How Digital Forensics Built a Defensible Timeline for Sonoma County’s Largest Wildfire
June 16, 2026
Sponsored Content
Presented by iDiscovery Solutions
When the smoke clears, the investigation begins.
Based in California, we face the ongoing threat of wildfires. The most recent major incidents, the Palisades and Eaton fires in January 2025, burned approximately 37,000 acres, claimed 30 lives, and destroyed more than 16,000 structures across Los Angeles County.
Thanks to the heroic efforts of firefighters and other first responders, these fires were eventually contained. Now, attention has shifted to how the fires started and who may be held responsible, as investigations and litigation begin to unfold. A wide range of electronic evidence may prove relevant, making digital forensic techniques essential for preserving and analyzing this data as part of the ongoing inquiry.
A previous fire our team investigated underscored the vast array of potential data sources involved and the complexity of preserving them. From mobile devices and security camera footage to utility logs and weather data, each source presents unique challenges for collection, authentication, and analysis.
The challenge
In 2019, a fire ignited in Northern California at a PG&E transmission line near a geothermal power plant. Known as the Kincade Fire, it became the largest wildfire in Sonoma County’s history, burning over 77,000 acres and destroying an estimated 167 homes before it was contained.
Our team was retained to investigate the actions taken by the geothermal facility in the period preceding the fire’s ignition. For safety and evidence preservation purposes, the plant was shut down, making rapid investigation and data preservation essential to facilitate its timely restart.
The approach
A digital forensics team was deployed to the site and began interviewing geothermal, mechanical, and electrical engineers to identify potential data sources. In addition to common sources such as email communications and standard operating procedure (SOP) documentation, the team identified several non-standard data sources that could be relevant to the investigation.
A strategy was developed to defensibly preserve each of the following:
- CCTV footage
- Two-way radio audio logs
- Circuit recloser logs
- Security access logs
- SCADA operations data
- Safety and operations logs
- Anemometer (wind) telemetry
- Mobile device SMS and video
While some of these sources were relatively straightforward to collect, others posed significant challenges, such as using a cherry picker to retrieve data from equipment mounted on poles, or entering pitch-black, shut-down turbine rooms to capture critical information.
From disparate data to a defensible timeline
Once the data had been preserved, the disparate and complex nature of the sources required constructing a clear, accessible timeline of events. Leveraging our specialist structured data team, we ingested each source, including emails, documents, audio, video, and log files, into a centralized repository for analysis. From there, individual entries within the log files were extracted and correlated, enabling the creation of a comprehensive, visualized timeline for effective review.
By visualizing the data in this way, we were able to clearly demonstrate that our client was not responsible for igniting the fire. The evidence showed unequivocally that our lines were powered down prior to the fire’s ignition at the PG&E transmission line.
The outcome
After investigating, the California Department of Forestry and Fire Protection (Cal Fire) determined that the fire was caused by PG&E equipment, specifically a high-voltage transmission line that failed during high winds. PG&E accepted this finding and later reached a $55 million settlement with Sonoma County to resolve criminal charges related to the fire.
What this means for the next fire investigation
In any investigation, success often hinges on identifying which data sources are in scope and acting quickly to preserve those most at risk. In this case, several critical log files faced imminent overwriting once plant operations resumed. Had that occurred, key evidence underpinning our findings would have been permanently lost. Rapid deployment of a digital forensics team capable of asking the right questions, prioritizing preservation, and engineering tailored workflows for non-standard data can make the difference between speculation and proof in high-stakes, time-sensitive matters.
How iDS approaches wildfire investigations
Our Digital Forensics team works seamlessly alongside our Structured Data and Visualization specialists to deliver a fully integrated view of fire investigations. This collaborative, multidisciplinary approach enables us to construct a clear, technically rigorous, and defensible narrative grounded not only in what the evidence shows, but also in what it definitively rules out.
Truth Through Data. Where expertise leads, defensible outcomes follow.
Must read intelligence for general counsel
Subscribe to the Daily Updates newsletter to be at the forefront of best practices and the latest legal news.
Daily Updates
Sign up for our free daily newsletter for the latest news and business legal developments.
