Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

The New Coffee Room

  1. TNCR
  2. General Discussion
  3. "No experience or expertise in data destruction services,"

"No experience or expertise in data destruction services,"

Scheduled Pinned Locked Moved General Discussion
4 Posts 3 Posters 44 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • George KG Offline
    George KG Offline
    George K
    wrote on last edited by
    #1

    Morgan Stanley Discarded Old Hard Drives Without Deleting Customer Data

    An investigation by the US Securities and Exchange Commission (SEC) discovered Morgan Stanley Smith Barney, now known as Morgan Stanley Wealth Management, put the personal information of 15 million customers at risk due to the way it handled old hard drives and servers.

    Starting in 2015, and for a period spanning five years, Morgan Stanley hired a moving and storage company multiple times to handle the decommissioning of old hard drives and servers. There were two problems with this decision. The first is that the company selected to handle the drives had "no experience or expertise in data destruction services," according to the SEC. The second problem was that Morgan Stanley didn't encrypt the data stored on these drives, and didn't attempt to delete any of it before handing them over to the moving company.

    This scenario led to the personal data of millions of Morgan Stanley customers being available on thousands of old hard drives without any form of protection. The SEC found that instead of permanently deleting the data stored on the drives, the moving company simply sold them on to a third-party, which in turn sold some of them on internet auctions sites with the data still intact. The vast majority of these hard drives have never been recovered.

    In total, the SEC investigation discovered records showing "42 servers, all potentially containing unencrypted customer PII and consumer report information, were missing." The devices being used by Morgan Stanley did have the ability to encrypt the data being stored, but it was never enabled.

    Gurbir S. Grewal, Director of the SEC’s Enforcement Division, said that Morgan Stanley's failures were "astonishing," and that the company "fell woefully short" of protecting its customer's personal information. Morgan Stanley has consented to the SEC's finding that it "violated the Safeguards and Disposal Rules under Regulation S-P," but did so without admitting or denying the findings. The company also agreed to pay a $35 million penalty to settle the charges against it.

    A Morgan Stanley spokesperson commented on the conclusion of the investigation and charges brought against the company, saying "We are pleased to be resolving this matter. We have previously notified applicable clients regarding these matters, which occurred several years ago, and have not detected any unauthorized access to, or misuse of, personal client information."

    "Now look here, you Baltic gas passer... " - Mik, 6/14/08

    The saying, "Lite is just one damn thing after another," is a gross understatement. The damn things overlap.

    1 Reply Last reply
    • George KG Offline
      George KG Offline
      George K
      wrote on last edited by
      #2

      "We get rid of data the old fashioned way. We burn it."

      "Now look here, you Baltic gas passer... " - Mik, 6/14/08

      The saying, "Lite is just one damn thing after another," is a gross understatement. The damn things overlap.

      1 Reply Last reply
      • jon-nycJ Online
        jon-nycJ Online
        jon-nyc
        wrote on last edited by
        #3

        Matt Levine had a biting and informative piece on this.

        "You never know what worse luck your bad luck has saved you from."
        -Cormac McCarthy

        1 Reply Last reply
        • X Offline
          X Offline
          xenon
          wrote on last edited by
          #4

          Damned if you bleachbit, damned if you don't

          1 Reply Last reply
          Reply
          • Reply as topic
          Log in to reply
          • Oldest to Newest
          • Newest to Oldest
          • Most Votes


          • Login

          • Don't have an account? Register

          • Login or register to search.
          • First post
            Last post
          0
          • Categories
          • Recent
          • Tags
          • Popular
          • Users
          • Groups