2016-06-08 SEC Press press_release 62 KB 2,883 chars

SEC: Morgan Stanley Failed to Safeguard Customer Data

Release
2016-112
summary

Morgan Stanley Smith Barney LLC paid a $1 million penalty to settle SEC charges for failing to protect customer data, enabling employee Galen J. Marsh to steal information on 730,000 accounts, which was later hacked and posted online, while Marsh was criminally convicted, sentenced to 36 months probation, ordered to pay $600,000 restitution, and barred from the industry for five years.

paragraph

Morgan Stanley Smith Barney LLC agreed to pay a $1 million penalty to settle SEC charges for violating Rule 30(a) of Regulation S-P by failing to adopt reasonable written policies and procedures to safeguard customer data. Between 2011 and 2014, former employee Galen J. Marsh exploited persistent deficiencies in access controls—such as the absence of effective authorization modules, audits, and monitoring—for over a decade to download confidential information on approximately 730,000 customer accounts to his personal server, which was subsequently hacked and data posted online. Marsh was criminally convicted, sentenced to 36 months of probation, ordered to pay $600,000 in restitution, and barred from the securities industry for five years, while Morgan Stanley settled without admitting or denying the allegations.

narrative

Morgan Stanley Smith Barney LLC agreed to pay a $1 million penalty to settle SEC charges for violating Rule 30(a) of Regulation S-P by failing to adopt reasonable written policies and procedures to protect customer data. For more than a decade, the firm neglected to implement effective authorization controls, audits, or monitoring for two internal web portals that allowed employees to access sensitive customer information, creating systemic vulnerabilities. Between 2011 and 2014, former employee Galen J. Marsh exploited these failures to improperly download and transfer confidential data on approximately 730,000 customer accounts to his personal server. This server was later hacked by third parties, resulting in portions of the data being posted online with offers to sell larger quantities. Marsh was criminally convicted in a separate proceeding, sentenced to 36 months of probation, ordered to pay $600,000 in restitution, and barred from the securities industry for five years with the right to reapply after that period. Morgan Stanley settled the SEC charges without admitting or denying the findings. The SEC acknowledged the cooperation of the FBI and the U.S. Attorney’s Office for the Southern District of New York in the investigation.

Enriched metadata

Scheme
cyber-fraud (90%)
Court
Southern District of New York
Outcome
settled
Settlement
$1,000,000
Restitution
$600,000
Civil penalty
$1,000,000
Classified cyber-fraud(confidence 90%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
data breachgalen j. marshmorgan stanleymorgan stanley smith barney llcsec investigationSecurities and Exchange Commissionthird parties
Keywords
morgan stanleysecmorganstanleydatacustomercustomer dataprotect customerpolicies proceduresstanley failedprocedures reasonablyreasonably designeddesigned protectpersonal serveremployees access

Exhibits & Attached Documents (2)

Extracted insights

Dollar amounts 2
  • $1.00M $1 million $1M–$10M
  • $600K $600,000 $100K–$1M
Entities 7
  • person data breach
  • person galen j. marsh
  • person morgan stanley
  • company morgan stanley smith barney llc
  • agency sec investigation
  • agency Securities and Exchange Commission
  • person third parties
Triples 10
  • Morgan Stanley Smith Barney LLC agreed to pay $1 Million Penalty
  • SEC issued order finding Morgan Stanley Failed To Adopt Written Policies And Procedures To Protect Customer Data
  • Galen J. Marsh downloaded and transferred Confidential Data Regarding Approximately 730,000 Accounts To Personal Server
  • Morgan Stanley violated Rule 30(a) Of Regulation S-P (Safeguards Rule)
  • Galen J. Marsh received 36 Months Probation And $600,000 Restitution Order
  • Galen J. Marsh agreed to Industry And Penny Stock Bar With Right To Apply For Reentry After Five Years
  • Morgan Stanley failed to have Effective Authorization Modules For More Than 10 Years To Restrict Employee Access
  • Third Parties hacked Galen J. Marsh's Personal Server
  • Data Breach occurred Between 2011 And 2014
  • William Martin And Simona Suh conducted SEC Investigation
PDF (from attached: pdf)
Text layers
Extracted body text (2,883c)
The Securities and Exchange Commission today announced that Morgan Stanley Smith Barney LLC has agreed to pay a $1 million penalty to settle charges related to its failures to protect customer information, some of which was hacked and offered for sale online. The SEC issued an order finding that Morgan Stanley failed to adopt written policies and procedures reasonably designed to protect customer data. As a result of these failures, from 2011 to 2014, a then-employee impermissibly accessed and transferred the data regarding approximately 730,000 accounts to his personal server, which was ultimately hacked by third parties. “Given the dangers and impact of cyber breaches, data security is a critically important aspect of investor protection. We expect SEC registrants of all sizes to have policies and procedures that are reasonably designed to protect customer information,” said Andrew Ceresney, Director of the SEC Enforcement Division. According to the SEC’s order instituting a settled administrative proceeding: The federal securities laws require registered broker-dealers and investment advisers to adopt written policies and procedures reasonably designed to protect customer records and information. Morgan Stanley’s policies and procedures were not reasonable, however, for two internal web applications or “portals” that allowed its employees to access customers’ confidential account information. For these portals, Morgan Stanley did not have effective authorization modules for more than 10 years to restrict employees’ access to customer data based on each employee’s legitimate business need. Morgan Stanley also did not audit or test the relevant authorization modules, nor did it monitor or analyze employees’ access to and use of the portals. Consequently, then-employee Galen J. Marsh downloaded and transferred confidential data to his personal server at home between 2011 and 2014. A likely third-party hack of Marsh’s personal server resulted in portions of the confidential data being posted on the Internet with offers to sell larger quantities. The SEC’s order finds that Morgan Stanley violated Rule 30(a) of Regulation S-P, also known as the “Safeguards Rule.” Morgan Stanley agreed to settle the charges without admitting or denying the findings. In a separate order, Marsh agreed to an industry and penny stock bar with the right to apply for reentry after five years. He was criminally convicted for his actions last year and received 36 months of probation and a $600,000 restitution order. The SEC’s investigation was conducted by William Martin and Simona Suh of the Enforcement Division’s Market Abuse Unit and supervised by Joseph G. Sansone, Co-Chief of the unit. The SEC appreciates the assistance of the New York Field Office of the Federal Bureau of Investigation and the U.S. Attorney’s Office for the Southern District of New York.
OCR text (2,883c · plain-text · 99% conf)
The Securities and Exchange Commission today announced that Morgan Stanley Smith Barney LLC has agreed to pay a $1 million penalty to settle charges related to its failures to protect customer information, some of which was hacked and offered for sale online. The SEC issued an order finding that Morgan Stanley failed to adopt written policies and procedures reasonably designed to protect customer data. As a result of these failures, from 2011 to 2014, a then-employee impermissibly accessed and transferred the data regarding approximately 730,000 accounts to his personal server, which was ultimately hacked by third parties. “Given the dangers and impact of cyber breaches, data security is a critically important aspect of investor protection. We expect SEC registrants of all sizes to have policies and procedures that are reasonably designed to protect customer information,” said Andrew Ceresney, Director of the SEC Enforcement Division. According to the SEC’s order instituting a settled administrative proceeding: The federal securities laws require registered broker-dealers and investment advisers to adopt written policies and procedures reasonably designed to protect customer records and information. Morgan Stanley’s policies and procedures were not reasonable, however, for two internal web applications or “portals” that allowed its employees to access customers’ confidential account information. For these portals, Morgan Stanley did not have effective authorization modules for more than 10 years to restrict employees’ access to customer data based on each employee’s legitimate business need. Morgan Stanley also did not audit or test the relevant authorization modules, nor did it monitor or analyze employees’ access to and use of the portals. Consequently, then-employee Galen J. Marsh downloaded and transferred confidential data to his personal server at home between 2011 and 2014. A likely third-party hack of Marsh’s personal server resulted in portions of the confidential data being posted on the Internet with offers to sell larger quantities. The SEC’s order finds that Morgan Stanley violated Rule 30(a) of Regulation S-P, also known as the “Safeguards Rule.” Morgan Stanley agreed to settle the charges without admitting or denying the findings. In a separate order, Marsh agreed to an industry and penny stock bar with the right to apply for reentry after five years. He was criminally convicted for his actions last year and received 36 months of probation and a $600,000 restitution order. The SEC’s investigation was conducted by William Martin and Simona Suh of the Enforcement Division’s Market Abuse Unit and supervised by Joseph G. Sansone, Co-Chief of the unit. The SEC appreciates the assistance of the New York Field Office of the Federal Bureau of Investigation and the U.S. Attorney’s Office for the Southern District of New York.