorised search criteria while limiting unnecessary exposure of unrelated data.

Independent Third-Party Forensic Assistance

The credibility of electronically acquired evidence is often critical in subsequent litigation.
Using an independent digital forensic practitioner provides a documented third-party record of:
  • What devices were encountered.
  • Which devices or data sources were acquired.
  • How the acquisitions were performed.
  • When the evidence was acquired.
  • Which forensic tools and methods were used.
  • What hash values were generated.
  • How the evidence was preserved.
  • Who had custody of the evidence.
Where required, our investigators can prepare affidavits, forensic reports, or other technical documentation related to the acquisition process and provide expert evidence on the forensic procedures performed.

After The Acquisition

Once the authorised acquisition is complete, the acquired evidence is handled in accordance with the court order.
Depending on the matter, this may include securely sealing or storing forensic evidence, providing it to the designated custodian, or retaining it pending further direction.
Where a subsequent forensic investigation is authorised, we can assist with:
  • Data indexing and processing.
  • Keyword searching.
  • File and document analysis.
  • Email investigation.
  • Deleted data recovery.
  • Internet and browser analysis.
  • USB device investigations.
  • Cloud activity analysis.
  • User activity reconstruction.
  • Timeline analysis.
  • Identification of data copying or exfiltration.
  • Forensic reporting.
  • Expert testimony.

Typical Anton Piller Matters

Anton Piller acquisitions involving digital evidence are commonly encountered in matters involving:
  • Theft of intellectual property.
  • Trade-secret disputes.
  • Confidential information taken by employees or former employees.
  • Unlawful competition.
  • Copyright infringement.
  • Fraud.
  • Data theft.
  • Misappropriation of customer databases.
  • Unauthorised possession of company information.
  • Destruction or concealment of electronic evidence.
  • Other commercial disputes where electronic evidence may be at risk.

Related Services:

See Also:

Contact us now for a free consultation, evaluation and preliminary quotation.

Terms and Conditions Apply