Morgan Stanley agrees to pay millions to settle data breach claims

Data Breach
(Image credit: Shutterstock)

The Wall Street bank Morgan Stanley has agreed to pay $60m to settle a lawsuit filed by customers who say the firm's poor security practices left their personal data at risk.

A preliminary settlement of the class action lawsuit was recently filed in Manhattan federal court though it still requires approval by US District Judge Analisa Torres according to a new report from Reuters.

If approved, the proposal would provide at least two years of identity theft protection for the 15m customers affected by two separate security breaches. They will also be able to apply for reimbursement of up to $10k in out-of-pocket losses.

According to Morgan Stanley's settlement, the company denies any wrongdoing though in time since the two incidents occurred, it has made “substantial” upgrades to its data security practices.

Decommissioned equipment

In their class action lawsuit, current and former Morgan Stanley customers accused the bank of failing to properly wipe decommissioned equipment from two data centers containing unencrypted customer data back in 2016 before it was resold to unauthorized third parties.

Additionally, the lawsuit says that several older servers which also contained customer data went missing after the firm transferred them to an outside vendor back in 2019. However, Morgan Stanley was later able to recover the servers in question according to court papers.

Back in October of 2020, Morgan Stanley agreed to pay a $60m civil fine to resolve accusations that its information security practices were unsafe or unsound put forth by the US Office of the Comptroller of the Currency.

In a recent email, the firm said that it had notified all affected customers and that it was pleased to finally settle the class action lawsuit against it.

We've also highlighted the best firewall, best malware removal software and best endpoint protection software

Via Reuters

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
PayPal
PayPal fined by New York for cybersecurity failures
Data Breach
US state sues T-Mobile over 2021 data breach which leaked data of millions
marriott
FTC orders Marriott and Starwood to boost cybersecurity following major incidents
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Security padlock and circuit board to protect data
Mexican fintech company Miio exposed millions of files of sensitive customer data
Latest in Security
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
DeepSeek
Fake DeepSeek installers are infecting your device with dangerous malware
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
Data leak
Top California sperm bank suffers embarrassing leak
An Android phone being held in the hand
These malicious Android apps were installed over 60 million times - here's how to stay safe
ransomware avast
Billions of credentials were stolen from businesses around the world in 2024
Latest in News
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedlyleft users exposed for months
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
The Nanoleaf PC Screen Mirror Lightstrip being used on a desktop computer.
Mac gaming could get an intriguing boost – but not in the way you'd expect
Snapdragon G Series
Qualcomm poised to muscle in on AMD's territory with powerful gaming handheld processors