In February 2025, the U.S. Attorney’s Office for the District of Columbia announced a guilty plea that should be required reading for every federal contracting officer responsible for IT disposition. A driver at an industry-leading, triple-certified IT asset disposition vendor had been stealing and reselling government devices for over a year — using fraudulent Certificates of Destruction to conceal the thefts from agencies that included the U.S. Capitol Police and USAID. The case reframes government ITAD supply chain risk as a logistics and contracting problem, not a certification problem.
What Happened in the Wisetek/Iron Mountain Incident?
IT asset disposition (ITAD) — the secure process of retiring, sanitizing, and routing end-of-life technology — depends on an unbroken chain of custody from the originating agency to verified destruction. Between February 2019 and September 2023, Nikhil Parekh worked as a driver for Wisetek, an international ITAD firm operating out of Maryland and later Virginia. Wisetek held active NAID AAA, e-Stewards, and R2 certifications during the relevant period and was acquired by Iron Mountain in September 2024 for $51.9 million.
Between July 2022 and August 2023, Parekh and unnamed co-conspirators — fellow drivers — systematically diverted IT assets before they reached secure destruction facilities. Court documents record two specific incidents among many:
In January 2023, Parekh removed personal computers, laptops, and other IT assets from a contractor of a federal executive branch agency. In March 2023, an additional 400 laptops, 1,300 smartphones, and 70 servers were stolen during a retirement job at a U.S. government warehouse in Landover, Maryland. Prosecutors later stated that Parekh “had difficulty recalling precisely how many thousands of devices he had personally taken.”
The conspiracy was concealed through fraudulent Certificates of Destruction. After diverting the devices to secondhand electronics resellers in the Washington, D.C. area, Parekh and his co-conspirators caused the company to issue certificates to the victim agencies falsely attesting that the assets had been wiped and destroyed according to contract specifications. Only 10 to 15 percent of the devices handled during the relevant period were actually destroyed as contracted.
The scheme was uncovered in summer 2023 when a secondhand reseller in Haymarket, Virginia purchased stolen devices — one of which was traceable. Parekh pleaded guilty on December 10, 2024, to one count of conspiracy to commit an offense against the United States (selling stolen goods), was sentenced May 5, 2025 to 12 months of probation plus $10,000 in restitution, and was debarred by USAID on August 28, 2025 for three years. USAID OIG investigations remain active and ongoing.
Why Didn’t Certifications Prevent This?
Wisetek held the three certifications that government contracting officers are typically instructed to require: NAID AAA for data destruction, e-Stewards for environmental stewardship, and R2 for responsible recycling. The scheme operated for more than a year inside a facility that passed certification audits during the same period.
Three structural weaknesses allowed that outcome.
First, certification audits evaluate documented controls and sampled transactions. They do not observe every pickup, every vehicle, every transfer point. A driver diverting assets during a routine route is outside the scope of what scheduled or even unannounced audits reliably detect.
Second, many certification schemes permit certified companies to select their own auditors. Industry stakeholders have since launched public petitions calling on e-Stewards, R2 (SERI), and i-SIGMA (NAID AAA) to reform this practice and publicly investigate the Wisetek breach. The argument is straightforward: independence requires the audited entity not to control the auditor selection.
Third, the ultimate evidence of destruction — the Certificate of Destruction — is a document. A driver with access to company systems, or complicit with someone who has that access, can generate a compliant-looking Certificate for devices that were never destroyed. If the intake and transit phases are not independently verified, the Certificate is attesting to something the issuer cannot actually confirm.
Government ITAD supply chain risk is therefore not reducible to “pick a certified vendor.” Certifications remain a necessary floor. They are not a sufficient ceiling.
Unsure whether your agency’s ITAD contract covers the transit-phase gaps the Wisetek case exposed? Take the free ITAD Readiness Assessment →
What Do FISMA and FedRAMP Not Prescribe?
Federal information security frameworks govern system-level controls with substantial rigor. The Federal Information Security Management Act (FISMA) mandates annual security assessments that include asset disposition controls. NIST Special Publication 800-88 Revision 2 (September 2025) specifies sanitization methods by media type and confidentiality level. NIST 800-171 governs Controlled Unclassified Information (CUI) handling including disposition. FedRAMP controls apply to cloud service providers and their infrastructure.
What these frameworks do not prescribe, at the level of specificity relevant to the Wisetek case, is the physical chain of custody during collection and transit:
- Vehicle specifications (GPS tracking, camera coverage, tamper-evident storage)
- Driver screening beyond baseline background checks
- Real-time asset tracking from the moment of pickup
- Independent verification that what was collected matches what arrived at the destruction facility
- Incident notification timelines when discrepancies appear
The standards reasonably assume that a certified vendor operating under contract has solved these operational questions. The Wisetek case demonstrates that this assumption can be wrong even when all the nominal controls are in place. Closing the gap requires treating government ITAD supply chain risk as a contracting exercise, not a standards-compliance exercise.
What Contract Terms Mitigate Government ITAD Supply Chain Risk?
The contracting response to the 2025 incident is straightforward: specify the operational controls that standards leave to vendor discretion, and make them contractual obligations with audit rights. Ten provisions should appear in every federal ITAD contract going forward:
Seal-tracked containers at the point of collection. Devices are placed into locked, tamper-evident containers the moment they leave the agency’s custody. The seal numbers are documented on the pickup manifest and verified intact at the destruction facility.
GPS-verified transport with continuous telemetry. Vehicles must stream location data to the agency on request, with any route deviation or unscheduled stop flagged for incident review.
Multi-camera cabin monitoring. Recorded video covering the driver seat, cargo area, and loading/unloading activity, retained for a specified period and available to agency investigators without subpoena.
Itemized asset tracking at pickup. Each device scanned, serialized, and logged into the chain-of-custody record at the originating facility — not at the vendor’s intake dock hours or days later.
Two-person custody at transfer points. No single driver or employee handles devices alone during intake, loading, transit, unloading, or pre-destruction staging.
Independent destruction verification. Witnessed destruction by cleared agency personnel, or a real-time video feed of the destruction process retained by the agency as immutable evidence, separate from vendor-issued documentation.
Serialized Certificates of Destruction cross-referenced to agency inventory. One certificate per device, matched to the agency’s asset tracking system. Aggregated batch certificates are not compliant.
Right to unannounced inspection. Agency representatives may inspect the vendor’s facility, processes, and records on reasonable notice — including interviewing drivers and reviewing vehicle telemetry.
Incident notification within 24 hours. Any discrepancy between pickup manifest and destruction manifest, any seal tampering, any missing device triggers formal notification to the contracting officer within 24 hours of vendor discovery.
Insurance floor with government as additional insured. Minimum $10 million cyber liability, $5 million general liability, $1 million crime and employee dishonesty coverage. Crime coverage is the provision the Wisetek incident most cleanly implicates.
Vendors who cannot or will not meet these provisions should not hold federal ITAD contracts. The False Claims Act exposure for fraudulent Certificates of Destruction, combined with suspension and debarment authority, provides enforcement teeth that post-hoc investigations like USAID’s now activate routinely.
Want to assess whether your current ITAD contract reflects these post-Wisetek standards? Take the free ITAD Readiness Assessment →
Where You Stand Matters
Government ITAD supply chain risk concentrates in the transit phase — the hours between when a device leaves agency custody and when it enters verified destruction. That phase sits almost entirely outside the framework of standards-based compliance that federal contracting officers are accustomed to verifying.
The Wisetek/Iron Mountain case will not be the last. It is the most documented, because a careless resale trail created evidence. The uncounted cases are the ones where stolen devices reached buyers who did not generate traceable transactions.
Agencies that rebuild ITAD contracts around physical custody controls, real-time telemetry, independent verification, and rapid incident notification close the gap. Agencies that continue to rely on certification status and post-destruction paperwork do not.
Ready to assess your agency’s ITAD readiness? SureDispose’s free assessment evaluates your current practices across chain-of-custody specifications, contract provisions, incident response timing, and independent verification — and connects you with providers matched to federal procurement requirements. Take the Assessment →
Further reading:
- U.S. Attorney’s Office, D.C. — Guilty Plea Press Release (February 4, 2025)
- USAID OIG Investigative Summary — Debarment (September 2025)
- NIST Special Publication 800-88 Rev. 2, Guidelines for Media Sanitization
- GAO Report on Federal IT Modernization and Legacy Systems (GAO-25-107795)
SureDispose is an independent advisory platform. We connect organizations with vetted ITAD service providers but do not perform disposition services directly. Providers compensate us for qualified introductions.