Introduction
Most of the cases on this site are about disposal: what happens when retired hardware is handed to the wrong vendor or left on a pallet. These two are about the step before that. In both, the hardware was still in service or staged for maintenance, and an insider with legitimate access removed the drives and sold or traded them. Neither case involved a network intrusion. Both were solved by physical evidence, and both would have been caught earlier by an inventory somebody reconciled.
Everything below comes from the Department of Justice press release in the Navy case and from court filings reported by the Portland Press Herald and Maine Public in the Customs and Border Protection case. The CBP case is a criminal complaint; the defendant is presumed innocent, and the details are allegations until a court says otherwise.
Case one: the shipyard contractor and 302 hard drives
Ernesto Saldivar was a civilian contractor at General Dynamics NASSCO in San Diego, working on the modernization of Navy ships under maintenance. Between November 2022 and August 2023, according to the Department of Justice, he stole hundreds of military hard drives and laptops from declassified areas of the USS Pinckney, USS Curtis Wilbur, and USS Spruance, then sold them on eBay. The final count was 302 hard drives, two laptops, two programmer units, and a collection of power converters, valued at $596,997.53. Two of the drives contained classified military communications.
He was caught three ways, all physical. The Army Criminal Investigation Laboratory lifted fingerprints from inside the empty drive trays, a surface you can only touch after a drive has been removed. NCIS traced eBay listings of the equipment back to him. A search of his home recovered 120 of the missing drives, a Toughbook from the Pinckney still loaded with shipboard voice-communications software, and equipment traceable to the Curtis Wilbur. He was sentenced in July 2024 to eighteen months in federal prison.
The detail worth sitting with is where the drives were. They were not in a dumpster or on a truck to a recycler. They were in spaces the ships' crews had cleared for maintenance, which is to say they were staged: out of service, out of daily sight, and waiting. Two hundred drives went missing before the pattern was noticed.
Case two: the border station supervisor and 46 computers
Terry Liu was a Customs and Border Protection supervisor at the Calais, Maine port of entry, with duties at the Ferry Point and Milltown crossings. His responsibilities included IT support for those stations. According to an FBI affidavit filed in September 2026, CBP IT staff noticed unauthorized work on machines in late 2025; hidden-camera footage later showed him opening government computers during overnight shifts. In all, 46 computers were altered: 38 at Calais, six at Ferry Point, two at Milltown. Processors, memory modules, and hard drives were removed and replaced with older, lower-specification parts, so the machines still turned on and were, in many cases, reconnected to the agency network afterward.
Records from Newegg showed sixteen trade-ins of 14th-generation Intel processors between May 2025 and July 2026, and matching credits appeared in his credit card records. In an interview on September 9, 2026, the affidavit says, he admitted replacing the parts and using the government components for trade-in credit; he first said he was trying to speed up the computers, then acknowledged the swaps degraded them. He was arrested and charged with theft of government property and destruction of government property, each carrying up to ten years. CBP put the cost of restoring the swapped parts at more than $20,000 and of replacing all 46 machines at more than $105,000. The port director had told him in March 2025 not to modify computers.
What the reporting does not say is where the removed hard drives went. Newegg's program accepts processors, memory, and graphics cards, not drives. Forty-six government computers at a border crossing had their storage pulled by one person, and the public record so far accounts for the processors, not the drives. That gap is the case.
What the two cases share
- Legitimate access. Neither man broke in. One was a contractor with a reason to be on the ships; the other was the supervisor responsible for the computers he was opening.
- Hardware that still looked normal. A ship in maintenance with some empty drive bays, and a border-station PC that still booted with a smaller drive, look exactly like a ship in maintenance and a working PC. Nothing in a network log flagged either.
- Long dwell time. Ten months in San Diego, more than a year in Maine. In both, the loss accumulated one drive at a time.
- Physical evidence closed the case. Fingerprints in drive trays, badge and access records, hidden cameras, and marketplace listings. Not one of the controls that caught them was a cybersecurity tool.
- An inventory would have caught it first. Both organizations had a record of what hardware they owned. Neither was reconciling it against what was physically present until the damage was done.
Why this matters outside the government
Banks and credit unions, hospitals, and school districts all keep the same two populations of hardware these cases were stolen from: machines in service, whose drives nobody checks because the machine works, and machines pulled from service and staged in a storage room, whose drives nobody checks because the machine is gone. The DOJ Inspector General found the same pattern at the FBI’s own destruction facility in 2024: drives not counted, computers arriving already empty, pallets waiting 21 months. The failure is not exotic. It is the absence of a count.
For a financial institution the drive that walks out is a Gramm-Leach-Bliley event and, under most state laws, a reportable breach, whether it was stolen from a working teller station or from the shelf where the old teller stations sit. For a hospital it is a HIPAA breach. For a contractor it is a CUI spill and, at worst, what it was on the Pinckney: classified material on eBay.
What would have caught them
- Reconcile the inventory, physically, on a scheduleNot the asset list against itself; the asset list against what is in the machine and on the shelf. Once a quarter for in-service hardware, monthly for anything staged. In Maine, a comparison of installed processors and drives against purchase records would have surfaced the swaps within a cycle.
- Serial numbers on the media, not just the chassisThe FBI’s auditors found the same gap: property tags on the case, nothing on the drive. Record the drive serial at deployment and again at removal. A drive that leaves a machine without a removal record is a finding, not a mystery.
- Two people on removalsThe Special Access Program rule for accountable material, applied to ordinary hardware: two initials on the log whenever storage leaves a machine. It removes the single-person opportunity both cases depended on.
- Short staging windowsRetired hardware should have a destruction date within thirty days of leaving service, and the certificate should list every serial. A storage room with a clock on it is a room somebody visits.
- Lay physical security next to ITBadge records showed who was on the ships and in the border stations at night. Nobody was comparing them to hardware changes until an investigation started. Give the two teams a reason to meet before the incident: a monthly review of after-hours access to rooms that hold hardware.
- Destroy at the point of removalHardware that is destroyed the day it comes out of service never sits in a declassified area waiting for a contractor with a duffel bag. On-site destruction with a serial-level certificate closes the window these cases lived in.
How our technical consultation applies
Most of what would have caught these two is program design, which is what our technical consultation does: an inventory procedure that records media serials at deployment and removal, a reconciliation schedule with named owners, a two-person rule for storage handling, staging limits with destruction dates, and the review that puts badge records and hardware changes on the same table. For the hardware already sitting in your storage room, the fastest fix is the truck: we inventory it by serial, destroy it on-site, and hand you the certificate, and the room is empty by the end of the day.
Sources
- U.S. Attorney’s Office, Southern District of California: shipyard contractor sentenced for stealing almost $600,000 of computer equipment from the U.S. Navy, July 10, 2024.
- Portland Press Herald: Border Patrol supervisor in Maine accused of modifying government computers, September 11, 2026.
- Maine Public: Calais border agent arrested for allegedly stealing government computer parts, September 14, 2026.
The charges in the CBP case are allegations, and the defendant is presumed innocent unless and until proven guilty. Written by Christopher McDevitt with AI assistance.
