fb

Second hand servers + personal data = $35 million

Second hand servers + personal data = $35 million

Morgan Stanley is one of the most renowned banks in the world. It started business on Wall Street in New York back in 1935 and has grown so that it now has a market capitalisation of around $150 billion and employs approximately 70,000.

It’s obviously good at a lot of things but one area it wasn’t so good at was looking after the personal data of about 15 million customers.

Probably one of the first things that come to mind when protecting the personal details of clients are the security systems to protect the data within the bank such as passwords, firewalls, etc.

The problem for Morgan Stanley though was the data that was in computer hardware that was scrapped.

The US Securities and Exchange Commission (SEC) accused Smith Barney (Morgan Stanley’s wealth management business), of “astonishing” shortcomings.

The problems arose when Morgan Stanley disposed of thousands of hard drives and servers.

On multiple occasions a moving and storage business with no experience in data destruction services was hired to decommission these hard drives.

In other words, the hard drives and servers which were being scrapped should have had all the personal details removed.

Unfortunately this didn’t happen and instead the moving business then sold thousands of these devices to a third party. This third party then resold them on an internet auction site.

Some of the devices were subsequently recovered but the SEC said that Morgan Stanley “has not recovered the vast majority of the devices”.

The devices which were recovered were found to contain “thousands of pieces of unencrypted customer data”.

The end result is that Morgan Stanley has agreed to pay a $35 million penalty to settle charges.

There’s a valuable lesson to be learnt from this as responsibility for the safeguarding of personal data remains with the organisation and this includes making sure that the destruction of hardware containing that data is done in such a way that the data is erased and does not find it’s way into other people’s hands.

Share this entry

Related articles

View All Articles

Recent articles

View All Articles
Out of this world fashion.
Oct 18, 2024
Title
Out of this world fashion.
Excerpt

If you’re lucky enough to buy your clothes from Prada, will your next purchase be a nice dress, […]

Should we park this?
Oct 16, 2024
Title
Should we park this?
Excerpt

Getting the balance right between innovation and ethics is important in business. Frankfurt’s new parking portal offers a […]

Would a good liar make a good accountant?
Oct 12, 2024
Title
Would a good liar make a good accountant?
Excerpt

Do you have children? Have they ever told you a lie? Even a small teeny weeny lie? Well, […]

Was that true? Was that fair?
Oct 09, 2024
Title
Was that true? Was that fair?
Excerpt

I’ve been a qualified accountant for a fair few years now. I had the pleasure of bumping into […]

How much do Big 4 partners get paid?
Oct 03, 2024
Title
How much do Big 4 partners get paid?
Excerpt

Making it to partner at one of the Big 4 accounting firms—Deloitte, EY, KPMG, and PwC—is considered by […]

Problems at Naomi Campbell’s charity…
Oct 02, 2024
Title
Problems at Naomi Campbell’s charity…
Excerpt

The Supermodel Naomi Campbell was recently banned from serving as a charity trustee for five years. This all […]

Lego – building strategy blocks…
Sep 29, 2024
Title
Lego – building strategy blocks…
Excerpt

Many a parent has felt the pain of standing on a Lego brick which their son or daughter […]

Famous accountants, but not for accounting…
Sep 27, 2024
Title
Famous accountants, but not for accounting…
Excerpt

Accounting, often called the “language of business”, has served as a foundational skillset for many who’ve achieved greatness […]