Live data from Hacker News

DOJ: Hackers broke into an SEC database and made millions from inside info

cnbc.com

11–20 of 198 posts

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#11
post #9
post #5

Earlier quoted context omitted.

Yes - so they're not released while the markets are open.

Just curious -- why does that matter? In either case there's a single moment wherein people can trade on it. Why is it better for that moment to be at 9:30 instead of say noon?

I guess it prevents people hammering the servers to get the earning reports ASAP.

With this, people have a few hours to get the reports which means miliseconds matter less.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#13

> said the same criminals also stole advance press releases sent to three newswire services Yeah I remember the charges against those people too Basically newswire services get hacked and people get the earnings reports beforehand SEC gets hacked and people get the earnings reports beforehand I think public resources shouldnt be spent on that. Prosecute the hacking but just drop the “trading on material non public in…

Insider trading is a balance.

On the one hand, we want market prices to be accurate. This means we want people with material information to trade on that information.

On the other hand, we need some fairness in a market. This is mostly to ensure people keep trading. In a world were inside-info is commonplace, trading without it is just stupid. This would cut off a lot of people from investing.

The line needs to be drawn somewhere. The US approach of insider trading requires a broken 'duty to keep secret' isn't nice, but considering the above trade-off I think it is better than "All non-public information is off-limits". Especially because it captures the 'most disruptive' form of insider trading: people who work at a company that is getting acquired / going bankrupt.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#14
post #4

Is there a reason why all SEC filing shouldn't be immediately publicly available?

Yes - certain filings are confidential while they are 'in process.' They then get released in batches on specific release dates, to the entire world, all at once. In particular, IPO registrations may be done confidentially in early stages. The information that is present in such filings is often valuable.

https://www.nytimes.com/2017/07/07/business/dealbook/sec-ini...

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#15
post #9
post #5

Earlier quoted context omitted.

Yes - so they're not released while the markets are open.

Just curious -- why does that matter? In either case there's a single moment wherein people can trade on it. Why is it better for that moment to be at 9:30 instead of say noon?

Because they need time to correct errors and to prevent fraud. Say someone gets into the SEC and decides to release a fraudulent report. If that happens during off hours it can be rectified, but if it happens during the trading day the markets will react instantly and the damage is done.

Fixed release times also means that the companies submitting the filings cannot pick an advantageous time. Imagine if Musk was sitting atop a really horrible Tesla earnings report. If he could manipulate the exact time of its release he could leverage all sorts of things.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#16

I'm more curious about how they hacked into the SEC database? Did they use an email trojan? Exploit an existing flaw or backdoor? If they did this via e-mail, who did they send the mail to?

This is covered in the story. They sent email to SEC employees.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#17

I'm more curious about how they hacked into the SEC database? Did they use an email trojan? Exploit an existing flaw or backdoor? If they did this via e-mail, who did they send the mail to?

The SEC’s complaint alleges that Ieremenko circumvented EDGAR controls that require user authentication and then navigated within the EDGAR system.

Looks like a way to say “exfiltrating data from the endpoints”.

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#19
post #13

> said the same criminals also stole advance press releases sent to three newswire services Yeah I remember the charges against those people too Basically newswire services get hacked and people get the earnings reports beforehand SEC gets hacked and people get the earnings reports beforehand I think public resources shouldnt be spent on that. Prosecute the hacking but just drop the “trading on material non public in…

Insider trading is a balance. On the one hand, we want market prices to be accurate. This means we want people with material information to trade on that information. On the other hand, we need some fairness in a market. This is mostly to ensure people keep trading. In a world were inside-info is commonplace, trading without it is just stupid. This would cut off a lot of people from investing. The line needs to be dr…

> On the other hand, we need some fairness in a market

American insider trading law has nothing to do with fairness. It is based on theft of information. In this case, the hacker’s stole information from the SEC that belonged to the reporting companies.

(This is a commonly misunderstood alley of securities law.)

Re: DOJ: Hackers broke into an SEC database and made millions from inside info

#20
> The New York Stock Exchange has asked the SEC to consider limiting the amount of data collected by the CAT, which would include data on around 58 billion daily trades, as well as the personal details of individuals making the trades, including their Social Security numbers and dates of birth

Dropping SSNs for natural persons would be a good idea.

Post reply on HN