Morgan Stanley to pay 6 states $6.5M for failing to protect customer data

Morgan Stanley to pay 6 states $6.5M for failing to protect customer data
About 15 million clients' details were exposed after information was left on decommissioned computers.
NOV 16, 2023

Morgan Stanley Smith Barney agreed Thursday to pay six states $6.5 million to settle charges that it failed to protect customers’ personal information while shutting down two data centers in 2016.

The problem occurred when computer devices were decommissioned and resold following the closure of the data centers. Morgan Stanley contracted with a vendor to remove data from the devices. But the vendor subcontracted some of the work to an unauthorized vendor and some customer information was left on the computers, according to an agreement released by New York Attorney General Letitia James.

A second incident involved a software flaw that could have allowed unencrypted customer data to remain on devices that Morgan Stanley could not locate after they were decommissioned. The vulnerabilities involved the disposal of computer hardware rather than an external breach.

Approximately 15 million clients' details were exposed over a five-year period beginning in 2015, Bloomberg News previously reported.

An investigation by James and the other state attorneys general “determined that Morgan Stanley failed to maintain adequate vendor controls and hardware inventories, and that had these controls been in place, the data incidents could have been prevented,” the New York agreement states.

The firm notified the attorneys general on July 10, 2020, about the potential vulnerability of the client data. The settlement with New York, Connecticut, New Jersey, Vermont, Indiana and Florida concluded an ongoing investigation. The firm reached a $35 million settlement with the Securities and Exchange Commission last year over the same charges.

“No one should have their personal information auctioned off without their knowledge because a company failed to take basic steps to erase it before selling their old computers,” James said in a statement. “Today’s agreement requires Morgan Stanley to bolster its cybersecurity so consumers will never again have to risk their personal data unintentionally being sold at an auction. Companies, big and small, must all take their responsibility to protect their customers’ data seriously, and if they do not, my office will take action.”

As part of the agreement, Morgan Stanley adopted several improvements to better protect sensitive customer data, such as encrypting customers’ personal information and strengthening risk assessments of vendors.

“We have previously notified all potentially impacted clients regarding these matters, which occurred several years ago, and are pleased to have resolved this related investigation,” a Morgan Stanley spokesperson said in a statement.

The firm has said that it has not detected unauthorized access to or misuse of customer information.

Why advisors should consider adding options overlays to client portfolios

Latest News

SEC charges Chicago-based investment adviser with overbilling clients more than $2.5M in fees
SEC charges Chicago-based investment adviser with overbilling clients more than $2.5M in fees

Eliseo Prisno, a former Merrill advisor, allegedly collected unapproved fees from Filipino clients by secretly accessing their accounts at two separate brokerages.

Apella Wealth comes to Washington with Independence Wealth Advisors
Apella Wealth comes to Washington with Independence Wealth Advisors

The Harford, Connecticut-based RIA is expanding into a new market in the mid-Atlantic region while crossing another billion-dollar milestone.

Citi's Sieg sees rich clients pivoting from US to UK
Citi's Sieg sees rich clients pivoting from US to UK

The Wall Street giant's global wealth head says affluent clients are shifting away from America amid growing fallout from President Donald Trump's hardline politics.

US employment report reactions: Overall better than expected, but concerns with underlying data
US employment report reactions: Overall better than expected, but concerns with underlying data

Chief economists, advisors, and chief investment officers share their reactions to the June US employment report.

Creative Planning's Peter Mallouk slams 'offensive' congressional stock trading
Creative Planning's Peter Mallouk slams 'offensive' congressional stock trading

"This shouldn’t be hard to ban, but neither party will do it. So offensive to the people they serve," RIA titan Peter Mallouk said in a post that referenced Nancy Pelosi's reported stock gains.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.