Morgan Stanley Paid $196.5M for Data-Erasure Failures. Are Your Retired Assets Putting You at Similar Risk?
Morgan Stanley's decommissioning missteps highlight a very specific risk: they hired a mover with no data destruction expertise to remove thousands of drives and servers. Those assets, still containing unencrypted data, were resold, exposing personal information for 15 million customers. The result so far: at least $196.5M in penalties and settlements, including a $60M OCC fine (2020), $60M class-action settlement (2022), $35M SEC fine (2022), $6.5M from state attorneys general (2023), and another $35M penalty scheduled for 2026. This was not a hacking incident. It was a breakdown in vendor management and data erasure. Ziperase helps you rethink decommissioning by erasing data on-site before ITAD, so no device leaves your building with live data. Each erasure automatically generates a tamper-proof certificate, searchable and exportable for audits and regulators. With certified compliance to IEEE 2883 and NIST SP 800-88, plus direct integration into ServiceNow and other ITAM/ITSM tools, you get a clear, verifiable chain of custody by serial number. Working with Ziperase, you can turn hardware refresh and data center shutdowns into controlled, documented processes instead of regulatory liabilities.

