Morgan Stanley on Thursday disclosed that a data breach at one of its contractors led to the theft of personal information about some customers whose stock accounts had gone dormant.
The bank said in a notice to affected clients that the cyber intrusion affected Guidehouse, a consulting company that Morgan Stanley uses to find current addresses for clients of its stock-plan business whose accounts had been inactive for long periods of time and whose assets were at risk of being liquidated and turned over to the state. The exposed information included customer names, dates of birth, Social Security numbers and company names but not passwords to access the accounts, the bank said.
The breach was previously reported by Bleeping Computer.
Morgan Stanley said Guidehouse discovered the breach in May and that it involved exploitation of a vulnerability in file-transfer software from Accellion, whose products have been the target of a range of advanced attacks that were discovered in December.
Read Also
- Sandberg USB-C PD 20W 10000 Powerbank Review Sep 13, 2021
- BOLSA EUROPE-Index prevents fall with support of defensive and travel actions – ISTOÉ MONEY Aug 18, 2021
- Exports totaled US$4,128.7 million between January-April 2022 May 20, 2022
- Iran Nuclear: With 60% Enriched Uranium, Deal Could ‘Be Dead’ Nov 23, 2022
- The Central Bank raises its interest rate from 5.50% to 6.50% per year Jun 1, 2022
- European stocks remain near record highs due to rebound in energy and consumption sectors Jun 3, 2021
- Cassavon: An initiative in favor of local industry May 4, 2022
“The protection of client data is of the utmost importance and is something we take very seriously,” Morgan Stanley said in a statement. It declined to comment on how many clients were affected. “We are in close contact with Guidehouse and are taking steps to mitigate potential risks to clients.”
In a statement, Guidehouse said it discontinued use of the breached Accellion system and alerted authorities to the intrusion. “We have already contacted clients whose information may have been impacted and are assisting them with making all appropriate notifications to individuals. There is no disruption of our operations and our internal systems were not compromised in any way by this issue. “
