Breaking NewsUpdated as information becomes available
News·Industry Insight·25 September 2026·Breaking

Morgan Stanley email error exposed an internal list of more than 100 potential deals

A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can turn confidential working information into a market-integrity and client-trust problem.

Mark Fermor
Mark FermorCTO, CMO & Founder, Firevault
6 min read
Share
A confidential deal file and an email warning displayed in a Hong Kong investment bank boardroom
A confidential deal file and an email warning displayed in a Hong Kong investment bank boardroom

Why it matters

What this means for organisations holding critical data

A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can turn confidential working information into a market-integrity and client-trust problem.

What happened

A senior Morgan Stanley banker in Hong Kong accidentally attached an internal deal-pipeline document to a weekly client email, according to reporting by Reuters, The Times and Bloomberg.

The intended attachment was reportedly a client-facing update on private equity and recent transactions. The file that went out was the bank's internal working list. Reuters said the sender later retracted the email, apologised and asked recipients to delete the attachment and not circulate it.

Morgan Stanley told Reuters: "Morgan Stanley takes client confidentiality extremely seriously. We promptly took steps to address this inadvertent sharing of information and we continue to engage with relevant parties."

This was not reported as a hack, malware incident or compromise of Morgan Stanley's systems. It was an accidental disclosure caused by the wrong file being attached to an ordinary email.

What the document reportedly contained

Reuters reported that the list was dated 21 September and included about 60 live IPO, merger and acquisition, and block-trade matters across Greater China, South Korea, Southeast Asia, India and the Europe, Middle East and Africa region. It also reportedly contained more than 50 opportunities marked as pitching and nearly 30 marked as on hold, all involving Asian companies.

Bloomberg's reporting, republished by The Business Times, described parts of the material as extensively price-sensitive and said the list named private equity and pension-fund backers. Reuters offered a narrower characterisation: people who received the email said it did not contain deal details and that many of the matters had already been reported publicly.

Those accounts are not necessarily mutually exclusive, but the difference matters. The exact sensitivity of every entry, the number of recipients and whether anyone traded or acted on the information have not been established publicly.

A blurred image of the document also appeared on Instagram, according to multiple reports. That illustrates why an email recall is containment, not recovery. Once an attachment reaches an external inbox, the sender can no longer know how many copies, screenshots or onward messages exist.

Why a list can matter even without full deal terms

A pipeline document does not need to contain a complete transaction file to be commercially sensitive.

The possible existence, status and timing of an IPO, acquisition or block trade can affect negotiations and market expectations. The identity of an adviser can reveal which bank is pitching for a mandate. The names of financial sponsors can help competitors target the same clients. A label such as "on hold" can disclose something about a transaction that the parties have not announced.

The incident therefore creates several distinct risks:

  • Client confidentiality: organisations had given a trusted adviser information for a limited purpose.
  • Market integrity: even partial knowledge of a possible transaction may be useful to traders or other market participants.
  • Competitive harm: rival banks can use the list to approach named companies and sponsors.
  • Execution risk: premature attention can complicate an IPO, sale or block trade.
  • Evidence risk: the bank must establish what was sent, who received it and what happened next.

The South China Morning Post reported on 25 September that competing banks were approaching companies named in the document. It also said, citing a source, that affected clients had not taken legal action or requested a replacement sponsor at that point.

What regulators expect

The Times reported that regulators in China and India were examining the matter. Whether that work will lead to formal action has not been established.

Hong Kong's Securities and Futures Commission did not comment on the specific incident when approached by Bloomberg. It said intermediaries should have robust internal controls to protect confidential information and prevent leakage that could harm clients or market integrity.

That reflects the regulator's existing public guidance. Its data-risk management circular specifically identifies inadvertent disclosure of material non-public information as a data risk and expects firms to govern, classify, monitor and control information throughout its lifecycle.

The control failure is more important than the click

It is easy to reduce an incident like this to one person's error. That misses the more useful question: why could one mistaken attachment expose the whole list?

Financial institutions know that employees will occasionally choose the wrong file, recipient or email thread. Controls should therefore be designed around predictable human error. For the most sensitive working documents, that can include:

  1. Separate internal and external versions. A client-safe report should not share an ambiguous filename or storage location with the unrestricted working file.
  2. Classify the information. Deal pipelines, acquisition lists and market-sensitive drafts should carry rules that travel with the file.
  3. Inspect outbound messages. Email controls can detect external recipients, unusual distribution, restricted labels and sensitive attachments before release.
  4. Require a second check. High-risk files sent outside the organisation can require another authorised person to approve the message.
  5. Use controlled sharing. A time-limited, authenticated portal can provide more control than a permanent attachment, although it cannot prevent every screenshot or copied note.
  6. Practise containment. Teams need a rehearsed path to identify recipients, preserve evidence, notify clients and regulators, and assess possible market impact.

The Firevault view

Offline Secure Storage® would not stop someone attaching the wrong live working document to an email. Any claim that it would is misleading.

Its role begins with reducing how much sensitive information remains continuously available in everyday collaboration systems, and with preserving a trusted record after an incident. Completed transaction files, historic mandates, board packs and evidence that no longer need to be live can be moved into a physically disconnected environment under deliberate access controls.

That reduces the searchable pool available to ordinary accounts and helps an organisation retain an authoritative copy while it investigates what was disclosed. The practical principle is simple: live systems should hold what people need for current work, not every sensitive record the institution has accumulated.

The Morgan Stanley incident is a reminder that data loss does not always begin with an attacker. Sometimes it begins with a familiar email, a plausible filename and one unchecked attachment.

What remains unknown

Public reporting has not established exactly how many clients received the file, whether the attachment was forwarded beyond them, whether anyone traded on the information, or whether any regulator will take formal action. No disciplinary action against the banker has been reported.

Those limits should remain part of the story. The confirmed incident is serious enough without turning uncertainty into fact.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker