When a phone, a computer or a drive passes into someone else’s hands, most of us assume the story is over. That is not always the case: a device you have passed on can keep talking about you, and it often does so through small signals that are easy to mistake for glitches in the system.
This post brings together the signs that your data or your accounts may have stayed on a device you sold, gave away, sent for repair or took to be recycled: what they mean, where you can see them, and what to do when you find one. In technical circles, the traces showing that something did not go the way it should have are called indicators of compromise, or IOCs (Indicators of Compromise). Here we apply them to the moment a device leaves your life — in plain terms, the signs your data was not fully erased.
It is the diagnostic deep dive on the recommendation about wiping data before passing on a device: wiping is the prevention; recognising the signs is how you find out whether it actually worked.
What the signs of incomplete erasure are
A sign of incomplete erasure is an observable trace suggesting that a device you have handed over still holds something of yours: files, signed-in accounts, links to your cloud storage.
It is not proof. It is a signal that deserves a check: it may have a harmless explanation — a device list that takes a few days to update, an old sign-in still in the history — or it may mean that the reset was never completed, or that one of your accounts is still connected to a device someone else is now using.
The value of these signs lies in timing: noticing one in the first few days after the handover means you can disconnect your accounts remotely before anyone, even without meaning to, sees or uses what was yours.
Why they matter more once the device is in someone else’s hands
While the device is still on your desk, any doubt can be cleared up in a few minutes: you switch it on, check, and run the procedure again. After the handover, though, you can no longer fix things on the device itself. You can only act from the outside, through your accounts.
There is a second reason too. A modern phone or computer does not just hold files: it is a doorway to your email, cloud storage, chats and payments. If the reset was skipped or interrupted, whoever receives the device may find not a dead archive but sessions that are still open — sign-ins that have already been authenticated and do not ask for the password again.
That is why the signs are worth reading above all in the days after the handover: it is the window in which a problem is still small and easy to close.
Technical indicators
These are the ones services record and make available in the security sections of your accounts.
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| The old device still appears among connected devices | The account still treats it as one of your devices | Whoever uses it may have access to your synced data | “Devices” or “Security” section of your main account | Remove it from the list, then change the account password |
| Sign-in alerts from a device you have passed on | Someone used the account on that device after the handover | Your credentials or a session are still active | Security emails, in-app notifications, sign-in history | Sign out of all sessions, change the password, check your recovery details |
| Active sessions in messaging or email apps | A chat or a mailbox shows as open on a device that is no longer yours | Messages and attachments can be read as they arrive | The app’s “Linked devices” option, active email sessions | Close the session remotely, then check your forwarding settings |
| New backups under the old device’s name | The device keeps saving copies to your cloud storage | Someone else’s files end up in your account, and yours stay visible to them | Backups page in your cloud settings | Delete that device’s recent backups and disconnect it from the account |
| The device still appears in the location service | The anti-theft lock — the protection that ties the device to your account — is still active | The new owner cannot use it, and you can see where it is: neither should be the case | The operating system’s “find my device” service | Remove the device from the list; do not use its location for anything else |
| Device still “trusted” for two-step verification | The account recognises it as trusted and may skip the second check | Two-step verification (a code or confirmation on top of the password) loses its effect | Security settings, “Trusted devices” option | Revoke the trusted status and review your active verification methods |
| Payment cards linked to the old device | That phone’s digital wallet still holds one of your cards | A payment could be made from a device you do not control | Your banking app, “Devices” or “Digital wallets” section | Remove the card from that device; if you cannot, contact your bank |
Signs you can observe yourself
These do not require you to open any dashboard: you notice them in everyday life, sometimes thanks to someone else.
| Signal | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| Photos you did not take in your gallery | The old phone is still syncing with your cloud storage | Your own photos are also visible from the device you passed on | Pictures of unfamiliar people or places appear in your gallery | Disconnect the device from the account, then delete the photos that are not yours |
| Messages read or sent from another device | A chat session was left open | Your private conversations are exposed, and someone could write in your name | Conversations marked as read, messages you do not remember | Close the linked-device sessions, let your contacts know if needed |
| The new owner asks you to unlock the device | When switched on, the device still asks for your account | It was reset without signing out: the anti-theft lock is still in place | You get a message or a call from the person who received it | Remove the device from your account remotely; never share your password |
| The new owner finds files or signed-in accounts | The reset was never done or never finished | Your data has already been seen, even if only by accident | They tell you, or you realise from something they say | Thank them, ask them to stop and reset it, then secure your accounts |
| Erasing the drive took only a few seconds | A quick format was probably used, which does not overwrite the data | With recovery tools, the files may reappear | You noticed an almost instant operation on a full drive | If you still have the drive, repeat with a full procedure; if not, focus on your accounts |
| A forgotten memory card or SIM | A physical storage medium was left in the device | Photos, contacts or your phone number have changed hands | You look for it in your new phone and it is not there, or it is handed back to you | Ask for it back; for the SIM, contact your mobile provider to block it |
| Purchases or notifications from apps you no longer use | An app store account is still active on the old device | Charges in your name and access to your payment methods | Receipts for apps or content you did not choose | Disconnect the device from your app store account, check your payments |
A concrete example
Sarah sells her old tablet to a colleague from another office. Before the handover she resets it to factory settings — or so she thinks: the procedure stopped halfway through because the battery ran low, and when it restarted the tablet looked fine.
A week later, photos of a birthday party she knows nothing about appear in the gallery on Sarah’s phone. The next day her colleague messages her, slightly embarrassed: a family group chat is still open on the tablet.
What links the two episodes is the account: the tablet had never been signed out of Sarah’s cloud storage, and it kept syncing in both directions.
Sarah does not panic. She removes the tablet from her list of devices, closes the chat sessions, changes her account password and asks her colleague to run the reset again, this time with the tablet plugged in. The first signal — the unfamiliar photos — was already enough: read as an indicator rather than a cloud error, it let her close everything in an afternoon.
What to check right away
On the main account of your phone or computer
- the list of connected devices;
- active sessions and recent sign-in history;
- backups saved to the cloud and the date of the latest one;
- the device location service.
On your communication apps (chat, email, social networks)
- linked devices or open sessions;
- automatic email forwarding rules;
- messages sent in the last few days.
On payments
- cards linked to your devices’ digital wallets;
- app store accounts and active subscriptions;
- recent receipts.
On drives and storage you have not handed over yet
- that the erasure was completed and not interrupted;
- that no memory card or SIM has been left inside;
- that when switched on, the device no longer asks for your account.
If you find a suspicious indicator
- Remove the device from your accounts. It is the most effective thing you can do remotely: it stops syncing, backups and the anti-theft lock.
- Change the password of your main account and sign out of all sessions, so that sign-ins already authenticated are closed too.
- Check payments and two-step verification: cards in digital wallets, trusted devices, recovery methods.
- Talk to whoever has the device, if you know them: calmly ask them not to use it until it has been reset, or to give it back so you can do it yourself.
- If the device is out of reach (recycled, lost, sold to strangers), focus on your accounts: you can no longer erase the files it held, but you can stop that device from continuing to open up your digital life.
The complete procedure, with the steps in the right order before a handover, is in the post on how to wipe your data securely.
What is not an indicator
Telling the difference helps you avoid two opposite mistakes: getting alarmed over nothing, and getting used to ignoring the real signals.
| Situation | Why it is usually not a signal |
|---|---|
| The old device stays on the list for a few days | Many services only update the list after a period of inactivity; what counts is any recent sign-in |
| An email confirming that the device was removed | It is the receipt for the step you took yourself, not a sign-in |
| The old device appears in your sign-in history | If every date is before the handover, those sign-ins were yours: only a later one counts |
| Old photos reappearing in your gallery | It is often the cloud catching up on a backlog of syncing from your current devices |
| Your new device shows up as “unknown” | A freshly set-up phone is registered under a generic name until you rename it |
The rule of thumb: one isolated signal deserves a check; two signals together deserve action.
How often to check
You do not need a demanding routine. You just need one to exist, especially in the days around a handover.
| Frequency | What to check |
|---|---|
| Before the handover | That, once switched back on, the device shows the first set-up screen and does not ask for your account |
| The day after the handover | Your list of connected devices: the one you passed on should no longer be there |
| After a week | Recent sign-ins, cloud backups, messaging app sessions |
| Every 2–3 months | A general review of the devices connected to your email, cloud storage and bank |
| When you change phone or computer | That the old one has been disconnected from every account before it ends up in a drawer |
The last row is the one people forget most often: a device left in a drawer stays connected to your accounts for years, and on the day you give it away or take it to be recycled, nobody remembers any more what was on it.
Two important warnings
An indicator is not proof. A device that stays on the list may simply be a slow update on the service’s side. An unfamiliar photo may come from an album shared with a relative. Check before you get alarmed — but always check.
No indicators is not a guarantee. This is especially true for drives. A drive emptied with a quick format sends no notifications, appears on no list and syncs nothing: it looks empty, but the data may still be there, recoverable with widely available tools. That is why protection does not rest on watching for signals, but on prevention: choosing a full format instead of a quick one, encrypting your personal devices well in advance, and backing up photos and videos regularly, so you can wipe without worrying about losing anything. How people hunting for data on used devices exploit incomplete erasure is explained in the post on recovering data from second-hand devices; what really happens inside a drive when you erase it is covered in the post on how secure data erasure works.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to read the list of connected devices and active sessions, and how to remove a device remotely |
| Awareness | Understanding that a device you pass on is not just a container of files, but a door still open onto your accounts |
| Secure Behaviour | Checking in the days after every handover, without waiting for someone else to point it out |
Reference level: FL3 — Autonomous. This is the level at which you recognise a signal and act on it without needing outside support.
Conclusion
The signs your data was not fully erased are not meant to make you suspicious of whoever receives your old device. They are meant for the opposite: knowing where to look, on the right days, so you can close a door left ajar before anyone walks through it, even by chance.
What to do right now. Open the connected devices section of your main account and scroll through the list. If you find a phone or computer you no longer own, remove it now: it takes less than a minute. If everything looks fine, you know where to look the next time you pass something on. To see where you stand on the other aspects of your digital security, you can take the digital resilience self-assessment.
Related resources
Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:
- The Final Step: How to Log Out of Your Accounts
- Data Encryption: Already On, and Worth Understanding
- Data Backup: The Only Protection That Works Afterwards
Related content
- Wiping data before passing on a device — the recommendation this belongs to
- Recovering data from second-hand devices — the threats that exploit these signs
- How to wipe your data securely — what to do, in the right order
- How secure data erasure works — the technologies and their limits
- Selling a device without wiping it — what happens when a signal is confirmed
- A full format instead of a quick format — the neighbouring recommendation on the drive case
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



