The Digital Evidence Behind Remote Work Fraud
Remote work fraud is not a fringe problem. Estimates from employment analytics firms put the number of U.S. workers holding two or more full-time remote positions simultaneously in the hundreds of thousands, and the volume of discovered cases has grown sharply since 2022 as return-to-office mandates pushed the practice into higher-stakes territory. What those employees may not appreciate, and what many employers and their counsel don't fully understand either, is that the company computer has been keeping records the entire time. Every application opened, every calendar entry accepted, every VPN handshake: those artifacts are sitting on the device and in the server logs right now. The question for employment attorneys on both sides is whether they're going to use that record or ignore it.
*Black Dog Forensics is a forensic services firm, not a law firm, and nothing in this post constitutes legal advice.*
What "Double-Dipping" Actually Looks Like on a Company Device
The popular framing treats double-dipping as a behavioral problem with a management solution: better monitoring tools, mandatory camera-on policies, productivity software. That framing is incomplete. The forensic record that matters in litigation is not generated by surveillance; it's a byproduct of the operating system doing its job. Here is what a forensic examiner actually looks at.
Application Focus Logs
Windows and macOS record application focus events: which application had foreground focus, when that changed, and for how long. The OS logging subsystem generates this data and does not require any employer-deployed monitoring software. If an employee was supposed to be in the first employer's daily standup, that conflict is documentable from the operating system logs alone.
Browser Session Artifacts
Chrome, Edge, and Firefox each maintain session-level history including typed URLs, search queries, timestamps, and tab activity. These artifacts persist across routine browser use and are recoverable even after history clearing in many forensic contexts. Browser session data can establish that an employee was actively using a second employer's internal tools, HR portals, or project management platforms during hours billed to the first employer.
Calendar Artifacts
Outlook PST and OST files retain calendar data including accepted meeting invitations, responses, and attachments — even after deletion. Exchange server logs maintain independent records of meeting metadata. A deleted calendar entry accepting a Teams meeting for Employer B's project kickoff at 10:00 a.m. — overlapping with Employer A's scheduled all-hands — exists in at least two places: the local OST file and the Exchange server log.
VPN Logs
Corporate VPN infrastructure generates authentication and connection logs: login timestamps, session duration, IP addresses, and data transfer volumes. A pattern of VPN connections from two different geographic locations within a short time window, or consistent VPN disconnections during what should be core work hours, are the kinds of anomalies that appear in the data before anyone asks a question.
Video Conferencing Metadata
Microsoft Teams and Zoom both generate rich administrative data: meeting participation records, camera-on/off events, chat activity, and file transfer logs. For Teams deployments, Microsoft 365 Compliance Center provides additional audit trail access to administrators. A pattern of joining Employer A's meetings with camera off, audio muted, and minimal participation — while simultaneously attending Employer B's calls — shows up in the data.
Email Client Artifacts
Outlook generates PST and OST files that retain send/receive timestamps, draft creation and modification timestamps, deleted item recovery, and attachment metadata. The send timestamp of an email to a second employer's team, compared against the employee's calendar and VPN records, can establish a detailed activity timeline.
Cloud Sync Artifacts
OneDrive, Dropbox, and Google Drive sync clients generate local log files documenting sync events, file access, and transfer activity. If an employee is moving company files to a personal cloud storage account — either to work on them for a second employer or to take them on the way out — those events leave forensic traces in the local sync client logs and in the server-side access logs.
USB Device Logs and Idle Time Analysis
Windows records USB device insertions in the registry: device type, serial number, first connection timestamp, and most recent connection. A pattern of large-file transfers to removable storage immediately before a resignation, combined with idle time analysis showing periods of inactivity during scheduled work hours, is the kind of data that user activity analysis is designed to surface.
The Texas Legal Framework
Texas is an at-will employment state. Employers don't need a documented reason to terminate, but that doesn't mean the forensic record is irrelevant. The record matters for what comes after termination: the unemployment claim, the civil suit, the trade secrets dispute, or the breach of fiduciary duty litigation. In each of those contexts, digital forensic evidence can be outcome-determinative.
Breach of fiduciary duty. Not every employee owes a fiduciary duty, but officers, directors, and those occupying positions of trust do. Schlumberger Ltd. v. Rutherford, 472 S.W.3d 881 (Tex. App. 2015) addressed the scope of employee fiduciary obligations, including loyalty duties owed by employees in positions of trust. An employee working full-time for a competitor while collecting a salary, and using employer resources, systems, and work time to do it, presents a viable breach of fiduciary duty claim in the right factual context. Salas v. Total Air Services, LLC, 550 S.W.3d 683 (Tex. App. 2018) and Cuidado Casero Home Health of El Paso, Inc. v. Ayuda Home Health Care Services, LLC, 404 S.W.3d 737 (Tex. App. 2013) both address related claims involving employees engaged in competing activity.
TUTSA. The Texas Uniform Trade Secrets Act governs misappropriation of confidential information and trade secrets. Double-dipping creates a particular TUTSA risk when the second employer is a competitor: confidential information accessed on company systems may find its way to the competing employer, either intentionally or through the employee's divided attention. Universal Plant Services, Inc. v. Dresser-Rand Group, Inc., 571 S.W.3d 346 (Tex. App. 2018) and Super Starr International, LLC v. Fresh Tex Produce, LLC, 531 S.W.3d 829 (Tex. App. 2017) address related TUTSA claims.
Unemployment compensation. When a terminated employee claims unemployment benefits, Texas Workforce Commission will examine whether the termination was for misconduct connected with the work. Kaup v. Texas Workforce Commission, 456 S.W.3d 289 (Tex. App. 2014) addresses the standard for misconduct disqualification. A documented record of the employee's double-dipping activity — hours worked for a competitor during paid work time, employer resources used for personal employment — supports a TWC misconduct finding and benefits disqualification. That documentation has to exist, which means the forensic investigation has to have happened before or immediately after termination.
Digital forensics in Texas courts. The admissibility and weight of digital evidence in Texas employment litigation has developed significantly. Sandberg v. STMicroelectronics, Inc., 600 S.W.3d 511 (Tex. App. 2020) and Marshall v. MarOpCo, Inc., 714 S.W.3d 724 (Tex. App. — Houston [1st Dist.] 2025, pet. filed) both address digital evidence standards in employment contexts, and reflect Texas courts actively engaging with electronic evidence in employment disputes.
What Coe Changes for Employer Counsel
Coe v. DNOW LP, 718 S.W.3d 338 (Tex. App. — Houston [14th Dist.] June 26, 2025) is the most recent Houston appellate decision addressing employer claims arising from remote employment misconduct. DNOW LP — a large oilfield products distribution company — is the type of employer with exactly the kind of digital infrastructure that generates the artifact record described above: corporate VPN, Microsoft 365, Teams, Exchange, SharePoint.
The 14th District's June 2025 decision provides guidance on the evidence standards applicable when an employer pursues claims based on employee conduct in a remote work context. For employer counsel in Houston, Coe is now the controlling appellate authority on the specific fact patterns it addresses, and its reasoning should inform how investigations are structured, how digital evidence is collected and preserved, and how claims are pleaded.
Two practical points. First, the case was decided after substantial discovery, meaning the digital artifact record was developed and tested — which reinforces the importance of getting that record before litigation begins rather than trying to reconstruct it through discovery. Second, a petition for review is pending in Marshall v. MarOpCo (1st Dist. 2025), meaning the Supreme Court of Texas may be asked to address related questions. Houston employer counsel should be tracking both decisions.
The BYOD Problem
Company-issued devices present a clean forensic picture. The employer owns the hardware, controls the network, and holds the administrative credentials for the platform. The evidentiary record is intact and accessible.
BYOD changes that picture significantly.
The Fourth Amendment doesn't apply to private-sector employment investigations, but Texas state law privacy claims, the scope of any monitoring consent obtained at onboarding, and the practical limits of what an employer can access on a device it doesn't own all constrain what a forensic examiner can do. An employee who performed all their remote work on a personal laptop may have a gap in the company-side artifact record — though server-side data almost always remains available.
Server-side data remains available regardless of device: Exchange logs, Teams participation records, VPN logs, and Microsoft 365 activity data all reside on company-controlled infrastructure, regardless of what device the employee was using. For the BYOD scenario, server-side correlation is the primary forensic path.
The lesson for employer counsel drafting BYOD policies: require written consent to access device data for investigative purposes as a condition of BYOD approval. That consent, documented at onboarding, avoids the argument about whether the employer can examine the device it resides on. Doing that work now is far cheaper than trying to reconstruct the agreement after the employee has already resigned with a hard drive full of company data.
Why Investigation Must Come Before Termination
The instinct when double-dipping is discovered is to terminate immediately. That instinct creates problems.
The device goes with the employee unless the employer had the foresight to require immediate return upon termination. By the time counsel is engaged, the forensic window may have closed. Data may have been deleted, synced away, or overwritten. The chain of custody — which is what makes the evidence usable in court — has not been established.
The correct sequence is: preserve first, investigate second, decide third. When there is a reasonable basis to suspect misconduct, the device should be secured — under a litigation hold, with documented chain of custody, before the employee is told anything is happening. The forensic image should be made before the investigation is disclosed. Termination, if warranted, follows the investigation — not the other way around.
This matters for several reasons beyond evidence preservation. An employer who terminates before investigating has lost leverage in any subsequent unemployment proceeding: the termination decision was made without documented cause, which makes the misconduct argument harder to establish. An employer who terminates after a proper forensic investigation can present the TWC with a documented record of what the device shows.
The investigation also protects the employer in the event the suspicion is wrong. A documented forensic examination that finds no evidence of competing employment is valuable evidence in the wrongful termination context. The employer made a reasonable inquiry and found what the data showed. That is a defensible position with a jury.
What Black Dog Forensics Includes in a Remote Worker Investigation
Black Dog Forensics handles employee misconduct investigations and departing employee matters for employers, HR teams, and counsel across Texas and nationally. For a remote worker double-dipping investigation, the work typically involves:
Forensic imaging. Certified forensic imaging of the company device using industry-standard tools creates a bit-for-bit copy that preserves the entire evidentiary record and establishes chain of custody. The original device can be returned or retained; the examination proceeds against the forensic image.
Artifact analysis. User activity analysis covers application focus logs, browser artifacts, calendar data, USB device history, idle versus active time, and document access patterns. The output is a timeline of what the device shows the employee was doing and when.
Server-side correlation. VPN logs, Exchange audit logs, Microsoft 365 activity reports, and Teams participation data are pulled and correlated against the device-side artifact timeline. This is where the picture of what the employee was actually doing — across all the employer's platforms — comes together.
Expert reporting. The findings are documented in a written report suitable for use in litigation, TWC proceedings, and internal HR decisions. BDF can provide expert testimony where required.
Pre-investigation consultation. Before any examination begins, BDF works with counsel and HR to define scope, confirm device ownership and consent posture, and ensure the investigation is structured to produce admissible, defensible findings. That conversation is worth having before the device is touched.
If you have a remote worker situation that may involve double-dipping, competing employment, or misappropriation of company information, the time to call is before the termination decision — not after. The forensic record is perishable.
