Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Security logs, medical records and missile data discovered in disused hard drives

Study involving university researchers in the UK, US and Australia, discovers an assortment of private data on ebay

A third, or 34 per cent, of disused hard drives still contain confidential data according to a new study, which found missile defence system data and media records on ebay purchases.

The study, sponsored by BT and Sims Lifecycle Services, researched by Wales’ University of Glamorgan, America’s Longwood University and Australia’s Edith Cowan University, also dug up secret data from the German Embassy in Paris and business dealings from a US bank.

Around 300 hard drives from he UK, America, Australia and other countries, bought through computer auctions and on eBay were studied.

“It is clear from the sensitive information revealed by this study that a wide range of organisations, businesses and individuals all over the world are fundamentally failing in their duty to properly manage sensitive data when their IT equipment passes outside of their control,” Sims Recycling Solutions Kumar Radhakrishnan said.

“It is vital to realise that residual data can still be accessed years after the equipment has been discarded and in the wrong hands could have not only financial consequences but potential implications for national security,” Radhakrishnan added.

The study’s most prominent discovery was that of a disk revealing details of test launch procedures for the Terminal High Altitude Area Defence (THAAD) ground to air missile system.

The disk also contained security policies, facility blueprints and employee social security numbers belonging to the system’s designer, aerospace manufacturer Lockheed Martin.

In Australia, a disk belonging to a nursing home was found, containing pictures of patients wounds.

A recent Verizon Business forensic data breach report found that data loss via portable hard drives accounted for one in 150, from a total of 285 million record breaches, and according to Mark Goudie, Verizon Business’ managing principal for investigative response in Asia Pacific, these numbers are insignificant.

“There is a lot of hype about the dangers of data leaks by portable media like USBs and laptops,” Goudie told CSO.

An investigation is currently underway at Lockheed Martin, and a spokesperson told Britain’s Telegraph that the company was not aware of any compromise of data related to the THAAD system.

"Until Lockheed Martin can evaluate the hard drive in question, it is not possible to comment further on its potential contents or source."

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: AAD, BT, Cowan, eBay, Edith Cowan University, Edith Cowan University, Lockheed Martin, Verizon
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: data breach, defence, edith cowan university, hard-disk drives, hard drives, lockheed martin, storage, usb
Latest Blog Posts
Whitepapers
  • SOA and Business Processes: Making the Connection
    Service-Oriented Architecture (SOA) is also complex, and one of its main characteristics is that an SOA system is comprised of multiple applications that are combined to accomplish critical business processes. Discussions of SOA can quickly grow so complex that the system’s main benefits to an organization are difficult to fully understand. This article discusses SOA Suite 11g, a family of products that take SOA to a new level and correct some of the problems caused by the very combination of components and multiplication of languages that make SOA a flexible, agile system.
    Learn more »
  • High Availability with Oracle Database 11g Release 2
    In this paper, we review the common causes of application downtime and discuss how technologies available in the Oracle Database can help avoid costly downtime and enable rapid recovery from unplanned failures and also minimize impact from planned outages. We also highlight new technologies introduced in Oracle Database 11g Release 2 that enable businesses to make their IT infrastructure even more robust and fault tolerant, maximize their return on investment on high availability infrastructure, and provide better quality of service to users.
    Learn more »
  • Top 5 Threat Protection Best Practices
    Small businesses are especially vulnerable to computer viruses and lost or stolen data, since they typically lack the IT resources to deal with these threats. Inadequately protected computers open the door to annoying infections, or worse, serious business disruption. Below are five simple and effective strategies to help you protect your business against an ever-increasing number of threats.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments