Skip to content

Morgan Stanley

Disclosed Sep 20, 20224 years ago15,000,000 affectedSettled

Official notice

SEC fines Morgan Stanley $35M over lost drives holding data of 15M customers

The SEC found that from 2015 Morgan Stanley's wealth unit hired a moving company without data destruction expertise to decommission servers and hard drives holding customer data, and many devices were resold unwiped. The firm agreed to pay $35 million without admitting or denying the findings.

What is known

People affected15,000,000 (as reported by the organization)
DisclosedSep 20, 2022
AttackVendor breach
Data exposedNames, Financial, Other, Health
SectorFinance · US
StatusSettled
Lawsuit or fine$35M SEC penalty (2022) (about $35M)

Sources

Notices filed

WhereFiledPeople
ResearchtotalSep 20, 202215,000,000
HHS archivetotalApr 18, 2023535

Other breaches at Morgan Stanley

BreachAffected
Auctioned devices with unwiped customer data; USD 6.5M multistate settlementNov 16, 20232 years agoLost or stolen deviceUnknown
Disclosed Jul 10, 2020Jul 10, 20206 years agoHacking14M
History of this record
  • 2026-09-25 · data_types: ["names","financial","other"] to ["names","financial","other","health"] · backfill source
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Morgan Stanley

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.