{"id":4837,"date":"2022-10-05T10:00:59","date_gmt":"2022-10-05T15:00:59","guid":{"rendered":"https:\/\/blogs.luc.edu\/compliance\/?p=4837"},"modified":"2022-10-05T10:00:59","modified_gmt":"2022-10-05T15:00:59","slug":"mismanagement-of-client-data-results-in-a-35-million-fine-for-large-investment-company","status":"publish","type":"post","link":"https:\/\/blogs.luc.edu\/compliance\/?p=4837","title":{"rendered":"Mismanagement of Client Data Results in a $35 Million Fine for Large Investment Company"},"content":{"rendered":"<p><em>Juhi Desai<\/em><\/p>\n<p><em>Associate Editor<\/em><\/p>\n<p><em>Loyola University Chicago School of Law, JD 2024<\/em><\/p>\n<p>Morgan Stanley Smith Barney (\u201cMorgan Stanley\u201d), a leading investment company, found itself in hot water after complaints of a data breach. In 2015, Morgan Stanley allegedly auctioned off devices that contained sensitive information. On September 20, 2022, the U.S. Securities and Exchange Commission (SEC) fined the multinational company $35 million because of the leak.<!--more--><\/p>\n<p><strong>What happened?<\/strong><\/p>\n<p>In 2015, as a part of their broader hardware refresh program, Morgan Stanley reportedly <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2022-168\">disposed<\/a> of old computer hardware, such as hard drives and computer services. This cleanout was done with the help of a moving company that did not have the proper expertise to destroy unencrypted client data. It was during this time when sensitive information of their clients was not properly disposed of.<\/p>\n<p>There were allegedly <a href=\"https:\/\/www.yahoo.com\/video\/oops-morgan-stanley-pays-35-112643362.html\">42 hard drives<\/a> that were disposed of at various times throughout the year by the investment company. These drives were later resold elsewhere with the company data still present and unencrypted. Morgan Stanley <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2022-168\">claims<\/a> it was not aware the privileged information was still on the files. Most of the data on these drivers was sensitive, with the data pertaining to an estimate <a href=\"https:\/\/arstechnica.com\/information-technology\/2022\/09\/morgan-stanley-pays-35m-penalty-for-extensive-failure-to-safeguard-customer-data\/\">15 million<\/a> of their clients. Morgan Stanley was informed about a leak after an <a href=\"https:\/\/fortune.com\/2022\/09\/21\/morgan-stanley-fined-35-million-after-customer-data-auctioned-off-online\/\">IT consultant<\/a> from Oklahoma notified them about the preexisting client data on the servers he retrieved from an auction. However, they were not made aware of the leak until <a href=\"https:\/\/arstechnica.com\/information-technology\/2022\/09\/morgan-stanley-pays-35m-penalty-for-extensive-failure-to-safeguard-customer-data\/\">2017<\/a>, more than a year after the leak occurred. Although Morgan Stanley was able to recover a few of the drives, most of the leaked data was lost.<\/p>\n<p>The lack of deleting privileged data was not the only thing that went wrong during this cleanout. Ironically, throughout this process, Morgan Stanley learned about the unused encryption capability their devices contained. Despite using these programs for years, Morgan Stanley neglected to trigger the <a href=\"https:\/\/www.wsj.com\/articles\/morgan-stanley-paying-35-million-to-settle-claims-of-failing-to-protect-customer-records-11663671600\">encryption software<\/a>. The system was meant to ensure privileged client data would be <a href=\"https:\/\/www.nytimes.com\/2022\/09\/20\/us\/morgan-stanley-smith-barney-settlement.html\">inaccessible<\/a> to third parties without inputting necessary credentials. If this system was activated, the likelihood of data disclosure would have been slim to none.<\/p>\n<p><strong>The hefty fine<\/strong><\/p>\n<p>The <a href=\"https:\/\/www.sec.gov\/\">SEC<\/a>, a federal agency that monitors and enforces laws against market manipulation, stated in its statement dated September 20, 2022, that Morgan Stanley violated the regulation that requires \u201cbrokers and money managers to <a href=\"https:\/\/www.cnn.com\/2022\/09\/20\/business\/morgan-stanley-fine-customer-data\/index.html\">protect the security and confidentiality<\/a> of certain customer records.\u201d<\/p>\n<p>The $35 million fee given to Morgan Stanley earlier this year represents a <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2022-168\">monetary punishment<\/a> against the investment company. No doubt, the SEC is hoping to encourage Morgan Stanley, and other similarly situated businesses, to comply with federal laws. The agency is not shy from fining those who are not in compliance with federal rules and regulations. In 2021, the agency reportedly \u201cimposed fines of <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2021-169\">$300,000<\/a> or less on three smaller financial -advisory firms\u201d regarding the same issue. The SEC emphasizes how important the protection of client data is and how otherwise disastrous the data leak could have been, had the data been acquired by someone who had <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2022-168\">ill intentions<\/a>.<\/p>\n<p>Morgan Stanley has <a href=\"https:\/\/www.reuters.com\/legal\/morgan-stanley-pay-35-mln-settle-sec-charges-it-mishandled-customer-data-2022-09-20\/\">agreed to pay the fine<\/a> without accepting or denying the charges. It states there was no misuse or \u201cexploitation\u201d of any sensitive data over the years. In a statement, the spokesperson for Morgan Stanley relayed how they were \u201c<a href=\"https:\/\/techcrunch.com\/2022\/09\/21\/morgan-stanley-hard-drives-data-breach\/\">pleased to be resolving this matter<\/a>.\u201d<\/p>\n<p><strong>Why it\u2019s important?<\/strong><\/p>\n<p>With more people utilizing the internet and inputting their personal information into online databases, there have been growing concerns about the lack of security around sensitive client information. At the beginning of the month, numerous <a href=\"https:\/\/www.npr.org\/2022\/09\/20\/1124098322\/american-airlines-hack-data-breach\">American Airlines employees and customers<\/a> were notified their personal data, including their passport number, was compromised during an alleged data breach that occurred in July. Similarly, earlier this week <a href=\"https:\/\/techcrunch.com\/2022\/09\/16\/uber-internal-network-hack\/\">Uber notified its users<\/a> that an anonymous third party hacked into their internal network and may have stolen some of their customer data. Concerns regarding cybersecurity remain at the top.<\/p>\n<p>Many citizens are worried these major companies are only getting a \u201c<a href=\"https:\/\/arstechnica.com\/information-technology\/2022\/09\/morgan-stanley-pays-35m-penalty-for-extensive-failure-to-safeguard-customer-data\/\">slap on the wrist<\/a>\u201d with these fines. Instead, they hope institutions, like the SEC, should be enforcing stricter penalties to ensure a full stop to future data breaches.<\/p>\n<p>As a company with high-profile clients the data that Morgan Stanley stores should be protected with the utmost integrity. Due to their respectable reputation, many clients fully entrust Morgan Stanley to keep their data private, especially from unknown third parties. It is their duty to ensure that not only are they themselves destroying privileged data but that they hire professional services to check their work before the devices are resold.<\/p>\n<p>This was not the only time Morgan Stanley has been a part of a scandal concerning a data breach. The firm had previously been a party to a cybersecurity hack in 2021 after cyber-attackers hacked into the <a href=\"https:\/\/techcrunch.com\/2021\/07\/08\/the-accellion-data-breach-continues-to-get-messier\/\">Accellion<\/a> server and stole its customer&#8217;s data.<\/p>\n<p>Hopefully, this hefty penalty serves as a reminder for all other organizations to ensure their data management is top tier and to invest in stronger cybersecurity.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Juhi Desai Associate Editor Loyola University Chicago School of Law, JD 2024 Morgan Stanley Smith Barney (\u201cMorgan Stanley\u201d), a leading investment company, found itself in hot water after complaints of a data breach. In 2015, Morgan Stanley allegedly auctioned off devices that contained sensitive information. On September 20, 2022, the U.S. Securities and Exchange Commission &#8230;<br \/><a class=\"read-more-link btn btn-outline-secondary\" href=\"https:\/\/blogs.luc.edu\/compliance\/?p=4837\">Read more<\/a><\/p>\n","protected":false},"author":103,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[1623],"class_list":["post-4837","post","type-post","status-publish","format-standard","hentry","category-finance-banking","tag-cybersecurity"],"_links":{"self":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/4837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/users\/103"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4837"}],"version-history":[{"count":0,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=\/wp\/v2\/posts\/4837\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4837"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.luc.edu\/compliance\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}