Merrill email error exposed Social Security numbers of Walmart 401(k) savers

Organization
Merrill Lynch, Pierce, Fenner & Smith Incorporated
Exploit
Human Error
Industry
Financial Services

Merrill Lynch, Pierce, Fenner & Smith Incorporated notified 1,883 participants in the Walmart 401(k) Retirement Plan in May 2024 that their personal information had been sent to someone who should not have received it. Merrill is the plan's recordkeeper.

In a notice filed with the Maine Attorney General, the firm said that on 16 April 2024 a Merrill employee inadvertently disclosed personal information to an unauthorized recipient in what it described as an isolated email error. The data involved first names, last names and Social Security numbers. Merrill said it learned of the mistake on 22 April and sent notification letters to affected participants on 23 May 2024.

Merrill said the email had been confirmed deleted and that it was not aware of any misuse of the disclosed information. Affected participants were offered a complimentary two-year membership in an identity theft protection service that included daily credit monitoring across the three major bureaus.

The exposure covered a small share of the plan, which held about $36.7 billion for roughly 1.9 million participants. Merrill characterized the event as an isolated error rather than a compromise of its systems, and no unauthorized access to Merrill or Walmart networks was reported.

Sources