An investigation(Opens in a new window) by the US Securities and Exchange Commission (SEC) discovered Morgan Stanley Smith Barney, now known as Morgan Stanley Wealth Management, put the personal information of 15 million customers at risk due to the way it handled old hard drives and servers.
Starting in 2015, and for a period spanning five years, Morgan Stanley hired a moving and storage company multiple times to handle the decommissioning of old hard drives and servers. There were two problems with this decision. The first is that the company selected to handle the drives had "no experience or expertise in data destruction services," according to the SEC. The second problem was that Morgan Stanley didn't encrypt the data stored on these drives, and didn't attempt to delete any of it before handing them over to the moving company.
This scenario led to the personal data of millions of Morgan Stanley customers being available on thousands of old hard drives without any form of protection. The SEC found that instead of permanently deleting the data stored on the drives, the moving company simply sold them on to a third-party, which in turn sold some of them on internet auctions sites with the data still intact. The vast majority of these hard drives have never been recovered.
In total, the SEC investigation discovered records showing "42 servers, all potentially containing unencrypted customer PII and consumer report information, were missing." The devices being used by Morgan Stanley did have the ability to encrypt the data being stored, but it was never enabled.
Gurbir S. Grewal, Director of the SEC’s Enforcement Division, said that Morgan Stanley's failures were "astonishing," and that the company "fell woefully short"
Read more on pcmag.com