Skip to content

Compliance Building

Doug Cornelius on compliance for private equity real estate

Menu
  • Home
  • About
    • About
    • About Doug
    • About This Website
    • Why I Blog
    • Speaking Engagements
    • Contact
    • Publications
  • Archives
    • Topic Archive
    • Book Reviews
    • Most Popular
  • Subscribe
  • Disclaimers
    • Disclaimers
    • Policies and Procedures
    • Use of Site Content
    • Comments
    • FTC Disclosure
Menu

The Russian Hack of the EDGAR

Posted on January 3, 2022March 25, 2024 by Doug Cornelius
Print Friendly, PDF & Email

A few years ago Ukranians hacked EDGAR to obtain nonpublic earnings information and used that information to trade stocks. The hackers made about $1.4 million and spread that information to associates for about $4.1 million in total profit. Now a bigger hacking plot has been discovered and it has bigger international implications.

The Securities and Exchange Commission brought fraud charges against five Russian nationals for engaging in a multi-year scheme to profit from stolen corporate earnings announcements obtained by hacking into the systems of two U.S.-based filing agent companies before the announcements were made public. These companies helped to “Edgar-ize” documents for filing in the EDGAR system. It looks like the SEC did a good job of securing its systems. This private provider did less so.

It was more lucrative. The SEC claims that the hacking group made over $80 million in profits. Maybe they made better use of the information than the Ukrainians did in their plot. Or maybe the five Russians had more capital.

The Russians hacked into the providers’ public company clients’ filings include, among other things, Forms 8-K and related exhibits, which consist of press releases containing the public companies’ earnings announcements. The Providers’ public company clients can use the platforms to create, edit, and submit their filings to the SEC through the EDGAR filing system. The weak security was at provider instead of the main database.

It looks like the hackers were not just hacking the SEC filings. Some of the five are implicated in the alleged hacking around the 2016 election.

One of them was just scooped up in Switzerland and has been extradited back to the United States for charges. Vladislav Klyushin. He had flown to Switzerland for a ski vacation at the Zermatt ski resort. It looks like US intelligence learned of the travel and had the Swiss pick up Klyushin at the airport. Russia and the US fought over extradition, with the US eventually winning and putting him on plane to face charges.

The five hackers worked at a Russian information technology firm called M-13 that specialized in penetration testing and other services. Looks like they were wearing white hats and black hats.

Sources:

  • When You Look And Find That You Are The Problem
  • SEC Brings Charges in EDGAR Hacking Case
  • Russian businessman, others made millions in insider trading through hacking -U.S.
  • Russian National Extradited for Role in Hacking and Illegal Trading Scheme
  • SEC Charges Five Russians in $80 Million Hacking and Trading Scheme
  • U.S. Catches Kremlin Insider Who May Have Secrets of 2016 Hack

Share this:

  • Print (Opens in new window) Print
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on X (Opens in new window) X
  • Email a link to a friend (Opens in new window) Email

Leave a ReplyCancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search for Stuff

Recent Stories

  • More on the Downsizing of the SEC
  • SEC Enforcement Results for FY 2025
  • Proposed Fundamental Reforms to AML Programs
  • Is It a Truck or a Security?
  • The One with Low IQ from Pet IQ
  • The Downsizing of the SEC
  • When “Today” Is Not all of “Today”
  • Compliance Bricks and Mortar for March 27
  • The One Where Theory Meets Reality
  • When the COVID Pandemic Hits Your Valuation

Fight Cancer

Please support my Pan-Mass Challenge
Make a donation to fight cancer. donate.pmc.org/DC0176
pan-mass challenge badge

I am a lawyer, but I am not your lawyer. Since I’m a lawyer, this website may be considered attorney advertising under the ethical rules of certain jurisdictions. Please read my disclaimers page before taking any action. And then, don't take any action based on what I wrote.

Creative Commons logo with the text 'Some Rights Reserved' and three symbols representing attribution, non-commercial use, and share alike.

Compliance Building - by Doug Cornelius is licensed under a Creative Commons Attribution-Noncommercial 3.0 United States License.