---
title: "Morgan Stanley email error exposed an internal… | Firevault"
url: https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026
description: "A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can…"
lang: en-GB
---

Breaking News Updated as information becomes available

News · Industry Insight · 25 September 2026 · Breaking

# Morgan Stanley email error exposed an internal list of more than 100 potential deals

A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can turn confidential working information into a market-integrity and client-trust problem.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

6 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmorgan-stanley-email-error-deal-list-2026
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmorgan-stanley-email-error-deal-list-2026&text=Morgan%20Stanley%20email%20error%20exposed%20an%20internal%20list%20of%20more%20than%20100%20potential%20deals%0A%0AA%20senior%20banker%20accidentally%20sent%20clients%20an%20internal%20deal-pipeline%20attachment.%20The%20incident%20was%20not%20a%20cyberattack%2C%20but%20it%20shows%20how%20one%20ordinary%20email%20can%20turn%20confidential%20working%20information%20into%20a%20market-integrity%20and%20client-trust%20problem.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fmorgan-stanley-email-error-deal-list-2026

Image: A confidential deal file and an email warning displayed in a Hong Kong investment bank boardroom (https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fmorgan-stanley-email-deal-list-2026.jpg)

A confidential deal file and an email warning displayed in a Hong Kong investment bank boardroom

Why it matters

## What this means for organisations holding critical data

## What happened

A senior Morgan Stanley banker in Hong Kong accidentally attached an internal deal-pipeline document to a weekly client email, according to reporting by Reuters (https://www.reuters.com/legal/transactional/morgan-stanley-asia-deals-leaked-missent-email-attachment-2026-09-24/), The Times (https://www.thetimes.com/business/companies-markets/article/morgan-stanley-email-error-hong-kong-v3bxns800) and Bloomberg.

The intended attachment was reportedly a client-facing update on private equity and recent transactions. The file that went out was the bank's internal working list. Reuters said the sender later retracted the email, apologised and asked recipients to delete the attachment and not circulate it.

Morgan Stanley told Reuters: "Morgan Stanley takes client confidentiality extremely seriously. We promptly took steps to address this inadvertent sharing of information and we continue to engage with relevant parties."

This was not reported as a hack, malware incident or compromise of Morgan Stanley's systems. It was an accidental disclosure caused by the wrong file being attached to an ordinary email.

## What the document reportedly contained

Reuters reported that the list was dated 21 September and included about 60 live IPO, merger and acquisition, and block-trade matters across Greater China, South Korea, Southeast Asia, India and the Europe, Middle East and Africa region. It also reportedly contained more than 50 opportunities marked as pitching and nearly 30 marked as on hold, all involving Asian companies.

Bloomberg's reporting, republished by The Business Times (https://www.businesstimes.com.sg/companies-markets/banking-finance/morgan-stanley-investment-bank-list-leaked-email-boo-boo), described parts of the material as extensively price-sensitive and said the list named private equity and pension-fund backers. Reuters offered a narrower characterisation: people who received the email said it did not contain deal details and that many of the matters had already been reported publicly.

Those accounts are not necessarily mutually exclusive, but the difference matters. The exact sensitivity of every entry, the number of recipients and whether anyone traded or acted on the information have not been established publicly.

A blurred image of the document also appeared on Instagram, according to multiple reports. That illustrates why an email recall is containment, not recovery. Once an attachment reaches an external inbox, the sender can no longer know how many copies, screenshots or onward messages exist.

## Why a list can matter even without full deal terms

A pipeline document does not need to contain a complete transaction file to be commercially sensitive.

The possible existence, status and timing of an IPO, acquisition or block trade can affect negotiations and market expectations. The identity of an adviser can reveal which bank is pitching for a mandate. The names of financial sponsors can help competitors target the same clients. A label such as "on hold" can disclose something about a transaction that the parties have not announced.

The incident therefore creates several distinct risks:

- **Client confidentiality:** organisations had given a trusted adviser information for a limited purpose.
- **Market integrity:** even partial knowledge of a possible transaction may be useful to traders or other market participants.
- **Competitive harm:** rival banks can use the list to approach named companies and sponsors.
- **Execution risk:** premature attention can complicate an IPO, sale or block trade.
- **Evidence risk:** the bank must establish what was sent, who received it and what happened next.

The South China Morning Post (https://www.scmp.com/business/banking-finance/article/3368751/morgan-stanley-deal-leak-triggers-rival-poaching-security-warnings-hong-kong-banks) reported on 25 September that competing banks were approaching companies named in the document. It also said, citing a source, that affected clients had not taken legal action or requested a replacement sponsor at that point.

## What regulators expect

The Times reported that regulators in China and India were examining the matter. Whether that work will lead to formal action has not been established.

Hong Kong's Securities and Futures Commission did not comment on the specific incident when approached by Bloomberg. It said intermediaries should have robust internal controls to protect confidential information and prevent leakage that could harm clients or market integrity.

That reflects the regulator's existing public guidance. Its data-risk management circular (https://apps.sfc.hk/edistributionWeb/api/circular/list-content/circular/intermediaries/supervision/doc?lang=EN&refNo=23EC15) specifically identifies inadvertent disclosure of material non-public information as a data risk and expects firms to govern, classify, monitor and control information throughout its lifecycle.

## The control failure is more important than the click

It is easy to reduce an incident like this to one person's error. That misses the more useful question: why could one mistaken attachment expose the whole list?

Financial institutions know that employees will occasionally choose the wrong file, recipient or email thread. Controls should therefore be designed around predictable human error (https://fire-vault.com/threats/human-error). For the most sensitive working documents, that can include:

1. **Separate internal and external versions.** A client-safe report should not share an ambiguous filename or storage location with the unrestricted working file.
2. **Classify the information.** Deal pipelines, acquisition lists and market-sensitive drafts should carry rules that travel with the file.
3. **Inspect outbound messages.** Email controls can detect external recipients, unusual distribution, restricted labels and sensitive attachments before release.
4. **Require a second check.** High-risk files sent outside the organisation can require another authorised person to approve the message.
5. **Use controlled sharing.** A time-limited, authenticated portal can provide more control than a permanent attachment, although it cannot prevent every screenshot or copied note.
6. **Practise containment.** Teams need a rehearsed path to identify recipients, preserve evidence, notify clients and regulators, and assess possible market impact.

## The Firevault view

Offline Secure Storage (https://fire-vault.com/offline-secure-storage)® would not stop someone attaching the wrong live working document to an email. Any claim that it would is misleading.

Its role begins with reducing how much sensitive information remains continuously available in everyday collaboration systems, and with preserving a trusted record after an incident. Completed transaction files, historic mandates, board packs and evidence that no longer need to be live can be moved into a physically disconnected environment under deliberate access controls.

That reduces the searchable pool available to ordinary accounts and helps an organisation retain an authoritative copy while it investigates what was disclosed. The practical principle is simple: live systems should hold what people need for current work, not every sensitive record the institution has accumulated.

The Morgan Stanley incident is a reminder that data loss does not always begin with an attacker. Sometimes it begins with a familiar email, a plausible filename and one unchecked attachment.

## What remains unknown

Public reporting has not established exactly how many clients received the file, whether the attachment was forwarded beyond them, whether anyone traded on the information, or whether any regulator will take formal action. No disciplinary action against the banker has been reported.

Those limits should remain part of the story. The confirmed incident is serious enough without turning uncertainty into fact.

Sources

## Where this reporting comes from

01

**Original report**Primary coverage referenced in this analysis View original article (https://www.thetimes.com/business/companies-markets/article/morgan-stanley-email-error-hong-kong-v3bxns800)

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Hardware**Your copy sits on dedicated encrypted hardware

**Disconnect**Offline by default, connected only when you say so

**Recovery**A known-clean copy to rebuild from, on your timetable

**Location**Held in a secure Firevault Bunker

Related Reading

## You may also find these useful

Industry Insight

### When Access Fails: Continuity Needs Offline Secure Storage

Fire and grid failure are only one of six ways organisations lose access to their own records. A practical case for holding critical material offline, whatever the cause.

18 Aug 2026 9 min
https://fire-vault.com/news/when-the-grid-fails-offline-secure-storage-business-continuity

Industry Insight

### Offline Is Not Enough: What the $114 Million Cold Wallet Sweep Teaches Us About Key Generation

An attacker emptied 1,196 bitcoin wallets in 41 minutes without ever touching a single device. The wallets were air gapped. The keys were not truly random. Here is what that means for anyone who relies on offline storage.

6 Aug 2026 4 min
https://fire-vault.com/news/cold-wallet-seed-entropy-flaw-offline-is-not-enough

Industry Insight

### The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure's Biggest Risk

More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.

31 Jul 2026 5 min
https://fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk

Industry Insight

### Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident

Firevault commentary on the first fully autonomous AI hack. Our take on what boards should do, informed by Joe Tidy's BBC reporting.

29 Jul 2026 4 min
https://fire-vault.com/news/rogue-ai-agents-hugging-face-opinion-2026

Industry Insight

### CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery

Insights from Mark Fermor on OT, ICS, and the underlying storage layer.

7 May 2026 7 min
https://fire-vault.com/news/cisa-ci-fortify-isolation-recovery-firevault

Industry Insight

### Data Integrity Attacks and Air Gap Defence

Data integrity attacks, a stealthier cousin to traditional ransomware, are on the rise, posing a significant threat to organisational trust and operational continuity. This article explores the growing danger of data manipulation and highlights how physically air-gapped storage offers an uncompromised defence.

21 Feb 2026 5 min
https://fire-vault.com/news/the-silent-threat-data-integrity-attacks-and-the-air-gap-defence

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026#webpage",
    "url": "https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026",
    "name": "Morgan Stanley email error exposed an internal…",
    "description": "A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fmorgan-stanley-email-deal-list-2026.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Morgan Stanley email error exposed an internal list of more than 100 potential deals",
        "item": "https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Morgan Stanley email error exposed an internal list of more than 100 potential deals",
    "description": "A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can turn confidential working information into a market-integrity and client-trust problem.",
    "url": "https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fmorgan-stanley-email-deal-list-2026.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fmorgan-stanley-email-deal-list-2026.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fmorgan-stanley-email-deal-list-2026.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fmorgan-stanley-email-deal-list-2026.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-09-25T09:30:00+00:00",
    "dateModified": "2026-09-25T09:26:54.278998+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026"
    },
    "inLanguage": "en-GB",
    "articleSection": "Industry Insight",
    "wordCount": 1076,
    "keywords": "Morgan, Industry Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "## What happened A senior Morgan Stanley banker in Hong Kong accidentally attached an internal deal-pipeline document to a weekly client email, according to reporting by [Reuters](https://www.reuters.com/legal/transactional/morgan-stanley-asia-deals-leaked-missent-email-attachment-2026-09-24/), [The Times](https://www.thetimes.com/business/companies-markets/article/morgan-stanley-email-error-hong-",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "Was Morgan Stanley hacked?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "No. The incident was reported as an accidental disclosure: a banker attached an internal deal-pipeline file to a client email instead of the intended client-facing version. No hack, malware or system compromise has been reported."
        }
      },
      {
        "@type": "Question",
        "name": "What was in the Morgan Stanley attachment?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Reuters reported about 60 live IPO, merger and acquisition, and block-trade matters, more than 50 pitching opportunities and nearly 30 matters on hold. Reports differ on how much detailed or price-sensitive information the file contained."
        }
      },
      {
        "@type": "Question",
        "name": "How many clients received the email?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "The exact number of recipients has not been disclosed publicly. Reporting says it was sent to some clients, then retracted, with recipients asked to delete the attachment and not circulate it."
        }
      },
      {
        "@type": "Question",
        "name": "Can an email recall recover a confidential attachment?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Not reliably. A recall may limit access in some systems, but it cannot establish that every external copy, download, screenshot or forwarded message has been removed. Containment must include recipient tracing, evidence preservation and impact assessment."
        }
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  }
]
```