Comms Around Emailed Morgan Stanley Deal List
Morgan Stanley’s mistakenly emailed document listing financial sponsors and pipeline deals offers three business communication lessons for students: crisis communication messaging, communication planning, and email safeguards.
A senior-level banker accidentally sent an attachment revealing financial sponsors (mostly private equity firms) and more than 100 deals, including IPOs and mergers and acquisitions. Some deals were not yet public; some were marked “pitching” or “on hold.”
To be fair, as a Bloomberg analyst says, “This could have happened to anyone,” reminding us that we have all sent misdirected emails. His focus is on compassion for the banker. At the same time, he and his interviewers acknowledge serious consequences, and they joke, “This is bad for insider traders.”
Crisis Communication Messaging
Morgan Stanley issued a brief statement for news reports:
Morgan Stanley takes client confidentiality extremely seriously. We promptly took steps to address this inadvertent sharing of information and we continue to engage with relevant parties.
The statement could be improved. The formal tone and clichéd first sentence fail to recognize the impact of the error, which is quite serious. “Engaging” with relevant parties says nothing about the company’s accountability. “Promptly” sounds self-congratulatory and is expected.
The company confirmed personal messaging that the public wouldn’t see, which tells us a bit more about actions taken:
The banker later retracted the email and apologised for the mishap, urging recipients to delete copies of the attachment and refrain from circulating the document.
Morgan Stanley uses a familiar crisis communication strategy: blaming one employee. In this case, unlike the Volkswagen and Boeing cases, the error was one employee’s, so the strategy may be appropriate (although later we’ll discuss safeguards, which are the company’s responsibility). In similar situations, a company might say the employee was terminated (which clients may demand). But that probably wouldn’t restore public confidence or improve the situation for clients. The focus, as it should be, is on damage control.
No public statements are on the Morgan Stanley website or social media accounts, which makes sense for an error limited to relatively few clients and for a company not wanting to publicize the error further.
Communication Planning
Students may complete a communication plan for this situation. Who are the audiences? What is important to them? How might each react? Who is the best messenger? What are the communication objectives, message points, medium, and timing?
Each company affected by the leak likely has its own communication plan to manage the fallout.
Email Safeguards
The Bloomberg analyst may be correct that emails are often sent to unintended recipients, but safeguards should be in place. In this situation, the banker attached the wrong file to a client email list.
Claude offered the following safeguards. The two most relevant in this situation may be automatic scanning for confidential files and sharing links instead of attachments. Scanning would have prevented sending the file, and sending a link could have limited the damage significantly. If Morgan Stanley didn’t have these safeguards in place, then the company might take more responsibility.
Stop the mistake before it goes out
Label sensitive files. Internal documents like a deal list should be tagged "Confidential – Internal Only." Email software can then refuse to send a tagged file to outside addresses, or at least demand a second confirmation.
Data loss prevention (DLP) scanning. These tools check outgoing mail and attachments for things like client names, deal code names, or "internal only" markings. They can block or quarantine a suspicious email before it leaves.
Warnings for external recipients. A pop-up such as "You're sending an attachment to 40 external recipients. Continue?" makes the sender stop and look.
A short send delay. Holding outgoing external mail for a minute or two gives the sender time to catch the error. Once an email reaches an outside company, "recall" rarely works.
Change how client emails are sent
Keep regular client mailings off personal inboxes. Recurring updates like the weekly one in this case should go through an approved template or mailing platform where only pre-approved content can be attached.
A second reviewer for mass client emails. A colleague or compliance officer checks anything going to many clients before it's sent.
Share links instead of attachments. A link to a secure file can be switched off after a mistake. A sent attachment is out of the company's control for good.
Limit the damage when something slips through
Protect the files themselves. Rights-management encryption means a confidential document only opens for authorized employees, even if it's forwarded outside.
Limit who can access sensitive files. The fewer people who can download a full deal list, the fewer chances there are to mis-send it.
Have a response plan ready. Know in advance who contacts recipients, who notifies regulators and affected clients, and what the company says publicly. Morgan Stanley's quick public statement suggests it had some version of this.
Build the right culture
Train staff with realistic examples of near-misses.
Encourage people to report their own mistakes right away. A sender who flags an error within minutes can prevent far more damage than one who hopes nobody noticed.
Students may discuss strategies they have seen at school or work and assess the effectiveness of each.