DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIdentity (basic)Government IDMediumContained

MORGAN STANLEY

bd_1dcf72e45ca387ea · schema v1 · pii pii-v1

Severity

Medium

Discovered

May 20, 2021

Filed

Jul 2, 2021

To disclose

6 weeks

Affected

43state residents only

Linked

8 filings

Confidence

66%
Full breach record for MORGAN STANLEY15 incidents on file

Morgan Stanley notified Montana of a data incident involving a third-party vendor, Guidehouse. An unauthorized individual obtained encrypted stock plan participant files and the decryption key in January 2021. Data included names, addresses, DOBs, and SSNs. Guidehouse remediated the vulnerability in Jan 2021 but discovered the breach in May 2021. Morgan Stanley offers 24 months of credit monitoring.

Incident timeline

undetected · 139 days
discovery → filing · 6 weeks / 43 days

Jan 1, 2021

Begins

May 20, 2021

Discovered

Jul 2, 2021

Filed

vs. sector median

2 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 5d gap

Filing propagation · 8 filings · 7 states

View merged incident ↗
California State AGJul 2 · first
Washington State AGJul 2 · first
Indiana State AGJul 2 · first
Oregon State AGJul 2 · first
Montana State AGJul 2 · first · this page

Pattern: first filing Jul 2 (CA), last Jul 7 (NH) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.