Introduction
High-profile data breaches have shown how vulnerable sensitive data becomes when organizations fail to follow proper data destruction protocols. The Morgan Stanley breach is the clearest example in the industry: a breach caused not by hackers but by improper sanitization of retired IT hardware. It shows what happens when a well-run firm with written policies hands its drives to a vendor whose business depends on reselling them.
Background
In 2016, Morgan Stanley decommissioned two data centers in its wealth management business. It outsourced disposal and recycling of the hardware to a third-party vendor, expecting the data on those devices to be securely wiped before the equipment was recycled or resold.
The vendor did not adequately sanitize the hardware. Morgan Stanley's leadership also failed to exercise proper oversight when it retired networking devices and computers during a branch refresh in 2019. Some of the equipment, still holding client data, ended up in the hands of unauthorized third parties. The exposure reached the personal data of millions of accounts and customers. Morgan Stanley had sanitization protocols on paper; the oversight failure was that nobody verified the vendor followed them.
What the hardware held
- Client financial data: account balances, investment portfolios, and transaction histories from the retired systems.
- Personally identifiable information: names, addresses, Social Security numbers, and contact details.
The devices were not wiped with approved software or physically destroyed as the firm's own policy required.
What it cost
- Regulatory penalties. In 2020 the Office of the Comptroller of the Currency fined Morgan Stanley $60 million for the deficient decommissioning. In 2022 the Securities and Exchange Commission added a $35 million penalty, finding the firm had failed to protect customer information over a five-year period.
- Litigation. A class action on behalf of affected customers settled for $60 million.
- Loss of client trust. In wealth management, the relationship is the product. Clients learned their financial records had been sold at auction inside used servers.
- Remediation. Forensic investigation, revised procedures, vendor audits, and customer notification, all on top of the fines.
Root cause: the incentive behind the wipe
The failure is usually described as vendor error, and it was. But look at why the vendor was there. Morgan Stanley required only logical sanitization of its hardware, which allowed the vendor to resell the equipment online and offer the bank a lower price for decommissioning. That is the standard ITAD business model: the vendor's revenue comes from the resale value of the hardware, so its incentive is to keep the hardware whole and working. The wipe is a cost center in that model, and the one step nobody can see whether it happened.
Four factors compounded it:
- Outsourcing without verification. Handing disposal to a vendor does not transfer the liability. Morgan Stanley remained responsible, and paid.
- No audit of the vendor's process. A policy existed; nobody checked that it was executed on each device.
- Logical-only sanitization. Visually, a wiped drive and an unwiped drive are identical. Human error in a wipe goes undetected until a buyer finds the data. Physical destruction costs more and removes that failure mode: you can see that a shredded platter is shredded.
- Standards on paper, not in practice. The protocols aligned with NIST 800-88. The execution did not.
What Morgan Stanley did afterward
- Brought in forensic experts to establish the scope of exposure.
- Revised its sanitization procedures so that all hardware, including backup devices, is wiped or destroyed to documented standards.
- Instituted regular audits of third-party disposal vendors.
- Notified affected clients and, per the settlement, provided monitoring.
Lessons
- Logical-only destruction is a bet. NIST 800-88 Clear and Purge are permitted and often effective, but they add a risk that Destroy does not have: a technician cannot see whether a purge worked. Physical destruction turns a bet into a fact.
- Vendor due diligence is not optional. Know the vendor's business model. If its revenue depends on reselling your hardware whole, its incentive and yours are not the same. Ask what happens to a drive that fails verification, and audit.
- Policy without enforcement is exposure. The policy must apply to every department, every vendor, and every device, and someone has to check.
How we read this case
This breach is why Mansfield Technologies does not resell whole devices. Every computer that comes to us is disassembled, its storage is destroyed in front of the client, and only parts that never held data are sold. We earn less per device than a resale-model vendor. Morgan Stanley's decommissioning discount cost it $155 million. How our resale works.
Written by Christopher McDevitt with AI assistance.
