Morgan Stanley agrees to pay $35 million fine for data security lapses 

September 21, 2022

Morgan Stanley will pay a $35 million fine to the Securities and Exchange Commission for data security failures. This includes reselling unencrypted hard drives from decommissioned data centers on auction platforms without first deleting them and not safeguarding the information of customers when displacing company hard drives and servers.

According to the SEC, Morgan Stanley’s actions in 2016 were part of a larger failure to protect customers’ data, as required by federal rules, and it outed data from 15 million of its customers by hiring a moving company with no experience or expertise in data destruction to destroy hard drives and servers containing customer data.

It went on to say that many of these storage devices were not even encrypted, despite the fact that the option existed.

Morgan Stanley provided the moving company with 53 RAID arrays with about 1,000 hard drives and about 8,000 backup tapes, and the company hired an IT specialist to destroy the sensitive data stored on the hard drives.

The moving company terminated its cooperation with that specialist and began selling the storage devices to a company, which then auctioned them off, until Morgan Stanley received an email in 2017 from an IT consultant informing them that hard drives, he had bought from an online auction site contained Morgan Stanley data.

Morgan Stanley agreed with the SEC’s finding that it violated the Safeguards and Disposal Rules under the S-P regulation and agreed to pay the $35 million penalty.

The sources for this piece include an article in ArsTechnica.

Top Stories

Related Articles

December 29, 2025 SoftBank Group Corp. has sold its entire remaining stake in Nvidia in hopes to help raise the more...

December 29, 2025 Google parent Alphabet said Monday it will acquire data-centre and energy developer Intersect Power in a deal more...

December 23, 2025 Google parent company Alphabet said Monday that it will acquire Intersect Power for $4.75 billion in cash more...

December 16, 2025 SpaceX has pulled its lowest-priced Starlink residential plan in the U.S., removing the $40-per-month 100 Mbps tier more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn