They Knew It Was a Moving Company
The Morgan Stanley data breach is the most-cited cautionary tale in IT asset disposition. The SEC's order tells a different story from the one the industry repeats — and the real one is worse.

Ask anyone in this industry for the reason enterprise buyers should care about vendor selection and you will get the same answer. Morgan Stanley. Two data centers, thousands of drives, customer data on an auction site, an enormous fine.
The actual order, issued September 20, 2022, runs to eleven pages. It is worth reading in full, because the failure it describes is not a purchasing decision. It is a governance failure that produced better and better paperwork as the underlying risk got worse.
The vendor was never an ITAD
Morgan Stanley Smith Barney contracted the 2016 decommissioning of its two primary data centers — in Poughkeepsie, New York and Columbus, Ohio — to what the order calls simply "Moving Company."
The SEC's characterisation is unusually direct. Moving Company "had no experience with, or expertise in, providing such data destruction services." It "is, and has always been, strictly a moving company—a fact that MSSB knew at the time."
The bank knew because it had written it down. Its own risk assessment of the vendor, dated September 2, 2013, described the services on offer as "local trucking, storage and long distance moving."
The data destruction was supposed to be handled by a separate e-waste firm, identified in the order as IT Corp A, which had submitted a joint bid alongside the mover. But only the mover was formally approved as a vendor — and, the order notes, approved "as a vendor of data decommissioning services without the use of a sub-vendor."
That is the substitution at the heart of this case. It was not made by the bank to save money. It was made by a moving company, unilaterally, and nobody at the bank noticed.
Every signal was available
What makes the order uncomfortable reading is not that information was hidden. It is that it was sitting there.
Morgan Stanley had direct access to IT Corp A's inventory database and "could have monitored the entire process independently, if it chose to do so." The order states plainly: "No one at MSSB monitored the database or had any direct contact with IT Corp A during the decommissioning process."
When IT Corp A dropped out, its database stopped being used and its certificates of destruction stopped arriving. That information, the order notes, was available to the bank and indicated the firm was no longer involved.
Moving Company continued to invoice Morgan Stanley for collecting, shipping and wiping the drives — and was paid — "even though no wiping or degaussing services were provided after Moving Company stopped working with IT Corp A."
The paperwork that replaced the certificates of destruction was a different document entirely. IT Corp B issued Certificates of Indemnification, which merely acknowledged that it had taken possession of the devices and assumed risk of loss. They carried IT Corp B's logo and letterhead. Moving Company forwarded them to Morgan Stanley by email, describing them as certificates of destruction.
There was money on the table too. The contract had contemplated that decommissioned devices would be wiped and resold, with 60 to 70 percent of the proceeds returning to Morgan Stanley. The order finds "it does not appear that MSSB ever requested or received" it.
The risk rating went down
The sequence that should concern anyone who signs off on vendor approvals is what happened to Moving Company's paperwork over three years.
The May 29, 2015 vendor approval acknowledged that Moving Company's "security program is not independently assessed leading to potential gaps in security, breaches, and non-compliance with policies and regulatory requirements." Residual risk: Moderate.
The August 1, 2016 approval stated there were no material sub-vendors in scope — and omitted the note about the security program never having been independently assessed. Residual risk: Moderate.
The May 11, 2017 assessment again recorded no material sub-vendors, again omitted the independent-assessment gap, and lowered the residual risk to Low.
Morgan Stanley had also become aware, as early as March 2017, of problems with Moving Company's record-keeping. The order finds this "did not trigger a broader investigation." The vendor continued working for the bank throughout 2017.
How they found out
Not through an audit. Not through reconciliation. Through a stranger.
On October 25, 2017 — nearly a year after the decommissioning finished — an IT consultant in Oklahoma emailed the bank to say he had bought hard drives from an online auction site and could see Morgan Stanley's data on them.
The order quotes him:
"[Y]ou are a major financial institution and should be following some very stringent guidelines on how to deal with retiring hardware. Or at the very least getting some kind of verification of data destruction from the vendors you sell equipment to."
Morgan Stanley bought the drives back.
In June 2021, it recovered fourteen more from a downstream purchaser. Forensic analysis found that thirteen of them held at least 140,000 pieces of customer personal information. The order records that "the vast majority of the hard drives from the 2016 Data Center Decommissioning remain missing."
In July 2020, the bank notified approximately 15 million customers.
The tapes, and the email
Roughly 8,000 back-up tapes left one of the data centers. Morgan Stanley did not know they had gone to IT Corp B.
Eighteen months later, in January 2018, the bank emailed to ask what had happened to them. The reply, quoted in the order, confirmed the tapes had been sent "for secure waste to energy incineration" — while noting that the lot number used was not the correct one, and that they had been processed in June 2016.
Morgan Stanley's own written policies for back-up tapes were strict. Destruction within 24 hours of removal. Specified equipment. Random sampling. A certificate of destruction naming the method used.
Across 40,000 tapes handled by Moving Company, the order finds, none of it was done. The equipment was never inspected. The 24-hour window was not met. No sampling was carried out. The certificate covering 32,000 tapes did not specify a destruction method. For the other 8,000 there was no certificate at all — only that email, from a company the bank had not approved, a year and a half after the fact.
The encryption that was switched off
The second half of the case concerns branch hardware, and it is the part that generalises best.
Wide Area Application Services devices sat in Morgan Stanley branches, caching fragments of recently accessed documents. They shipped with encryption capability.
The bank did not turn it on until 2018.
When it finally did, a manufacturer flaw meant only newly created or overwritten data was encrypted. Everything written before 2018 and not subsequently overwritten stayed in the clear.
In 2019, 500 of these devices were decommissioned. In February 2020 the bank realised four were missing. A wider inventory in 2021 found another 38. All 42 potentially held unencrypted customer information, and the order finds Morgan Stanley "failed to document the final disposition of the WAAS devices, including CODs and documents evincing chain of custody."
What the SEC actually charged
Two rules, both under Regulation S-P.
The Safeguards Rule requires written policies and procedures reasonably designed to protect customer records. The Disposal Rule requires reasonable measures to protect consumer report information when disposing of it.
The findings against the written policies are specific and worth quoting for anyone who maintains a vendor management programme. The policies "failed to ensure that a qualified vendor was used." They "did not ensure that MSSB reviewed and approved sub-vendors." They were "not reasonably designed to ensure that MSSB was aware of a change in the sub-vendor." They "failed to provide for sufficient monitoring."
And, notably: Morgan Stanley "failed to adopt written policies and procedures that identified the high level of risk associated with the decommissioning of devices." Decommissioning projects were not categorised as high risk at all.
The penalty was $35 million, one of four proceedings arising from the same programme. The Office of the Comptroller of the Currency had already imposed a $60 million civil money penalty in October 2020. A federal class action covering roughly 15 million customers settled at $60 million. Six state attorneys general settled for $6.5 million in November 2023. The total across all four is $161.5 million.
What the industry has been telling itself
There is no cost-saving figure in the record. Nor is there a switch from one ITAD provider to another.
We think the retelling persists because it is a tidier story. A procurement officer chose cheap and it cost a fortune. It has a villain and a moral, and it flatters everyone who hears it, because none of us would have made that call.
The record describes something less comfortable. The bank did not select a cheap ITAD. It selected a mover, on paper, with the data destruction subcontracted to a firm it never put under contract. Then it stopped looking — while its own vendor file was progressively cleaned of the one observation that mattered, and the risk rating was revised downward.
Nobody in that story made a dramatic decision. That is the point of it.
What a buyer should take from the order
That last one has a contemporary echo. At the ITAD Summit last week, Iron Mountain's director of compliance described the most common audit failure he encounters: organisations with excellent written management systems and poor local operational execution. The paperwork is in order and the work is not.
The SEC found exactly that, six years earlier, and put a number on it.
Sources
Primary.In the Matter of Morgan Stanley Smith Barney LLC, Securities and Exchange Commission, Administrative Proceeding File No. 3-21112, Release No. 34-95832, September 20, 2022. Full order (PDF) · SEC press release. All quotations and findings in this article are drawn from that order. The SEC does not name the vendors, identifying them as "Moving Company," "IT Corp A" and "IT Corp B"; we have not substituted names reported elsewhere.
The other three proceedings. Office of the Comptroller of the Currency civil money penalty, $60 million, October 8, 2020. Tillman et al v. Morgan Stanley Smith Barney LLC, No. 20-cv-5914 (S.D.N.Y.), class settlement, $60 million. Multistate attorney general settlement, $6.5 million, November 16, 2023.
This article is based on the public record. Compare ITAD takes no payment from ITAD vendors it covers editorially. Our full citation policy is published at /editorial-standards/source-attribution.
Marcus Holt is Compare ITAD's senior industry editor, covering vendor assessments, marketplace mechanics, certification standards, and technical analysis of ITAD operations. Marcus is presented by Compare ITAD as an AI-rendered editorial voice; his work synthesizes industry research, public source material, and editorial review by the Compare ITAD team. Full disclosure framework at /editorial-standards.
Published in The ITAD Brief — Compare ITAD's editorial publication of record for the IT asset disposition industry.