Case Library / Physical Social Engineering (Tailgating & Baiting) / Shred-It and Iron Mountain Pay $1.1 Million to Settle GSA Shredding False Claims Act Whistleblower Suit (2013)

Shred-It and Iron Mountain Pay $1.1 Million to Settle GSA Shredding False Claims Act Whistleblower Suit (2013)

A Pennsylvania shredding-business owner's 2010 qui tam suit alleged that Shred-It, Iron Mountain, and Cintas billed federal agencies for GSA-spec micro-cut document shredding while using equipment that could not physically produce that particle size, settling in July 2013 for $1.1 million combined ($800K Iron Mountain, $300K Shred-It), with Cintas continuing to contest the claims.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Douglas Knisely, owner of a small, family-run document-shredding business (Knisely Security/Knisely Shredding) in Lock Haven, Pennsylvania, repeatedly lost bids for federal shredding work because his own shredders (unlike, he alleged, those of the industry's "big three") actually met the GSA's mandated ultra-fine residue-particle specification (no larger than 1/32 inch wide, with 1/64-inch tolerance, by 1/2 inch long). Recognizing from his own expertise, observation of competitors' trucks, and conversations with their line employees that Iron Mountain, Shred-It, and Cintas were not using equipment capable of meeting that spec despite certifying compliance and billing the government for it, Knisely filed a qui tam whistleblower suit under the False Claims Act in 2010 in the U.S. District Court for the Eastern District of Pennsylvania. The DOJ investigated and, on July 9, 2013, announced that Iron Mountain and Shred-It had agreed to pay a combined $1.1 million ($800,000 and $300,000 respectively) plus attorneys' fees to resolve the allegations, without admitting liability; Cintas did not settle at that time.

How the Attack Worked

Since at least 2006, Iron Mountain, Shred-It, and Cintas held GSA Schedule 36 contracts to provide secure document-shredding services to federal agencies including the Department of Defense, Department of Homeland Security, Department of Justice, Social Security Administration, Department of the Treasury, and Department of Veterans Affairs. The GSA solicitation for approved shredding vendors unambiguously specified that shredders must produce residue particles no larger than 1/32 inch in width (1/64-inch tolerance) by 1/2 inch in length, an exacting cross-cut/micro-cut size meant to prevent reconstruction of sensitive or classified material. Vendors were contractually required to issue a signed "Certificate of Destruction" after each job, attesting to the date, method, and completeness of destruction, with destruction officials certifying "through their personal knowledge" that the material was destroyed to spec. The complaint alleged the three companies routinely used shredding trucks/equipment that were not designed to hit that particle size (Cintas, for example, allegedly used a pierce-and-tear process yielding shreds roughly 5/8 inch by 2 inches, about 100 times larger than the GSA-mandated size), and that employees of Iron Mountain and Cintas admitted their equipment could not shred that small. Despite this, the companies allegedly submitted certificates of destruction and invoices as if the contract spec had been met, making each such claim for payment a "false claim" under the FCA. The complaint also alleged a profit motive for skipping the ultra-fine cut: paper shredded to the GSA's micro-cut spec is generally unusable for recycling, so by shredding to a coarser, non-compliant size the companies could resell the waste paper to recyclers for extra revenue the compliant method would have foreclosed.

The Lure & the Tell

There was no interpersonal "lure" in the classic social-engineering sense; the deception was documentary: a Certificate of Destruction signed and submitted with each invoice, attesting that shredding met a spec the companies' own trucks and equipment allegedly could not achieve. The "tell" that exposed the scheme came from an outside expert with a competitive stake: Douglas Knisely, owner of a small family-run shredding business in Lock Haven, Pennsylvania, had repeatedly lost bids for the same government work because his shredders genuinely met the strict 1/32-inch GSA spec (which required more expensive equipment). Recognizing that the "big three" incumbents' visible trucks and equipment were not built to hit that spec, and after employees of two of the three companies admitted as much to him directly, Knisely retained FCA counsel and filed a qui tam suit in 2010 rather than compete by cutting the same corners.

Outcome

On July 9, 2013, the DOJ (via the U.S. Attorney's Office for the Eastern District of Pennsylvania, announced by U.S. Attorney Zane David Memeger) announced that Iron Mountain and Shred-It had agreed to pay the United States a combined $1.1 million ($800,000 and $300,000 respectively) plus the relator's attorneys' fees, to resolve the False Claims Act allegations. Neither company admitted wrongdoing: Shred-It "expressly denie[d] that it engaged in any wrongdoing," and Iron Mountain characterized the GSA's original particle-size requirement as "a size unattainable by most commercial shredding services," noting GSA had since revised the specification to better match industry practice, and that it continued to hold U.S. government shredding contracts afterward. Cintas did not settle at that time and the whistleblower's case against it continued separately. Knisely, the relator, was statutorily entitled to 15%-25% of the government's recovery. The case also drew trade-press attention (e.g., National Association for Information Destruction commentary) noting that particle size alone is not the sole determinant of secure destruction.

Why It Matters

This case is a clear, documented example of how attestation-based trust, in the form of a signed "Certificate of Destruction", can substitute for actual verification in a security-critical process, and how that gap can be exploited for profit at scale across years and across the federal government's most sensitive agencies (DoD, DHS, DOJ, VA, Treasury, SSA). It underscores a recurring theme relevant to Diopter's audience: paper compliance (a signed certification, a checked box, a vendor's self-attestation of a security control) is not the same as verified performance, and adversaries, or in this case profit-motivated contractors, will exploit whichever is cheaper to produce. It also illustrates the outsized role a single well-informed insider/competitor whistleblower can play in surfacing fraud that neither the contracting agency nor routine oversight caught for years.

Defenses

Independent, physical verification of destruction output (measuring actual residue particle size) rather than relying on vendor self-issued Certificates of Destruction; third-party audits/certification of destruction vendors (this case increased attention on NAID, the National Association for Information Destruction, AAA certification and on-site audits); contracting-officer spot checks against the GSA spec actually being met, not just attested; functioning whistleblower/qui tam channels for insiders and competitors with domain expertise to report specification fraud; GSA itself revised the shred-size specification after the case to be more consistent with achievable industry standards, reducing the gap between the written spec and what vendors could truthfully certify.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Solicitation and spec reconnaissance: Prospective GSA Schedule 36 vendors reviewed the published solicitation, which unambiguously required shredders to produce residue particles no larger than 1/32 inch wide (1/64-inch tolerance) by 1/2 inch long, and, per the qui tam complaint, recognized that meeting this spec required equipment few commercial operators actually owned, while the award and payment process relied on the vendor's own paperwork rather than a physical test of shredder output.
Countering Stage 1: A purchasing agency writing an achievable, physically verifiable spec helps somewhat (GSA later did revise its shred-size requirement), but the stronger control is requiring documented proof of compliant equipment, such as equipment specifications or independent lab test results, in the bid package itself rather than accepting a written attestation of intent to comply.
2
Equipment gap assessment and bid decision: Per the complaint, Iron Mountain, Shred-It, and Cintas each proceeded to apply for and hold GSA Schedule 36 shredding contracts despite using existing high-volume shredding equipment, such as Cintas's pierce-and-tear trucks, that was not designed to produce that particle size, likely weighing the cost of upgrading equipment against the low likelihood that a paperwork-based certification process would be independently checked.
Countering Stage 2: A vendor's internal cost-benefit calculation is not directly observable from outside, so the practical control is raising the expected cost of noncompliance, for example contract clauses that allow surprise physical audits and impose clawback or debarment penalties, making the decision to skip compliant equipment a bad bet before a single job is performed.
3
Contract award via self-certification: The vendors were approved as GSA Schedule 36 shredding contractors and began billing federal agencies, including the Department of Defense, Department of Homeland Security, Department of Justice, Social Security Administration, Department of the Treasury, and Department of Veterans Affairs, for shredding services performed to the certified spec.
Countering Stage 3: Contracting officers requiring a physical demonstration or independent lab certification of actual shredder output, measuring real residue particle size, before contract award, rather than accepting the vendor's own attestation as sufficient for approval.
4
Non-compliant service delivery: Since at least 2006, per the complaint, the companies performed shredding jobs at federal facilities nationwide using trucks and equipment that produced a coarser particle size than contracted, with Cintas allegedly yielding shreds roughly 5/8 inch by 2 inches, about 100 times larger than the GSA-mandated size, and employees of Iron Mountain and Cintas reportedly admitting their equipment could not shred that small.
Countering Stage 4: Unannounced, in-person spot checks of shredding trucks and equipment at the point of service, comparing physical output against the contracted particle-size spec, rather than relying solely on paperwork submitted after the fact.
5
False Certificate of Destruction issuance: After each job, per the GSA solicitation's own certification requirement, vendor personnel signed and submitted a Certificate of Destruction attesting, through their personal knowledge, that the material had been destroyed to the contracted spec, despite the equipment used being incapable of that output.
Countering Stage 5: Third-party accreditation of destruction vendors, such as NAID AAA certification and on-site audits, so the signed certificate is backed by periodic independent verification instead of resting entirely on the vendor's own personnel attesting compliance.
6
Invoicing and secondary revenue extraction: Vendors submitted claims for payment referencing the certified but false destruction standard and collected the full contracted rate; the complaint also alleged the companies profited further because paper shredded to the coarser, non-compliant size remained sellable to recyclers (unlike GSA-spec micro-cut waste, which is generally unusable for recycling), generating extra revenue the compliant method would have foreclosed.
Countering Stage 6: Government invoice-review processes that reconcile claims for payment against independently verified performance data rather than the vendor's own certificate, plus functioning whistleblower and qui tam channels that give competitors and insiders with domain expertise a route to report specification fraud, which is ultimately what surfaced this scheme.
Quick Facts
Victim
U.S. federal government agencies purchasing document-shredding services under GSA Schedule 36 contracts, including the Department of Defense, Department of Homeland Security, Department of Justice, Social Security Administration, Department of the Treasury, and Department of Veterans Affairs
Location
U.S. District Court for the Eastern District of Pennsylvania (Philadelphia); underlying shredding services were performed at federal facilities nationwide under GSA contracts
Date
2013-07-09 (DOJ settlement announced); underlying conduct alleged from at least 2006; qui tam complaint filed 2010 in U.S. District Court, E.D. Pennsylvania
Impact
$1,100,000 total settlement: Iron Mountain paid $800,000 plus the relator's attorneys' fees; Shred-It paid $300,000 plus attorneys' fees. Under the False Claims Act, relator Douglas Knisely was entitled to a statutory 15%-25% share of the government's recovery (exact dollar amount not publicly disclosed in the sources reviewed). A third named defendant, Cintas Corporation, did not settle and continued to contest the allegations, so no payment from Cintas is reflected in this $1.1M figure. Separately and unrelated in mechanism (a pricing/overcharging issue, not shred-size fraud), Iron Mountain later paid $44.5 million in a 2014 GSA storage-contract False Claims Act settlement; this should not be conflated with this shredding case.
Status
Confirmed
Case Type
Real-World Incident
Sector
Government & Public Sector, Professional & Business Services
Related

Related Cases

TD Bank Lost Unencrypted Backup Tapes - Multistate and Massachusetts AG Settlements

Two unencrypted TD Bank backup tapes carrying data on 260,000 customers vanished in transit between Massachusetts offices in 2012; a…

Incident 2012Read →

Roger Roger's Costa Rica Sweepstakes Call Center: VOIP-Spoofed Government Impersonation Bilks Hundreds of Elderly Victims of $4M+

Costa Rica-based telemarketing ringleader Roger Roger used VOIP-spoofed Washington D.C. caller ID and fake government-official personas to convince hundreds of…

Incident 2014Read →

Saudi Aramco "Badge Surfer" Claim in the 2012 Shamoon Attack - A Security-Awareness Narrative Without Primary-Source Corroboration

A widely circulated security-awareness case study (NINJIO) claims a tailgating "badge surfer" photographed passwords exposed by a clean-desk-policy failure to…

Incident 2012Read →