Moneycontrol PRO
Open App
Upcoming Event: Finterest EduTech Technical Analysis Programme in Oct, book your seats.
you are here: HomeNewsBusinessBanks

Morgan Stanley pays $35 million SEC fine over data security

The bank improperly disposed of thousands of devices and some were auctioned off online without checking that customer data they contained had been deleted, according to the SEC

September 20, 2022 / 07:50 PM IST
Morgan Stanley headquarters (Image: Bloomberg)

Morgan Stanley headquarters (Image: Bloomberg)

Morgan Stanley will pay $35 million to settle US Securities and Exchange Commission allegations that one of its units failed to secure the personal data of millions of customers when replacing company hard drives and servers.

The bank improperly disposed of thousands of devices and some were auctioned off online without checking that customer data they contained had been deleted, according to the SEC. About 15 million clients’ details were compromised over a five-year period starting 2015.

Following the announcement by the SEC, Morgan Stanley said in a statement that it was pleased to have resolved the matter. “We have previously notified applicable clients regarding these matters, which occurred several years ago, and have not detected any unauthorized access to, or misuse of, personal client information,” the firm said.

Morgan Stanley agreed to pay the penalty and settle the case without admitting or denying the allegations.

The violations occurred because the firm hired a moving and storage company with no experience in data destruction and then failed to properly monitor the company’s work, the SEC said. Morgan Stanley recovered some of the devices, which had thousands of pieces of unencrypted customer data. The vast majority of devices were not found, according to the regulator.

Close

Gurbir Grewal, director of the SEC’s enforcement division, called the findings “astonishing.” Grewal added that “customers entrust their personal information to financial professionals with the understanding and expectation that it will be protected.”

Tuesday’s penalty is also related to the brokerage’s failure to properly dispose of customer and consumer report information as part of a broader hardware refresh program, during which the firm found that 42 servers were missing. The unit didn’t activate available encryption programs that were available on the devices, the SEC said.
Bloomberg
first published: Sep 20, 2022 07:50 pm
Sections
ISO 27001 - BSI Assurance Mark