Browse > Home / Data Security / Buy a used hard drive on eBay, get government secrets for free!

| Subcribe via RSS

Buy a used hard drive on eBay, get government secrets for free!

May 14th, 2009 | Brian Wahoff | Posted in Data Security
Bookmark and Share

Data DestructionImagine it, you purchased a computer on eBay, plug it in, and find top secret missle defense secrets. What would you do? This is the situation a research group at Longwood University found themselves in after purchasing a used hard drive from the popular auction site.

This hard drive reportedly contained files from Lockheed Martin, a large US military contractor. The data recovered included: test launch procedures for the Terminal High Altitude Area Defense (THAAD) ground-to-air missile defense system, security policies, blueprints of facilities and social security numbers for individual employees.

A representative from Lockheed Martin is quoted in the article as saying:

Lockheed Martin is not aware of any compromise of data related to the Terminal High Altitude Area Defense program. Until Lockheed Martin can evaluate the hard drive in question, it is not possible to comment further on its potential contents or source.

Fortunately, this drive as purchased as part of a controlled study to see what information could be recovered from used hard drives and did not fall into the wrong hands. The study also uncovered other sensitive information including bank account details, medical records, confidential business plans, financial company data, personal id numbers, and job descriptions.

The drives were bought from the UK, America, Germany, France and Australia by BT’s Security Research Centre in collaboration with the University of Glamorgan in Wales, Edith Cowan University in Australia and Longwood University in the US.

A spokesman for the project said they found 34 per cent of the hard disks scrutinized contained ‘information of either personal data that could be identified to an individual or commercial data identifying a company or organization.’

Even though the information in this case did not fall into the wrong hands, this story illustrates the importance of having a controlled data destruction process in every organization. Ask yourself this: can you track every computer, every hard drive after it is pulled from production? Do you know for a fact that every hard drive is wiped or destroyed? If you cannot answer yes to both questions, you owe it to yourself to work with a vendor that can fill this gap.

A hat tip to ExportLawBlog for their analysis of the incident.

Related posts:

  1. Data Destruction: Is One Pass Overwriting Enough? There is some controversy regarding data destruction in the IT...
  2. Stimulus Bill significantly modifies HIPAA regulations Buried within the huge American Recovery and Reinvestment Act (a.k.a,...
  3. Hacking the Dot-Matrix Printer It sounds like something out of a bad spy movie,...
  4. 5 Questions to ask your Data Destruction Company When you replace your computers, what happens to the data...
  5. Do you know who your friends are? It sounds like a plot out of one of a...

EPC is a provider of IT asset recovery, data destruction, computer recycling, hard drive shredding, used computer sales, website hosting, and more throughout the US and Canada. EPC is a member of the Basel Action Network and its data destruction processes have been certified by NAID. EPC has been in business for over 25 years and is a wholly owned subsidiary of CSI Leasing, Inc. To learn more about the services we offer, see our home page.

One Response to “Buy a used hard drive on eBay, get government secrets for free!”

  1. Daily News About Ebay : A few links about Ebay - Thursday, 14 May 2009 11:38 Says:

    [...] Buy a used hard drive on eBay, get government secrets for free! [...]