Court Rules
All enforcement actions
SettlementHigh RiskMultistate

State AGs Fine Morgan Stanley $6.5M for Data Security Failures

Morgan Stanley Smith Barney LLCNovember 16, 2023New York Attorney General

Penalty Amount

$6,500,000

Summary

Morgan Stanley failed to properly decommission computer devices containing unencrypted customer data, leading to the sale of devices with personal information at auction and missing servers with potential data. A multistate coalition secured a $6.5 million settlement requiring Morgan Stanley to implement enhanced data security measures.

Remedy

Morgan Stanley must pay a $6.5 million fine and adopt a comprehensive information security program, including encryption, incident response plans, hardware tracking, and vendor risk assessments.

Monetary PenaltyCompliance Program

Contract Impact

In-house legal teams should review vendor agreements, especially those involving data destruction, asset disposal, or IT decommissioning services, to ensure they include specific clauses on data security standards, encryption requirements, vendor monitoring, and liability for data breaches. Customer agreements may need enhancements to data protection obligations, and internal policies should address hardware inventory controls and decommissioning procedures. Changes could involve mandating security certifications for vendors, implementing rigorous audit trails for disposed assets, and adding clear remedies for unauthorized data access to prevent incidents like unencrypted data being sold at auction or missing servers.

Contract Search Terms

vendor oversight clausedata destruction services agreementhardware inventory requirementencryption mandatedecommissioning protocolthird-party security assessmentasset disposal termscustomer data handlingdata breach liabilitysecurity audit clause

Violation Types

Entity Details

Entity

Morgan Stanley Smith Barney LLC

Also known as: Morgan Stanley

Industry

Financial Services

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Morgan Stanley Smith Barney LLC (Morgan Stanley)"
Fine Amount
"a $6.5 million fine"
Violation Types
"Morgan Stanley failed to decommission its computers and erase unencrypted data in certain computer devices that were later auctioned while still containing consumers’ personal information"

Related Enforcement Actions

NY

VGW Holdings Pty. Ltd.

$8.0M

New York Attorney General Letitia James secured an $8 million settlement from VGW Holdings Pty. Ltd. and its affiliates for unlawfully operating online sweepstakes casinos — Chumba Casino, Global Poker, and Luckyland Slots — that allowed New Yorkers to play casino games with virtual coins exchangeable for cash or prizes. The OAG's June 2025 cease and desist letter stopped the company from offering virtual coin gambling in New York, and Governor Hochul signed a formal ban on sweepstakes casinos into law in December 2025. Under the settlement, VGW will pay $8 million in disgorgement, penalties, and costs; note this is an illegal-gambling enforcement action rather than a privacy matter, so no privacy violation taxonomy categories apply.

NY

425 Marcy, LLC

$824K

New York Attorney General Letitia James secured a settlement with 425 Marcy, LLC and its principal Ezra Unger over the unlawful pre-sale of condominium units at 427 Marcy Avenue in Williamsburg before the required Martin Act offering plan was accepted for filing, and the misuse of $6.715 million in buyer down payments that were never placed in escrow. Unger agreed to repay residential buyers their down payments with interest or provide purchase credits, pay up to $824,000 in penalties, and is barred from selling securities in New York for six years. Note: this is a real estate offering-plan/escrow enforcement action rather than a data privacy matter; 'notice_failure' is the closest available taxonomy mapping (selling without the required offering plan disclosures).

NY

N/A (no company named - general consumer alert about unidentified scammers)

New York Attorney General Letitia James issued a consumer alert (not an enforcement action) warning New Yorkers about scammers exploiting confusion from recent federal changes to student loan repayment programs, including the elimination of the SAVE plan and phase-out of income-driven repayment plans. The alert describes common scam tactics — upfront fees, false guarantees of loan forgiveness, manufactured urgency, demands for powers of attorney, and requests for federal student aid (FSA) credentials — and urges consumers to report scams to the OAG. No company was named, no violation was alleged against a specific entity, and no penalty was imposed.

NY

Unidentified student loan scammers (no specific entity named)

New York Attorney General Letitia James issued a consumer alert warning borrowers about scammers exploiting recent federal changes to student loan repayment programs, including the elimination of the SAVE plan and phase-out of income-based plans. The alert provides tips for borrowers, including refusing upfront fees, never granting powers of attorney to unknown parties, and never sharing Federal Student Aid login credentials. No specific company was named and no penalties or remedies were imposed; this is an advisory alert, not an enforcement action.

NY

Amazon.com, Inc.

New York Attorney General Letitia James, joined by 21 other states and the FTC, sued Amazon for secretly overcharging its advertising customers more than $20 billion by submitting fake second-place bids to inflate ad auction prices since 2018. More than 1.2 million advertisers, including hundreds of thousands of small businesses, were allegedly overcharged. The coalition seeks a court order stopping the scheme plus penalties, restitution, and damages.

NY

Meta Platforms, Inc.

$17.1B

Attorney General James and a bipartisan coalition of 50 other attorneys general secured a landmark settlement with Meta Platforms, Inc. (Meta) worth up to $17.1 billion to address the company's harmful and addictive features targeting minors on Facebook and Instagram. The settlement requires Meta to implement significant changes, including age verification, time limits for minors, restrictions on notifications, and options to opt out of algorithmic feeds, along with monetary payments to states for mental health and education programs.