• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • LOGIN
  • Law Office ManagerHOME
  • Book StoreBook Store
  • WebinarsWebinars
  • LOGIN
  • Manage Your Account
  •  
Law Office Manager

Law Office Manager

  • Hiring
  • Increasing profits
  • Technology
  • Billing
  • Managing staff
  • More! ⇩
    • Newsletter Archive
    • Time tracking
    • Client relations
    • Termination
    • Tool Box
    • Risk management
    • Recordkeeping
    • Cartoons
    • Reader tips
    • Purchasing & leasing
    • Marketing
    • Managing the office
    • Information security
    • Your career
    • Working with lawyers
    • Employee benefits
    • Compliance
    • Workplace Safety
  • Special Reports

Is your firm’s sensitive data being sold on eBay?

July 1, 2016

Ecommerce sites are reselling used electronics without permanently erasing data from them, according to The Leftovers: A Data Recovery Study recently released by Blancco Technology Group.

Based on an analysis of 200 second-hand hard disk drives and solid state drives purchased from eBay and Craigslist in the first quarter of 2016, 67 percent of the used drives contained personally identifiable information and 11 percent held sensitive corporate data, including company emails, CRM records, and spreadsheets containing sales projections and product inventories.

The study’s findings reiterate just how easy, common, and dangerous it is when businesses buy back and/or resell used electronics without properly wiping all data from them.

Recent examples of data breaches and backlash resulting from this mistake reiterate how important it is to improve this area of data security. As Paul Henry, IT Security Consultant for Blancco Technology Group, explains, “With the Ashley Madison hack, in particular, users who wanted to make sure all of their data was erased from the dating site put all of their trust into the site’s $20 ‘Full Delete’ program. Even though the obvious identifiers had been removed, enough information was left to expose the site’s users.

The big lesson for Ashley Madison—and any other type of business—should be to test that your deletion methods are adequate and to not blindly trust that simply ‘deleting’ data will truly get rid of all of it for good. Remaining data can still be accessed and recovered unless the data is securely and permanently erased.”

Key findings from the study include:

  • Company emails, CRM records, and spreadsheets are highly susceptible to leaks. Blancco’s digital forensics experts found company emails on 9 percent of the drives, followed by spreadsheets containing sales projections and product inventories (5 percent), and CRM records (1 percent).
  • Delete doesn’t always mean delete. On 36 percent of the used HDDs/SSDs containing residual data, users previously attempted to wipe the drives clean by dragging files to the ‘Recycle Bin’ or using the ‘delete’ button.
  • Quick formatted data can still be recoverable. A quick format was performed on nearly half (40 percent) of the used drives with lingering data found on them.

Despite proven capabilities, data erasure is still the lesser-known unicorn. Out of the 200 used HDDs and SSDs, only 10 percent had a secure data erasure method performed on them.

For Blancco Technology Group CEO, Pat Clawson, these findings are not surprising. “In even the most technology-inclined companies today, IT executives and CIOs often put most of their attention, resources, and budgets towards tackling ‘scary’ data security threats, such as backdoor attacks, extortion hacks, malicious insider intrusions, and malware. So investing in tools and methods to erase data from IT assets tends to sit low on their organization’s list of IT security priorities. But as our study shows, the dangers are just as precarious when data isn’t securely and completely erased.


Editor’s picks:

Trending HR issues your employee handbook should cover


Secrecy in the age of social media: six ways to keep sensitive practice information offline


The War Against Data Breaches:
What Law Firms Need to Know


Filed Under: Topics, Client relations, Information security, Managing staff, Managing the office, Risk management, Technology, Working with lawyers, articles Tagged With: Information security, Technology, Managing the office, Managing staff, Client relations, Working with lawyers, Risk management

Primary Sidebar

Free Reports

    • Guide to Advanced Hiring Techniques
    • Employee Morale in the Law Office
    • Workplace Bullying

Free Premium Reports

    • 7 Smart Cost-Cutting Strategies for Your Law Office
    • Guide to Advanced Hiring Techniques
    • Employee Morale in the Law Office
    • Workplace Bullying
    • 7 Proven Ways to Make Your Billing and Collections More Profitable
    • 7 Simple, Proven Steps to Hiring the Right Staff
    • 7 Policies Every Law Office Should Have

Download Current Issue

Current Issue

Recent Headlines

Billing: Should You Keep It In-House or Go Outsourced?

Year-End Reflections: Taking Stock of Your Law Office’s Successes and Challenges

Winter Safety Checklist for Parking Lots, Walkways, and Office Entrances

January To-Do List for a Busy Law Office Manager

Want to Work Smarter, Not Harder? AI Can Help You Do Just That

Your Career

Year-End Reflections: Taking Stock of Your Law Office’s Successes and Challenges

Want to Work Smarter, Not Harder? AI Can Help You Do Just That

Administrator a Key Player in Firm’s Ethics and Integrity

Reconnecting with Purpose: How to Invite Someone from the Past into Your Career Network

To Make a Point, Use the Body Language that Supports Your Words

Deliver Your Message

Footer

Return to the Top

Download the Current issue
Monthly Magazine Archive
Advertise in Law Office Manager
Download Media Kit

Become a Premium Member
Download a Sample Issue of LOM
Renew your Law Office Manager Membership
Manage Your Account
Contact Law Office Manager
About Law Office Manager
Terms & Conditions
Privacy Policy
Give Us Feedback


Copyright © 2025 Plain Language Media, LLLP • 1-888-729-2315