SEC fines Morgan Stanley $1 million for data-protection failures

SEC fines Morgan Stanley $1 million for data-protection failures
The fine relates to an ex-broker, Galen Marsh, who took data from hundreds of thousands of the wirehouse's clients, some of which ultimately ended up online.
JUN 07, 2016
The Securities and Exchange Commission slapped Morgan Stanley with a $1 million penalty to settle charges related to failures to protect customer data, the agency announced Wednesday. A former broker working in Morgan Stanley's wealth management group, Galen Marsh, was fired early last year for the theft of client data, which affected hundreds of thousands of the firm's clients. Now, the SEC is saying Morgan Stanley failed to adopt written policies and procedures reasonably designed to protect customer data, and violated what's known as the “Safeguards Rule.” “As a result of these failures, from 2011 to 2014, a then-employee impermissibly accessed and transferred the data regarding approximately 730,000 accounts to his personal server, which was ultimately hacked by third parties,” the SEC said in a news release. “Given the dangers and impact of cyberbreaches, data security is a critically important aspect of investor protection. We expect SEC registrants of all sizes to have policies and procedures that are reasonably designed to protect customer information,” Andrew Ceresney, director of the SEC's enforcement division, said in the release. Morgan Stanley settled without admitting or denying the allegations. In a statement, Morgan Stanley said after it discovered the data breach it had promptly alerted law enforcement and regulators, and notified affected clients. "Morgan Stanley worked quickly to protect affected clients by changing account numbers and offering credit monitoring and identity theft protection services, and has strengthened its mechanisms for safeguarding client data," the statement said. "No fraud against any client account was reported as a result of this incident.” The SEC took issue with two of Morgan Stanley's internal web applications, or portals, that allowed its employees to access clients' confidential account information. Morgan Stanley didn't audit or test modules authorizing access to such portals, and didn't monitor or analyze employees' access to and use of them, according to the SEC. That allowed Mr. Marsh to download and transfer confidential data to his personal server at home over a period of three years. Some of that data was ultimately stolen from him and posted on the internet. Mr. Marsh received a criminal conviction of three years' probation and a $600,000 restitution order for his actions. In August of last year, the Federal Trade Commission said it wouldn't take action against Morgan Stanley for the data breach because it determined the breach was due to a glitch in data security controls and not a failure on the firm's part to secure account information in a reasonable and appropriate manner.

Latest News

Ashton Thomas-linked Amplify debuts QuantumRisk to help RIAs weather market shocks
Ashton Thomas-linked Amplify debuts QuantumRisk to help RIAs weather market shocks

"QuantumRisk, by design, recognizes that these so-called “impossible” events actually happen, and it accounts for them in a way that advisors can see and plan for," Dr. Ron Piccinini told InvestmentNews.

Turning conversations into clients: Attract prospects and gain new clients with these five strategies
Turning conversations into clients: Attract prospects and gain new clients with these five strategies

Advisors who invest time and energy on vital projects for their practice could still be missing growth opportunities – unless they get serious about client-facing activities.

Tax Foundation analysis highlights biggest OBBBA beneficiary states, counties
Tax Foundation analysis highlights biggest OBBBA beneficiary states, counties

The policy research institution calculates thousands in tax cuts for Washington, Wyoming, and Massachusetts residents on average, with milder reductions for those dwelling in wealth hotspots.

Meltdown of some Yieldstreet real estate funds raises eyebrows from financial advice industry
Meltdown of some Yieldstreet real estate funds raises eyebrows from financial advice industry

Yieldstreet real estate funds turned out to be far riskier than some clients believed them to be, according to CNBC.

RIA M&A activity hits record pace in H1 2025: Fidelity
RIA M&A activity hits record pace in H1 2025: Fidelity

The race to 100 transactions ended a month early this year, with April standing out as the most active month on record for RIA dealmaking.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.