Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    contact@mansfieldtech.us

The FBI's Media Destruction Program

Right machines, wrong everything before them: what the DOJ Inspector General found in 2024 and 2025

Introduction

This case study is different from the others on this site. Nobody was breached, nobody was fined, and the destruction itself, when it finally happened, was done correctly on the right equipment. It is here because the organization involved is the FBI, whose Asset Management Unit sanitizes media to National Security Agency standards and NIST guidelines, and whose destruction contractor did what its contract said. The Department of Justice Office of the Inspector General still found enough wrong to issue an emergency advisory to the Director. Every problem it found sat between the moment a drive left a computer and the moment it reached the machine.

Everything below is drawn from two public OIG documents: Management Advisory Memorandum 24-093, issued August 21, 2024 after site visits in October 2023 and February 2024, and the OIG's April 1, 2025 audit of the FBI's media destruction services contract.

The program as designed

The FBI centralizes destruction. As of June 2024, its Asset Management Unit received retired electronics from headquarters, the National Capital Region offices, and 36 field offices across the country and Puerto Rico: desktops, laptops, servers, hard drives, USB drives, optical discs, and phones. A Property Turn-in Team takes custody at intake and stages the items in pallet-sized boxes. A Media Destruction Team, staffed by contractor technicians under a $21.6 million contract awarded in September 2022, disassembles the devices, groups like components, and sanitizes them with a degausser, a shredder, and a disintegrator. The contract requires every memory component to be treated as though it holds sensitive or classified information.

On paper, that is a sound program. It is also, in its equipment, the same three-machine approach we run on our trailer.

What the Inspector General found

1. Extracted drives were not counted

The FBI affixes property tags and classification labels to the chassis of a computer or server, not to the hard drive inside it. When a field office pulls the drive and ships it for destruction, the tag stays with the chassis and the drive becomes, in the OIG's words, a standalone asset that nobody is tracking. Intake staff told the OIG that field offices may not say how many drives they shipped, so quantities received could not be checked against quantities sent. Computers sometimes arrived with no hard drive at all, and intake personnel confirmed they would not ask why. The same was true of drives pulled from Top Secret computers, which travel separately by Defense Courier Service to save shipping cost and arrive with no property label and no individual record.

The root of it was a policy gap. The FBI's property policy treated internal hard drives as expendable assets with a life expectancy under two years, so it required accountability only for removable drives. DOJ's own policy statement, meanwhile, requires accountability for all portable IT equipment with memory. Two policies, one drive, no owner.

2. Extracted media was not marked

FBI policy since 2013 has required that fixed storage media be labeled with its classification at the moment it is removed from a system, and that small media like flash drives be marked as far as their size allows. The OIG found extracted drives and thumb drives arriving with no classification marking at all. A drive that held Secret information and a drive that held nothing look identical on a pallet.

3. The facility did not secure what it was holding

During the October 2023 visit, the OIG photographed an open pallet-sized box in the intake work area labeled "NON-ACCOUNTABLE," holding unmarked drives alongside drives marked Unclassified and Secret. Staff said such boxes sat unsecured for days or weeks until full. On the warehouse floor, the OIG found a container dated January 2022 with its shrink wrap torn, boxes open, and Secret-marked hard drives visible. Because extracted drives were the lowest destruction priority, pallets waited on shelves as long as 21 months.

The facility is shared with logistics, mail, and IT fulfillment operations. In May 2024 it had 395 people with active access, including 28 task force officers and 63 contractors from at least 17 companies, with no physical barrier between them and the pallets. A roll-up door to the destruction area was not lowered at night. A camera was not working, and other areas had no coverage. The supervisor and the contractor both confirmed they would not know if someone took drives from a pallet.

The FBI's explanation was that the facility was an accredited open-storage area for material up to Secret. The OIG asked for the accreditation and found an interim approval granted in 2015 that expired in March 2016. Final accreditation was issued in January 2024, after the OIG's visit. The FBI's destruction policy, meanwhile, set no timeframe for destruction at all, so a 21-month wait did not violate it.

4. The contract had no way to measure the work

The April 2025 contract audit found that the contractor supplied its sixteen technicians, filed its monthly reports, and invoiced accurately. It also found that the statement of work contained no quality assurance measures, that the FBI was not using available data to judge productivity, that the Media Destruction Team was operating without standard operating procedures or other written guidance, and that required contractor assessment reports were completed late. The FBI agreed with all four recommendations.

Why the destruction itself was right

It is worth being fair to the FBI here. The machines were the right machines. The method, degauss then shred for magnetic media and disintegrate for solid-state, is what NSA/CSS Policy Manual 9-12 requires. The contractor performed. The FBI concurred with every recommendation, installed secure cages in the intake area by February 2024, finalized the facility's accreditation, drafted a new Physical Control and Destruction of Classified and Sensitive Electronic Devices and Material Policy Directive, and committed to tracking extracted drives by serial number from the field office to the shredder.

The lesson is not that the FBI is careless. It is that destruction is the easy part, and an organization with cleared people, listed equipment, and a $21 million contract still let the boring steps slide: counting, labeling, staging, timing, watching, and writing it down.

The mistakes, and what we would have done about each

  • No serial-level inventory at extraction
    The failure that made every other failure invisible. Our program design starts here: every drive gets its own serial record the moment it leaves a chassis, tied to the parent asset tag, and that record is the first line of the chain of custody. If you cannot say how many drives you sent, you cannot say how many were destroyed.
  • No classification marking on the drive itself
    Labels belong on the media, not the box around it. We write the marking step into the extraction procedure, with a color scheme for media too small for a full label, exactly as the FBI's own 2013 directive already required.
  • Staging for months in a shared warehouse
    This is the strongest argument for mobile destruction there is. A drive destroyed at the field office on the day it is pulled is never on a pallet, never in a shared building, never in a box with torn wrap, and never shipped anywhere. The queue the OIG photographed does not exist when the shredder comes to the drive.
  • No destruction timeframe in policy
    A policy with no clock permits a 21-month wait. We write timeframes into media sanitization policies, with the DoD SAP manual's 30-day limit on accumulated waste as the reference point, and a staging control that says what happens to media that misses it.
  • Lowest priority for the most numerous item
    The FBI processed capitalized assets and Top Secret systems first and loose extracted drives last, which is why the drives piled up. Priority should follow data risk and quantity, not the dollar value of the chassis the data came out of.
  • Physical security that had lapsed on paper
    An accreditation that expired in 2016 and a camera that did not work are the kind of thing a periodic review catches. If you must stage media, we help specify the controls: enclosure, access list, camera coverage, and a review date. If you do not have to stage it, do not.
  • A contract with no quality measures and no SOPs
    The contractor met its deliverables because the deliverables were headcount and reports, not verified destruction. We help clients write destruction statements of work that specify sampling, verification, throughput, and certificate content, and we build the operating procedures and training a destruction team runs on. This is also the core of the buy-or-outsource analysis: a program without procedures fails whether the machines are yours or a vendor's.
  • Two policies that disagreed about a hard drive
    The property policy called an internal drive expendable; the security policy called it accountable. We reconcile property, security, and IT policies into one media sanitization policy that leadership signs and technicians can follow.

Lessons for your organization

  1. Count at extraction. The serial number of the drive, not the asset tag on the chassis, is the unit of accountability.
  2. Mark the media. If it held classified or sensitive data, it says so on the device, from removal to destruction.
  3. Shorten the distance between extraction and destruction to zero if you can. Every day and every mile between them is exposure. Witnessed on-site destruction removes the staging problem instead of managing it.
  4. Put a clock in the policy. Timely sanitization is a requirement only if the policy says what timely means.
  5. Measure the vendor, not the invoice. Headcount and monthly reports prove the contractor showed up. Sampling, verification, and certificates prove the data is gone.

How our technical consultation applies

Most of what the OIG recommended is program design, and program design is what our technical consultation does. We build media sanitization policies that reconcile property, security, and IT rules; write extraction, marking, staging, and destruction procedures with timeframes; design chain-of-custody records from serial capture to certificate; specify statements of work and quality measures for destruction contracts; train the people who run the machines; and give you a written buy-or-outsource recommendation based on your volume and standard. And for the largest problem the OIG found, the months of staging in a shared building, we offer the simplest fix: the truck comes to the drive, and the drive is gone before it can become a pallet.

Sources

Written by Christopher McDevitt with AI assistance.

About the author. Christopher McDevitt is the founder of Mansfield Technologies, a service-disabled veteran-owned company that performs on-site data destruction to NSA/CSS 9-12 and NIST 800-88. He spent ten years in the U.S. Army Signal Corps and six years supporting the U.S. Intelligence Community. More about the company.

More case studies

Retiring hardware? Start with the destruction.

Request a custom quote