Morgan Stanley agrees $60 million settlement in data breach lawsuit
The two separate data incidents occurred in 2016 and 2019 and concerned the investment bank's handling of legacy IT equipment


US investment banking giant Morgan Stanley has agreed to pay $60 million (£44 million) to settle a lawsuit following two data incidents that left customer information exposed.
The proposed class-action lawsuit was brought to Morgan Stanley on behalf of around 15 million customers affected by the data incidents. The preliminary settlement was filed on Friday night and requires approval by US District Judge Analisa Torres, Reuters reported.
Morgan Stanley denies wrongdoing as part of the settlement but has made upgrades to its data security posture, settlement papers showed. The settlement will see all affected customers receive at least two years of fraud insurance coverage and they will be able to apply for a sum of up to $10,000 (£7,400) each for out-of-pocket losses.
The data incidents in question refer to two separate cases in 2016 and 2019 respectively and question Morgan Stanley's position on retiring legacy IT systems. Affected customers in 2016 claimed the investment bank failed to properly decommission two wealth management data centres before they were sold on to third parties with customer data still stored on them.
In a similar case, customers said data went missing in 2019 after Morgan Stanley transferred older servers to an outside vendor - servers that were later recovered by the bank, court papers showed.
RELATED RESOURCE
Bridging the DevSecOps divide: Spotlight on key relationships
The importance of relationships between security and development
"We have previously notified all potentially impacted clients regarding these matters, which occurred several years ago, and are pleased to be resolving this related litigation," said a Morgan Stanley spokesperson to IT Pro.
Morgan Stanley was infamously caught up in the wide-reaching hack on Accellion's File Transfer Appliance (FTA) last year. Personal data belonging to its corporate clients was stolen in January 2021 after its systems were breached via the Accellion FTA server operated by third-party vendor Guidehouse, it said at the time.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Social security numbers, birth dates and affiliated corporate company names were also believed to be among the sensitive data stolen in the attack, the bank confirmed.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
The business value of Zscaler Data Protection
Whitepaper Understand how this tool minimizes the risks related to data loss and other security events
By ITPro Published
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro Published
-
Three essential requirements for flawless data protection
Whitepaper Want a better CASB and stronger DLP? You have to start with the right foundation
By ITPro Published
-
The gratitude gap
Whitepaper 2023 State of Recognition
By ITPro Published
-
The top five risks of perimeter firewalls
Whitepaper ...and the one way to overcome them all
By ITPro Published
-
Redefining modern enterprise storage for mission-critical workloads
Whitepaper Evolving technology to meet the mission-critical needs of the most demanding IT environments
By ITPro Published
-
The business value of storage solutions from Dell Technologies
Whitepaper Streamline your IT infrastructure while meeting the demands of digital transformation
By ITPro Published
-
Building a data governance strategy in 2023
In-depth Data governance will continue to expand as attitudes change and businesses look to optimise the value of their data
By Keri Allan Published