Morgan Stanley Discloses Data Breach After the Hack of a Third-party Vendor

Morgan Stanley Discloses Data Breach
Share It On:

13th July 2021, Kathmandu

The Investment banking firm Morgan Stanley has disclosed a knowledge breach after threat actors have compromised the Accellion FTA server of the third-party vendor Guidehouse.

The company has offices in additional than 42 countries and quite 60,000 employees, its clients in several industries.

The account and maintenance facilities are provided by the guide house for Morgan Stanley’s StockPlan to Connect business, hackers breached its Accellion FTA server and stole information belonging to Morgan Stanley stock plan participants. It is the security breach and top reported by BleepingComputer that also exchange a copy of the data breach notification letter sent to the impacted customers.

When Morgan Stanley was notified dated on may 20,2021 to Guidehouse, a vendor that given account maintenance facilities to Morgan Stanley’s StockPlan Connect business, that it had suffered an information security incident. Then, the Guidehouse is supporting that type of data it is maintained for Morgan Stanley had been accessed through the Accellion FTA vulnerability.” reads the letter.

Morgan Stanley documents the possession of Guidehouse containing the private information of StockPlan Connect participants, including participants in New Hampshire, were obtained by an unauthorized individual.”

The provider is already informed for Morgan Stanley in May 2021 that hackers compromised its FTA install back in January by exploiting a zero-day vulnerability later addressed by the seller.

The hack of the FTA server happened in March, but the hacker had access to the info of Morgan Stanley customers in May. The participant ( take apart ) details (information) accessed by the hackers included name; address (last known address); date of birth; Social Security number (if the participant had one); and company name.

The company acknowledged that exposed files didn’t contain passwords that would be wont to access financial accounts. It is stolen files and it is stored in encrypted form on the compromised Guidehouse Accellion FTA server, but the attackers were also ready to obtain the key to decrypt it.

It is the investment banking firm that has no evidence that hackers have abused stolen info or disseminated it online. Morgan Stanley acknowledged that its systems weren’t breached by the threat actors. “in any Morgan Stanley applications,” if there was no data security breach then we will not continues the letter.

February, the security experts from FireEye linked a series of cyberattacks against organizations running Accellion File Transfer Appliance (FTA) servers to the cybercrime group UNC2546, aka FIN11 in February.

In mid-December 2020 the wave of attacks is started, and threat actors exploited multiple zero-day vulnerabilities within the Accellion File Transfer Appliance (FTA) software to deploy a shell dubbed DEWMODE on the target networks.

The attackers exfiltrate sensitive data from the target systems then published it on the CLOP ransomware gang’s leak site.

It has been guessed that the group has targeted approximately 100 companies across the planet between December and January.


Share It On:

Recent Posts

Garima Bikas Bank Online Payment Service: Secure E-commerce Transactions with Debit and Credit Cards

Garima Bikas Bank Online Payment Service: Secure E-commerce Transactions with

Share It On: 24th January 2025, Kathmandu Garima Bikas Bank has introduced a new e-commerce service for its customers. They

First Microfinance Q2 Results: Net Profit Down 38% Amidst Rising NPLs

First Microfinance Q2 Results: Net Profit Down 38% Amidst Rising

Share It On:24th January 2025, Kathmandu First Microfinance Laghu Bitta Bittiya Sanstha has released its financial results for the second

Best Finance Founder Shares Sale: Exclusive Offer for Existing Shareholders

Best Finance Founder Shares Sale: Exclusive Offer for Existing Shareholders

Share It On:24th January 2025, Kathmandu Best Finance Company Limited has placed 535,927 founder shares up for sale. These shares

NLG Insurance Appoints Noor Prakash Pradhan as Independent Director to Strengthen Corporate Governance

NLG Insurance Appoints Noor Prakash Pradhan as Independent Director to

Share It On:24th January 2025, Kathmandu NLG Insurance has appointed Noor Prakash Pradhan as its Independent Director. The board made

Nepal Economic Recovery: RBB CEO Khanal on Growth, Challenges, and Opportunities

Nepal Economic Recovery: RBB CEO Khanal on Growth, Challenges, and

Share It On:24th January 2025, Kathmandu Devendra Raman Khanal, CEO of Rastriya Banijya Bank, spoke at the bank’s 60th Annual

  • by Mina Aryal
  • January 24, 2025
ChatGPT Down: Global Outage Impacts Users in Nepal & Beyond

ChatGPT Down: Global Outage Impacts Users in Nepal & Beyond

Share It On: 24th January 2025, Kathmandu ChatGPT, the popular AI chatbot developed by OpenAI, experienced a major outage on

  • by Mina Aryal
  • January 24, 2025