MORGAN STANLEY
ent_019e0b1fa33aabe7c87a2c1b586b1038
Disclosures
10
HHS OCR · State AG · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
401,246
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MORGAN STANLEY
- Normalized
- morgan stanley— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- IGJSJL3JD5P30I6NJZ34
- SEC EDGAR CIK
- 0000895421
- Domain
- morganstanley.com
Disclosure history (10)newest first
- NEW YORKHHS OCRas victim2023-04-18
Morgan Stanley (Health Plan, NY) reported to HHS on 2023-04-18 an Unauthorized Access/Disclosure breach affecting 535 individuals. A vendor employee inadvertently mailed PHI — including names, dates of birth, addresses, Social Security numbers, diagnoses, lab results, medications, and other treatment information — to wrong addresses. Breached information located on Paper/Films. The CE notified HHS and affected individuals and implemented additional administrative, technical, and security safeguards.
- 🐻California State AGas victim2021-07-02
Morgan Stanley notified California AG that a third-party vendor suffered a data security incident in May 2021. An unauthorized individual obtained decryption keys for encrypted files containing PII (name, address, DOB, SSN) of stock plan participants. Morgan Stanley arranged 24 months of credit monitoring via Experian. The vendor remediated the vulnerability in January 2021.
- 🦬Montana State AGas victim2021-07-02
Morgan Stanley reported a data breach to the Montana Attorney General. The breach was reported on 2021-07-02. The breach occurred from 1/1/2021 to 1/31/2021. 43 Montana residents were affected.
- 🌲Washington State AGas victim2021-07-02
Morgan Stanley, a finance sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-05-20 and filed notice on 2021-07-02. 2,080 Washington residents were affected. 43 days elapsed between awareness and notification.
- 🦞Maine State AGas reporting2021-07-02
Morgan Stanley, a financial services company, reported a data breach affecting various entities to whom it provides StockPlan Connect Services. The breach occurred at a third-party vendor, Guidehouse. The incident, which took place on January 20, 2021, and was discovered on May 20, 2021, involved an external system breach or hacking. The personal information of 116 Maine residents was compromised, including names and Social Security numbers. In response, Guidehouse offered affected individuals 24 months of credit monitoring and identity theft protection services through Experian IdentityWorks. Consumer notifications were sent on July 2, 2021.
- 🦫Oregon State AGas victim2021-07-02
Morgan Stanley reported a data breach to the Oregon Attorney General. The breach was reported on 2021-07-02. The breach occurred during 1/20/2021. The breach was discovered on 5/20/2021. 33,443 individuals were affected. Notice was sent on 7/2/2021.
- 🦫Oregon State AGas victim2020-07-10
Morgan Stanley reported a data breach to the Oregon Attorney General. The breach was reported on 2020-07-10. 209,881 individuals were affected.
- 🌲Washington State AGas victim2020-07-10
Morgan Stanley, a finance sector entity reported a unauthorized access incident to the Washington Attorney General. 401,246 Washington residents were affected.
- 🦬Montana State AGas victim2020-07-10
Morgan Stanley reported a data breach to the Montana Attorney General. The breach was reported on 2020-07-10. The breach occurred from 1/1/2016 to 7/10/2020. 32,370 Montana residents were affected.
- 🐻California State AGas victim2020-07-10
Morgan Stanley disclosed a data security incident involving the potential exposure of unencrypted personal information on decommissioned computer equipment and a disconnected branch office server. The incident involved data centers closed in 2016 and a server disconnected in 2019. Affected data may include names, account numbers, Social Security numbers, dates of birth, and asset values. Morgan Stanley offered 24 months of credit monitoring through Experian. No unauthorized access or misuse was detected.
Subsidiary disclosures (1)filed by group companies
◈ These filings were made by or about subsidiaries of MORGAN STANLEY — not by MORGAN STANLEY itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.