Unwiped servers and drives from NCIX appear on Craigslist
A security researcher found data relating to 3,848,000 orders on one server


Servers and disk drives from dissolved computer company NCIX have been found for sale on US trading site Craigslist, with all customer, partner and employee data still recoverable.
Although it's unclear who's selling them, one seller said they were helping the landlord get rid of equipment left in their warehouse after the Canadian company went bust last year.
Bleeping Computer reported that security consultant Travis Doering decided to try and buy one of the servers to investigate into whether they were being sold with any data still on them. After seeing one for sale on Craigslist, he set about buying it and was successful.
The seller said he was offering an entire server farm on behalf of the landlord. He also had 300 desktop computers as well as the 18 DELL PowerEdge servers and two SuperMicro servers with StarWind iSCSI software.
Apparently, NCIX had failed to pay the property owner CAD150,000 in rent and so he was trying to recoup the costs by selling the equipment, without clearing it securely.
One of the servers Doering bought contained the data from 3,848,000 orders placed between 2007 and 2010, including names, email addresses, company names, addresses, phone numbers and even payment data.
In all, there was payment data relating to more than 250,000 customers.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Another dataset included unsalted MD5 hashed passwords for 385,000 customers.
The seller's name was Jeff and although speculators think it could be NCIX's former CEO, Jeff Chiang, who wants to make some quick cash, Doering said he didn't think that was the case.
However, whoever is selling the equipment risks getting into serious trouble for essentially selling customer data illegally.
"Both sellers and buyers of the customer records, allegedly belonging to the retailer, can face harsh legal ramifications," High-Tech Bridge's CEO Ilia Kolochenko commented. "Under certain sets of circumstances it can be a serious criminal offense, however, it is too early to make any decisive conclusions prior to thorough investigation of the incident."
But, as NCIX has gone bust, compensation claims are unlikely to fly as there's no one to pay them except those selling the equipment and it's unlikely they'll have the funds to cover any costs like that.
"Nowadays, such negligence is unfortunately not all that uncommon, even amid operating and profitable companies, let alone bankrupt ones, Kolochenko added. "Many large organisations have been exposed for throwing away plaintext PII and other sensitive data of their customers on paper, hard drives or mobile devices.
"This is why certifications similar to ISO 27001 play an important role to ensure that at least the fundamental of information security management are properly implemented in a company."

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
The threat prevention buyer's guide
Whitepaper Find the best advanced and file-based threat protection solution for you
By ITPro Published
-
The business value of Zscaler Data Protection
Whitepaper Understand how this tool minimizes the risks related to data loss and other security events
By ITPro Published
-
BCDR buyer's guide for MSPs
Whitepaper How to choose a business continuity and disaster recovery solution
By ITPro Last updated
-
Three essential requirements for flawless data protection
Whitepaper Want a better CASB and stronger DLP? You have to start with the right foundation
By ITPro Published
-
Anticipate, prevent, and minimize the impact of business disruptions
Whitepaper Nine best practices for building operational resilience
By ITPro Published
-
Business value of ServiceNow security operations
Whitepaper Experience transformational gains from automating workflows and data-sharing among IT, security, and risk teams to rapidly remediate threats
By ITPro Published
-
Top ten ways to anticipate, eliminate, and defeat cyber threats like a boss
Whitepaper Improve your cyber resilience and vulnerability management while speeding up response times
By ITPro Published
-
Morgan Advanced Materials still unable to restore systems after January cyber attack
News Billion-pound manufacturing firm’s sites are still running processes manually nearly five months after its suspected ransomware attack
By Connor Jones Published