A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec micro-cut document shredding while using equipment that could not physically produce that particle size, settling in July 2013 for $1.1 million combined ($800K Iron Mountain, $300K Shred-It), with Cintas continuing to contest the claims.
Reviewed by the Social Engineering Examples team.
Douglas Knisely, owner of a small, family-run document-shredding business (Knisely Security/Knisely Shredding) in Lock Haven, Pennsylvania, repeatedly lost bids for federal shredding work because his own shredders (unlike, he alleged, those of the industry's "big three") actually met the GSA's mandated ultra-fine residue-particle specification (no larger than 1/32 inch wide, with 1/64-inch tolerance, by 1/2 inch long). Recognizing from his own expertise, observation of competitors' trucks, and conversations with their line employees that Iron Mountain, Shred-It, and Cintas were not using equipment capable of meeting that spec despite certifying compliance and billing the government for it, Knisely filed a qui tam whistleblower suit under the False Claims Act in 2010 in the U.S. District Court for the Eastern District of Pennsylvania. The DOJ investigated and, on July 9, 2013, announced that Iron Mountain and Shred-It had agreed to pay a combined $1.1 million ($800,000 and $300,000 respectively) plus attorneys' fees to resolve the allegations, without admitting liability; Cintas did not settle at that time.
Since at least 2006, Iron Mountain, Shred-It, and Cintas held GSA Schedule 36 contracts to provide secure document-shredding services to federal agencies including the Department of Defense, Department of Homeland Security, Department of Justice, Social Security Administration, Department of the Treasury, and Department of Veterans Affairs. The GSA solicitation for approved shredding vendors unambiguously specified that shredders must produce residue particles no larger than 1/32 inch in width (1/64-inch tolerance) by 1/2 inch in length, an exacting cross-cut/micro-cut size meant to prevent reconstruction of sensitive or classified material. Vendors were contractually required to issue a signed "Certificate of Destruction" after each job, attesting to the date, method, and completeness of destruction, with destruction officials certifying "through their personal knowledge" that the material was destroyed to spec. The complaint alleged the three companies routinely used shredding trucks/equipment that were not designed to hit that particle size (Cintas, for example, allegedly used a pierce-and-tear process yielding shreds roughly 5/8 inch by 2 inches, about 100 times larger than the GSA-mandated size), and that employees of Iron Mountain and Cintas admitted their equipment could not shred that small. Despite this, the companies allegedly submitted certificates of destruction and invoices as if the contract spec had been met, making each such claim for payment a "false claim" under the FCA. The complaint also alleged a profit motive for skipping the ultra-fine cut: paper shredded to the GSA's micro-cut spec is generally unusable for recycling, so by shredding to a coarser, non-compliant size the companies could resell the waste paper to recyclers for extra revenue the compliant method would have foreclosed.
There was no interpersonal "lure" in the classic social-engineering sense; the deception was documentary: a Certificate of Destruction signed and submitted with each invoice, attesting that shredding met a spec the companies' own trucks and equipment allegedly could not achieve. The "tell" that exposed the scheme came from an outside expert with a competitive stake: Douglas Knisely, owner of a small family-run shredding business in Lock Haven, Pennsylvania, had repeatedly lost bids for the same government work because his shredders genuinely met the strict 1/32-inch GSA spec (which required more expensive equipment). Recognizing that the "big three" incumbents' visible trucks and equipment were not built to hit that spec, and after employees of two of the three companies admitted as much to him directly, Knisely retained FCA counsel and filed a qui tam suit in 2010 rather than compete by cutting the same corners.
On July 9, 2013, the DOJ (via the U.S. Attorney's Office for the Eastern District of Pennsylvania, announced by U.S. Attorney Zane David Memeger) announced that Iron Mountain and Shred-It had agreed to pay the United States a combined $1.1 million ($800,000 and $300,000 respectively) plus the relator's attorneys' fees, to resolve the False Claims Act allegations. Neither company admitted wrongdoing: Shred-It "expressly denie[d] that it engaged in any wrongdoing," and Iron Mountain characterized the GSA's original particle-size requirement as "a size unattainable by most commercial shredding services," noting GSA had since revised the specification to better match industry practice, and that it continued to hold U.S. government shredding contracts afterward. Cintas did not settle at that time and the whistleblower's case against it continued separately. Knisely, the relator, was statutorily entitled to 15%-25% of the government's recovery. The case also drew trade-press attention (e.g., National Association for Information Destruction commentary) noting that particle size alone is not the sole determinant of secure destruction.
This case is a clear, documented example of how attestation-based trust, in the form of a signed "Certificate of Destruction", can substitute for actual verification in a security-critical process, and how that gap can be exploited for profit at scale across years and across the federal government's most sensitive agencies (DoD, DHS, DOJ, VA, Treasury, SSA). It underscores a recurring theme relevant to Diopter's audience: paper compliance (a signed certification, a checked box, a vendor's self-attestation of a security control) is not the same as verified performance, and adversaries, or in this case profit-motivated contractors, will exploit whichever is cheaper to produce. It also illustrates the outsized role a single well-informed insider/competitor whistleblower can play in surfacing fraud that neither the contracting agency nor routine oversight caught for years.
Independent, physical verification of destruction output (measuring actual residue particle size) rather than relying on vendor self-issued Certificates of Destruction; third-party audits/certification of destruction vendors (this case increased attention on NAID, the National Association for Information Destruction, AAA certification and on-site audits); contracting-officer spot checks against the GSA spec actually being met, not just attested; functioning whistleblower/qui tam channels for insiders and competitors with domain expertise to report specification fraud; GSA itself revised the shred-size specification after the case to be more consistent with achievable industry standards, reducing the gap between the written spec and what vendors could truthfully certify.
Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a…
Costa Rica-based telemarketing ringleader Roger Roger used VOIP-spoofed Washington D.C. caller ID and fake government-official personas to convince hundreds of…
A widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to…