Capitol Breach Investigations are Changing eDiscovery

On January 6, supporters of then-President Donald Trump breached the U.S. Capitol in an attempt to prevent Congress from certifying Joe Biden as the winner of the 2020 presidential election. As authorities look into who is responsible and what kinds of repercussions perpetrators should face, they’ll have over 140,000 pieces of digital media to aid their efforts. Throughout the Capitol Breach investigations, officials will be reliant on something much of the world knows nothing about: eDiscovery.

eDiscovery is the art and science of sorting through digital data to find the relevant pieces needed to build a legal case. 5-10 years ago, much of this data came in the form of emails and their attachments. However, many of the arrests relating to the Capitol riots cite digital evidence uploaded to social media sites.

One Connecticut man was charged because of a YouTube video. Two Massachusetts citizens were arrested because of photos on Twitter. A New Mexico County Commissioner was connected to the riots in part because of videos he posted on a “Cowboys for Trump” Facebook page. A man from Texas was arrested in part due to his posts on Parler. One such post allegedly included a threat to return to Washington, D.C. on January 19 armed and ready for insurrection: “We will come in numbers that no standing army or police agency can match,” the post allegedly states. 

That shift away from email-exclusive discovery strategies was already happening, but the Capitol riots may expedite it. Investigators are still sorting through digital data, and we likely haven’t seen the last of arrests related to this incident. Many cases will hinge on whether or not eDiscovery professionals can connect individuals to the scene and whether or not there’s digital evidence that reveals offenders’ true intentions. Either way, the Capitol breach investigations shed a light on what kind of technology is available and how law enforcement is using it. Depending on the outcomes of these cases, we may see social media-based data integrated into discovery on a much larger scale.

The Value of Geolocation

Ordinary people probably know that investigators can find incriminating things people have published on the internet. However, they might be surprised to learn just how easy it is to figure out which electronic devices were actually at the Capitol on the day of the attack. Geolocation, or more specifically “geofencing”  involves drawing a virtual boundary around a specific location, and then using technology such as GPS or Bluetooth to find devices within that boundary.

“Right now, law enforcement can pull social media information from a geolocation at will or with relatively few roadblocks,” says James Whitehead, Contact Discovery’s Associate Director of Digital Forensics. “Law enforcement agencies can capture wireless communications and pull packets off wires. This technology/capability is expanding among law enforcement departments at a rapid pace.”

This is important because many people have said hyperbolic things on the internet, and that in and of itself isn’t a crime. One of the challenges facing investigators is separating those who simply wrote inflammatory messages from those who acted on their intent. With geolocation, investigators can prove that someone who published violent threats online was actually at the Capitol at the time of the attack.

An offender’s sentence could also vary quite a bit if prosecutors can use social media posts to prove there was prior intent to attack the Capitol. That’s a very different scenario from someone who showed up for what they thought was a peaceful protest, got caught in the moment, and then showed remorse after the fact.

Social media companies are also aiding law enforcement in matching locations to other parts of a user’s profile.

“At one point Facebook had 100+ metadata fields for its site,” Whitehead says. “This includes user names, likes, names of the likers, time of the likes and/or shares, and then most if not everything is geolocated. Often these metadata records include associations to the authoring/viewing device’s unique identifiers including IP address, which further aids in geolocating.”

In the case of Twitter, investigators can collect tweets in a geolocated fence and by hashtag.

“I could essentially drill down to the Capitol and then to hashtags of interest,” says Whitehead. “If I expanded my resources, I could cross-reference known individuals and pull all their tweets and anyone who shared or viewed them within a geofenced area.”

That combination of what people said online and their whereabouts at the time of the Capitol attacks gives investigators added insight. Suddenly they’re able to comprehend not only the “what” but the “who,” “where,” and “why” as well. Geolocation could also play an important role in providing alibis to those who published inflammatory statements, but were not physically present at the Capitol at the time of the attack.

Constructing Larger Narratives

Not only can law enforcement use social media data to pinpoint where suspects were the day of the attacks, they can also use it to show what kinds of things suspects were writing weeks before. This helps investigators tell a more complete story.

One suspect, Brendan Hunt, allegedly called for the murder of elected officials on an online video platform called BitChute. However, the charges against him also mention a Facebook post on or from approximately December 6, 2020, a whole month before the Capitol breach. According to the affidavit, this post called for “revenge on Democrats” and a “public execution” of Senator Chuck Schumer and Representatives Nancy Pelosi and Alexandria Ocasio-Cortez.

“If you [Trump] don’t do it, the citizenry will,” says Hunt’s post.

Another case revolves around a Utah man named John Earle Sullivan. Sullivan handed over 50 minutes of video footage to authorities. He’s also uploaded large amounts of video content regarding the riots to YouTube under the name JaydenX. The criminal complaint against Sullivan claims his voice can be heard on the tape saying celebratory things like “We accomplished this s**t. We did this together.”

At the time of this writing, JaydenX’s YouTube channel not only features footage of the Capitol riots on January 6, but other MAGA, Proud Boys, and Black Lives Matter protests dating back to June 1, 2020. If you’re the defense, you might argue this YouTube account proves that Sullivan is just an independent video journalist, attending and recording any protest he thinks will be of interest regardless of the cause. If you’re the prosecution, you might use it to establish that Sullivan is a dangerous agent of chaos and has been for some time. Either way, it’s hard to imagine that legal teams will look at what’s likely hundreds of hours of political protest footage from the last six months and think that only the January 6 footage is relevant.

General Awareness of ESI in Law Enforcement

Perhaps most importantly of all, the riots have made the general public more aware of how digital data can be helpful to law enforcement. Sometimes, public ignorance can aid investigators. People incriminate themselves largely because they don’t know their messages can be found later. The events at the Capitol have created large scale awareness of the role that social media posts and other electronic messages can play in investigations.  

That awareness is a double-edged sword. On the one hand, it could drive bad actors to alternative platforms where they’re harder to find. On a more optimistic note, well-intentioned people are more likely to be on the lookout for digital evidence in their day-to-day lives. Heck, one Twitter user even mentioned using dating apps as a way of getting perpetrators to volunteer evidence against themselves:

Only time will tell how this case shakes up the world of eDiscovery. What won’t change is the critical role that legal technology plays in finding the truth.

Subscribe to the Contact Blog to receive more updates on all things eDiscovery.


The Ghosts of Discovery Past, Present, and Future

Here at Contact Discovery, we talk a lot about the importance of preparing for the future. That oftentimes involves getting a better understanding of the past. The world of legal technology moves fast, so it’s easy to lose track of just how far we’ve come. However, past challenges can inform how we tackle present and future challenges. In some cases that involve older documents, we find ourselves working the past, present, and future all at once. It is in that spirit that we take this holiday season to reflect on our industry. Specifically, the Ghosts of Discovery Past, Present, and Future.  

The Ghost of Discovery Past = Paper

Before eDiscovery, there was just Discovery, with a nifty little thing called “paper.” Companies kept paper records as far as the eye could see. Tens of thousands of documents scattered across various offices, filing cabinets, and even warehouses. 

If there was litigation on the horizon, lawyers and their associates would have to manually go through these documents and hope they found information they could use to build a case. It required a lot of people, and it was much easier to miss metaphorical smoking guns if reviewers weren’t communicating effectively.  

In the earliest days of eDiscovery, practitioners scanned these documents so reviewers could read them on computer screens. This meant that documents no longer took up as much physical space, and reviewers wouldn’t have to spend as much time on site or reviewing copies upon copies in law firm storage rooms. However, it still paled in comparison to platforms such as Relativity and others that are common in today’s Discovery landscape.  

The Ghost of eDiscovery Present = Mobile Meets Global  

While the past was largely about taking paper documents and converting them to electronic documents, today’s world is different. Now, most of our communication originates electronically. That came with new challenges. How do you find server space to store all those documents? How do you make sure the right people have access and the wrong people don’t? How do you take advantage of technology like email threading and data analytics without letting relevant documents go unnoticed?   

For the most part, legal teams have figured out systems to combat those issues. However, there’s one innovation that’s still tripping up review teams: the mobile phone. While mobile phones have been with us for decades now, mobile chats supplanting email for professional communication is a relatively recent phenomenon.  

Many professionals would’ve scoffed at the idea of texting a teammate about a work assignment even five years ago. Now, it’s quite common for co-workers to talk shop over text as well as exchange more personal messages they would never email. Many businesses also rely on collaboration platforms such Microsoft Teams, which has seen its userbase skyrocket in light of the pandemic.  

This presents new challenges to legal teams. Not only are there technical challenges involved with more messages in a wider array of file formats, there’s also the change in user behavior. Personal and professional messages are more likely to comingle in a text chat than they are in an email thread. This raises privacy concerns and can increase the need for redactions.  

Apps like WhatsApp has also made it easier to communicate across national borders. As more Americans start having more conversations with people abroad, there’s more regulations that lawyers have to tiptoe around to maintain defensibility. The EU’s General Data Protection Regulation, enacted in 2018, helps protect the privacy of people who have communicated with someone under a legal hold. Even if your business isn’t based in the EU, you need to be mindful of this if anyone stateside was communicating with someone in Europe.  

When shopping around for legal technology partner in the present, look for teams that are GDPR compliant, even if you don’t necessarily do that much business abroad. Remember, as your business scales, your legal needs will as well, and it’s best to be prepared. Also avoid companies that are designing their discovery strategies exclusively around email communication. Some companies such as Contact offer software specifically designed for mobile data review. Even if your current technology doesn’t, at least ensure that your team isn’t neglecting these communications altogether.  

Future = Artificial Intelligence and Decentralization

As technology becomes more and more advanced, sheer man power won’t be the prized commodity it once was. In the past, most businesses relied on big name law firms with recognizable brands. They knew that top attorneys flocked to these reputable firms in droves, so why go through the trouble of investigating other options? That was really the only to get an edge over opposing counsel anyway: good attorneys and lots of them.   

More and more legal technology companies are starting to integrate artificial intelligence that can search and review documents faster than any human could. AI simulates an elite crew of top notch attorneys doing ALL your review, rather than a massive army of attorneys who bring varying levels of talent and experience to the equation. This technology is still in its infancy, but if used to its fullest potential, it will eliminate that need for sheer man power. Suddenly, one attorney will do review that might take 30 attorneys now.  

“The right people with the right technology can adapt quicker than large companies can, and that leads to positive outcomes.”  

– Rich Albright, Contact Discovery CBO

As AI helps make review more user friendly, companies on both the service side and the technology side are helping corporate counsel internalize more of their discovery. In this new frontier, businesses don’t need their law firms to be a one-stop shop, but can instead seek out strategic relationships with more specialized partners. 

“Smaller firms like Contact are winning victories in huge matters that never would’ve gone to a company our size 5-10 years ago,” says Rich Albright, CBO of Contact Discovery. “People are starting to figure out that a team of the right people with the right technology can adapt quicker than large companies can, and that leads to positive outcomes. They’re choosing quality over quantity and it’s paying off.”  

As the legal technology market becomes more decentralized, you can expect to see smaller companies that specialize in different steps of the EDRM or different types of technology to gain market share. This model empowers businesses to only pay for what they can’t internalize and make sure they’re getting the absolute best version of it. The internet also makes it easier than ever for clients to seek these partners out for themselves rather than trusting a larger law firm to make all the tech decisions for them.

What challenges are you facing in the present? Where do you think the future of legal tech is going? Let us know in the comments!  

Contact Welcomes New Forensics Powerhouse James Whitehead

Contact Discovery Services is ecstatic to announce James Whitehead as new Associate Director of Digital Forensics.

James Whitehead,
Associate Director of Digital Forensics

In his own words, James has done collections “anywhere there’s a hard drive.” In September 2020, James came on board at Contact to help expand the company’s forensics offerings.

“I think the goal is to increase the visibility of our forensic offering by removing communication road blocks and solving our clients’ technical business issues,” said James. “As technologists we strive to build useful partnerships with our end clients that allow them to wield our expertise to solve problems.”

While Contact has always prided ourselves on offering end-to-end discovery services, including forensic collection, preservation, and analysis, the company believes that James’s arrival can take our Forensics department to soaring new heights.

This is particularly true in regards to testimony and depositions. In his 10+ years of experience in forensics, James has taken the stand to verify data and defend a client’s collection process. Now, Contact clients who need that service don’t need to rope in an additional vendor.

“We are very excited to have James lead our digital forensics team,” said Dave DiGiovanni, CEO at Contact. “He’s a phenomenal industry leader that really enhances Contact’s existing capability to deliver world class forensic analysis and testimony.”

James made the jump into forensics in 2009. At the time, he was working in project management for a litigation support vendor, often handling the toughest technical projects of that company.

“We got a large backup tape job and decided to handle it in house,” James said while reminiscing about the early days of his forensics career. “From there, I grew into data collections and then into full fledged forensics.”

Through his career, James has always been fascinated by the industry’s rapid pace of evolution. “The cutting edge of Forensics continues to evolve as technology evolves, creating new challenges we get to solve for our clients,” says James.

It’s precisely that passion for the end client that helps make James such a great fit for Contact, where client-centric innovations are at the center of company culture.

“From our first conversation, James and I immediately clicked,” said Scott Keeble, Director of eDiscovery Operations at Contact. “His attention to detail, attitude towards work, and ideas for innovation were immediately apparent, which enables him to quickly become an integral part of our team.”

When James is NOT using his strong inquisitive sense to find the truth in a circuit board, he loves unwinding by watching racing and learning about cars. More recently, he discovered a love for furniture building. “During COVID, everyone else got baking, I got sanding!” he joked.

Contact has yet to try out the furniture James has built, but is fully confident in his ability to help you build your case.