HackingStolen CredentialsSupply Chain (3P Vendor)Delayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
MORGAN STANLEY
bd_1858bfd9dbcb4a68 · schema v1 · pii pii-v1
Full breach record for MORGAN STANLEY →Morgan Stanley notified California AG that a third-party vendor suffered a data security incident in May 2021. An unauthorized individual obtained decryption keys for encrypted files containing PII (name, address, DOB, SSN) of stock plan participants. Morgan Stanley arranged 24 months of credit monitoring via Experian. The vendor remediated the vulnerability in January 2021.
California clockDiscovered May 1, 2021 → Notified Jul 20, 202180d ✗ CA 60-day late9 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_1dcf72e45ca387eaMontana State AGfiled 2021-07-02Candidate
- bd_2bbc0c7d3717c282Washington State AGfiled 2021-07-02Verified by operator
- bd_81be7ab9e152b118Oregon State AGfiled 2021-07-02Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542538
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 2, 2021
- Raw hash
- 1943ef1c0669e2ba84da6f2d2d0a7a7de879718889c9faf77511c1e881835186
Reporting entity
- Name
- MORGAN STANLEYnorm: morgan stanley
- Domain
- morganstanley.com
Victim entity
- Name
- MORGAN STANLEYnorm: morgan stanley
- Domain
- morganstanley.com
Incident
- Discovered
- May 1, 2021
- Materiality determined
- —
- Notification sent
- Jul 20, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- CA 60-day late · 80d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 1, 2021→ Notified: Jul 20, 202180d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.