• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Finance

SEC Says Morgan Stanley Complicit in Giant Hack Attack

Lucinda Shen
By
Lucinda Shen
Lucinda Shen
Down Arrow Button Icon
Lucinda Shen
By
Lucinda Shen
Lucinda Shen
Down Arrow Button Icon
June 8, 2016, 3:46 PM ET
Morgan Stanley To Announce Earnings
Photograph by Victor J. Blue—Bloomberg via Getty Images

The financial advisor who took confidential data of 730,000 customer accounts from Morgan Stanley servers was not the only one at fault. So, too, was his employer.

Morgan Stanley (MS) enabled the behavior, the Securities and Exchange Commission said in a press release Wednesday. The SEC found that the investment banking giant Morgan Stanley failed to take proper precautions to safeguard customer data during a hack that resulted in private information being offered for sale online.

The SEC also fined the bank $1 million, saying in a press release: “Morgan Stanley failed to adopt written policies and procedures reasonably designed to protect customer data.”

Between 2011 and 2014, now former Morgan Stanley financial advisor, Galen Marsh, downloaded the confidential information of about 730,000 customer accounts to his home computer. Information from at least 900 clients appeared online in Dec. 2014, with the poster offering to sell additional data. Morgan Stanley later said it suspected Russian hackers had stolen the data from the former employee.

Marsh pled guilty to illegally accessing confidential client information in September. He received 36 months of probation and was ordered to pay $600,000 in restitution.

But now the SEC is saying that Morgan Stanley’s internal database of confidential customer data was not properly secure. Morgan Stanley did not restrict employee access to its customer’s information based on legitimate business need. Meaning Marsh, being a financial advisor, was given access to all clients within the bank’s Manhattan office. He also accessed information from other branches by using the identification numbers of other bank branches, financial advisors, and customer service associates.

The investment banking giant also failed to test its authorization practices, or monitor and analyze employees’ access to customer information, the SEC said.

Morgan Stanley agreed to settle the charges without admitting or denying the findings.

The decision also comes at a time when the federal government has become increasingly concerned about cybersecurity in banks. A few weeks earlier, the SEC said that the biggest threat facing financial systems both in the U.S. And abroad is cybersecurity. SEC chair Mary Jo White noted that while major financial entities were aware of the risk, they generally have “policies and procedures (that) are not tailored to their particular risks,” Reuters noted.

“Morgan Stanley is pleased to settle this matter,” a representative for the bank wrote in a statement. “No fraud against any client account was reported as a result of this incident.“

About the Author
Lucinda Shen
By Lucinda Shen
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.