{"id":20171,"date":"2022-09-22T16:10:23","date_gmt":"2022-09-23T00:10:23","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/09\/22\/news-13904\/"},"modified":"2022-09-22T16:10:23","modified_gmt":"2022-09-23T00:10:23","slug":"news-13904","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/09\/22\/news-13904\/","title":{"rendered":"Morgan Stanley&#8217;s years-long &#8220;extensive failure&#8221; to protect customer data ends in huge fine"},"content":{"rendered":"<p>On Tuesday, the Securities and Exchange Commission (SEC) charged financial company Morgan Stanley&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/www.sec.gov\/news\/press-release\/2022-168\" target=\"_blank\">a $35M fine<\/a>&nbsp;for &#8220;the firm&#8217;s extensive failures, over five years, to protect the personal identifying information, or PII, of approximately 15 million customers. The company agreed to settle the penalty.<\/p>\n<p>As early as 2015, Morgan Stanley wasn&#8217;t properly disposing of devices containing sensitive customer data, according to a press release. In one instance, it hired a moving company with &#8220;no experience or expertise&#8221; in data destruction to eliminate thousands of devices containing hard drives and servers with thousands of unencrypted customer data. The company later auctioned these devices online with data still intact.<\/p>\n<p>Gurbir Grewal, the SEC&#8217;s director of the Division of Enforcement, described Morgan Stanley&#8217;s failures as &#8220;astonishing&#8221;.<\/p>\n<p>&#8220;Customers entrust their personal information to financial professionals with the understanding and expectation that it will be protected, and MSSB fell woefully short in doing so,&#8221; Grewal said in a statement. &#8220;If not properly safeguarded, this sensitive information can end up in the wrong hands and have disastrous consequences for investors. Today&#8217;s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.&#8221;<\/p>\n<p>Morgan Stanley recovered some of the re-sold assets, but &#8220;a vast majority&#8221; of these devices were not.<\/p>\n<p>On top of that, 42 servers, potentially containing unencrypted data by the thousands, from a local office and branch servers Morgan Stanley shut down went &#8220;missing&#8221;.<\/p>\n<p>Regardless of the amount of data that&nbsp;was &#8220;misplaced&#8221; for seven years, the company said it&#8217;s not aware any of the lost sensitive data were exploited.<\/p>\n<p>&#8220;We have previously notified applicable clients regarding these matters, which occurred several years ago, and have not detected any unauthorized access to, or misuse of, personal client information,&#8221; a spokesperson from Morgan Stanley said in&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/edition.cnn.com\/2022\/09\/20\/business\/morgan-stanley-fine-customer-data\/index.html\" target=\"_blank\">a statement to CNN<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/09\/morgan-stanleys-years-long-extensive-failure-to-protect-customer-data-ends-in-huge-fine\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding='10'>\n<tr>\n<td valign='top' align='left'>\n<p>Categories: <a href='https:\/\/www.malwarebytes.com\/blog\/category\/news' rel='category tag'>News<\/a><\/p>\n<p>Categories: <a href='https:\/\/www.malwarebytes.com\/blog\/category\/privacy' rel='category tag'>Privacy<\/a><\/p>\n<p>The SEC has unearthed a long list of whoopsies by Morgan Stanley, all involving the mishandling of sensitive data when disposing of devices.<\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/09\/morgan-stanleys-years-long-extensive-failure-to-protect-customer-data-ends-in-huge-fine' title='Morgan Stanley's years-long \"extensive failure\" to protect customer data ends in huge fine'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel='nofollow' href='https:\/\/www.malwarebytes.com\/blog\/news\/2022\/09\/morgan-stanleys-years-long-extensive-failure-to-protect-customer-data-ends-in-huge-fine'>Morgan Stanley&#8217;s years-long &#8220;extensive failure&#8221; to protect customer data ends in huge fine<\/a> appeared first on <a rel='nofollow' href='https:\/\/www.malwarebytes.com'>Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[32,5897],"class_list":["post-20171","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-news","tag-privacy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=20171"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/20171\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=20171"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=20171"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=20171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}