Avernar I read about it at the time, and it was mentioned here as well. However, just because it happened in the NCIX case doesn't mean that it should happen, nor that we should be forced to accept such behaviour. When entrusted with such data, any business or person should be required to handle any data they collect responsibly, which should include securely destroying said data if/when they wind down operations.
As was also discussed recently in the former forum, when dealing with credit card data, there is the matter of PCI compliance. If, as claimed above, credit card data were present in the NCIX case, that alone should have been enough to cause major trouble, both for the former business and the party who allowed it to be sold intact.