When companies plan a hardware refresh, most of the attention goes to the new equipment. One of the most expensive data-security failures on record shows why the old equipment deserves just as much care.
What happened
In September 2022, the U.S. Securities and Exchange Commission announced that Morgan Stanley Smith Barney would pay a $35 million penalty over how it disposed of old hardware. According to the SEC:
The firm hired a moving and storage company with "no experience or expertise in data destruction services" to decommission its devices.
The movers sold thousands of devices to a third party. Some still held customer data and were resold on an internet auction site.
During a separate hardware refresh, 42 servers that may have held unencrypted customer data went missing.
About 15 million customers' personal data was put at risk. As of the SEC's 2022 order, the firm had not recovered most of the devices.
The real risk is the old hardware
New equipment comes with warranties, support contracts, and a clear owner. Old equipment often goes into a closet, onto a pallet, or into the hands of whoever quotes the lowest price for hauling it away. That's where data walks out the door.
A retired laptop or server can hold customer records, financial data, and credentials long after it stops being useful. If you can't show where every device went and what happened to its data, you carry the risk.
Four questions to ask before anything leaves your building
Whoever handles your retired IT equipment should be able to answer these clearly:
Who has custody of every device from pickup to final disposition? You should know where your equipment is at every step.
How is the data removed? Look for data erasure to NIST 800-88, and physical destruction for drives that can't be wiped.
What paperwork do I get, and is it per device? Documentation is what proves the job was done.
Do I get an R2 certificate of destruction when it's done?
If your current vendor can't answer all four, that's a problem worth fixing before your next refresh.
How RePower handles it
RePower is an ITAD and IT buyback company in Buffalo Grove, Illinois, handling about 25,000 devices a month. We accept any IT equipment in any condition, and data security comes with every job:
NIST 800-88 certified data erasure, with a serialized certificate of erasure for every job
Physical destruction when a drive can't be wiped
R2 certificates of destruction provided
We pay for items with resale value. Items without resale value still get the same secure data handling and are recycled responsibly. We pick up equipment anywhere in the country and log the serial number of every device we receive, so you know where each one is at every step.
Don't let your refresh become a headline
Before your next refresh, talk to a vendor that can answer all four questions.
Send us your equipment list and get a free quote within 24 hours, or call (224) 360-1500 (8 AM–4 PM CT, Monday–Friday).
