Some of the largest data-security penalties on record did not come from hackers. They came from old hard drives, servers, and even a photocopier that were disposed of without the data being destroyed. These are three real cases, what went wrong, and the simple controls that would have prevented every one of them.
In almost every case, the data was never destroyed, and nobody could prove where the equipment went. A device was handed to the wrong party, with no verified destruction, no certificate, and no chain of custody, and it resurfaced with the data intact, often on an auction site. The fix is the same every time: destroy the data to a recognised standard, get a certificate for every device, and track each asset from your office to the point of destruction.
When people picture a data breach, they picture a hacker. But some of the most expensive breaches on record involved no hacking at all. They happened because a business threw out, sold, or handed off old IT equipment without making sure the data on it was gone. The information was not stolen through a firewall. It walked out the door on a hard drive, and the company had no idea until it turned up in someone else's hands.
These cases are worth studying because they are entirely preventable, and because the failures they reveal are common. The three below span finance and healthcare, and involve servers, hard drives, and a leased photocopier. They were penalised overseas, under US and UK law, but the failures behind them would breach Australia's Privacy Act just as squarely. Each one ends with a clear, cheap lesson that any Australian business can apply today.
Written by the ITC Asset Management team. ITC is a Sydney-based IT asset disposition provider operating since 2018, holding ISO/IEC 27001:2022, ISO 14001:2015, ISO 9001:2015, and ISO 45001:2018 certifications, and destroying data to the NIST 800-88 standard with certificates and a documented chain of custody. Preventing exactly the failures described here is the work.
Before the cases, it helps to name the failure modes, because they repeat. A disposal breach is almost never one big mistake. It is a chain of small omissions that each seem reasonable at the time: choosing a cheaper provider who is not a data-destruction specialist, assuming a device has been wiped when it has only been collected, skipping the certificate because the job felt routine, and forgetting that machines like printers and copiers store data at all.
Any one of these on its own can be survivable. Stacked together, they are how a business ends up with its customers' records on an auction site and a regulator on the phone. As you read the three cases, watch for the same gaps appearing again and again. The point is not that these were unusually careless organisations. Two of them were sophisticated, well-resourced institutions. The point is that without the right controls, this happens to anyone.
This is the case that should be on every IT manager's wall. Starting in 2015, Morgan Stanley Smith Barney needed to decommission thousands of devices, including servers and hard drives, from its wealth-management data centres. Instead of using a specialist data-destruction firm, it hired a moving and storage company with, in the regulator's words, no experience or expertise in data destruction, and then failed to oversee it for years.
The movers sold thousands of the devices to third parties, and many were resold on an internet auction site with the customer data still on them. Morgan Stanley recovered some, but not the vast majority. The data was unencrypted: the firm had the encryption capability but had never switched it on. In a separate hardware refresh, another 42 servers went missing, all potentially holding unencrypted customer information. Around 15 million customers were affected.
The bill arrived in two parts. In 2020 the Office of the Comptroller of the Currency assessed a $60 million civil penalty, citing failures to assess the risk of decommissioning, to vet and monitor the subcontractor, and to keep an inventory of the customer data on the hardware. In 2022 the Securities and Exchange Commission added $35 million for breaching the safeguards and disposal rules. The SEC's enforcement director called the failures astonishing.
Sources: OCC news release 2020-134; SEC press release 2022-168.
This one is unsettling because the device involved is one almost nobody thinks of as a computer. Affinity Health Plan, a US health insurer, returned leased photocopiers to the leasing company at the end of their term. What it overlooked was that modern photocopiers contain a hard drive that stores an image of everything they scan, copy, and print. The drives were never wiped.
The breach came to light when a television network, investigating used-copier security, bought one of Affinity's returned machines and found confidential medical information on its hard drive. In total, the personal health information of an estimated 344,000 individuals was potentially exposed. In 2013, Affinity settled with the US Department of Health and Human Services for $1,215,780 for the HIPAA violation.
Source: US HHS Office for Civil Rights, photocopier breach case.
An NHS trust in England engaged a contractor to destroy around a thousand hard drives holding highly sensitive patient and staff data. The trust believed the drives were being destroyed. Instead, the individual doing the work sold a number of them, and drives containing the confidential data turned up for sale on an internet auction site, where a member of the public bought them and found the records.
In 2012 the Information Commissioner's Office issued a fine of £325,000, at the time the largest it had ever imposed. The failure was not that the trust did nothing. It was that it trusted an unverified process and had no proof, no genuine certificate of destruction, and no chain of custody confirming that each drive had actually been destroyed rather than diverted.
Source: UK Information Commissioner's Office, 2012 monetary penalty.
Three breaches, none involving a hacker, all from equipment disposed of without destroying the data. Figures from named regulators.
Different countries, different industries, different equipment, and yet the same handful of failures. Each one maps to a control that would have stopped it.
The controls that would have prevented all three cases fit into a short, repeatable process. This is what a safe IT disposal looks like for an Australian business.
Before anything leaves, list the equipment being retired and mark which items store data. Remember the ones that are easy to forget: photocopiers and multifunction printers, network devices, backup tapes, and any loose drives. You cannot protect what you have not counted.
Use a provider whose actual business is secure data destruction and IT asset disposal, with information-security certification and destruction to the NIST 800-88 standard. The Morgan Stanley lesson is that saving money on the provider is how the largest bills are made. Our guide on how to choose a responsible e-waste recycler covers what to check.
Your equipment should be logged and tracked, ideally by serial number, from the moment it leaves your site to the point it is destroyed. This is the control that stops a device being quietly diverted, sold, or lost along the way.
A promise is not proof. A certificate of data destruction that records the serial number and method for each item is your evidence that the data was actually destroyed, and it is what an auditor or regulator will ask to see.
Deletion and formatting leave data recoverable. Drives must be sanitised to the NIST 800-88 standard or physically destroyed. See certified data destruction for how this is done and verified.
What makes these cases sting is not just the size of the penalties. It is how cheap the prevention would have been by comparison. Every control that would have stopped them, a certified destruction provider, an inventory, a chain of custody, and a certificate, is a routine line item, not a capital project. Set against a $95 million outcome, a $1.2 million settlement, or a record regulatory fine, the cost of doing it properly rounds to nothing.
And the penalty is only the visible part of the bill. None of these figures include the cost of the investigation, the legal fees, the mandatory breach notifications, the remediation, or the reputational damage of having your customers read that their records were found on an auction site. For a bank or a hospital, the trust cost can dwarf the fine. A business weighing whether certified disposal is worth the spend has the answer in front of it: the organisations in this article would each have paid many times over to go back and do it the cheap, correct way.
The uncomfortable truth is that most disposal breaches are not decisions to cut corners. They are the result of nobody owning the process, so the old equipment goes to whoever is cheapest or nearest, and the questions that would have surfaced the risk are never asked. Assigning that ownership, and using a provider who answers those questions as a matter of course, is the entire fix. It is also, by a wide margin, the cheapest insurance a business can buy.
You will never be fined for destroying your data too thoroughly. Every case in this article came from destroying it too little, or not proving it at all. Certified destruction with a certificate and a chain of custody is the difference between a routine disposal and a headline.
The penalties above were issued in the US and UK, but the failures behind them map directly onto Australian obligations. The same mistakes here would be just as serious.
Common questions about the data-breach risk in IT disposal.
Morgan Stanley used a moving and storage company with no data-destruction expertise to decommission servers and hard drives holding unencrypted customer data, and failed to oversee it. Thousands of devices were sold on and resold at auction with the data intact. The OCC fined it $60 million in 2020 and the SEC added $35 million in 2022, a combined $95 million.
Yes. Modern photocopiers and multifunction printers contain a hard drive that keeps images of what they scan, copy, and print. Affinity Health Plan returned leased copiers without wiping those drives, exposing an estimated 344,000 people's health information, and settled for $1.2 million. Treat any copier, printer, or network device as a data-bearing asset.
Yes. Engaging a contractor does not transfer your obligation to protect the data. In the NHS case, a contractor sold drives that were meant to be destroyed, and the trust was fined £325,000. Under Australia's Privacy Act the duty stays with you, which is why you need a provider you can verify and a certificate proving destruction.
A chain of custody is a documented record tracking each asset from your site to the point of destruction, ideally by serial number. In every case above, the equipment became untracked once it left, so nobody could stop it being diverted or sold. A chain of custody is the control that closes that gap.
Almost certainly. Under the Privacy Act 1988, APP 11.2 requires reasonable steps to destroy personal information you no longer need, and an exposure like these would likely be reportable under the Notifiable Data Breaches scheme, with penalties reaching $50 million or more. Financial entities also face obligations under APRA CPS 234.
Inventory what holds data, including copiers and tapes, use a certified destruction specialist rather than the cheapest hauler, insist on a documented chain of custody, get a serialised certificate for every device, and make sure data is destroyed to the NIST 800-88 standard rather than just deleted. See our guide on the hidden data risk in retired IT hardware.
No. Deletion and formatting leave data recoverable, which is why 42 percent of second-hand drives in one study still held data. For business equipment, drives should be sanitised to the NIST 800-88 standard or physically destroyed, with a certificate. For a personal device, see how to securely wipe a laptop before recycling.
Keep the serialised Certificate of Destruction and the chain-of-custody record for every disposal. These record which device was destroyed, by which method, and when, and they are your evidence that you took reasonable steps under the Privacy Act. Without them, you cannot prove the data was destroyed if you are ever asked.
The ones nobody thinks of as computers: photocopiers and multifunction printers, backup tapes, network switches and routers, uninterruptible power supplies with logging, loose or spare hard drives in a drawer, and decommissioned servers left in a store room. The Affinity Health Plan breach came from a copier. A safe disposal starts by inventorying every one of these, not just the laptops and desktops.
Not on its own. Morgan Stanley is one of the largest financial institutions in the world, and it was fined $95 million because the disposal itself was handed to the wrong party with no oversight. Safety comes from the controls, a certified specialist, an inventory, a chain of custody, and a certificate, not from the size of the business doing the disposing.
ITC destroys data to the NIST 800-88 standard with Blancco certified erasure or witnessed shredding, tracks every asset by serialised chain of custody, and issues a certificate for each device, so you can always prove the data was destroyed.