The Best Data Is on Sale at the Liquidation Auction

The final round of bidding for the internal records of a dead airline came down to two companies. Google offered $10 million, and the runner-up, at $7.5 million, was Mercor, an AI training-data firm. Neither company flies planes, runs turnaround operations, or collects archives. Both train AI models.

That auction happened on August 14 in the Chapter 11 case of Spirit Aviation Holdings, Case No. 25-11897, before U.S. Bankruptcy Judge Sean Lane in the Southern District of New York. Nothing’s final, because Judge Lane postponed the approval hearing to September 9 after the flight attendants’ union filed a limited objection, so the sale remains exactly that: proposed. But anyone running an enterprise, an IT department, or a security program should pay attention. Two companies were the only credible bidders for another company’s emails, and the fact that the loser was also an AI firm is the tell.

What $10 million may buy

Assuming the deal clears, Google would take possession of an enterprise’s entire digital residue. Based on the auction results notice filed in the case:

Asset categoryVolume
Emails and email accounts100 million / 80,000 accounts
Microsoft Teams messages500 million items
OneDrive / SharePoint files17 million / 20.5 million items
Customer service calls30 million recordings
Transaction records (back to 2008)7.5 billion
Flights / crew pairings763,000 / 5 million
Fuel slips / parts purchases1.2 million / 787,452

For Google, the price is a rounding error. The interesting part is what the price implies: none of this material exists on the public web, it can’t be scraped, and it represents decades of real workplace behavior and operational decisions. That’s precisely the kind of private, unique corpus AI companies now treat as the scarce input, because the public web has been picked clean.

Why the demand exists

Anyone who has watched enterprise AI projects implode already understands the logic. Most AI projects don’t fail because the model is weak, they fail because the enterprise around the model isn’t ready. The data is fragmented, stale, and ungoverned, and the model amplifies the mess.

Training corpora sit upstream of that problem. If good proprietary data is the bottleneck, the fastest way to acquire it is to let a company with ten years of operational records die, then bid on the corpse and hope that the data are usable for training purposes. Healthy companies will never sell their internal communications. A bankruptcy trustee has no such scruples; the fiduciary duty runs to creditors, and everything of value gets liquidated. Bankruptcy court has become the only market where corporate data exhaust reliably changes hands, because it’s the one place the owner is compelled to name a price.

The RadioShack problem, briefly

There’s precedent for selling data out of a bankruptcy estate, and it shaped this deal more than the parties admit. When RadioShack went under in 2015, it tried to auction more than 65 million customer records and walked into a wall: its own privacy policy promised never to sell personally identifiable information (PII). Attorneys general from roughly 38 states objected, the Federal Trade Commission piled on, and the negotiated settlement became the de facto template for consumer data sales in bankruptcy. The pattern predates RadioShack – the FTC first drew this line in the 2000 Toysmart case – but the 2015 fight is what hardened it into a checklist. These conditions survive today:

  • The data can’t be sold as a standalone asset
  • The buyer must be in substantially the same line of business
  • The buyer must honor the original privacy policy
  • Consumers get consent rights over material changes

That framework exists to protect customers. Now read what Spirit marked “Not Included” on its Assets Schedule: customer profiles, loyalty data, active email addresses, call recordings, Department of Transportation complaints. Nearly every consumer-facing category is excluded. Marked “Included” is the workforce record: 3.4 million payroll records, roughly 1 million time cards, employee tax forms, training files, litigation case files, and the full Microsoft 365 corpus going back decades.

The gap, in the union’s own words

The Association of Flight Attendants-CWA’s objection, filed August 18 by counsel Charles M. Rubio, contains the sharpest sentence written about this deal:

“The privacy architecture of this transaction is consumer-facing; its payload is disproportionately employee-facing. Hence, the employee data is far more confidential than the customer data, yet receives far less protection than the customer data.”

The distinction is simple and legally significant. Deidentification removes traceability to a named person, but it does nothing for confidentiality of content. A pseudonymized disciplinary letter is still a disciplinary letter. Three features in the Sale Agreement make this more than griping:

  • Deidentification must preserve “referential integrity across the data set,” so the joins between payroll, training, and communications records survive by design
  • The crew base is only 4,600 people, so inference about individuals across a decade of linked records isn’t speculative
  • The buyer gets a voice in its own scrub: the deidentification agent must be acceptable to the buyer, and certification runs to the buyer’s reasonable satisfaction under the California Consumer Privacy Act standard

Credit where it’s due on both sides. Google’s structure includes real protections: third-party scrubbing, a covenant against re-identification, no customer PII in the package. But every protection is calibrated to consumers. The union isn’t blocking the sale, and its proposed carve-outs cost the estate nothing, since deidentification hasn’t happened yet and the buyer already pays for it. The objection simply asks the court to treat employee records the way the Code already treats customer records.

Why the next auction won’t be the last

Three forces converge here.

  • Supply: every company that dies with its files intact becomes a candidate for the next auction.
  • Demand: unique proprietary data is the scarce AI input, and Mercor’s losing bid proves the demand runs deeper than one hyperscaler.
  • Mechanism: Section 363 sales (the Bankruptcy Code’s mechanism for selling estate assets free and clear) are fast, court-supervised, and designed to maximize creditor recoveries, and Google’s Sale Agreement now exists as a public, citable template for structuring around the consumer-privacy framework.

Whatever Judge Lane rules on September 9, the template’s already public. Approve the sale as drafted and the path is proven, so the next estate’s lawyers will just re-use it. Impose conditions instead, and it marks the first time RadioShack-style logic has been extended to employee data, which means future deals get drafted around that instead. The next test probably won’t involve an airline. It’ll be a retailer, a hospital system, or a bank, and possibly the one where the FTC decides its 2015 framework needs a sequel.

For twenty years, companies hoarded data as a proprietary asset. In the AI era, the most reliable way for that data to reach the market is for the company to stop existing. A bankruptcy judge in Manhattan is about to decide whether the first large sale of a corporate soul goes through as written.

Security Risks ARE Business Risks. Get the Weekly Context.

Every week, I break down the most important intersections of cybersecurity, AI regulation, and business risk. Plus: early access to 'Cyber Risk is a Myth' chapter resources and course updates.

I don’t spam! Read the privacy policy for more info.

Similar Posts