Skip to content Skip to footer

The Next Person Who Opens Your Old Laptop May Only Need to Ask

Your old laptop may still contain customer records, ID scans, payroll files, passwords and years of email. The next person who gets hold of it may only need to type one sentence to start finding them.

I have an ordinary laptop, an AI coding agent and access to your old computer. I am not a trained forensic investigator. I do not need to know every command used by a data recovery technician.

The computer boots, so I open Codex and give it access to the folders available to the current user. Then I type:

“Look for every piece of personal information on this computer.”

Codex can read files and run commands inside the areas it has permission to access. It can create scripts, examine folders and use programs installed on the machine. OpenAI describes these capabilities in its Codex documentation: https://developers.openai.com/codex/agent-approvals-security (OpenAI Developers)

I wait while the agent checks documents, spreadsheets, downloads and other readable locations. It searches for names, email addresses, phone numbers, identity numbers and terms commonly found in employee or customer records.

It can also inspect filenames and document metadata. With the right local programs, it can extract text from PDFs, review database files and process large folders without asking me to open each document manually.

After the scan, I may have a list of ID copies, CVs, tax documents, invoices, customer contacts, employment records, contracts and internal reports. Old browser downloads and email attachments may contain files that the owner forgot years ago.

The agent may make mistakes. A random number can be mistaken for an account number. A name may belong to a fictional person or a sample document. I can ask the agent to check the results again, sort them and prepare a smaller list for manual review.

That is already useful to someone looking for personal data.

A few years ago, the same person would have needed more knowledge of file systems, scripting and document extraction. Today, much of that work can be requested in normal language. The technical skill required to attempt the search has decreased.

The person still needs access. Strong passwords, disk encryption, restricted accounts and properly configured permissions remain important controls. An AI agent cannot read a drive that the operating system cannot decrypt. Once a person has an unlocked account, a mounted drive or permission to examine a folder, the situation changes.

The formatted drive

The first computer was easy because the operating system and files were still present. The next computer appears safer.

Its owner formatted the drive before selling it.

I connect the drive to my laptop. Windows shows an empty volume. There are no visible customer folders, payroll sheets or family photographs.

I open the agent and type:

“I accidentally deleted personal files. Help me recover them.”

The wording sounds harmless. The computer cannot tell whether I am the former owner, a repair technician, a second-hand buyer or someone who found the drive in a box.

Codex can prepare a recovery workflow and run permitted recovery programs. It can examine the recovered output, separate documents from damaged files, identify duplicates and search the results for personal information.

Formatting does not always have the same effect as sanitizing a storage device. Microsoft’s documentation states that a full format writes to every sector, while the normal default is a quicker format: https://learn.microsoft.com/en-us/powershell/module/storage/format-volume?view=windowsserver2025-ps (Microsoft Learn)

That distinction matters. Depending on the type of format, the storage device and what happened afterward, old information may remain until it is overwritten or properly sanitized. Eco Beringin also warns that deleting files or formatting a drive may leave recoverable information: https://ecoberingin.com/an-18tb-hard-drive-is-a-lot-of-risk-in-a-small-metal-box/ (Eco Beringin)

Results will vary. A formatted HDD that has seen little further use may still contain documents, photographs, database records and parts of its former folder structure. An SSD may behave differently because of its internal management functions. Encryption, later use and previous sanitization also affect what can be recovered.

A properly sanitized device should leave the next person with no practical route to the target information. NIST defines media sanitization as a process that makes access to the data infeasible for a given level of effort. Its current guidance is available at https://csrc.nist.gov/pubs/sp/800/88/r2/final (NIST Computer Security Resource Center)

One laptop or an entire office

One discarded laptop may expose information belonging to an employee, a customer or a family. An office hardware replacement may involve hundreds of laptops, server drives, backup disks, memory cards and USB devices.

Each device can contain several copies of the same information. A file may exist in the main folder, an email attachment, a local backup and a temporary export. Formatting the visible partition does not provide evidence that every relevant copy has been dealt with.

At larger volumes, the company also needs to know which devices were collected, where they went, how they were processed and which items were approved for reuse.

This is why data destruction should be planned for a single computer as carefully as it is planned for a data centre project. The quantity changes. The basic responsibility stays the same.

How Eco Beringin handles storage devices

We begin by identifying and recording the devices. Their type, condition and intended destination determine the next step.

A drive that will be reused may go through verified data wiping. This allows the hardware to continue working after the previous information has been removed and checked.

Magnetic storage such as an HDD or magnetic tape may be processed through degaussing when that method is appropriate. Degaussing disrupts the magnetic recording used to store the data.

When physical destruction is required, drives can be crushed or shredded. This is used for equipment that will not return to service or when the information requires a final physical method.

The work can take place onsite when the devices cannot leave the client’s premises, or offsite through a controlled collection and processing procedure. Clients may witness the destruction, and written records provide evidence of what happened to the devices. Eco Beringin describes its onsite, offsite and reporting procedures at https://ecoberingin.com/services/data-destruction/ (Eco Beringin)

After the data has been handled, the remaining equipment still needs proper treatment. Metals, circuit boards, plastics and other components should enter a controlled recycling process rather than an informal dismantling route. Eco Beringin combines data destruction with IT asset assessment and e-waste processing, including certified wiping, degaussing, crushing and shredding where appropriate.

AI agents have made file searching and recovery easier to request. A person can now describe the desired result in plain language and let the software prepare much of the technical work.

The responsibility remains with the owner of the equipment. Before any laptop, server or storage device leaves your control, decide whether it will be reused or destroyed, select a method suited to the media and the sensitivity of its data, then keep written proof of the result.

A format screen is not a destruction record.

Leave a comment

Office
Jl. Kapuk Kamal Raya No.9-10 A, RT 03/RW 02,
Kamal Muara, Kec. Penjaringan
Jakarta Utara 14470

Eco Beringin © 2026. All Rights Reserved.

Add Your Heading Text Here

https://ecoberingin.com/
https://ecoberingin.com/