SEC victim of hacking, filing system breached

Hackers may have profited from insider trading by using stolen confidential information

The US Securities and Exchange Commission was subject to hacking last year, it has disclosed. It said that its database of corporate announcements was breached and cybercriminals may have used the information for profit.

In a statement, SEC chairman Jay Clayton said that last month it had learned that an incident previously detected in 2016 "may have provided the basis for illicit gain through trading". It added that a software vulnerability in the test filing component of its EDGAR system, which was patched promptly after discovery, was exploited and resulted in access to non-public information.

Advertisement - Article continues below

"Notwithstanding our efforts to protect our systems and manage cybersecurity risk, in certain cases, cyber threat actors have managed to access or misuse our systems," said Clayton.

"We believe the intrusion did not result in unauthorized access to personally identifiable information, jeopardize the operations of the Commission, or result in systemic risk. Our investigation of this matter is ongoing, however, and we are coordinating with appropriate authorities."

"Effective management of internal cybersecurity risk is critical to the SEC achieving its mission and to protecting the non-public information that is entrusted to this agency," SEC Commissioner Michael S. Piwowar said in a statement.

Ilia Kolochenko, CEO of web security company High-Tech Bridge, told IT Pro that the disclosed breach may have disastrous consequences outshining Equifax.

Advertisement
Advertisement - Article continues below

"Cybercriminals could have manipulated the entire stock market and make billions of illicit profit. Ethical investors, including pension and sovereign funds, without the insider information could have lost fortunes as a result," he said.

Advertisement - Article continues below

"This incident clearly exposes how vulnerable our global financial ecosystem is, and how unprepared we are to fight skyrocketing cybercrime. In the future, we will see a steady fusion of common crime with cyber gangs that jointly may challenge state power and dictate their laws, while law enforcement agencies are catastrophically underfinanced by governments and just don't have enough resources to tackle global cybercrime."

Featured Resources

Top 5 challenges of migrating applications to the cloud

Explore how VMware Cloud on AWS helps to address common cloud migration challenges

Download now

3 reasons why now is the time to rethink your network

Changing requirements call for new solutions

Download now

All-flash buyer’s guide

Tips for evaluating Solid-State Arrays

Download now

Enabling enterprise machine and deep learning with intelligent storage

The power of AI can only be realised through efficient and performant delivery of data

Download now
Advertisement

Recommended

Visit/security/355013/10-quick-tips-to-identifying-phishing-emails
Security

10 quick tips to identifying phishing emails

16 Mar 2020
Visit/business-strategy/mergers-and-acquisitions/354941/panda-security-to-be-acquired-by-watchguard
mergers and acquisitions

Panda Security to be acquired by WatchGuard

9 Mar 2020
Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/mobile/mobile-phones/355088/apple-lifts-iphone-purchase-restrictions
Mobile Phones

Apple lifts iPhone purchase restrictions

23 Mar 2020
Visit/operating-systems/microsoft-windows/355105/microsoft-puts-windows-development-on-lockdown
Microsoft Windows

Microsoft puts Windows development on lockdown

25 Mar 2020
Visit/security/data-breaches/355097/ge-employees-hit-by-canon-data-breach
data breaches

General Electric employees hit by Canon data breach

24 Mar 2020
Visit/cloud/355098/ibm-dedicates-supercomputing-power-to-coronavirus-researchers
high-performance computing (HPC)

IBM dedicates supercomputing power to coronavirus research

24 Mar 2020