Morgan Stanley raced to contain the damage from a leaked deal list as clients sought explanations and at least two regulators began assessing the potential fallout.
The leak has gripped Asia's investment banking industry this week after one of Morgan Stanley's top bankers accidentally sent an email to some clients containing a list of more than 100 deals the Wall Street firm was working on and monitoring.
Morgan Stanley held urgent meetings with some private equity firms to apologize and assure executives the bank would work to mitigate the fallout, people familiar with the matter said, asking not to be named discussing private information.
Regulators in China and India have started assessing the incident, though it's unclear if that will lead to any actions, according to people familiar with the matter.
The roster included candidates for initial public offerings spanning China, South Korea, and India, according to a copy seen by Bloomberg News and verified by people familiar with the matter. The list — which focused primarily on Asia alongside Europe, the Middle East, and Africa — also named private equity and pension funds backing the companies, as well as stalled projects.
Some rivals seized on the opportunity to potentially gain ground as the document was circulated among competitors. Several bankers at rival firms said they would use the list to target deals and court potential clients. Others said most of the deals were already known and came as little surprise.
Traders and investors were also monitoring potential block trades mentioned in the list.
Mohamed Atmani, Asia-Pacific head of financial sponsors in the investment-banking department, sent the list via email before seeking to recall the message, according to people familiar with the matter.
The banker intended to send a client-facing document containing general updates on the private equity sector and recent transactions, but mistakenly sent the internal pipeline instead, the people said.
In an internal memo after the leak became public, Morgan Stanley told staffers to escalate any contacts with clients and the media to senior management. Employees were also ordered to do a compliance training that includes handling the fallout from misdirected emails, according to a person familiar with the matter. It wasn't immediately clear whether the training was a direct response to the incident.
The immediate priority has been managing the affected clients, with Atmani personally meeting some who had inadvertently received the internal material and other key clients, people familiar with the matter said. Relationship bankers are also separately reaching out to other affected clients individually.
There has been no client disengagement so far as a result of the leak, the people said.
The bank couldn't immediately be reached for a comment, but in a statement to Bloomberg News on Wednesday, the firm said it takes client confidentiality extremely seriously. "We promptly took steps to address this inadvertent sharing of information and we continue to engage with relevant parties," the New York-based bank said.
In a memo on Thursday, Goldman Sachs Group Inc. instructed staff not to store or distribute the list on personal or company devices, according to people familiar with the matter. A Goldman spokesperson declined to comment.
One firm mentioned in the document, Hong Kong-based Link REIT, said it's aware of the leaked information. "Link does not have any current transaction engagement with Morgan Stanley, nor have we engaged with them in any recent deal-related discussions," a spokesperson said in an emailed statement.
The incident is an embarrassing misstep for the bank, which has ranked among the top underwriters of Hong Kong stock sales and Asia mergers for years. While such errors are rare, it highlights the sensitivity of information handled by investment-banking teams, where details of prospective client transactions are typically closely guarded.
Leaks about an imminent share placement can frustrate clients pursuing block trades, especially if details emerge before a deal is launched. Such disclosures can weigh on the stock as investors brace for additional supply, potentially cutting proceeds for the seller and making execution more difficult for banks.
A spokesperson for Hong Kong's Securities and Futures Commission said in a statement that it doesn't comment on individual incidents.
However, he added that the regulator "expects intermediaries to have robust internal controls in place to protect their clients' confidential information and prevent data leakage which may harm the interests of their clients or impact the integrity of the market."
China Securities Regulatory Commission is also aware of the matter and is contacting some of the big private equity firms, but as of now has no plans to reach out to Morgan Stanley, according to a person familiar with the matter. CSRC wasn't immediately available for comment.
The Securities and Exchange Board of India is also doing an internal assessment of the incident, according to people familiar with the matter. Based on their findings, it will decide if any action is required at a later stage, the people said. SEBI did not immediately reply to Bloomberg's query seeking a comment.
"The incident sounds an alarm for all companies that they should pay close attention to confidentiality and stay vigilant to employees' use of IT systems and increasingly AI tools," said Joseph Zeng, founder of Arcadia Fund Management in Hong Kong. "They should have some security software in place to identify whether outgoing emails contain sensitive information and take corresponding actions."











