SEC Fines Morgan Stanley $35 Million for Data Security Failures

SEC Fines Morgan Stanley $35 Million for Data Security Failures

By: Ken Chase.

Estimated reading time: 2 minutes

The U.S. Securities and Exchange Commission confirmed this week that it has levied a $35 million penalty against Morgan Stanley Smith Barney related to the firm’s failure to protect its customers’ personal identifying information (PII) over a five-year period. The data security failures reportedly impacted the personal information of roughly 15 million MSSB customers.

In a press release announcing the action, the SEC alleged that the firm “hired a moving and storage company with no experience or expertise in data destruction services to decommission thousands of hard drives and servers containing the PII of millions of its customers,” and failed to implement any monitoring of the contracted company’s work.

The SEC investigation found that the devices were then sold to a third party, and ultimately ended up on an internet auction website. Some of those devices reportedly contained customer PII—information that had not been removed prior to sale. Despite later efforts by MSSB to recover the devices, the investigation found that most of them remained at large.

According to the SEC, the company’s failures also included the loss of 42 servers which went missing during a decommissioning effort at the firm’s branches. The SEC alleges that all of those servers could potentially contain customer PII, as well as consumer report data. Apparently, the company’s own investigation discovered that its personnel had not even activated the servers’ equipped encryption software.

SEC Enforcement Division Director Gurbir S. Grewal stressed the magnitude of the firm’s negligence and its potential impact on customers:

“MSSB’s failures in this case are astonishing. Customers entrust their personal information to financial professionals with the understanding and expectation that it will be protected, and MSSB fell woefully short in doing so. If not properly safeguarded, this sensitive information can end up in the wrong hands and have disastrous consequences for investors. Today’s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.”

Learn more on this topic

Related Insights

FDIC Issues New Draft Guidance for Bank Merger Scrutiny

FDIC Issues New Draft Guidance for Bank Merger Scrutiny

This week, the Federal Deposit Insurance Corporation issued draft guidance that would increase bank merger scrutiny. According to Reuters, the proposed guidance would be the first change to the FDIC’s merger principles in 16 years. The regulators’ board of directors...

Powell: Growing Fed Confidence for Rate Cuts

Powell: Growing Fed Confidence for Rate Cuts

On Thursday, Federal Reserve Chairman Jerome Powell testified before the Senate Banking Committee. During that testimony, he suggested that the central bank is becoming more confident that the nation’s inflation rate is moving in the right direction. If that trend...

Capital One Announces $35B Megamerger with Discover

Capital One Announces $35B Megamerger with Discover

Capital One recently confirmed its intent to purchase Discover Financial for $35.3 billion. Regulators will still need to approve the megamerger before the sale can proceed. If that approval happens, Capital One would become the nation’s largest credit card issuer,...