Data RecoveryPlaybookSeptember 16, 202512 min read

The First 60 Minutes After a Mass Delete

An incident playbook for IT: freeze further damage, classify the loss, use Trash and Recycle Bin correctly, and restore to a side path before you overwrite anything live.

David Wilson
David Wilson
Security Specialist
The First 60 Minutes After a Mass Delete
Share
Key takeaways
  • Stop the bleeding: pause sync clients and revoke risky tokens before you restore.
  • Classify: delete vs overwrite vs hide vs account lockout — each path is different.
  • Native recycle tools are the first restore source, not Takeout and not a full tenant export.
  • Restore to a side path. Verify. Then copy back.

Minute 0–10: freeze, do not “fix”

The instinct is to restore immediately. If a sync client or attacker is still connected, restore becomes a race you lose. First:

  • Identify which account and which machine last modified the tree (Drive activity / OneDrive version history / audit logs if you have them).
  • Pause Drive for desktop / OneDrive / Offline Files on suspect PCs. Unplug is acceptable.
  • If an admin session looks wrong, reset that password and revoke sessions. Do not wait for a perfect forensic picture.
  • Stop well-meaning colleagues from emptying Trash “to help.”

Minute 10–20: classify the incident

What you seeLikely classFirst restore tool
Items in Trash / Recycle BinDeleteRestore from recycle, then verify
Files present but contents wrongOverwrite or ransomwareVersion history; do not restore from Trash
Files missing locally, still in the web UISync / filter / selective syncSee sync-conflict playbook
Cannot sign inLockout / offboardingIdentity first, then mailbox/user restore

Minute 20–40: native restore only

Work the recycle path that matches the product:

  • Google Drive: user Trash, then Shared Drive trash (managers), then admin recovery if the user was recently deleted.
  • OneDrive / SharePoint: first-stage Recycle Bin, then second-stage, then site restore if a whole site vanished.
  • Mail: Deleted Items, then Recover Deleted Items, then compliance content search if holds apply.

Do not start a Google Takeout or a tenant-wide eDiscovery export in the first hour unless recycle is already empty. Those jobs are slow and they are archives, not surgical restore.

Minute 40–60: side path and samples

Restore a slice — one folder, one mailbox folder — to a location named for the incident date. Open PDFs, Office files, and a few threads with attachments. If samples are wrong, stop. Restoring the entire tree on top of live data is how you destroy a newer copy that survived in another user’s My Drive.

Write a five-line incident log: what disappeared, when, who froze what, what you restored, what is still missing. That log is the handoff to the next hour (backup copy, vendor ticket, or legal).

What not to do

  • Re-enable sync “just to see if it comes back.”
  • Restore over the production path before sampling.
  • Assume Takeout will include items already gone from Google.
  • Wipe the suspect laptop before you image it if you may need forensics.

For overwrites, use version history restore. If recycle is already empty, continue with when native recovery windows expire.

Frequently asked questions

Incident ResponseData RecoveryMass DeleteIT AdminPlaybook
Free backup checklist

Get the IT backup checklist

A one-page policy template for Gmail, Drive, Calendar, and Microsoft 365 — plus new guides when we publish. Questions? Email support@celerosoft.com.