Researchers Bought 614 New USB Drives. 75 Had Someone Else's Data.
75 of 614 new USB drives held other people's photos and documents, from chips recycled out of phones, TVs, printers and a server. What it means for ITAD.

Researchers bought 614 USB drives sold as new. On 75 of them, they recovered someone else's data: private photos and videos, a recorded conversation, documents, source code. One drive held 10,298 images, most of them private.
The drives were new. The memory chips weren't. The data traced back to phones, smart TVs, printers, voice recorders and navigation systems: devices that were thrown away, stripped for parts, and had their chips sold on as new.
Somewhere in that chain, a device was "recycled" without its storage being erased. For anyone in ITAD, that's the part worth sitting with.
- 75 of 614 "new" USB drives held other people's data, from memory chips recycled out of discarded devices.
- The chips came from phones, smart TVs, printers, an in-car display and even a server's management module, all devices with storage soldered onto the board.
- If your process only sanitizes removable drives, check what happens to every other board with a memory chip on it.
"In Search of Lost Data: A Study of Flash Sanitization Practices," by researchers from FAU Erlangen-Nürnberg, Leiden University of Applied Sciences, Albstadt-Sigmaringen University and MSAB, posted to arXiv in May 2025. The drives were ordered in 2018. Findings in sections 1 to 4 are the researchers'; sections 5 to 7 are our analysis.
1. What the researchers found
The research groups ordered low-cost USB drives from suppliers on Alibaba, deliberately choosing the cheapest promotional products, at roughly $2 to $4 per drive for 2 GB and 4 GB models. Each drive was imaged and examined with file-carving tools.
| Measure | Result |
|---|---|
| Drives acquired | 650 |
| Drives fully analysed | 614 |
| Drives with non-trivial user data | 75 (more than 12%) |
| Attributed to recycled chips | at least 73 (two held test photos written by the supplier) |
"Non-trivial user data" meant data clearly distinguishable from random noise, such as a viewable photo. The material recovered included photos, videos, voice recordings, documents, archives and source code. One drive contained 10,298 images, most of a private nature. Another held a recording of a private conversation.
2. Where the chips came from
By reverse-searching images and examining operating-system files, the researchers identified what many of the chips had previously been part of: Android devices, Chrome OS devices, Linux systems, smart TVs (most of them Samsung), printers and voice recorders. Their chart of identified systems also lists an IBM IMM, the management module built into IBM servers, a JAC Motors in-car display, and TomTom navigation.
Their conclusion: "the USB drives were not reused as a whole but the chips have been recycled."
3. Why it happens
The paper describes an informal electronics recycling sector in China where valuable components are recovered from discarded devices, next to a USB drive manufacturing industry centred on Shenzhen. The economics are simple. On eMMC spot markets, the researchers note, a 64 GB chip cost around $7, so a working chip pulled from a scrapped device is worth reselling. They also note "strong incentives to declare old as new."
If nobody erased the chip before the device was scrapped, its old contents go with it into the new product.
Spotting a reused chip is hard. The researchers found scratches, glue, flux, paint, irregular stamps and handwritten notes on some chips, but no external factor clearly correlated with data being present. The findings clustered within individual supplier batches.
4. What the study doesn't show
- How common this is today. The drives were ordered in 2018 from the cheapest end of the promotional market. The study doesn't measure chip reuse across mainstream retail products.
- Whose devices they were. No individuals or organizations were identified, and nothing suggests any source device passed through a certified ITAD facility.
- Which link failed. Data survived somewhere between the original owner and the recycled chip. The study can't say whether the owner, a collector, a recycler or a broker skipped sanitization.
5. The blind spot: storage soldered onto the board (analysis)
Most ITAD programs, and most of the conversations we have with operators, are built around drives: pull the HDD or SSD, wipe or destroy it, issue a certificate. So here's a question worth asking on your own floor: which devices come through that have storage you never pull? The source devices in this study were mostly the other kind, where storage is soldered onto the board and there's no drive to pull. One was a server's own management module.
| Device type | Where the data lives | How to handle it |
|---|---|---|
| Phones and tablets | Soldered flash (eMMC or similar) | Software-controlled sanitization where it exists. A plain factory reset isn't reliable on unencrypted devices (see below) |
| Chromebooks and thin laptops | Often soldered flash, not a removable SSD | Treat as data-bearing; use a sanitization method that reaches the soldered storage, or destroy it |
| Smart TVs, printers, navigation units, recorders | Soldered flash on the mainboard | Often no verifiable sanitization method; physically destroy the storage before the board leaves custody |
| Servers | The management controller (such as IBM's IMM) has its own flash, separate from the data drives | Include it in the server's sanitization scope; wiping the drives doesn't touch it |
| IoT and in-vehicle units | Soldered flash or memory cards | Same rule: sanitize verifiably, or destroy the storage |
Factory resets. SERI, which publishes R2v3, makes the point directly: unencrypted Android devices that have been factory reset "show no data when one visually inspects the device," but "when using a commercial data recovery software, a scan will often return pictures, contacts, and messages that are still accessible." It adds that manual resets "can be effective where data is encrypted from the initial setup of the device, but not effective when the device is unencrypted or was encrypted later."
When there's no reliable method. NIST SP 800-88 Rev. 2 notes that destruction "may be the only option" when clear or purge "cannot be effectively applied." For a TV or printer mainboard, that's often the honest answer.
6. Recycling isn't destruction
A board sent for materials recovery can be stripped for valuable parts before anything is shredded or smelted. That's how a chip outlives the device it came from. Unless you've sanitized or physically destroyed the storage before it leaves your custody, assume it may be resold.
R2v3's Appendix A, the "Downstream Recycling Chain," exists because your responsibility doesn't end at the loading dock. SERI describes it as a network of pre-qualified and audited downstream vendors. Five questions worth asking each one:
- Do you remove or destroy memory chips before boards go to materials recovery?
- Do you harvest components for resale, and which ones?
- Where do boards go after you, and are those vendors qualified too?
- What evidence do you return per device or per lot?
- If storage arrives intact, what do you do with it?
Then record the route for every data-bearing device you handle: sanitized, destroyed, or sent downstream intact, and to whom. "Sent to recycler" isn't a disposition.
7. Where reCore fits
reCore's station sanitizes the drives in PCs and servers running its Windows or Linux environment. It chooses a purge method per drive, verifies the result, and keeps a per-drive record that includes the drive's disposition (reuse, transfer or destroy) and the downstream vendor it went to. See the data wipe page.
It does not sanitize the embedded storage in phones, smart TVs, printers or similar devices. Those need their own process: a verifiable sanitization workflow for the device type, or physical destruction of the storage, recorded per device. For removable drives, our SSD reuse vs shredding guide covers the options.
Conclusion
A $3 USB stick shouldn't carry a stranger's photos. In this study, 75 did, because chips from discarded phones, TVs and printers were harvested and resold without anyone erasing them. We don't think the lesson is about USB sticks. Every board with a memory chip on it is a data-bearing asset until its storage has been dealt with, and "recycled" doesn't mean "destroyed."
Sources
- J. Schneider et al., In Search of Lost Data: A Study of Flash Sanitization Practices, arXiv:2505.14067, May 2025 (drives ordered 2018).
- SERI, Discussion on Logical Data Sanitization in R2v3, updated November 29, 2022.
- SERI, Specialty Process Requirements, Appendix A, Downstream Recycling Chain.
- NIST, SP 800-88 Rev. 2, September 2025, Section 3.1.3.
Frequently asked questions
Can a brand-new USB drive contain someone else's data?
Yes. In a study by researchers from FAU Erlangen-Nürnberg, Leiden University of Applied Sciences, Albstadt-Sigmaringen University and MSAB, 75 of 614 low-cost USB drives sold as new contained non-trivial user data such as photos, videos, voice recordings and documents. The researchers attribute at least 73 of them to recycled memory chips.
Where did the recycled chips come from?
From the data recovered, the researchers identified former use in Android devices, Chrome OS devices, Linux systems, smart TVs (mostly Samsung), printers and voice recorders, and their chart also lists an IBM server management module (IMM), an in-car display and TomTom navigation. Their findings indicate the chips were recycled, not the USB drives as a whole.
Is a factory reset enough to sanitize a phone?
Not always. SERI notes that unencrypted Android devices that have been factory reset can look empty, yet commercial data recovery software will often still find pictures, contacts and messages. It says manual resets can be effective where data was encrypted from initial setup, but not when the device was unencrypted or encrypted later.
How old is this study and how far does it generalize?
The drives were ordered in 2018 from suppliers on Alibaba, deliberately choosing the cheapest promotional drives, and the paper was posted to arXiv in May 2025. It shows what can happen at the low-cost end of the market; it does not measure how common chip recycling is across all flash products today.
What should an ITAD facility do with devices that have soldered storage?
Treat them as data-bearing. Use a verifiable sanitization method for the device type where one exists, and physically destroy the storage where one doesn't. Record what was done per device, and confirm with each downstream vendor what happens to boards and memory chips.
Can you tell a recycled chip by looking at it?
Not reliably. The researchers opened the drives and found scratches, glue, flux, paint, irregular stamps and handwritten notes on some chips, but no external factor clearly correlated with data being present. The data findings did cluster by supplier batch.
reCore Research Lab
OfficialCompliance & Security Group
Technical research group specializing in NIST SP 800-88, IEEE 2883, SERI R2v3 standards, and forensic data recovery testing.
Automate Testing & Evidence for R2v3 Operations
Deploy reCore across hundreds of devices simultaneously with zero-touch PXE or USB boot. Generate SHA-256 verified PDF erasure certificates with separation of duties enforcement.
Related Guides & Research
Continue exploring compliance standards, firmware sanitization, and hardware diagnostics.

Overwrite, Block Erase or Crypto Erase: Choosing the Wipe Method per Drive, and Verifying Each One
The right wipe method depends on what each drive supports, and each method needs a different check. How to choose per drive, what to do when purge isn't available, and how to verify it.

5%, 10% or 100%? How Much of a Wiped Drive You Should Read Back
NIST, ADISA, IEEE 2883 and R2v3 each set a different verification number, and two of them don't measure the same thing. What each requires, and how to choose.

SSD Reuse vs Shredding: What Makes Reuse Defensible, and What Your Contract Should Say
NIST SP 800-88 Rev. 2 advises against shredding modern storage for anything but low-sensitivity data. What SSD reuse needs to be defensible, and the contract terms to agree.
Stay Ahead in Data Sanitization & ITAD Compliance
Join enterprise IT managers and electronics refurbishers receiving our monthly technical standards breakdowns, NIST/R2v3 audit tips, and benchmark releases.