SEC Fines Morgan Stanley $35 Million for Data Security Failures

SEC Fines Morgan Stanley $35 Million for Data Security Failures

By: Ken Chase.

Estimated reading time: 2 minutes

The U.S. Securities and Exchange Commission confirmed this week that it has levied a $35 million penalty against Morgan Stanley Smith Barney related to the firm’s failure to protect its customers’ personal identifying information (PII) over a five-year period. The data security failures reportedly impacted the personal information of roughly 15 million MSSB customers.

In a press release announcing the action, the SEC alleged that the firm “hired a moving and storage company with no experience or expertise in data destruction services to decommission thousands of hard drives and servers containing the PII of millions of its customers,” and failed to implement any monitoring of the contracted company’s work.

The SEC investigation found that the devices were then sold to a third party, and ultimately ended up on an internet auction website. Some of those devices reportedly contained customer PII—information that had not been removed prior to sale. Despite later efforts by MSSB to recover the devices, the investigation found that most of them remained at large.

According to the SEC, the company’s failures also included the loss of 42 servers which went missing during a decommissioning effort at the firm’s branches. The SEC alleges that all of those servers could potentially contain customer PII, as well as consumer report data. Apparently, the company’s own investigation discovered that its personnel had not even activated the servers’ equipped encryption software.

SEC Enforcement Division Director Gurbir S. Grewal stressed the magnitude of the firm’s negligence and its potential impact on customers:

“MSSB’s failures in this case are astonishing. Customers entrust their personal information to financial professionals with the understanding and expectation that it will be protected, and MSSB fell woefully short in doing so. If not properly safeguarded, this sensitive information can end up in the wrong hands and have disastrous consequences for investors. Today’s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.”

Learn more on this topic

Related Insights

Senators Move to Block CFPB Rule on Credit Card Fees

Senators Move to Block CFPB Rule on Credit Card Fees

Several Republican Senators are attempting to block the Consumer Financial Protection Bureau’s new rule restricting credit card feed. In a press release, the Republican Senate minority detailed their resolution that seeks to overrule the CFPB’s new policy. The CFPB’s...

New York Fed: Inflation Pressures Cooled in February

New York Fed: Inflation Pressures Cooled in February

A key inflation gauge cooled in February, down from January’s 3% to 2.9%, the Federal Reserve Bank of New York reported Monday. The decline in the bank’s Multivariate Core Trend Inflation index is seen by many as a signal that underlying inflation pressures may be...

FDIC Issues New Draft Guidance for Bank Merger Scrutiny

FDIC Issues New Draft Guidance for Bank Merger Scrutiny

This week, the Federal Deposit Insurance Corporation issued draft guidance that would increase bank merger scrutiny. According to Reuters, the proposed guidance would be the first change to the FDIC’s merger principles in 16 years. The regulators’ board of directors...