🔒 Real Case Studies 💼 For Business

When IT Disposal Goes Wrong Real Data Breach Case Studies, and the Lessons

Some of the largest data-security penalties on record did not come from hackers. They came from old hard drives, servers, and even a photocopier that were disposed of without the data being destroyed. These are three real cases, what went wrong, and the simple controls that would have prevented every one of them.

ISO/IEC 27001:2022 Certified NIST 800-88 Data Sanitisation Serialised Certificates

The Quick Answer

What do IT disposal data breaches have in common?

In almost every case, the data was never destroyed, and nobody could prove where the equipment went. A device was handed to the wrong party, with no verified destruction, no certificate, and no chain of custody, and it resurfaced with the data intact, often on an auction site. The fix is the same every time: destroy the data to a recognised standard, get a certificate for every device, and track each asset from your office to the point of destruction.

When people picture a data breach, they picture a hacker. But some of the most expensive breaches on record involved no hacking at all. They happened because a business threw out, sold, or handed off old IT equipment without making sure the data on it was gone. The information was not stolen through a firewall. It walked out the door on a hard drive, and the company had no idea until it turned up in someone else's hands.

These cases are worth studying because they are entirely preventable, and because the failures they reveal are common. The three below span finance and healthcare, and involve servers, hard drives, and a leased photocopier. They were penalised overseas, under US and UK law, but the failures behind them would breach Australia's Privacy Act just as squarely. Each one ends with a clear, cheap lesson that any Australian business can apply today.

ITC

Written by the ITC Asset Management team. ITC is a Sydney-based IT asset disposition provider operating since 2018, holding ISO/IEC 27001:2022, ISO 14001:2015, ISO 9001:2015, and ISO 45001:2018 certifications, and destroying data to the NIST 800-88 standard with certificates and a documented chain of custody. Preventing exactly the failures described here is the work.

The Pattern Behind Every Disposal Breach

Before the cases, it helps to name the failure modes, because they repeat. A disposal breach is almost never one big mistake. It is a chain of small omissions that each seem reasonable at the time: choosing a cheaper provider who is not a data-destruction specialist, assuming a device has been wiped when it has only been collected, skipping the certificate because the job felt routine, and forgetting that machines like printers and copiers store data at all.

Any one of these on its own can be survivable. Stacked together, they are how a business ends up with its customers' records on an auction site and a regulator on the phone. As you read the three cases, watch for the same gaps appearing again and again. The point is not that these were unusually careless organisations. Two of them were sophisticated, well-resourced institutions. The point is that without the right controls, this happens to anyone.

Case One: The $95 Million Moving Company

1

Morgan Stanley

$95M in penalties

This is the case that should be on every IT manager's wall. Starting in 2015, Morgan Stanley Smith Barney needed to decommission thousands of devices, including servers and hard drives, from its wealth-management data centres. Instead of using a specialist data-destruction firm, it hired a moving and storage company with, in the regulator's words, no experience or expertise in data destruction, and then failed to oversee it for years.

The movers sold thousands of the devices to third parties, and many were resold on an internet auction site with the customer data still on them. Morgan Stanley recovered some, but not the vast majority. The data was unencrypted: the firm had the encryption capability but had never switched it on. In a separate hardware refresh, another 42 servers went missing, all potentially holding unencrypted customer information. Around 15 million customers were affected.

The bill arrived in two parts. In 2020 the Office of the Comptroller of the Currency assessed a $60 million civil penalty, citing failures to assess the risk of decommissioning, to vet and monitor the subcontractor, and to keep an inventory of the customer data on the hardware. In 2022 the Securities and Exchange Commission added $35 million for breaching the safeguards and disposal rules. The SEC's enforcement director called the failures astonishing.

The lesson: the cheapest option is not a bargain when it is the wrong specialist. A mover is not a data-destruction provider. The controls that would have prevented this are ordinary: use a certified destruction specialist, keep an inventory of what holds data, track it with a chain of custody, and get a certificate that the data was destroyed.

Sources: OCC news release 2020-134; SEC press release 2022-168.

Case Two: The Photocopier That Remembered Everything

2

Affinity Health Plan

$1.2M settlement

This one is unsettling because the device involved is one almost nobody thinks of as a computer. Affinity Health Plan, a US health insurer, returned leased photocopiers to the leasing company at the end of their term. What it overlooked was that modern photocopiers contain a hard drive that stores an image of everything they scan, copy, and print. The drives were never wiped.

The breach came to light when a television network, investigating used-copier security, bought one of Affinity's returned machines and found confidential medical information on its hard drive. In total, the personal health information of an estimated 344,000 individuals was potentially exposed. In 2013, Affinity settled with the US Department of Health and Human Services for $1,215,780 for the HIPAA violation.

The lesson: your data lives in more places than you think. Any device with storage is a data device, and that includes photocopiers, multifunction printers, network gear, and old backup tapes. A disposal process that only covers the obvious computers and phones leaves the forgotten machines to become the breach.

Source: US HHS Office for Civil Rights, photocopier breach case.

Case Three: The Certificate That Was Not True

3

Brighton and Sussex University Hospitals NHS Trust

£325,000 fine

An NHS trust in England engaged a contractor to destroy around a thousand hard drives holding highly sensitive patient and staff data. The trust believed the drives were being destroyed. Instead, the individual doing the work sold a number of them, and drives containing the confidential data turned up for sale on an internet auction site, where a member of the public bought them and found the records.

In 2012 the Information Commissioner's Office issued a fine of £325,000, at the time the largest it had ever imposed. The failure was not that the trust did nothing. It was that it trusted an unverified process and had no proof, no genuine certificate of destruction, and no chain of custody confirming that each drive had actually been destroyed rather than diverted.

The lesson: a promise to destroy is not proof of destruction. This is exactly what a serialised certificate of destruction and a documented chain of custody exist to prevent. Ask for the certificate, check it lists the serial numbers, and use a provider whose process you can verify, not just take on trust.

Source: UK Information Commissioner's Office, 2012 monetary penalty.

The Cost, in Numbers

Three breaches, none involving a hacker, all from equipment disposed of without destroying the data. Figures from named regulators.

$95M
Combined US penalties against Morgan Stanley for improper hardware decommissioning
Source: OCC (2020) and SEC (2022)
$1.2M
Affinity Health Plan HIPAA settlement over unwiped photocopier hard drives
Source: US HHS Office for Civil Rights (2013)
£325k
NHS trust fine after drives meant for destruction were sold online
Source: UK ICO (2012)
42%
Of second-hand drives sold online still held recoverable data
Source: Blancco and Kroll Ontrack study

What the Three Cases Have in Common

Different countries, different industries, different equipment, and yet the same handful of failures. Each one maps to a control that would have stopped it.

What went wrong The control that prevents it Wrong provider (a mover, a contractor) Use a certified destruction specialist No record of what held data Keep an inventory of data-bearing assets Equipment untracked after collection Documented chain of custody Destruction assumed, never proven Serialised certificate of destruction Forgotten devices (copiers, tapes) Cover every device with storage
Every breach above is a row on the left. Every fix is on the right, and none of them is expensive or complicated. Together they are simply what a responsible disposal process looks like.

How to Make Sure It Does Not Happen to You

The controls that would have prevented all three cases fit into a short, repeatable process. This is what a safe IT disposal looks like for an Australian business.

01

Inventory what holds data

Before anything leaves, list the equipment being retired and mark which items store data. Remember the ones that are easy to forget: photocopiers and multifunction printers, network devices, backup tapes, and any loose drives. You cannot protect what you have not counted.

02

Choose a certified destruction specialist, not the cheapest hauler

Use a provider whose actual business is secure data destruction and IT asset disposal, with information-security certification and destruction to the NIST 800-88 standard. The Morgan Stanley lesson is that saving money on the provider is how the largest bills are made. Our guide on how to choose a responsible e-waste recycler covers what to check.

03

Insist on a documented chain of custody

Your equipment should be logged and tracked, ideally by serial number, from the moment it leaves your site to the point it is destroyed. This is the control that stops a device being quietly diverted, sold, or lost along the way.

04

Get a serialised certificate for every device

A promise is not proof. A certificate of data destruction that records the serial number and method for each item is your evidence that the data was actually destroyed, and it is what an auditor or regulator will ask to see.

05

Destroy the data, do not just delete it

Deletion and formatting leave data recoverable. Drives must be sanitised to the NIST 800-88 standard or physically destroyed. See certified data destruction for how this is done and verified.

The Maths: Prevention Costs a Fraction of the Breach

What makes these cases sting is not just the size of the penalties. It is how cheap the prevention would have been by comparison. Every control that would have stopped them, a certified destruction provider, an inventory, a chain of custody, and a certificate, is a routine line item, not a capital project. Set against a $95 million outcome, a $1.2 million settlement, or a record regulatory fine, the cost of doing it properly rounds to nothing.

And the penalty is only the visible part of the bill. None of these figures include the cost of the investigation, the legal fees, the mandatory breach notifications, the remediation, or the reputational damage of having your customers read that their records were found on an auction site. For a bank or a hospital, the trust cost can dwarf the fine. A business weighing whether certified disposal is worth the spend has the answer in front of it: the organisations in this article would each have paid many times over to go back and do it the cheap, correct way.

The uncomfortable truth is that most disposal breaches are not decisions to cut corners. They are the result of nobody owning the process, so the old equipment goes to whoever is cheapest or nearest, and the questions that would have surfaced the risk are never asked. Assigning that ownership, and using a provider who answers those questions as a matter of course, is the entire fix. It is also, by a wide margin, the cheapest insurance a business can buy.

The one-line takeaway

You will never be fined for destroying your data too thoroughly. Every case in this article came from destroying it too little, or not proving it at all. Certified destruction with a certificate and a chain of custody is the difference between a routine disposal and a headline.

Would This Breach an Australian Business?

The penalties above were issued in the US and UK, but the failures behind them map directly onto Australian obligations. The same mistakes here would be just as serious.

The Australian rules that apply

  • Privacy Act 1988, APP 11.2, requires reasonable steps to destroy or de-identify personal information no longer needed
  • Notifiable Data Breaches scheme, an exposure like these would likely be a reportable breach to the OAIC and affected individuals
  • OAIC penalties, up to $50 million or more for a serious or repeated interference with privacy
  • APRA CPS 234, information-security obligations for regulated financial entities, including asset disposal

🛡 What that means in practice

  • The duty is yours, engaging a contractor does not transfer the obligation to protect the data
  • Proof matters, without a certificate and chain of custody you cannot show you took reasonable steps
  • Reputation, a notifiable breach becomes public, and the cost is rarely just the penalty
  • Prevention is cheap, certified destruction with documentation costs a tiny fraction of any of these outcomes

Frequently Asked Questions

Common questions about the data-breach risk in IT disposal.

Morgan Stanley used a moving and storage company with no data-destruction expertise to decommission servers and hard drives holding unencrypted customer data, and failed to oversee it. Thousands of devices were sold on and resold at auction with the data intact. The OCC fined it $60 million in 2020 and the SEC added $35 million in 2022, a combined $95 million.

Yes. Modern photocopiers and multifunction printers contain a hard drive that keeps images of what they scan, copy, and print. Affinity Health Plan returned leased copiers without wiping those drives, exposing an estimated 344,000 people's health information, and settled for $1.2 million. Treat any copier, printer, or network device as a data-bearing asset.

Yes. Engaging a contractor does not transfer your obligation to protect the data. In the NHS case, a contractor sold drives that were meant to be destroyed, and the trust was fined £325,000. Under Australia's Privacy Act the duty stays with you, which is why you need a provider you can verify and a certificate proving destruction.

A chain of custody is a documented record tracking each asset from your site to the point of destruction, ideally by serial number. In every case above, the equipment became untracked once it left, so nobody could stop it being diverted or sold. A chain of custody is the control that closes that gap.

Almost certainly. Under the Privacy Act 1988, APP 11.2 requires reasonable steps to destroy personal information you no longer need, and an exposure like these would likely be reportable under the Notifiable Data Breaches scheme, with penalties reaching $50 million or more. Financial entities also face obligations under APRA CPS 234.

Inventory what holds data, including copiers and tapes, use a certified destruction specialist rather than the cheapest hauler, insist on a documented chain of custody, get a serialised certificate for every device, and make sure data is destroyed to the NIST 800-88 standard rather than just deleted. See our guide on the hidden data risk in retired IT hardware.

No. Deletion and formatting leave data recoverable, which is why 42 percent of second-hand drives in one study still held data. For business equipment, drives should be sanitised to the NIST 800-88 standard or physically destroyed, with a certificate. For a personal device, see how to securely wipe a laptop before recycling.

Keep the serialised Certificate of Destruction and the chain-of-custody record for every disposal. These record which device was destroyed, by which method, and when, and they are your evidence that you took reasonable steps under the Privacy Act. Without them, you cannot prove the data was destroyed if you are ever asked.

The ones nobody thinks of as computers: photocopiers and multifunction printers, backup tapes, network switches and routers, uninterruptible power supplies with logging, loose or spare hard drives in a drawer, and decommissioned servers left in a store room. The Affinity Health Plan breach came from a copier. A safe disposal starts by inventorying every one of these, not just the laptops and desktops.

Not on its own. Morgan Stanley is one of the largest financial institutions in the world, and it was fined $95 million because the disposal itself was handed to the wrong party with no oversight. Safety comes from the controls, a certified specialist, an inventory, a chain of custody, and a certificate, not from the size of the business doing the disposing.

Retiring business IT and want to avoid these mistakes? Contact our team or call 1300 048 226.

Dispose of IT the Way These Companies Wish They Had

ITC destroys data to the NIST 800-88 standard with Blancco certified erasure or witnessed shredding, tracks every asset by serialised chain of custody, and issues a certificate for each device, so you can always prove the data was destroyed.

✓ ISO/IEC 27001:2022 ✓ NIST 800-88 ✓ Serialised certificates ✓ Full chain of custody

Book Your Free Collection

Request a callback