SEC Investigates Hackers For Insider Trading

The US securities regulator is investigating a group of hackers who are alleged to penetrated the corporate email accounts of at least eight unnamed companies listed on the stock market.

The US Securities and Exchange Commission (SEC) has asked these as-yet-unnamed firms to provide information on these breaches.

Hack And Trade

The SEC’s involvement in the investigation comes as the hackers reportedly used stolen information to conduct insider trading deals, according to Reuters.

cyber securityIt is an “absolute first” for the SEC to approach companies about possible breaches in connection with an insider trading probe, John Reed Stark, a former head of Internet enforcement at the SEC is reported by Reuters as saying.

“The SEC is interested because failures in cybersecurity have prompted a dangerous, new method of unlawful insider trading,” Stark said. He is now a private cybersecurity consultant.

The US Secret Service is also conducting a parallel investigation, but it reportedly denied to comment on the Reuters report.

The probe was reportedly triggered by a warning in December from security company FireEye, which revealed details about a sophisticated hacking group it called “FIN4.”This group of hackers has been operating since mid-2013 and have targeted the corporate email accounts of over 100 companies.

Rather than conducting corporate espionage or stealing state secrets, this group of hackers was reportedly hunting for information about mergers and acquisitions, as well as other events that can affect the stock market.

So who were the targets? Well, no names have been released, but it seems that more than 60 listed companies in biotechnology and other healthcare-related fields were targeted by FIN4. These types of firms were targeted because apparently their stocks tend to be volatile, and thus potentially more profitable.

The hackers made use of “spear phishing” techniques to get staff members to provide their usernames and email passwords. The hackers apparently used fake Microsoft Outlook login pages to dupe unsuspecting employees. And it seems that the hackers were well versed in the financial markets and spoke “flawless English”.

Cyber Sanctions

It is rare for the SEC to investigate cyber crimes, as it tends to stick to its remit of only probing questionable trading activity in stocks and options.

The regulator can only file civil, not criminal charges, but it shows how serious US government agencies are now taking cyber attacks.

Earlier this year, in response to the ongoing attacks, President Obama created a US sanctions program to financially punish hackers outside the United States who are involved with malicious cyber attacks.

Are you a security pro? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Virgin Media O2 To Invest £700m To ‘Transform’ 4G, 5G Network

Virgin Media O2 confirms it will invest £2m a day for new mobile masts, small…

18 hours ago

Tesla Cybertruck Deliveries On Hold Due To Faulty Side Trim

Deliveries of Telsa's 'bulletproof' Cybertruck are reportedly on hold, amid user complaints side trims are…

19 hours ago

Apple Plots Live Translation Option For AirPods – Report

New feature reportedly being developed by Apple for iOS 19, that will allow AirPods to…

20 hours ago

Binance Token Rises After Trump Stake Report

Binance BNB token rises after WSJ report the Trump family is in talks to secure…

2 days ago

iRobot Admits ‘Substantial Doubt’ Over Continued Operation

After failed Amazon deal, iRobot warns there is “substantial doubt about the Company's ability to…

2 days ago

Meta’s Community Notes To Use X’s Algorithm

Community Notes testing across Facebook, Instagram and Threads to begin next week in US, using…

2 days ago