AccidentalMisconfigurationData ExfiltratedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
MORGAN STANLEY
bd_41e5015956b7b403 · schema v1 · pii pii-v1
Full breach record for MORGAN STANLEY →Morgan Stanley disclosed a data security incident involving the potential exposure of unencrypted personal information on decommissioned computer equipment and a disconnected branch office server. The incident involved data centers closed in 2016 and a server disconnected in 2019. Affected data may include names, account numbers, Social Security numbers, dates of birth, and asset values. Morgan Stanley offered 24 months of credit monitoring through Experian. No unauthorized access or misuse was detected.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-191926
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 10, 2020
- Raw hash
- 5f86900a9e670707356eb4597945688f7d1b6d8c807b2a33d4be29bcd48de8f5
Reporting entity
- Name
- MORGAN STANLEYnorm: morgan stanley
- Domain
- morganstanley.com
Victim entity
- Name
- MORGAN STANLEYnorm: morgan stanley
- Domain
- morganstanley.com
Incident
- Discovered
- Jul 1, 2020
- Materiality determined
- Jan 15, 2024
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1563 System Software Process Injection
- Regulator citations
- Submitted breach notification to California Office of the Attorney General
Compliance
- Time to disclose
- 9 days(9 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.