Take a fresh look at your lifestyle.

Morgan Stanley to pay $35 million to settle SEC charges it mishandled customer data

Morgan Stanley to pay $35 million to settle SEC charges it mishandled customer data © Reuters. FILE PHOTO: The logo for Morgan Stanley is seen on the trading floor at the New York Stock Exchange (NYSE) in Manhattan, New York City, U.S., August 3, 2021. REUTERS/Andrew Kelly

By Pete Schroeder

WASHINGTON (Reuters) – A Morgan Stanley (NYSE:) unit has agreed to pay $35 million to settle Securities and Exchange Commission charges it repeatedly failed to safeguard personal information for millions of customers, the regulator said Tuesday.

The SEC said that for five years, Morgan Stanley Smith Barney failed to protect personal identifying information for 15 million customers. The firm agreed to pay the fine without admitting or denying its findings.

Dating back to 2015, the firm failed to properly dispose of devices containing sensitive information, including repeatedly hiring a moving and storage company with no proper expertise to decommission thousands of hard drives and servers, the SEC said. Those devices wound up being sold to a third party and ultimately auctioned online with the personal information intact and unencrypted. Only a portion of those devices were recovered, according to the regulator.

The SEC also said the firm lost track of 42 servers containing personal information when it was undergoing a hardware refresh program, and failed to activate existing encryption software on those devices for years beforehand.

“MSSB’s failures in this case are astonishing. Customers entrust their personal information to financial professionals with the understanding and expectation that it will be protected, and MSSB fell woefully short in doing so,” Gurbir Grewal, the SEC’s enforcement director, said in a statement.

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More