2019-01-01 SEC Press press_release 64 KB 4,481 chars

SEC Brings Charges in EDGAR Hacking Case

Release
2019-1
Caption
Securities and Exchange Commission v. Andrey Sarafanov, et al.
summary

Ukrainian hacker Oleksandr Ieremenko and eight others, including six traders and two entities, hacked the SEC’s EDGAR system in 2016 to steal nonpublic earnings data, used it to execute illegal trades ahead of 157 earnings releases, generating $4.1 million in illicit profits, and now face SEC charges for securities fraud alongside parallel criminal charges.

paragraph

The SEC charged Ukrainian hacker Oleksandr Ieremenko, six individual traders in California, Ukraine, and Russia, and two entities for hacking into the SEC’s EDGAR system in 2016 to extract nonpublic test filings containing confidential earnings results. These traders executed illegal trades ahead of 157 earnings announcements, generating at least $4.1 million in illicit profits, while concealing their activities through offshore entities and nominee accounts. The SEC seeks disgorgement of ill-gotten gains with prejudgment interest, civil penalties, and permanent injunctions, and has named four relief defendants who facilitated the trades; a parallel criminal case was filed by the U.S. Attorney’s Office for the District of New Jersey.

narrative

Ukrainian hacker Oleksandr Ieremenko hacked the SEC’s EDGAR system in 2016 by circumventing authentication controls and extracting nonpublic test filings that contained confidential earnings results before public release. He passed this information to six traders located in California, Ukraine, and Russia, along with two corporate entities—Capyield Systems, Ltd. and Spirit Trade Ltd.—who used it to execute illegal trades ahead of at least 157 earnings announcements, generating $4.1 million in illicit profits. To conceal their fraud, the defendants used offshore entities and nominee brokerage accounts, prompting the SEC to also name four relief defendants who unknowingly or complicitly held accounts used for the illicit trades. The SEC charged all nine defendants with violating federal securities antifraud laws and is seeking disgorgement of profits, prejudgment interest, civil penalties, and permanent injunctions against future violations. In a parallel action, the U.S. Attorney’s Office for the District of New Jersey filed criminal charges against the same individuals. The SEC’s investigation, led by its Market Abuse and Cyber Units with support from the FBI, Secret Service, and IT forensics teams, relied on sophisticated trading analysis to trace the common source of the illegal trades back to the EDGAR breaches. The SEC emphasized that this case underscores its ability to detect and prosecute international cyber-enabled fraud, even when perpetrators operate across borders and use complex concealment techniques.

Enriched metadata

Scheme
cyber-fraud (100%)
Court
District of New Jersey
Classified cyber-fraud(confidence 100%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
andrey sarafanovcapyield systems, ltd.david kwonhacked edgar informationigor sabodakhaivan olefirnonpublic test files from sec serversOleksandr Ieremenkorelated criminal chargessec edgar system in 2016Securities and Exchange Commissionspirit trade ltd.sungjin choU.S. Attorney's Office for the District of New Jerseyvictoria vorochek
Keywords
secedgarinformationtradershackingnonpublicieremenkohackerukrainefilesbrings edgaredgar hackingscheme hackedgar systemnonpublic information

Extracted insights

Dollar amounts 1
  • $4.10M $4.1 million $1M–$10M
Entities 15
  • person andrey sarafanov
  • company capyield systems, ltd.
  • person david kwon
  • person hacked edgar information
  • person igor sabodakha
  • person ivan olefir
  • agency nonpublic test files from sec servers
  • person Oleksandr Ieremenko
  • person related criminal charges
  • agency sec edgar system in 2016
  • agency Securities and Exchange Commission
  • company spirit trade ltd.
  • person sungjin cho
  • agency U.S. Attorney's Office for the District of New Jersey
  • person victoria vorochek
Triples 17
  • SEC announced charges against nine defendants for hacking EDGAR system
  • Oleksandr Ieremenko hacked SEC EDGAR system in 2016
  • Oleksandr Ieremenko extracted EDGAR files containing nonpublic earnings results
  • Traders generated $4.1 million in illegal profits
  • Traders traded before at least 157 earnings releases from May to October 2016
  • Sungjin Cho received and traded on hacked EDGAR information
  • David Kwon received and traded on hacked EDGAR information
  • Igor Sabodakha received and traded on hacked EDGAR information
  • Victoria Vorochek received and traded on hacked EDGAR information
  • Ivan Olefir received and traded on hacked EDGAR information
  • Andrey Sarafanov received and traded on hacked EDGAR information
  • Capyield Systems, Ltd. charged with violating federal securities antifraud laws
  • Spirit Trade Ltd. charged with violating federal securities antifraud laws
  • SEC seeks penalties and return of ill-gotten gains from defendants
  • U.S. Attorney's Office for the District of New Jersey announced related criminal charges
  • Oleksandr Ieremenko circumvented EDGAR controls requiring user authentication
  • Oleksandr Ieremenko obtained nonpublic test files from SEC servers
View original SEC press releasesec.gov
Extracted body text (4,481c)
The Securities and Exchange Commission today announced charges against nine defendants for participating in a previously disclosed scheme to hack into the SEC’s EDGAR system and extract nonpublic information to use for illegal trading. The SEC charged a Ukrainian hacker, six individual traders in California, Ukraine, and Russia, and two entities. The hacker and some of the traders were also involved in a similar scheme to hack into newswire services and trade on information that had not yet been released to the public. The SEC charged the hacker and other traders for that conduct in 2015 (see here, here and here). The SEC’s complaint alleges that after hacking the newswire services, Ukrainian hacker Oleksandr Ieremenko turned his attention to EDGAR and, using deceptive hacking techniques, gained access in 2016. Ieremenko extracted EDGAR files containing nonpublic earnings results. The information was passed to individuals who used it to trade in the narrow window between when the files were extracted from SEC systems and when the companies released the information to the public. In total, the traders traded before at least 157 earnings releases from May to October 2016 and generated at least $4.1 million in illegal profits. “International computer hacking schemes like the one we charged today pose an ever-present risk to organizations that possess valuable information,” said Enforcement Division Co-Director Stephanie Avakian. “Today’s action shows the SEC’s commitment and ability to unravel these schemes and identify the perpetrators even when they operate from outside our borders.” “The trader defendants charged today are alleged to have taken multiple steps to conceal their fraud, including using an offshore entity and nominee accounts to place trades,” said Enforcement Division Co-Director Steven Peikin. “Our staff’s sophisticated analysis of the defendants’ trading exposed the common element behind their success, providing overwhelming evidence that each of them traded based on information hacked from EDGAR.” The SEC’s complaint alleges that Ieremenko circumvented EDGAR controls that require user authentication and then navigated within the EDGAR system. Ieremenko obtained nonpublic “test files,” which issuers can elect to submit in advance of making their official filings to help make sure EDGAR will process the filings as intended. Issuers sometimes elected to include nonpublic information in test filings, such as actual quarterly earnings results not yet released to the public. Ieremenko extracted nonpublic test files from SEC servers, and then passed the information to different groups of traders. The SEC’s complaint alleges that the following traders received and traded on the basis of the hacked EDGAR information: • Sungjin Cho, Los Angeles, California • David Kwon, Los Angeles, California • Igor Sabodakha, Ukraine • Victoria Vorochek, Ukraine • Ivan Olefir, Ukraine • Andrey Sarafanov, Russia • Capyield Systems, Ltd. (owned by Olefir) • Spirit Trade Ltd. In a parallel action, the U.S. Attorney’s Office for the District of New Jersey today announced related criminal charges. The SEC’s complaint charges each of the defendants with violating the federal securities antifraud laws and related SEC antifraud rules and seeks a final judgment ordering the defendants to pay penalties, return their ill-gotten gains with prejudgment interest, and enjoining them from committing future violations of the antifraud laws. The SEC also named and is seeking relief from four relief defendants who profited from the scheme when defendants used the relief defendants’ brokerage accounts to place illicit trades. The SEC’s investigation, which is ongoing, was conducted by Market Abuse Unit and Cyber Unit staff David Bennett, Arsen Ablaev, Michael Baker, Jason Burt, Laura D’Allaird, Adam Gottlieb, James Scoggins, David Snyder, Jonathan Warner, Darren Boerner, John Marino, and John Rymas, and IT Forensics staff Ken Zavos, Douglas Bond, Stephen Haupt, Gi Nguyen, and Jennifer Ross. The Division of Economic and Risk Analysis and the Office of Information Technology provided substantial assistance. The investigation was supervised by Robert Cohen, Joseph Sansone, and Carolyn Welshhans. Cheryl Crumpton and Stephan Schlegelmilch are leading the SEC’s litigation. The SEC appreciates the assistance of the U.S. Attorney’s Office for the District of New Jersey, the Federal Bureau of Investigation, and the U.S. Secret Service.
OCR text (4,481c · plain-text · 99% conf)
The Securities and Exchange Commission today announced charges against nine defendants for participating in a previously disclosed scheme to hack into the SEC’s EDGAR system and extract nonpublic information to use for illegal trading. The SEC charged a Ukrainian hacker, six individual traders in California, Ukraine, and Russia, and two entities. The hacker and some of the traders were also involved in a similar scheme to hack into newswire services and trade on information that had not yet been released to the public. The SEC charged the hacker and other traders for that conduct in 2015 (see here, here and here). The SEC’s complaint alleges that after hacking the newswire services, Ukrainian hacker Oleksandr Ieremenko turned his attention to EDGAR and, using deceptive hacking techniques, gained access in 2016. Ieremenko extracted EDGAR files containing nonpublic earnings results. The information was passed to individuals who used it to trade in the narrow window between when the files were extracted from SEC systems and when the companies released the information to the public. In total, the traders traded before at least 157 earnings releases from May to October 2016 and generated at least $4.1 million in illegal profits. “International computer hacking schemes like the one we charged today pose an ever-present risk to organizations that possess valuable information,” said Enforcement Division Co-Director Stephanie Avakian. “Today’s action shows the SEC’s commitment and ability to unravel these schemes and identify the perpetrators even when they operate from outside our borders.” “The trader defendants charged today are alleged to have taken multiple steps to conceal their fraud, including using an offshore entity and nominee accounts to place trades,” said Enforcement Division Co-Director Steven Peikin. “Our staff’s sophisticated analysis of the defendants’ trading exposed the common element behind their success, providing overwhelming evidence that each of them traded based on information hacked from EDGAR.” The SEC’s complaint alleges that Ieremenko circumvented EDGAR controls that require user authentication and then navigated within the EDGAR system. Ieremenko obtained nonpublic “test files,” which issuers can elect to submit in advance of making their official filings to help make sure EDGAR will process the filings as intended. Issuers sometimes elected to include nonpublic information in test filings, such as actual quarterly earnings results not yet released to the public. Ieremenko extracted nonpublic test files from SEC servers, and then passed the information to different groups of traders. The SEC’s complaint alleges that the following traders received and traded on the basis of the hacked EDGAR information: • Sungjin Cho, Los Angeles, California • David Kwon, Los Angeles, California • Igor Sabodakha, Ukraine • Victoria Vorochek, Ukraine • Ivan Olefir, Ukraine • Andrey Sarafanov, Russia • Capyield Systems, Ltd. (owned by Olefir) • Spirit Trade Ltd. In a parallel action, the U.S. Attorney’s Office for the District of New Jersey today announced related criminal charges. The SEC’s complaint charges each of the defendants with violating the federal securities antifraud laws and related SEC antifraud rules and seeks a final judgment ordering the defendants to pay penalties, return their ill-gotten gains with prejudgment interest, and enjoining them from committing future violations of the antifraud laws. The SEC also named and is seeking relief from four relief defendants who profited from the scheme when defendants used the relief defendants’ brokerage accounts to place illicit trades. The SEC’s investigation, which is ongoing, was conducted by Market Abuse Unit and Cyber Unit staff David Bennett, Arsen Ablaev, Michael Baker, Jason Burt, Laura D’Allaird, Adam Gottlieb, James Scoggins, David Snyder, Jonathan Warner, Darren Boerner, John Marino, and John Rymas, and IT Forensics staff Ken Zavos, Douglas Bond, Stephen Haupt, Gi Nguyen, and Jennifer Ross. The Division of Economic and Risk Analysis and the Office of Information Technology provided substantial assistance. The investigation was supervised by Robert Cohen, Joseph Sansone, and Carolyn Welshhans. Cheryl Crumpton and Stephan Schlegelmilch are leading the SEC’s litigation. The SEC appreciates the assistance of the U.S. Attorney’s Office for the District of New Jersey, the Federal Bureau of Investigation, and the U.S. Secret Service.