CYBER WELFARE

Protect your Digital Privacy

Recovering data from second-hand devices, and the other attacks that exploit what is left in memory

A phone sold online, a laptop left at the recycling centre, an external drive handed to a friend. For the person giving it away, the device has left the stage. For the person receiving it, sometimes, that is exactly where the story begins.

Recovering data from second-hand devices is the set of practices through which someone finds photos, documents and sign-ins left on a device that its previous owner believed they had emptied. Almost always, a person buying a used phone just wants a phone. But not always.

This post explains how these attacks happen across the whole life cycle of a device, from sale to disposal, and why almost all of them lose their power when the data has been properly erased. It is the threat-side companion to the recommendation on wiping data before passing on a device.

One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.

The starting point

You have got a new phone. The old one still works, so you list it on a classified ads site. Before posting it, you delete the photos from the gallery, remove a few chats and sign out of your banking app. It feels like enough.

The buyer switches it on and finds the home screen just as you left it. The gallery is empty, but the notes app still holds a photo of your identity card, taken years ago for a contract. The email app is still open. And the cloud service keeps syncing, that is, automatically copying to the device, the new photos you take with your new phone.

From that moment on, part of your digital life is no longer yours alone: it sits on an object that belongs to someone else.

Why a device that has not been wiped increases the risk

All the attacks that follow share one thing: they do not need to break in anywhere, because you handed them the device.

Normally, to reach your data, someone has to get past a password or a screen lock. With a device passed on without being wiped, those obstacles are often gone, and whoever holds it can examine it at leisure.

On top of that comes a very common misunderstanding. Deleting a file or emptying the bin usually does not erase its content: it only removes the reference that tells the system where it is. The same goes for a quick format, an operation that prepares a drive to receive new data without overwriting the old. How files survive that operation is explained in the post on recovering files from formatted drives: here we focus on who looks for that data, and where they find it.

1. Buying second-hand devices to look for data

In plain terms. Someone buys used phones, computers or drives not to use them, but to see what is on them.

How it works. Second-hand devices are cheap and easy to find: online listings, car boot sales, job lots sold off by businesses or shops. People looking for data buy them in quantity, knowing that some of them were passed on without a real wipe.

Why an unwiped device makes it possible. A device emptied only on the surface keeps most of its content. One erased with a secure procedure, on the other hand, has nothing left to recover: for someone looking for data, it is a wasted purchase.

Possible impact. Exposure of photos, documents, messages and saved passwords; material that can feed the other attacks described in this post.

What should make you suspicious. Buyers who insist on getting the device “as it is”, without a reset, or who seem more interested in its contents than in its condition.

How to protect yourself. A secure wipe before every sale, even if the device no longer works well. Even a device that will not switch on can have memory that is still readable.

2. Drives recovered from e-waste

In plain terms. A drive or memory chip that ended up as electronic waste is picked up by someone who, instead of disposing of it, tries to read it.

How it works. E-waste goes through collection, storage and dismantling before it is recycled, and the chain almost always works as it should. But a computer left next to a bin, a drive thrown out with general rubbish, or a batch of equipment sold on before processing can end up in the wrong hands.

Why an unwiped device makes it possible. People disposing of an old drive often assume that if it no longer works, the data no longer exists. That is not the case: the faulty part may be the electronics, while the surface that holds the data is intact.

Possible impact. Recovery of years of archives — photographs, tax returns, contracts — relating to you and your family, often without you ever finding out.

What should make you suspicious. Here there are almost no signals: the harm happens far away from you. That is why protection has to come beforehand.

How to protect yourself. A secure wipe before disposal while the device still works; for drives that no longer power on, asking the recycling centre or a specialist service for certified destruction; always taking equipment to official collection points.

3. Access to data during a repair

In plain terms. The device you take in for repair stays in someone else’s hands for days, and the person fixing it has the chance to look at things that have nothing to do with the fault.

How it works. For many repairs the technician needs your unlock code, or the device is handed over already unlocked. Almost all repair shops work properly, but in an isolated case someone may browse the gallery or copy files.

Why an unwiped device makes it possible. A repair is a temporary handover: everything on the device becomes accessible to whoever holds it. Where possible, a backup followed by a wipe reduces the content to nothing; where it is not, what matters is knowing what you are entrusting.

Possible impact. Viewing or copying of private photos, documents, conversations; access to accounts left open during the repair.

What should make you suspicious. Persistent requests for your unlock code for faults that do not require it, sign-in notifications on your accounts while the device is at the shop, recently opened files you did not touch.

How to protect yourself. A backup before handing it over, signing out of the most sensitive accounts, a repair mode or guest profile if the system offers one, and choosing recognisable repair centres. After collecting it, a check of recent sign-ins.

4. Accounts left connected and used by the new owner

In plain terms. Whoever receives the device finds your email, cloud storage or a social network still open in your name, and can use them.

How it works. A session is a sign-in that has already been verified: as long as it stays active, the service does not ask for the password again. If you pass on the device without closing your sessions, the person receiving it can read your email, see your synced photos, open your chats or, in some cases, change the password and take over the account. Sometimes the buyer simply notices; other times the access gets used.

Why an unwiped device makes it possible. Resetting the device, together with signing out of every account and removing it from the list of connected devices, closes all sessions. Without these steps, as far as your accounts are concerned, the old phone is still “you”.

Possible impact. Your email and chats read, access to your new photos, other passwords reset through your email.

What should make you suspicious. The old device still appears among those connected to your account, recent sign-ins from a town where you are not, messages marked as read that you never opened. The signs your data was not fully erased are gathered in a dedicated post.

How to protect yourself. Signing out of every account before passing the device on, removing it from your list of trusted devices, changing the password of your main email account if in doubt, and multi-factor authentication (MFA, a second check on top of the password) switched on.

5. Identity theft with the documents found

In plain terms. Using documents found on a device, someone presents themselves as you to banks, online shops or services.

How it works. Identity theft is the use of another person’s personal details to pretend to be them. Devices accumulate scans of identity cards, payslips, utility bills: exactly what is needed to open a contract or an account in your name.

Why an unwiped device makes it possible. Documents photographed “on the fly” end up in unexpected places: the gallery, the notes, email attachments, the downloads folder. Deleting a few photos is not enough; a secure wipe of the whole device is.

Possible impact. Contracts or loans you never asked for, payment reminders, a long process to prove it was not you.

What should make you suspicious. Letters or messages about services you never signed up for, unexpected payment demands, identity verification alerts for transactions you did not make.

How to protect yourself. A secure wipe, the habit of deleting document scans after use, and device encryption switched on. If it happens: report it to the authorities and to the organisations involved, keeping every communication as evidence.

6. Extortion with private photos

In plain terms. Someone finds intimate or very personal images on a device that was passed on, and threatens to share them unless they receive money or something else.

How it works. Images recovered from an old phone or computer can be used as leverage: a message arrives, often from an anonymous profile, with one or two images as proof and a demand. Whoever is making the threat relies on shame and haste.

Why an unwiped device makes it possible. The most private photos are often also the most hidden: secondary folders, messaging apps, old local backups. Precisely because nobody has looked at them in a long time, they are the ones people forget to delete.

Possible impact. Heavy emotional pressure, fear, isolation; in the most serious cases, the content being shared. The responsibility always lies with the person making the threat, never with the person being threatened.

What should make you suspicious. Messages from strangers that mention personal details, very short deadlines, a demand not to tell anyone.

How to protect yourself. A secure wipe before every handover, even to people you know. If it happens: do not pay and do not reply, keep the messages as evidence, talk to someone you trust and contact the police. When minors are involved, report it straight away. This is not something to face alone.

Summary table

AttackMain riskWhat should make you suspiciousEffective defences
Buying second-hand devicesContent recovered from a device emptied only on the surfaceBuyers interested in the contents, requests not to resetA secure wipe before selling
E-wasteFaulty drives that are still readableAlmost none: the harm happens far away from youWiping before disposal, certified destruction, official collection points
RepairAccess to data while the device is being fixedAccount sign-ins while the device is out of the houseBackup, signing out of accounts, repair mode
Accounts left connectedSessions still open in your nameDevice passed on still listed, unusual sign-insSigning out of accounts, removing the device, MFA
Identity theftDocuments used to pretend to be youServices you never requested, unexpected remindersA secure wipe, scans deleted after use, encryption
Extortion with private photosPressure using personal imagesMessages from strangers, short deadlines, secrecyA secure wipe, not paying, asking for help and reporting

What they have in common

Six different attacks, three defences that cut across almost all of them:

  1. A secure wipe before every handover — a device that no longer contains anything has nothing to offer, wherever it ends up. How to do it, step by step, is explained in the guide on how to wipe your data securely.
  2. Signing out of accounts and removing the device — it closes the doors that stay open even when the files are gone.
  3. Encryption switched on throughout the device’s life — encryption turns data into a form that can only be read with the right key, so it protects you even when wiping is not possible, such as with a faulty drive or a phone that will not switch on. The recommendation on encrypting your personal devices explains why.

These are not advanced measures: they are things to do once, at the right moment.

Protection checklist

  • ☐ A complete, verified backup before erasing anything
  • ☐ Signed out of email, cloud storage, social networks, chats and payment apps
  • ☐ Device removed from the list of devices connected to your accounts
  • ☐ Encryption switched on before the reset
  • ☐ A secure wipe or full reset, never just the bin or a quick format
  • ☐ Memory cards and external drives treated like the main device
  • ☐ For repairs: backup, signed out of sensitive accounts, repair mode if available
  • ☐ Faulty drives sent for certified destruction or taken to official collection points

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that a device you pass on keeps existing, and that its data can go through many hands
SkillsRecognising the moments in a device’s life cycle when data is most exposed
Secure BehaviourWiping and disconnecting before every handover, even to people you trust

Reference level: FL3 — Autonomous, with elements of FL2 — Beginner in the sections on repairs and connected accounts.

Conclusion

Someone recovering data from a used device usually does not know who you were, and does not care. They buy, collect or repair many devices, and find something on the ones that were passed on in a hurry.

That is why the most effective defence is also the simplest: a device leaves your home only after your data has left the device. To find out whether a device you have already passed on is still tied to you, the signs your data was not fully erased are the next step; for a broader picture of your situation, you can start with the digital resilience self-assessment.

Something to think about. How many devices have you sold, given away or thrown out in the last ten years, and how many of them could you say for certain were empty?

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.