Tens of thousands of hard drives are improper IT disposal of or destroyed daily due to the rapid turnover of equipment in data-driven companies. According to a study, around 20 to 70 million end-of-life hard disk drives are generated per year in the US, and most of these end up in landfills since companies would rather discard outdated or damaged hardware rather than repair or recycle them. The accumulated e-waste not only presents a real threat to the environment, but it also becomes a potential pathway for threat actors to breach a company’s systems since some hard drives may contain residual sensitive data.Â
To protect against data breaches, organizations should practice proper technology disposal to avoid exposing sensitive information. The repercussions of incorrect hard drive disposal are considerable, so here’s what you need to know about the risks of improperly disposed devices, and how these can affect your business.Â
Financial Loss and Legal Penalties
Hackers frequently target discarded electronics, and most of them won’t hesitate to dig through piles of trash in landfills or go dumpster diving to harvest sensitive information. In some cases, a veritable hoard of data-rich hardware may fall right into their hands due to oversight. Back in 2016, Morgan Stanley failed to properly wipe and destroy data on decommissioned hard drives from two of their data centers. The devices were sold to a third party in 2020, which led to exposure of their client data. This resulted in a $35 million SEC penalty, plus $60 million in total fines. In 2023, it was reported that Morgan Stanley also agreed to pay a$6.5 million settlement to a coalition of six states, three years after the breach was first discovered.Â

Regulations mandate that all personal and sensitive data should be unrecoverable before hard drives and devices are recycled, discarded, or resold. Simply throwing devices in the trash or poor deletion methods are direct violations of data protection regulations like the GDPR (General Data Protection Regulation), which is imposed on businesses in Europe and the UK, as well as FACTA (Fair and Accurate Credit Transactions Act), which requires proper disposal of consumer information in the US. Non-compliance can result in fines up to €20 million in the EU, while US violators may have to pay up to $1.5 million in fines per year.
To prevent the risks of getting fined, data-driven companies should prioritize IT asset disposition, also known as business ITAD, for compliant data erasure. Effective ITAD involves using certified software to wipe away data, physically destroying devices, and managing the retrieval and disposal of tech devices from remote employees. ITAD prevents unauthorized personnel from recovering data, which helps organizations to avoid severe penalties which can lead to loss of business and damaged reputation.
Identity Theft and Fraud
Discarded devices from universities, banks, and healthcare institutions are a hot commodity among cybercriminals since these contain a wealth of information that they can exploit for personal gain. In 2021, it was reported that the personal information of more than 116,000 patients of the HealthReach Community Health Centers has been potentially compromised. The Maine-based health center discovered that a worker at a third-party data storage facility improperly disposed of hard drives that contained crucial patient information, such as dates of birth, Social Security numbers, and health insurance information, among others. At the time, HealthReach did not receive any reports of attempted misuse of the stolen data, but they warned their patients that there’s a risk that their information may be fraudulently used.
This incident highlights the importance of compliant disposal of IT equipment since failure to do so can potentially lead to identity theft or fraud. Hackers can exploit stolen data in various ways, and one of their most common tactics is using social security numbers, birthdates, and names to take out loans or open new bank accounts. They may commit financial fraud by using saved credit card or bank account information. They may even attempt to blackmail companies by threatening to leak sensitive information unless they get paid a certain amount of money. Since 1 out of 4 data breaches is caused by negligence, it’s important to train employees on the proper way to store and dispose of hard drives, and to keep devices secure at all times.
When it comes to wiping data from obsolete devices, clicking on ‘delete’ or doing a factory reset isn’t enough to protect sensitive information from wrongdoers. Work with professionals who specialize in IT asset disposition to dispose of hardware properly, and keep data safe from cybercriminals lurking in storage facilities, dumpsters, and landfills.