Categories: SecurityWorkspace

Hedge Fund Hit For Trade Details, Says BAE Systems

A US hedge fund was breached by hackers who stole trade secrets and interfered with its trading, according to security firm BAE Applied Systems, and observers have warned there may be plenty of other similar incidents.

The attackers installed malicious code on servers at one of the world’s leading finance companies, and slowed down its trading, while re-routing sensitive information to remote computers according to BAE, which told CNBC it had detected and fixed the problem – but only after the attack cost the un-named hedge fund “millions of dollars” over a period of months.

Hedge trimming

The attack disrupted the hedge fund’s trading and shared details of the trades themselves, according to Paul Henninger, global products director at BAE Systems Applied Intelligence (previously known as Detica). He described it as one of the most complex hits he had ever seen as the method would have allowed the attackers to benefit from advance warning of the victim’s trades.

The hedge fund – a BAE customer – has not been named, and it’s not known if the attack was reported to the Securities and Exchange Commission (SEC) or the FBI. However, the servers were apparently compromised in late 2013. BAE was called in and shut the attack down after eight weeks.

Security firms have lined up to describe other attacks, with Canadian eSentire telling Bloomberg of a hit which took $1.5 million from a hedge fund in two minutes, using three wire transfers. Again, the fund in question is not named, and no further details were given.

Such attacks normally use “phishing” emails which fool staff into clicking on unsafe links giving hackers access to their systems, from where they can gain access to the victim’s networks. A recent high-profile phishing attack at retailer Target exposed customers’ financial details and led to the exit of the company’s CEO and CTO.

How well do you know network security? Try our quiz and find out!

Peter Judge

Peter Judge has been involved with tech B2B publishing in the UK for many years, working at Ziff-Davis, ZDNet, IDG and Reed. His main interests are networking security, mobility and cloud

Recent Posts

Spyware Maker NSO Group Found Liable In US Court

Landmark ruling finds NSO Group liable on hacking charges in US federal court, after Pegasus…

2 days ago

Microsoft Diversifying 365 Copilot Away From OpenAI

Microsoft reportedly adding internal and third-party AI models to enterprise 365 Copilot offering as it…

2 days ago

Albania Bans TikTok For One Year After Stabbing

Albania to ban access to TikTok for one year after schoolboy stabbed to death, as…

2 days ago

Foldable Shipments Slow In China Amidst Global Growth Pains

Shipments of foldable smartphones show dramatic slowdown in world's biggest smartphone market amidst broader growth…

2 days ago

Google Proposes Remedies After Antitrust Defeat

Google proposes modest remedies to restore search competition, while decrying government overreach and planning appeal

2 days ago

Sega Considers Starting Own Game Subscription Service

Sega 'evaluating' starting its own game subscription service, as on-demand business model makes headway in…

2 days ago