
Wall Street Journal reporter Dave Michaels has the story of a Ukrainian man who allegedly hacked into SEC databases twice, and on one occasion was able to pilfer confidential corporate earnings data.
Loading summary
Small Business Owner
Access to affordable credit helps me pay my employees, but I don't really need it.
Retail Industry Advocate
Inflation is killing me, but who cares? Big retailers are making record profits. That's why we support the Durbin Marshall credit card bill.
Small Business Owner
See banks and credit unions help small businesses make payroll. This bill would cut the vital resources
Retail Industry Advocate
they need while increasing megastore profits. They deserve it, don't they?
Small Business Owner
Tell Congress Stop the Durbin Marshall money grab for corporate megastores paid for by the Electronic Payments Coalition.
J.R. Whalen
With your Money briefing. I'm J.R. whalen at the Wall Street Journal in New York. Imagine hacking into government databases, getting caught, then doing it again and scoring millions in profits off of confidential corporate earnings data. Well, that actually happened. We've got the story behind it. That's coming up first. These money and market stories you should know if you didn't have enough money withheld from your paychecks last year. The IRS has got some good news for you. It'll waive penalties for some people who didn't pay enough taxes through 2018, which illustrates the uncertainty surrounding the implementation of the tax law Congress passed at the end of 2017. Now, while the new law reduced taxes for most taxpayers, it also complicated things by leaving some people vulnerable to penalties of the changes to their paycheck withholding line up with the changes to their total tax bills. Taxpayers can normally avoid penalties if they had paid 90% of the current year's tax owed. Under the change announced Wednesday by the IRS, that number comes down to 85%. A Harvard business School study focuses on what it calls a caregiver crisis in the US and it finds that employers underestimate the struggle their employees face in balancing the professional and caregiving responsibilities. But 75% of U.S. workers face some kind of caregiving responsibility, and of those, 32% say they have left a job because they couldn't balance work and family duties. The study found a disconnect in the workplace as well. Although 80% of workers said their productivity had been affected by their caregiving responsibilities, less than a quarter of employers said that caregiving was affecting their employees performance. And the Federal Reserve says that student debt has prevented hundreds of thousands of young Americans from from buying a home in recent years and may help explain why many college graduates have moved out of rural areas. The share of households headed by someone between the ages of 24 and 32 years old who owned a home from 2004 to 2014 fell from 45% to 36%, and the Fed says about 20% of that decline was directly due to Households owing student debts. It's a storyline you might find in a movie on Netflix. Hackers break into government database, pose as a company, see secret data from other corporations, and trade off the data that actually happened. And Wall Street Journal financial regulation reporter Dave Michaels is on the line with us with details. So, Dave, this was a Ukrainian man who essentially spent six months snooping around a government database.
Dave Michaels
There were two hackers. According to an indictment that was returned in federal court in New Jersey, both of these men were, are allegedly hackers who got into a database known as edgar, which is an enormous repository of information that is relevant to investors, including sort of the standard corporate filings that reveal how a company did in terms of earnings for a quarter. So this EDGAR database is full of information that if you got to it early enough and got a sneak peek before the rest of the market saw, could be very lucrative for a trader.
J.R. Whalen
And he and his associates were able to trick SEC employees into giving them access by posing as SEC security personnel.
Dave Michaels
Yeah, that was one of the ways that they furthered their reach into this database. They sent these phishing emails to SEC workers which made it look like they were. Made it looked like the hackers were SEC security personnel. The SEC's documents in their case and the indictment, they don't give you a lot of, give us a lot of detail on what those emails said. But clearly some SEC workers clicked on them and it gave the hackers allegedly another path to get deeper and deeper into the database so they could look for documents that would provide information that they or their conspirators could trade on.
J.R. Whalen
And there is some detail in your story that's remarkable, not really a surprise, the difference in the trading results when this Ukrainian man and his associate had the illegal data in hand.
Dave Michaels
Yeah, The SEC put this table in their lawsuit to show how these traders really were not very good when they traded without allegedly without access to this information that was in the database. So over some like 837 trades, when they were not trading on information relevant to this hack, allegedly these traders had net loss of about $38,000. Whereas when they traded based upon or they had some information allegedly that they got out of the database, they traded and their net profit was about 3.6 million.
J.R. Whalen
That's just remarkable. It just really shows that all that data is being locked up until a certain time for a reason. To more or less create an even playing field for all the traders out there.
Dave Michaels
I should make it clear that this database known as edgar, where if you go to the SEC'S website. And you're an investor, you're managing your own money. You probably use Edgar. You probably go to sec.gov and pull up corporate filings. Most of the time, when companies send filings into edgar, that information, if it's from a public company and it's relevant to a required periodic disclosure, the information will become public immediately. What these hackers got, which a lot of us didn't even know was there, were these were so called test filings. And these were like filings that the public companies or their lawyers or their printers would send to the SEC's Edgar system, sort of just to ping it to make sure that the filing went through so that when they had to file before a deadline, they knew it would get there. And in some cases, these test filings contain the actual quarterly earnings results. I mean, they were test filings, but they weren't really test filings. They had real information that could be traded upon. And these guys, these hackers who I should also mention they had previously broken into allegedly companies that disseminate corporate news releases, and they were able to trade upon that. They, they found these test filings that many of us didn't even know existed. And they exploited them, allegedly to the tune of the profit that they and their conspirators earned.
J.R. Whalen
And this really did expose an issue of security here. I mean, as you mentioned, this hack first happened that we're talking about in late 2017, but this man and his associates had actually been accused of data breaches before. You would think that when the data breaches involving the press releases and such happened, that would create an extra piece of urgency to lock things up.
Dave Michaels
Well, you would think that, I mean, it wasn't inside the sec. They probably didn't know that they had this vulnerability. Allegedly it came from a software, you know, vulnerability. It was like one, it was like one way into the system that was vulnerable. And who knows how much sort of routine maintenance or routine checks would have found that. But it is interesting that there was this other hack that, that these hackers had been accused of that was actually before this even started. These hackers were indicted in 2015 for allegedly hacking three companies that release corporate news releases. In other words, earnings releases, information that went into the market that immediately everyone would see and potentially trade upon. They were indicted in 2015, so they were known to law enforcement. In 2016, they broke into the SEC's Edgar system. So, you know, if you take the facts at face value, it was kind of a brazen hack that these guys were willing, after they'd already been indicted to then go into the database run by the agency that had already sued them.
J.R. Whalen
And it seems like this scenario and other scenarios like this really illustrate the point that in terms of having cybersecurity protection, good is never really good enough. It just seems like it's a constant game of cat and mouse.
Dave Michaels
It is. And stock exchanges, banks, very large money managers. You can imagine that a big part of their risk profile has to do with cybersecurity and trying to ensure that they've made all the investments they need to make and have all the experts they need to have to defend against this relentless computer hacking. But we're talking about the government in this case, and the SEC does not spend as much money on computer infrastructure or cybersecurity defense as probably even a single large bank does, much less the whole industry. So for the SEC and maybe other regulators, that sort of custody information that could be market moving, the risk profile is very high. And I'm not sure that we know right now whether these agencies are up to the challenge of defending against that risk.
J.R. Whalen
Well, the story of the data breach with the SEC is a remarkable one. You can see all the details, all the numbers in Dave Michael's story in the Wall Street Journal, WSJ.com and the WSJ app. And Dave Michael is good enough to join us here on the line from our Washington bureau. Dave, thanks for being with us.
Dave Michaels
Thanks for having me.
J.R. Whalen
And that's your money briefing. I'm JR Whalen in New York for the Wall Street Journal.
Small Business Owner
Access to affordable credit helps me pay my employees, but I don't really need it.
Retail Industry Advocate
Inflation is killing me, but who cares? Big retailers are making record profits. That's why we support the Durbin Marshall credit card bill.
Small Business Owner
See, banks and credit unions help small businesses make payroll. This bill would cut the vital resources
Retail Industry Advocate
they need while increasing megastore profits. They deserve it, don't they?
Small Business Owner
Tell Congress, stop the Durbin Marshall money grab for corporate megastores paid for by the Electronic Payments Coalition.
Date: January 17, 2019
Host: J.R. Whalen (Wall Street Journal)
Guest: Dave Michaels (WSJ Financial Regulation Reporter)
This episode delves into a high-profile cybersecurity breach involving Ukrainian hackers who accessed the SEC's confidential EDGAR database. The discussion covers how the attack was carried out, the profits made from illicit trading, the shortcomings of cybersecurity in government agencies, and the broader implications for investors and the regulatory landscape.
The conversation maintains a conversational yet investigative tone, mirroring the accessible analysis typical of WSJ reporting. Both J.R. Whalen and Dave Michaels speak in clear, direct language aimed at financial professionals and informed general audiences.
This episode uncovers how hackers exploited overlooked vulnerabilities in the SEC's EDGAR database, profiting millions by trading on early earnings data. It highlights the difficulties regulators face in keeping pace with sophisticated cyber criminals and underscores the market’s dependence on secure, fair financial information systems. The discussion leaves listeners with the sobering realization that cyber threats to financial markets are deeply entrenched and that regulators may not be equipped to match the resources or sophistication of those they’re up against.