DisclosureLens
AccidentalFinancial ServicesFinanceMisconfigurationCustomer Data InvolvedGovernment IDIdentity (basic)Financial accountHighContained

MORGAN STANLEY

bd_547fe0a280ba343b · schema v1 · pii pii-v1

Severity

High

Discovered

Filed

Jul 10, 2020

To disclose

Affected

77,296state residents only

Linked

7 filings

Confidence

68%
Full breach record for MORGAN STANLEY15 incidents on file

Morgan Stanley notified the New Hampshire Attorney General on July 10, 2020, of two data security incidents involving approximately 77,296 NH residents. The 'Data Center Event' involved unencrypted data remaining on decommissioned devices from 2016. The 'WAAS Device Event' involved missing servers from 2019 with a software flaw leaving data unencrypted. No unauthorized access was detected. Morgan Stanley provided 24 months of credit monitoring via Experian.

Incident timeline — partial

? — ?

Breach window unknown

Jul 10, 2020

Filed

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

This filing is one of 7 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (6) · sorted by filing gap

Show 2 more filings

Filing propagation · 7 filings · 6 states

View merged incident ↗
Oregon State AGJul 10 · first
Washington State AGJul 10 · first
Montana State AGJul 10 · first
California State AGJul 10 · first
Massachusetts State AGJul 10 · first
Massachusetts State AGJul 10 · first
New Hampshire State AGJul 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.