MORGAN STANLEY
bd_41e5015956b7b403 · schema v1 · pii pii-v1
Full breach record for MORGAN STANLEY →15 incidents on fileMorgan Stanley notified customers of two incidents involving potential exposure of personal data. In 2016, decommissioned data center equipment may have retained unencrypted data despite vendor wiping. In 2019, a replaced branch server with encrypted disks was lost; a software flaw may have left small amounts of deleted data unencrypted. No unauthorized access was detected. Affected data included names, account numbers, SSNs, and contact info. Morgan Stanley offered 24 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 1, 2016
Begins
Jul 10, 2020
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Oregon State AGbd_11f7388fd30c23a42020-07-10Candidate
- Washington State AGbd_1ae5e07b0d2263112020-07-10Verified
- Montana State AGbd_2fb0a16ad9d0455c2020-07-10Verified
- New Hampshire State AGbd_547fe0a280ba343b2020-07-10Verified
Show 2 more filings ↓Show fewer ↑
- Massachusetts State AGbd_a335ef95525320982020-07-10Verified
- Massachusetts State AGbd_ead70df0ae64231d2020-07-10Verified
Filing propagation · 7 filings · 6 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.