Hack of U.S. securities regulator rattles investors, stirs doubts

Reuters  |  WASHINGTON/NEW YORK 

By Sarah N. Lynch and Jonathan Spicer

WASHINGTON/NEW YORK (Reuters) - Wall Street's top regulator faced questions on Thursday about its defenses against criminals after admitting hackers breached its electronic of corporate announcements and may have used it for insider trading.

The incursion at the Securities and Exchange Commission (SEC) struck at the heart of the U.S. financial system. The SEC's EDGAR filing system is the central repository for market-moving information on corporate America with millions of filings ranging from quarterly earnings to statements on acquisitions.

Accessing documents before they are released publicly would offer hackers a lucrative opportunity to trade on that information.

The said late on Wednesday that a hack occurred in 2016 but it had only discovered last month that the criminals may have used the information to make illicit trades.

Chairman Jay Clayton gave members of Congress a "courtesy call" about the hack late on Wednesday afternoon, said Rep. Bill Huizenga, chairman of the House subcommittee on Capital Markets, Securities, and Investment, which oversees the

"I'm glad that Jay Clayton has decided to acknowledge this and release it, warts and all," Huizenga said.

"It's hugely problematic and we've got to be serious about how we protect that information as a regulator. I'm hoping that this leads to some vast improvements and an uptick in the vigilance that all the regulators are going to have with information that's coming to them."

The disclosure has rattled investors' faith in the security of their data. It comes two weeks after credit-reporting company Equifax said hackers had stolen data on more than 143 million U.S. customers, and in the wake of last year's attack on SWIFT, the global bank messaging system.

It is particularly embarrassing for the and its new boss Clayton, who has made tackling crime one of the top enforcement issues during his tenure.

"The Chairman obviously recognizes the irony of the potentially serving as the unwitting tipper in an insider trading scheme," said John Reed Stark, a former staff member and expert.

The has said it was investigating the source of the hack but it did not say when exactly it happened or what sort of non-public data was retrieved. The agency said the attackers had exploited a weakness in part of the EDGAR system and it had "promptly" fixed it.

SLEUTHS NEEDED

Clayton will be grilled on the incident and its aftermath at a hearing by the Senate Banking Committee on Tuesday. In particular, questions are likely about how prepared the was against such an attack and why it waited until now to disclose it.

Securities industry rules require companies to disclose breaches to investors and the has investigated firms over whether they should have reported incidents sooner.

In July, months after the breach was detected, a congressional watchdog office warned that the regulator was "at unnecessary risk of compromise" because of deficiencies in its information systems.

The 27-page report by the Government Accountability Office found the did not always fully encrypt sensitive information, used unsupported software, failed to fully implement an intrusion detection system and made missteps in how it configured its firewalls, among other things.

It also shut down a specialized unit on crimes as part of a reorganization in 2010 despite former chair Mary Jo White, in office when the hack occurred, telling in 2016 that security posed the biggest risk to the U.S. financial system.

"crimes have continued to spread, thrive and become more innovative. Now, more than ever, the needs a dedicated and specialized corps of sleuths to track down and deter hackers," said Stark, currently president of a consulting firm.

The has scored some victories in tackling criminals. In 2015, the commission unmasked a ring of stock traders and hackers who had accessed company press releases from distributors Marketwire, PR Newswire and Business Wire before the information was made public to make $100 million in illegal profits.

(Writing by Lisa Lambert; Editing by Carmel Crimmins and Nick Zieminski)

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

First Published: Thu, September 21 2017. 20:41 IST