Wells Fargo gets regulatory questions after data breach

Recent data breach began with a financial spat between two Wells Fargo brothers over less than $1 mn

Wells Fargo
Regulators have started asking questions about the breach, after the data was mistakenly provided to an attorney as part of a lawsuit involving two brothers, one a Wells Fargo employee and the other a former employee | Photo: Reuters
Laura J Keller | Bloomberg
Last Updated : Jul 23 2017 | 11:56 PM IST
Wells Fargo & Co, already in the regulatory spotlight because of last year’s fake-account scandal, is drawing renewed scrutiny after a lawyer’s unauthorised release of sensitive client details for tens of thousands of accounts belonging to wealthy customers of its brokerage unit.

Regulators have started asking questions about the breach, according to a person with knowledge of the matter, after the data was mistakenly provided to an attorney as part of a lawsuit involving two brothers, one a Wells Fargo employee and the other a former employee. A person briefed on the matter said Wells Fargo has determined the accounts were all from one brokerage branch in the Northeast.

Representatives of the Financial Industry Regulatory Authority informally contacted at least one of the attorneys involved in the dispute for information about how the breach occurred and how Wells Fargo failed to detect it, said the person, who asked not to be identified because the matter isn’t public. Lawyers for the bank are taking steps to contact regulators about the data breach, according to another person with knowledge of the matter. The person didn’t specify which agencies.

Ray Pellecchia, a spokesman for Finra, which licenses and supervises Wall Street workers including financial advisers, didn’t have an immediate comment. Representatives for the Consumer Financial Protection Bureau, the Office of the Comptroller of the Currency and the Securities and Exchange Commission didn’t immediately respond to messages seeking comment.

While this latest black eye may not rise to the level of the retail-bank debacle, it further calls into question Wells Fargo’s ability to manage its people and information.

“Wells Fargo takes the security and privacy of our customers’ information very seriously," the bank said in a statement.

"We are currently taking legal action to ensure the additional data is not disseminated, and we are requesting its rapid return. We continue to thoroughly investigate this matter and will take the proper steps, including corrective action, based on the outcome of our investigation.”

The bank’s latest troubles come just 10 months after regulators disclosed that Wells Fargo employees had been opening potentially millions of accounts in its retail banking division without customers’ permission over a half decade. The bank’s stock valuation and reputation were tarnished, and Wells Fargo has spent at least $520 million on fines, remediation, consultants and civil litigation since then, including a near-final $142 million to consumers who accused the bank of creating bogus accounts.

Insufficient Oversight

The OCC, the bank’s main regulator, said in September Wells Fargo had "failed to provide sufficient oversight" of its sales programs and didn’t adequately monitor employees in its retail bank. Part of the consent order the OCC forced the bank to carry out afterward included beefing up internal controls and risk management.

The recent data breach began with a financial spat between a pair of brothers over less than $1 million. Gary Sinderbrand, a former managing director at Wells Fargo Advisors, is engaged in two legal actions against his older brother Steven Sinderbrand, a managing director at the bank, one in New York and one in New Jersey.

Lawyers for Gary Sinderbrand received client names, Social Security numbers and account balances earlier this month for 50,000 Wells Fargo accounts, the New York Times first reported, including one file with details on the holdings of a "well-known hedge fund billionaire" with at least $23 million invested.

Protective Order

The trove of confidential client data was sent by attorney Angela A. Turiano of law firm Bressler, Amery & Ross, who’s representing Wells Fargo in both of the disputes. Turiano sent the information without a protective order or confidentiality agreement between the parties.

Turiano, who indicated that an outside vendor was involved in the information breach, asked the information be returned when Gary Sinderbrand’s attorneys informed her of the breach this week, the New York Times reported. Turiano didn’t return messages for comment on Saturday.

Gary Sinderbrand’s lawyers had been seeking documents related to a squabble over allegedly unpaid fees for a consulting arrangement with his brother. Sinderbrand alleges Wells Fargo knew about and approved of a verbal arrangement that he provide risk-management and client-retention coaching to his brother Steven, while Gary Sinderbrand took a two-year sabbatical from managing wealthy clients’ money.

The New York dispute is over what Gary Sinderbrand alleges is roughly $870,000 more he’s owed from 50 percent of fees his brother made managing their joint book of client business over a period of about two years.

Andrew L. Miller and Aaron Zeisler, attorneys for Gary Sinderbrand, either declined to comment or didn’t immediately return messages on Saturday. The brothers didn’t return messages seeking comment.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Next Story