Knowledge Vault


Follow us





US government data found on HDD in Africa

Red faces at contractor

The safe disposal of old computer equipment is once again in the headlines after a hard disk drive (HDD) purchased from a market in Ghana was found to contain sensitive documents belonging to US government contractor Northrop Grumman.

The drive had belonged to a Fairfax, Virginia, employee who still works for the company and contained "hundreds and hundreds of documents about government contracts," said Peter Klein, an associate professor with the University of British Columbia, who led the investigation for the Public Broadcasting Service show Frontline.

Klein would not disclose details of the documents, but he said that they were marked "competitive sensitive" and covered company contracts with the Defense Intelligence Agency, the National Aeronautics and Space Administration and the Transportation Security Agency.

The data was unencrypted, Klein said in an interview. The cost? $40 (£24.60).

Northrop Grumman is not sure how the drive ended up in a Ghana market, but apparently the company had hired an outside vendor to dispose of the PC. "Based on the documents we were shown, we believe this hard drive may have been stolen after one of our asset-disposal vendors took possession of the unit," the Northrop Grumman said in a statement. "Despite sophisticated safeguards, no company can inoculate itself completely against crime."

A Northrop Grumman spokesman would not say who was responsible for disposing of the drive, but in its statement the company noted that "the fact that this information is outside our control is disconcerting."

Some of the documents talked about how to recruit airport screeners and several of them even covered data security practices, Klein said. "It was a wonderful, ironic twist," Klein said. "Here were these contracts being awarded based on their ability to keep the data safe."

According to Klein, it's common for old computers and electronic devices to be improperly dumped in developing countries such as Ghana and China, where locals scavenge the material for components, often under horrific working conditions.

Last year the US Government Accountability Office found that a substantial amount of the country's e-waste ended up in developing countries, where it was often dangerously disposed of.

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

The reporters bought seven hard drives, Klein said. The other drives contained sensitive information about their previous owners, including credit-card numbers, resumes and online account information.

Off-camera, sources in Ghana told the reporters that data thieves routinely scour these hard drives for sensitive information, Klein said.

Although that may be worrying to some, security experts say that there is already a vast quantity of this type of information available online from criminals who have stolen it from hacked computers.

Compared to hacking, stealing data from old hard drives is pretty inefficient, said Scott Moulton, an Atlanta data-recovery expert who teaches classes on data recovery. "It's a tremendous amount of work, so it's only going to be the bottom-of-the-barrel guys who would do that," he said. "It's happening on a small scale."



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

The financial economics of cloud email

This white paper evaluates cloud computing as a flexible alternative to your current IT capability that delivers tangible benefits including: projects delivered earlier, faster adoption to change, lower risk, reduced costs and easier to scale up or down services.

Beyond Dropbox: Requirements for Enterprise Secure File Sharing

This whitepaper explores the danger “Dropbox” type services pose for enterprises, and the security and compliance requirements for deploying enterprise-wide file sharing solutions.

Top 10 considerations for your IT operations management in the cloud

This paper explores ten questions every IT organization should answer to help determine their cloud based ITOM needs.

How to get your business ready for the 2012 Olympics

IT Manager: "I'm working on contingency plans to ensure that we can keep the business running whatever happens during the Olympics. Hopefully, it'll just be a case of letting people work from home but we need to be ready for anything".


CIO UK - Business - Technology - Leadership

Voice Applications in the Cloud

Watch this webcast to learn about new network and telecoms options.

Register now

Download the CIO BlackBerry App -
Access CIO's Content on the Move


The CIO UK BlackBerry App provides daily business and technology news, opinion and indepth features direct to your BlackBerry device.

Find out more

CIO Transformation Summit

CIO Roundtable:
The Private Cloud

Wed 29 Feb 2012
Tower 42, London, 7pm.

Join a select group of your fellow CIO's to discuss private cloud computing and how best to apply the private cloud to your organisation

Register here to book your place.



Knowledge Vault


* *