Researchers bought 228 phones from PropertyRoom.com, a top auction house for US police departments, and found many had not been wiped and had no PIN or passcode
Countless smartphones seized in arrests and searches by police forces across the United States are being auctioned online without … Mastodon: @briankrebs@infosec.exchange . Tweets: @mattjay , @distributeddave , and @rr_edmonds Mastodon: BrianKrebs / @briankrebs@infosec.exchange : Countless smartphones seized in arrests and searches by police forces across the United States are being auctioned online without first having the data on them erased, a practice that can lead to crime victims being re-victimized, a new study found. … Tweets: Matt Johansen / @mattjay : Researchers bought cell phones that were seized by law enforcement and found none of the data was wiped... “...one had the PIN on the back ... The message chain on that phone had 24 Experian and TransUnion credit histories”. [image] @distributeddave : Police auction off many of the items they come into possession of. This includes cellphones. In a study led by @stack__trace we asked: are police wiping phones before they sell them? @briankrebs wrote about our study. In this 🧵, I'll give some highlights. https://krebsonsecurity.com/ ... RR Edmonds / @rr_edmonds : Researchers at the University of Maryland last year purchased 228 smartphones sold “as-is” from https://propertyroom.com/, which bills itself as the largest auction house for police departments in the United States. https://krebsonsecurity.com/ ...
Context & Ripple Effects
The University of Maryland study turns the spotlight on the last unexamined link in the seized-phone chain: what happens after police are done with a device. The corpus has already documented how much data law enforcement touches on these phones — Cellebrite's work extracting data from locked phones across 20 states shows departments systematically pull contents from devices in custody — so unwiped handsets reaching a top auction house like PropertyRoom.com is the predictable downstream failure.
It is also not an isolated slip in police data hygiene: months earlier, the SweepWizard app leaked location and names on officers and 5,770 suspects through a simple misconfiguration. Together the two stories sketch law enforcement as a recurring, under-audited custodian of sensitive civilian data.
First-order effects
- Buyers of the 228 as-is phones acquired crime victims' personal data with no PIN or passcode standing in the way — re-victimizing people whose only connection was that police once held their phone.
- PropertyRoom.com and its police-department suppliers now own the exposure: the study gives auditors, journalists, and attorneys a concrete procurement trail showing which agencies shipped live-data devices to auction.
Second-order effects
- Auction intermediaries serving law enforcement will be pushed toward certified-wipe attestations and chain-of-custody checks before listing seized devices, because one documented breach shifts liability onto their platform.
- Departments that already extract data via tools like Cellebrite face a second copy problem — forensic pulls stored on department systems plus physical handsets leaving custody — doubling the surface that needs destruction policies.
Third-order effects
- If the pattern holds, device disposition becomes a regulated step in police workflows rather than a surplus-property afterthought, with state procurement rules requiring verifiable erasure — mirroring how the corpus shows ad hoc police data practices (impersonation-driven location lookups, misconfigured apps) eventually forced formal controls.
The trend: Law enforcement is emerging as a systemic weak point in consumer data protection, where seized-device custody, forensic tooling, and sloppy disposal repeatedly expose civilians long after the original incident.