MORGAN STANLEY
ent_019e0b1fa33aabe7c87a2c1b586b1038
Disclosures
25+
HHS OCR · State AG · 9 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
401,246
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MORGAN STANLEY
- Normalized
- morgan stanley— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- IGJSJL3JD5P30I6NJZ34
- SEC EDGAR CIK
- 0000895421
- Domain
- morganstanley.com
Disclosure history (newest 25)newest first
- NEW YORKHHS OCRas victim2023-04-18
Morgan Stanley (Health Plan, NY) reported to HHS on 2023-04-18 an Unauthorized Access/Disclosure breach affecting 535 individuals. A vendor employee inadvertently mailed PHI — including names, dates of birth, addresses, Social Security numbers, diagnoses, lab results, medications, and other treatment information — to wrong addresses. Breached information located on Paper/Films. The CE notified HHS and affected individuals and implemented additional administrative, technical, and security safeguards.
- Massachusetts State AGas victim2022-03-21
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-03-21. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2021-07-07
Morgan Stanley, via its third-party administrator for Telephone and Data Systems (TDS), notified New Hampshire authorities of a data security incident involving a vendor. The vendor suffered a breach in January 2021, where an unauthorized individual obtained encrypted files and the decryption key. Data exposed included names, addresses, DOBs, and SSNs. Morgan Stanley discovered the impact in May 2021. TDS mailed notifications on July 2, 2021, offering 24 months of credit monitoring via Experian.
- California State AGas victim2021-07-02
Morgan Stanley notified the California AG of a data security incident involving a third-party vendor (Shareworks) that provides account maintenance services for Morgan Stanley's Stock Plan business. In May 2021, the vendor informed Morgan Stanley that an unauthorized individual had obtained personal information, including names, addresses, dates of birth, and Social Security numbers, from files in the vendor's possession. The data was obtained around January 2021 when the vendor's vulnerability was remediated. Morgan Stanley offered 24 months of complimentary credit monitoring through Experian to affected individuals.
- Montana State AGas victim2021-07-02
Morgan Stanley notified Montana of a data incident involving a third-party vendor, Guidehouse. An unauthorized individual obtained encrypted stock plan participant files and the decryption key in January 2021. Data included names, addresses, DOBs, and SSNs. Guidehouse remediated the vulnerability in Jan 2021 but discovered the breach in May 2021. Morgan Stanley offers 24 months of credit monitoring.
- Massachusetts State AGas victim2021-07-02
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-07-02. 407 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2021-07-02
Morgan Stanley notified the Washington AG of a data breach involving vendor Guidehouse. An unauthorized individual exploited the Accellion FTA vulnerability to access encrypted files containing PII (names, addresses, DOB, SSNs) of StockPlan Connect participants. Morgan Stanley was notified on May 20, 2021. 2,080 Washington residents were affected. Credit monitoring was offered.
- Maine State AGas reporting2021-07-02
Morgan Stanley, a financial services company, reported a data breach affecting various entities to whom it provides StockPlan Connect Services. The breach occurred at a third-party vendor, Guidehouse. The incident, which took place on January 20, 2021, and was discovered on May 20, 2021, involved an external system breach or hacking. The personal information of 116 Maine residents was compromised, including names and Social Security numbers. In response, Guidehouse offered affected individuals 24 months of credit monitoring and identity theft protection services through Experian IdentityWorks. Consumer notifications were sent on July 2, 2021.
- Indiana State AGas victim2021-07-02
Morgan Stanley reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-20 and was reported on 2021-07-02. 395 Indiana residents were affected. 33,443 individuals affected in total.
- Oregon State AGas victim2021-07-02
Morgan Stanley reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-02. The breach occurred during 1/20/2021. The breach was discovered on 5/20/2021. 33,443 individuals were affected. Notice was sent on 7/2/2021.
- New Hampshire State AGas victim2021-07-02
Morgan Stanley notified the New Hampshire Attorney General on July 2, 2021, of a data security incident involving third-party vendor Guidehouse. An unauthorized individual exploited a vulnerability in the Accellion File Transfer Appliance (FTA) to access encrypted files containing personal information of approximately 108 New Hampshire residents, including names, addresses, dates of birth, and Social Security numbers. The incident was discovered by Morgan Stanley on May 20, 2021, and notifications were sent to affected individuals and corporate clients. Credit monitoring services were provided via Experian.
- Massachusetts State AGas victim2020-12-01
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-12-01. 10 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2020-09-08
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-09-08. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2020-07-10
Morgan Stanley reported a data breach to the Oregon Attorney General. The breach was reported on 2020-07-10. 209,881 individuals were affected.
- Washington State AGas victim2020-07-10
Morgan Stanley notified Washington AG of two incidents involving ~401,246 residents. Data Center Event (2016): vendor retained unencrypted data on decommissioned devices. WAAS Device Event (2019): lost servers with encrypted disks; software flaw may have left deleted data unencrypted. Data included SSNs, passport numbers, account numbers, DOB. No unauthorized access detected. Credit monitoring offered.
- Montana State AGas victim2020-07-10
Morgan Stanley Smith Barney LLC notified customers of two incidents involving potential exposure of unencrypted personal data. In 2016, decommissioned devices from closed data centers retained data despite wiping. In 2019, a replaced branch server with encrypted disks was lost, and a manufacturer flaw could have left deleted data unencrypted. No unauthorized access was detected. Affected data included names, account numbers, SSNs, passport numbers, DOB, and asset values. 24 months of credit monitoring via Experian was offered.
- California State AGas victim2020-07-10
Morgan Stanley notified customers of two incidents involving potential exposure of personal data. In 2016, decommissioned data center equipment may have retained unencrypted data despite vendor wiping. In 2019, a replaced branch server with encrypted disks was lost; a software flaw may have left small amounts of deleted data unencrypted. No unauthorized access was detected. Affected data included names, account numbers, SSNs, and contact info. Morgan Stanley offered 24 months of credit monitoring.
- New Hampshire State AGas victim2020-07-10
Morgan Stanley notified the New Hampshire Attorney General on July 10, 2020, of two data security incidents involving approximately 77,296 NH residents. The 'Data Center Event' involved unencrypted data remaining on decommissioned devices from 2016. The 'WAAS Device Event' involved missing servers from 2019 with a software flaw leaving data unencrypted. No unauthorized access was detected. Morgan Stanley provided 24 months of credit monitoring via Experian.
- Massachusetts State AGas victim2020-07-10
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-07-10. 1,799 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2020-07-10
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-07-10. 389,969 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2019-02-08
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-02-08. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2017-03-31
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2017-03-31. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2016-12-21
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-12-21. 1 Massachusetts residents were affected. The report records the breach type as undefined.
- Massachusetts State AGas victim2016-09-30
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-09-30. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas victim2014-05-06
Morgan Stanley reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-05-06. 1 Massachusetts residents were affected. The report records the breach type as electronic.
Subsidiary disclosures (6)filed by group companies
◈ These filings were made by or about subsidiaries of MORGAN STANLEY — not by MORGAN STANLEY itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- Massachusetts State AGvia MORGAN STANLEY SMITH BARNEY LLC2023-06-16
Morgan Stanley Smith Barney LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-06-16. 1 Massachusetts residents were affected. The report records the breach type as paper.
- South Carolina State AGvia MORGAN STANLEY SMITH BARNEY LLC2020-07-10
Morgan Stanley Smith Barney LLC notified South Carolina residents of two data security incidents involving the improper disposal of computer equipment. In 2016, decommissioned devices contained unencrypted data. In 2019, a replaced server's encrypted disks contained residual data due to a software flaw. Morgan Stanley stated no unauthorized access was detected but offered 24 months of credit monitoring via Experian.
- Massachusetts State AGvia MORGAN STANLEY SMITH BARNEY LLC2019-03-04
Morgan Stanley Smith Barney reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-04. 17 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGvia MORGAN STANLEY SMITH BARNEY LLC2018-12-10
Morgan Stanley Smith Barney LLC reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-10. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGvia EATON VANCE MANAGEMENT2013-09-06
EatonVance Management reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-09-06. 8 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGvia EATON VANCE MANAGEMENT2012-02-07
Eaton Vance Management reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2012-02-07. 346 Massachusetts residents were affected. The report records the breach type as paper.