An unknown electronic module in a wall socket, a miniature lens in a piece of furniture, or a device with a SIM card can trigger a natural urge to disconnect and dismantle it immediately. Yet hasty actions often destroy fingerprints, disturb the object’s original position, erase digital data, or alert the person monitoring the discovered device.
Basic rule: do not touch the find unless necessary, stop confidential conversations in that area, and document the scene. Further steps depend on whether the item appears safe, whether it may pose a physical threat, and whether the premises owner intends to contact law enforcement.
What to do immediately after discovering a suspicious device
First move to a safe distance and visually assess the situation without moving the object. Do not press buttons, cut power, remove a memory card or SIM, connect the device to a laptop, or try to check whether it is working. Even powering it down can change internal logs, the time of last activity, or connection state.
If the item has unusual wiring, batteries, unknown substances, signs of tampering, or may otherwise endanger life, do not treat it as an ordinary bug. Leave the area, restrict access, and contact emergency services from a safe location. Do not use a phone or radio near a potentially dangerous object. In that situation people’s safety comes first — not photographing the device.
A general principle for safe response to an unknown or suspicious item is set out in ProtectUK — Unattended and suspicious items. Specific emergency numbers and procedural rules are defined by national law and local response protocols.
If there is no clear physical danger, take these initial organisational steps:
- Stop discussing sensitive information. Do not discuss inspection plans, names of suspects, or the next response steps near the device.
- Restrict access. Keep casual staff, visitors, cleaners, and technicians away from the find until a responsible person is designated.
- Do not announce the find in a general chat. Share information only with management, security, counsel, and specialists involved in the response.
- Preserve the room’s normal state. Do not rearrange furniture, open housings of nearby devices, or conduct a chaotic DIY search.
- Define an escalation channel. In a business there should be one person coordinating TSCM specialists, legal support, security, and, if needed, contact with police.
Do not call the SIM number if known, and do not message related accounts. That can trigger remote wiping, a change of operating mode, or destruction of other traces. The goal of the initial stage is to preserve the object’s state and information silence around the incident.
Get a consultation
A quick case assessment — no obligation
How to document the find without destroying evidence
The physical device, its data carriers, cables, fasteners, and packaging may have evidential value. Photographs, video, access-control records, visitor logs, maintenance tickets, and CCTV footage can matter just as much. Under the Criminal Procedure Code of Ukraine (including Articles 98–99), material objects and documents may, under certain conditions, be sources of evidence; a specific procedural assessment is made by authorised bodies. General principles for handling evidence in criminal investigations are also described in UK Home Office — Evidence in criminal investigations.
If it is safe and does not require approaching a potentially dangerous object, record:
- a general view of the room and the exact location of the find;
- several angles of the object without moving it;
- distance to a workstation, meeting table, socket, network equipment, or window;
- the date and exact time of discovery, and the full name of the person who first saw the item;
- who entered the area after discovery and what they did;
- what drew attention: a new object, an opening, a cable, an unusual indicator, a change in mounting;
- recent repairs, cleaning, equipment installation, contractor visits, and any unauthorised access.
Do not edit original photos and videos, and do not send them through services that compress or alter metadata. Create working copies and keep originals separately. For corporate systems, immediately preserve CCTV, access-control logs, Wi-Fi and network equipment logs, and facilities tickets — automatic retention periods can be short.
Keep a simple chain-of-custody log: who received the item or digital medium, when, from whom, and in what condition. Pack, shield, or transport the device yourself only after agreeing with law enforcement or a specialist. Poor shielding, removing a battery, or placing a powered device in unsuitable packaging can change its state or create additional risk.
Do not post photographs of the find on social media before consulting specialists. Appearance alone does not always reliably establish a module’s function, and a public post can warn those involved and complicate establishing the facts.
What a professional inspection after a find should include
Finding one device does not mean the threat is gone. It may be part of a wider scheme, work with other modules, or sit in a zone where conversations are only partly accessible. After initial documentation, it is advisable to check all rooms, adjacent technical areas, and related systems. See also finding bugs and hidden cameras.
A professional response usually includes:
- documenting the original state and location of the object before removal;
- identifying the device: construction, power source, storage media, interfaces, markings, and available identifiers;
- assessing how data is transmitted or stored without unjustified actions that could alter the device’s state;
- surveying the radio-frequency environment, bearing in mind that not all devices transmit continuously;
- physical and optical inspection of sockets, cable routes, furniture, ventilation elements, lighting, and equipment;
- checking wired lines and network equipment if the threat model assumes use of building infrastructure;
- access analysis: when and by whom the device could have been installed, and what work or visits preceded it;
- a final report with photographs, inspection methods, established facts, limitations, and recommendations.
Legal characterisation depends on who installed the device, what information was obtained, where it happened, and whether lawful authority existed. Not every unknown module is an eavesdropping device, and suspicion alone does not prove an offence. Violation of privacy is addressed, among other provisions, in Article 182 of the Criminal Code of Ukraine. Separately, understand when law enforcement may lawfully intercept private communications.
Found a suspicious device? ProDefence helps you act without losing evidence
ProDefence specialists conduct professional TSCM surveys, document the discovery site, check premises for other technical leakage channels, and prepare a structured technical report. Where needed, work is coordinated with counsel, security, and authorised bodies.
Do not dismantle the find yourself. Contact ProDefence through the official website form, briefly describe the location and circumstances of discovery, and do not share confidential details with outsiders. We will explain a safe order of next steps and the limits of possible examination.
Response to a find
Found a bug or hidden camera?
Describe the location and circumstances without unnecessary detail on open channels. ProDefence will help preserve traces and inspect the premises — without “we will find everything” guarantees.
No DIY device disassembly. No unfounded promises.
