Morgan Stanley accidentally emails list of over 100 confidential investment deals
An employee inadvertently sent sensitive details about Asia-focused deals, raising questions about information controls at one of Wall Street's largest banks.
A Morgan Stanley employee accidentally emailed a list containing details of more than 100 confidential investment deals, most of them focused on the Asia-Pacific region. The incident, first reported by Bloomberg on September 23, immediately spotlighted the kind of operational risk that keeps compliance officers up at night.
The leak involved sensitive client information tied to the bank’s deal pipeline in Asia, a region where Morgan Stanley has built a formidable presence across equity capital markets, IPOs, block trades, and M&A advisory.
What we know so far
The disclosure has been characterized as inadvertent, meaning this appears to be a case of human error rather than deliberate leaking.
Morgan Stanley has not publicly commented on the incident. The bank has not disclosed which specific deals were included, how many recipients received the email, or what internal steps have been taken in response. No information about the dollar values of the deals or the identities of the companies involved has surfaced publicly.
The incident is notably distinct from a prior, more deliberate pattern of information-sharing that dogged the bank between 2018 and 2021. That earlier episode involved intentional disclosures, a fundamentally different category of misconduct.
The news moving money, markets, and the world—before your day starts.
Daily. Free. Join 34,000+ readers across crypto, finance, and policy.
Why this matters beyond one email
Each entry on the leaked list is a company at some stage of a capital raise, acquisition, or strategic transaction. Many of those companies haven’t publicly disclosed their plans. Some may be publicly traded, meaning premature knowledge of a pending deal could create trading advantages for anyone who received the email.
Securities regulators in multiple jurisdictions across Asia, including Hong Kong’s SFC and Singapore’s MAS, take a dim view of trading on material non-public information, regardless of how that information was obtained.
Morgan Stanley has spent years building its franchise in Asian capital markets, competing with Goldman Sachs, JPMorgan, and regional powerhouses for mandates. The bank has successfully increased its market share due to a resurgence in deal flow across major markets including Hong Kong, India, and China.
The broader information security problem
Depending on the jurisdictions involved, Morgan Stanley could face inquiries from multiple regulatory bodies seeking to understand how the leak occurred, who received the information, and what safeguards failed.
What happens next depends largely on factors still hidden from public view: how many people received the email, whether any of them acted on the information, and how aggressively regulators choose to investigate. Morgan Stanley’s internal response, including whether the bank proactively contacted affected clients and notified relevant authorities, will shape both the legal and reputational fallout.