The U.S. Securities and Exchange Commission displayed how vulnerable government agencies are to cyberattacks when it disclosed last week that hackers had breached its database. The
The cyber attackers were able to exploit a software vulnerability in the test filing component of Edgar. The SEC learned of the data breach last year, the same year that the incident occurred. However, the SEC didn’t determine that the hackers used the stolen data to make illicit trades until August of this year. The SEC immediately patched the security gap when it was discovered, but by this time the hackers had already seen confidential information. It is not yet known which companies may have been affected by the hackers’ insider trading.











