• Home
  • News
  • Fortune 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Financedata breach

Oops. Morgan Stanley pays $35 million fine after customer data turns up in hard drives bought by IT consultant in Oklahoma

By
Chloe Taylor
Chloe Taylor
Down Arrow Button Icon
By
Chloe Taylor
Chloe Taylor
Down Arrow Button Icon
September 21, 2022, 7:26 AM ET
Morgan Stanley has been fined $35 million after devices containing millions of its customers' data turned up in an online auction.
Morgan Stanley has been fined $35 million after devices containing millions of its customers' data turned up in an online auction. Mario Tama—Getty Images

Most of us make IT blunders from time to time—but it’s not often that those mistakes are so egregious that they cost tens of millions of dollars.

That’s the situation Morgan Stanley Smith Barney found itself in on Tuesday, when the investment bank agreed to pay $35 million to settle charges brought against it by the U.S. Securities and Exchange Commission (SEC).

An SEC investigation found that over a five-year period, Morgan Stanley had been failed to properly dispose of devices that were storing its customers’ personal identifying information (PII). The SEC said in a statement that Morgan Stanley’s “extensive failures” had put around 15 million customers’ personal data at risk.

“Customers entrust their personal information to financial professionals with the understanding and expectation that it will be protected, and [Morgan Stanley] fell woefully short in doing so,” Gurbir S. Grewal, director of the SEC’s Enforcement Division, said in the statement.

Litany of ‘astonishing’ mistakes

The litany of failures the SEC discovered during the investigation were, in the words of Grewel, “astonishing.”

On multiple occasions dating back to 2015, it was found that the bank hired a moving and storage company with no experience or expertise in data destruction to decommission hard drives and servers containing millions of customers’ PII.

Morgan Stanley failed to properly monitor the moving company’s work, the SEC said—and the moving company went on to sell thousands of Morgan Stanley devices that were storing PII.

Those devices were eventually resold, complete with the data, in an online auction.

Morgan Stanley had managed to recoup some of the devices, which contained thousands of pieces of unencrypted customer data, but the SEC said the company had failed to recover the vast majority of its improperly disposed hardware.

The devices had been equipped with encryption software, but the software had never been activated.

In 2017—a year after the completion of the data center decommissioning project—an Oklahoma IT consultant emailed Morgan Stanley to inform the bank he had purchased a hard drives online that were full of the company’s data.

“You are a major financial institution and should be following some very stringent guidelines on how to deal with retiring hardware,” the consultant said in the email. “Or at the very least getting some kind of verification of data destruction from the vendors you sell equipment to.”

Morgan Stanley repurchased the hard drives from the consultant.

‘Disastrous consequences’ for investors

“If not properly safeguarded, this sensitive information can end up in the wrong hands and have disastrous consequences for investors,” the SEC’s Grewel said. “Today’s action sends a clear message to financial institutions that they must take seriously their obligation to safeguard such data.”

Morgan Stanley consented to pay $35 million to the SEC without admitting or denying the organization’s charges.

“We are pleased to be resolving this matter,” a Morgan Stanley spokesperson told Fortune on Wednesday. “We have previously notified applicable clients regarding these matters, which occurred several years ago, and have not detected any unauthorized access to, or misuse of, personal client information.”

Sign up for the Fortune Features email list so you don’t miss our biggest features, exclusive interviews, and investigations.
About the Author
By Chloe Taylor
LinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Finance

Alex Amouyel is the President and CEO of Newman’s Own Foundation
Commentaryphilanthropy
Following in Paul Newman and Yvon Chouinard’s footsteps: There are more ways for leaders to give it away in ‘the Great Boomer Fire Sale’ than ever
By Alex AmouyelDecember 7, 2025
2 hours ago
CryptoCryptocurrency
So much of crypto is not even real—but that’s starting to change
By Pete Najarian and Joe BruzzesiDecember 7, 2025
2 hours ago
Hank Green sipping tea
SuccessPersonal Finance
Millionaire YouTuber Hank Green tells Gen Z to rethink their Tesla bets—and shares the portfolio changes he’s making to avoid AI-bubble fallout
By Preston ForeDecember 7, 2025
3 hours ago
MagazineWarren Buffett
Warren Buffett: Business titan and cover star
By Indrani SenDecember 7, 2025
4 hours ago
EconomyEurope
JPMorgan CEO Jamie Dimon says Europe has a ‘real problem’
By Katherine Chiglinsky and BloombergDecember 6, 2025
16 hours ago
Elon Musk
Big TechSpaceX
SpaceX to offer insider shares at record-setting $800 billion valuation
By Edward Ludlow, Loren Grush, Lizette Chapman, Eric Johnson and BloombergDecember 6, 2025
16 hours ago

Most Popular

placeholder alt text
AI
Nvidia CEO says data centers take about 3 years to construct in the U.S., while in China 'they can build a hospital in a weekend'
By Nino PaoliDecember 6, 2025
21 hours ago
placeholder alt text
Real Estate
The 'Great Housing Reset' is coming: Income growth will outpace home-price growth in 2026, Redfin forecasts
By Nino PaoliDecember 6, 2025
1 day ago
placeholder alt text
Economy
The most likely solution to the U.S. debt crisis is severe austerity triggered by a fiscal calamity, former White House economic adviser says
By Jason MaDecember 6, 2025
16 hours ago
placeholder alt text
Big Tech
Mark Zuckerberg rebranded Facebook for the metaverse. Four years and $70 billion in losses later, he’s moving on
By Eva RoytburgDecember 5, 2025
2 days ago
placeholder alt text
Asia
Despite their ‘no limits’ friendship, Russia is paying a nearly 90% markup on sanctioned goods from China—compared with 9% from other countries
By Jason MaNovember 29, 2025
8 days ago
placeholder alt text
Success
Nvidia CEO Jensen Huang admits he works 7 days a week, including holidays, in a constant 'state of anxiety' out of fear of going bankrupt
By Jessica CoacciDecember 4, 2025
3 days ago
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Fortune Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.