On September 22, a senior Morgan Stanley banker in Hong Kong attached the wrong file to his weekly client email and sent clients the firm’s Asia deal pipeline. He tried to recall it, but the message had already reached clients outside the firm. The bank still knew exactly what had gone out and who had it, and within days it was meeting the private equity firms on the list. If the same pipeline had been pasted into ChatGPT on a personal account, most security teams would have no record of it at all.
How a weekly client email carried Morgan Stanley’s deal pipeline
According to Reuters, the banker covers financial sponsors in Asia and sends clients an update every week. That week’s email carried the group’s confidential deal list, dated September 21. It named roughly 60 live IPO, M&A and block-trade deals across Greater China, South Korea, Southeast Asia, India and the EMEA region, plus more than 50 deals still being pitched and nearly 30 on hold. Most of the companies belonged to the portfolios of large private equity and venture capital firms.
Bloomberg broke the story on September 23. The banker had asked recipients to delete the attachment and not share it. By then the list was moving around Asia’s banking community, and a blurred copy turned up on Instagram. Morgan Stanley said it “promptly took steps to address this inadvertent sharing of information” and would “continue to engage with relevant parties.”
The next day, Bloomberg reported urgent meetings with private equity clients and at least two regulators assessing the fallout. Because the mail system had the exact file and every recipient on record, the bank could ask each recipient to delete it and go straight to the firms whose deals were exposed. Later coverage has India’s securities regulator running an internal assessment and China’s reaching out to private equity firms. Hong Kong’s Securities and Futures Commission declined to discuss the case but said it expects the firms it licenses to keep strong internal controls around client information. Recipients told Reuters the list was light on detail and that many of the deals were already public. Most of the damage is to client trust and to deals that hadn’t been announced.
Why most DLP would have let it through
Most data loss prevention looks for the wrong person or the wrong destination. Here a senior banker emailed clients he writes to every week, from the firm’s own mail system. Bankers send confidential files to clients all day, and a rule that blocked every confidential attachment would block a lot of legitimate work.
The file was the one thing out of place. The weekly update normally carries a client-ready document, and this time it carried one that never leaves the financial sponsors group. You can catch that, but only if you know what this banker usually sends these clients and where the attached file came from. We don’t know how Morgan Stanley’s controls are configured, and no report says one of them failed.
Why the recall was never going to work
One wrong click was enough to cause this leak, and after it nothing the sender did could pull the file back. In Microsoft 365, for example, Outlook can only recall a message when the sender and the recipient are in the same organization. A recall aimed at clients’ inboxes was never going to work, and everything Morgan Stanley did afterward was cleanup.
The same file in ChatGPT
Every AI tool on a company laptop is one more place where a single click moves a file, and it has even less of an undo than email. Drop a deal list into ChatGPT on a personal account and there’s no recipient list to work from and nothing to recall. The text sits with OpenAI under that account’s terms, and many consumer plans, ChatGPT’s included, let the provider train on it unless the user opts out.
On September 25, OpenAI said its research agents had posted 53 images from ChatGPT users to image-hosting sites. Every one came from a user who hadn’t opted out of training.
When the assistant picks the attachment
Teams are starting to hand recurring jobs like a weekly client update to AI assistants that pick files from shared drives by name and date. If one grabs the internal version, it sends it without a second look. Unless the system records who asked, the log shows only the assistant as the sender.
Sensitivity labels don’t always stop an assistant either. In February, Microsoft confirmed a bug in which Microsoft 365 Copilot Chat summarized emails from users’ Sent Items and Drafts that confidentiality labels and DLP policies should have kept out.
Five things to set up before your own misfire
Hong Kong’s regulator said it expects the firms it licenses to keep strong internal controls around client information, and we’d read that to include what goes into AI tools.
- Pick the five files your firm could least afford to leak, such as a deal pipeline or a client roster, and trace everywhere each one went in the last 30 days, AI tools included. Note where you lose the trail.
- Find out which AI tools people use and under which accounts, and separate corporate accounts from personal ones on the same laptop.
- Test whether your sensitivity labels and DLP rules fire inside those tools, including browser chatbots, extensions and coding assistants. A rule that works in email may not see a prompt at all.
- Decide now what happens when one of those files heads for a personal AI account, whether that’s a warning to the user or a block, and write it down so nobody has to decide mid-incident.
- Make sure anything an AI assistant sends on someone’s behalf is logged with the person who asked, so the next wrong attachment has a name on it.
Anzenna keeps that record for AI. It shows which files and text went into which AI tools, under a corporate or a personal account, and ties each one to the person who sent it. When something like a deal pipeline is about to go where it shouldn’t, Anzenna can warn the person or stop it before it leaves. To see what that record looks like, take our interactive tour, which runs on sample data. If you’d rather look at your own environment, book a walkthrough and we’ll show you where your sensitive files are already going.
References
- Bloomberg News, “Morgan Stanley Investment Bank Deal List Leaked in Email Misfire,” September 23, 2026.
- Bloomberg News, “Morgan Stanley Rushes to Check Fallout After Deal List Leak,” September 24, 2026.
- Reuters, “Morgan Stanley Asia deals leaked in missent email attachment,” September 24, 2026.
- South China Morning Post, “Morgan Stanley leak of confidential deal pipeline alarms Hong Kong market,” September 24, 2026.
- Axios, “OpenAI agents posted user images online, disclose dozens of third party incidents,” September 25, 2026.
- Microsoft Support, “Recall or replace an email message that you sent,” accessed September 29, 2026.
- BleepingComputer, “Microsoft says bug causes Copilot to summarize confidential emails,” February 18, 2026.
