PBS Loses 50TB of Data: A Storage Security Wake-Up Call After a Cloud Provider Goes Bankrupt

PBS lost 50TB of irreplaceable historical archives after its cloud storage provider went bankrupt.
PBS permanently lost approximately 50TB of data spanning 70 years of television history when its cloud storage provider went bankrupt. This incident highlights the underestimated risk of vendor lock-in and single-provider dependency. The article examines why cloud durability guarantees fail when providers cease to exist, revisits the 3-2-1 backup principle for the cloud era, and offers practical recommendations including cross-provider redundancy, data exit planning, and tiered protection for irreplaceable assets.
A Digital Catastrophe Spanning 70 Years of Television History
Recently, a story from Hacker News caught the attention of the tech community: the Public Broadcasting Service (PBS) permanently lost approximately 50TB of precious data—including 70 years of television history—after its cloud storage provider went bankrupt. These materials were not merely media assets but public cultural heritage carrying the collective memory of society.
PBS (Public Broadcasting Service), founded in 1969, is the largest nonprofit public television network in the United States, reaching approximately 350 million viewers nationwide. Its content library spans from the 1950s educational television era to the present, encompassing vast collections of documentaries, news archives, and cultural programming—including early Sesame Street segments, Vietnam War-era news reports, and other irreplaceable historical footage. As a public institution receiving federal funding, PBS has long operated under budget constraints, which likely led to selecting lower-cost vendors for IT infrastructure—indirectly planting the seeds of this disaster.
For any organization, losing 50TB of data is devastating. For a media institution like PBS, whose core asset is its content archive, this amounts to an irreversible cultural catastrophe. What makes this even more alarming is that the direct cause wasn't a cyberattack or natural disaster, but a seemingly routine business event—the bankruptcy of a cloud service provider.
Provider Bankruptcy: A Severely Underestimated Cloud Storage Risk
Cloud Storage Does Not Equal Absolute Safety
For years, "moving to the cloud" has been viewed by many organizations as a silver bullet for data security. Cloud vendors routinely promise "11 nines" of data durability (99.999999999%), creating the illusion that data stored in the cloud is completely safe.
The "11 nines" durability metric is a standard promise from mainstream cloud storage services like AWS S3. It means that if you store 10 million objects, you might lose one object on average every 10,000 years. This is achieved through automatic data redundancy across multiple physical facilities, using technologies like Erasure Coding to split and distribute data so it can be fully recovered even if some hardware fails. However, this durability guarantee is fundamentally a technical countermeasure against hardware failures and localized disasters—its implicit premise is that the operator continues to maintain the underlying infrastructure.
PBS's experience reveals a harsh reality: cloud service reliability guarantees are predicated on the provider's continued existence. No amount of technical redundancy can withstand the commercial collapse of the provider itself. When a cloud vendor ceases operations and enters bankruptcy proceedings, user data stored in its data centers may face deletion, auction, or complete inaccessibility due to infrastructure shutdown.
The Hidden Costs of Vendor Lock-in
This incident also exposes the deeper risks of "Vendor Lock-in." Vendor lock-in is not merely a business concept—it has deep technical roots. Different cloud providers use proprietary API interfaces, proprietary data formats, and customized metadata management systems. For example, some archival storage services impose retrieval delay windows (such as AWS Glacier, where data retrieval takes hours to days), and large-scale data exports can incur steep egress fees. Taking 50TB as an example, at a typical rate of approximately $0.09 per GB for egress, network transfer costs alone could exceed $4,500, and completing the transfer over standard bandwidth could take weeks.
Many organizations focus solely on price, performance, and usability when selecting cloud services, while overlooking exit mechanisms and data portability. Once a provider encounters problems, customers may find themselves unable to migrate data in time and lacking effective emergency recovery channels.
For massive datasets like 50TB, even if export is possible, the migration process itself requires sufficient time, bandwidth, and financial resources. When a provider has already entered bankruptcy proceedings, customers often receive an extremely short disposal window—or no time to react at all.
The 3-2-1 Backup Rule: From Classic Principle to Cloud-Era Practice
Core Tenets of the 3-2-1 Backup Rule
In the field of data protection, the industry has long upheld a golden rule—the 3-2-1 backup principle:
- 3 copies of data: Maintain at least three copies of your data
- 2 different media types: Use two different storage media (e.g., cloud storage + tape, SSD + HDD)
- 1 offsite backup: Keep at least one copy at a different location or with a different service provider
Regarding the "different media" requirement, tape (LTO Tape) remains the workhorse for large-scale cold data archiving. The current LTO-9 generation offers 18TB per cartridge (45TB compressed), with per-unit storage costs far below hard drives and SSDs, and offline shelf life exceeding 30 years. Approximately 70% of the world's archived data is still stored on tape. Another critical advantage of tape is its "air gap" property—offline stored data is naturally immune to ransomware attacks and provider bankruptcy risks. Hollywood studios, national libraries, and similar institutions have long relied on tape for cultural heritage preservation.
PBS's lesson perfectly validates the wisdom of "don't put all your eggs in one basket" embedded in this principle. If these precious materials had independent copies stored with different providers and in different geographic locations, a single cloud vendor's bankruptcy would not have caused such devastating consequences.
The Necessity of Cross-Provider Redundancy
As cloud computing becomes ubiquitous, the 3-2-1 principle must evolve with the times. Simply replicating data across multiple Availability Zones (AZs) within the same cloud provider is insufficient, as this cannot address provider-level systemic risk.
Cloud providers typically offer two forms of data redundancy: same-region redundancy (replicating data to multiple data centers within the same geographic region) and cross-region replication (syncing data to different geographic regions). However, regardless of which approach is chosen, the data remains within the same provider's control system. Provider-level systemic risks—such as bankruptcy, asset freezes due to legal disputes, or even a provider-wide configuration error—can simultaneously affect data copies across all regions. This is precisely why cross-provider redundancy is irreplaceable.
A truly robust data backup strategy should incorporate cross-provider redundancy—distributing critical data across at least two independent service providers, or maintaining a local/offline cold backup.
Practical Data Protection Recommendations for Organizations
Establish a Cloud Provider Risk Assessment Framework
When selecting cloud storage providers, organizations should look beyond technical capabilities and carefully evaluate the provider's financial health, market position, and long-term viability. While smaller cloud service providers may offer attractive pricing, their risk resilience is often weaker, requiring more cautious assessment of their operational sustainability.
Specifically, evaluation dimensions should include: the provider's annual revenue and profitability, funding rounds and investor backgrounds, customer concentration, industry reputation, and whether they hold third-party security audit certifications such as SOC 2 or ISO 27001. Additionally, organizations can look at whether the provider participates in industry data portability initiatives (such as inter-cloud data transfer protocols), which often reflects their fundamental attitude toward customer data rights.
Develop a Clear Data Exit Plan
The following questions should be clearly addressed from the moment a contract is signed:
- How can data be exported? Is the export format a standard, universal format?
- In the event of provider bankruptcy, are there contractual provisions protecting data disposition rights?
- How much time and cost does large-scale data migration require?
A clear data exit plan is the last line of defense against provider risk. It is recommended to contractually specify: the provider must offer no less than 90 days for data migration upon service termination; data should be stored in open standard formats (such as common video codecs, open document formats, etc.) to ensure portability; and the provider must offer bulk data export tools or physical media shipping services (such as AWS Snowball devices) to handle ultra-large-scale data transfer needs.
Provide the Highest Level of Protection for Irreplaceable Data
Historical archive materials like those held by PBS constitute irreplaceable data—once lost, they cannot be regenerated by any means. For assets with unique historical value, investing in higher backup costs is entirely justified. In contrast, temporary data that can be recomputed or reacquired at any time can employ more economical storage strategies.
The industry typically classifies data by reproducibility and business impact: Tier 1 covers irreplaceable critical data (such as original master footage, historical archives), which should receive the highest level of multi-copy, multi-media, cross-geographic protection; Tier 2 covers data that is reconstructable but at high cost (such as complex computation results), for which at least two offsite copies are recommended; Tier 3 covers temporary data that can be regenerated at any time (such as caches, logs), which can use single-copy storage. The 70 years of television materials PBS lost unquestionably fall into Tier 1 and should have received the most rigorous protection strategy.
Conclusion: Data Protection Is Strategy, Not Just Technology
PBS losing 50TB of data—70 years of television history gone forever—is a sobering wake-up call. It reminds us that data protection has never been merely a technical problem; it is fundamentally a matter of strategy and governance.
Cloud computing has brought unprecedented convenience, but behind that convenience lurk new risk dimensions. For data carrying public memory, cultural heritage, and critical business functions, organizations cannot place all their trust in any single provider. Multiple copies, multiple media, cross-provider distribution, offsite storage—these seemingly "outdated" principles have become more precious than ever in the cloud era.
This incident also sounds an alarm for the entire industry: amid the digital transformation wave, have we become too credulous of technical promises while neglecting fundamental risk management principles? As "Everything as a Service" becomes the dominant paradigm, do we need to rethink the boundaries of data sovereignty and control? These questions deserve deep reflection from every technology decision-maker.
After all, deleted bytes can be rewritten, but lost history can never be recovered.
Related articles

Claude Autonomously Designs Proteins with 35% Success Rate, Far Exceeding Human Expert Performance
Anthropic's Claude achieves 35% wet-lab success rate in autonomous protein design, far surpassing the 10-15% human expert average, signaling AI's move toward real scientific productivity.

Perplexity Discover's Multilingual Support Suddenly Disappears — Why Are International Users Upset?
Perplexity Discover's multilingual news feature suddenly dropped non-English support, frustrating international users. We analyze possible causes and the broader challenges of AI product internationalization.

GitHub Daily · August 20: Mojo Tops the Charts & The Local-First Open Source Rebellion
GitHub Trending Aug 20: Mojo tops charts for AI compute stack ambitions, OpenLogi surges 1225 stars with local-first philosophy, and privacy rebellion dominates.