Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

9/21/2017
04:45 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

SEC Says Intruders May Have Accessed Insider Data for Illegal Trading

2016 breach of the Securities and Exchange Commission's EDGAR database dents its reputation as a federal cybersecurity enforcer.

The Securities and Exchange Commission's (SEC) credibility as an enforcer of cybersecurity requirements took a bit of beating this week after it disclosed a 2016 data breach that might have given intruders access to nonpublic information for illegal trading.

In brief comments buried in the middle of a long public statement on the agency's cybersecurity posture, SEC Chairman Jay Clayton tied the breach to a software vulnerability in the test filing component of the SEC's EDGAR system.

The breach was discovered and addressed at some unspecified time in 2016. But it wasn't until August 2017 that the SEC learned that the incident might have allowed the intruders to profit illegally through trading, Clayton said, without providing any additional details on how that might have happened. The vulnerability provided access to certain nonpublic information in EDGAR and was patched promptly after discovery, he noted.

EDGAR is an automated system for electronically collecting, validating, accepting, and forwarding disclosure documents from public companies that are required by US law to file with the SEC. On average, the EDGAR system receives and processes some 1.7 million electronic filings annually, a lot of which is publicly available data. Some of the typical data in EDGAR includes statements for IPOs and quarterly and annual reports. But some documents that companies might file voluntarily — such as the proposed sale of securities — may remain nonpublic.

"The EDGAR database contains or has the potential to contain the filings companies make that are labeled as private," says Chris Pierson, chief security officer and general counsel at Viewpost.

For instance, companies can make filings for mergers and acquisitions that they might want to keep private for a period of time. "These are the filings that a hacker would want to find and see as it indicates the intentions of a public company and can be translated into monetary reward," Pierson says.

The incident is the second one that the SEC has disclosed this year involving unauthorized access or misuse of its systems. In May, the SEC announced that it had filed fraud charges against a mechanical engineer who managed to make a fake regulatory filing on the agency's systems in an attempt to manipulate the prices of Fitbit's stock.

The almost complete lack of details surrounding the 2016 breach incident has resulted in some speculation over what might have happened and the true extent of the compromise.

The SEC's language surrounding the breach discovery and vulnerabilities sound intentionally vague, says Atiq Raza, CEO of Virsec Systems. "They are implying that as soon as the vulnerability was discovered, they patched it promptly using all due diligence," he says.

"But this begs more questions: discovered by whom and when?" he says. "It may well be that the SEC discovered an unpatched server that was being exploited, for an unknown, probably long period, and only then took steps to apply critical patches."

Ilia Kolochenko, CEO of Web security firm High-Tech Bridge, says the vagueness of the SEC's disclosure is sure to provoke speculation about nation-state involvement or actions by known cybercrime groups.

"In the financial world, even a press release can make you millions if you get it before everybody else does," Kolochenko says. "In the Equifax situation, victims may be attacked to steal a couple of hundreds of dollars on average, while in this breach smart attackers could potentially make huge amounts of money at the expense of unaware honest investors."

Clayton's disclosure pertaining to an incident that happened back in 2016 has also raised some questions about the SEC's own breach notification obligations.

But some executives such as Jeremiah Grossman, head of security strategy at cybersecurity firm SentinelOne, says the apparent lag is not all that surprising.

"There's no legal obligation I'm aware of for the SEC to ever disclose this kind of breach, or to notify the parties whose data was compromised," Grossman notes. "We're talking EDGAR data, not PII. That might be one possible explanation."

Related content:

 

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
New 'Nanodegree' Program Provides Hands-On Cybersecurity Training
Nicole Ferraro, Contributing Writer,  8/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15058
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.
CVE-2020-15059
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to bypass authentication via a web-administration request that lacks a password parameter.
CVE-2020-15060
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to conduct persistent XSS attacks by leveraging administrative privileges to set a crafted server name.
CVE-2020-15061
PUBLISHED: 2020-08-07
Lindy 42633 4-Port USB 2.0 Gigabit Network Server 2.078.000 devices allow an attacker on the same network to denial-of-service the device via long input values.
CVE-2020-15062
PUBLISHED: 2020-08-07
DIGITUS DA-70254 4-Port Gigabit Network Hub 2.073.000.E0008 devices allow an attacker on the same network to elevate privileges because the administrative password can be discovered by sniffing unencrypted UDP traffic.