Social Engineering Attacks Resulted in Compromise of Morgan Stanley Client Accounts

This article has been indexed from

CySecurity News – Latest Information Security and Hacking Incidents

 

Morgan Stanley’s wealth and asset management division, Morgan Stanley Wealth Management, says that social engineering attacks have compromised some of its customers’ accounts. 
Vishing (also known as voice phishing) is a social engineering attack in which scammers impersonate a reputable business (in this case Morgan Stanley) over the phone to persuade their targets to expose or pass over sensitive information such as banking or login credentials. 
According to a notice sent to impacted clients, a threat actor portraying Morgan Stanley acquired access to their accounts “on or around February 11, 2022” after deceiving them into submitting their Morgan Stanley Online account information. The attacker also electronically transferred money to their accounts after successfully compromising their own accounts. 
The alert reads, “As you are aware, on or around February 11, 2022, you were contacted by a bad actor claiming to be with Morgan Stanley. The bad actor was able to obtain information relating to your Morgan Stanley Online account, subsequently accessing this account and initiating unauthorized Zelle payments.” 
A Morgan Stanley spokesperson told BleepingComputer that “there was no data breach or information leak from Morgan Stanley.” The Morgan Stanley division also stated that all affected customers’ accounts had been disabled, adding that its s

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: