Market Manipulation. Search

Hack to trade

Hack to trade is obtaining unpublished, market-moving information by breaking into a computer system, such as a newswire, filing agent or law firm, and trading on it before release; it exploits a true signal and injects no false one into the price.

Also called hack and trade, hacked news release trading, hack-to-trade. Observed in equities, options, derivatives. One of the related but distinct techniques. 13 enforcement actions in the library.
Updated 2026-09-20

What is hack to trade, and where is the line drawn?

Hack to trade is a two-step scheme. First, someone breaks into a computer system that holds market-moving news before it is published: a newswire, a company’s filing agent, a law firm, a regulator’s filing system. Second, that person, or people they pass the information to, trades on it before the news is released.

The line is drawn by what enters the price. Nothing false does. The earnings figures or merger terms that are eventually published are accurate, and the price moves to where they put it. The traders were simply there first.

That is why this technique sits in the related but distinct section and not with the manipulation techniques. It is not market manipulation. Manipulation falsifies the price signal, as a spoofed order or a wash trade does. Hack to trade exploits a true signal that others cannot yet see.

It is also not insider trading in the classic sense. Insider trading liability turns on a breach of a duty of trust or confidence owed to the source of the information. A hacker owes the newswire no such duty, and neither does a trader who receives what the hacker stole. That gap is what made the legal question hard, and it is the reason this page exists separately.

It is not hijacked-account ramping either: that technique steals control of other people’s accounts to move a price, while this one steals information and leaves the price alone.

How hacked, unpublished news is turned into tradesA flow that runs left to right on the top row and back on the bottom row. Someone breaks into a computer system that holds news before it is published, such as a newswire, a filing agent or a law firm. They copy an unpublished release containing earnings or deal news and pass it to a network of traders. The traders buy or sell stock, options or contracts for difference before the news is out. The owner then publishes the news, which is true, and the price moves to where that news puts it. Nothing false is told to the market at any point; the false step is the way the information was obtained. copiedpassed ontrade firstwaitreaction Break-innewswire, filing agent,law firm Unpublished releaseearnings or deal news Trader networktold before the market Tradesstock, options, CFDs Publicationthe true news isreleased Price movesto where the news putsit
The false step comes before the market: the information is obtained by intrusion, and the news that is later published is true.

How does it work?

The matters in this library follow the same pipeline, though the details differ.

  1. Break in. An intruder gains access to a system holding unpublished material. In the newswire and SEC filing-system cases the regulators and prosecutors describe stolen log-in credentials and access to areas the intruders were not permitted to see. In the 2021 case the targets were two filing agents that prepare companies’ periodic reports.
  2. Copy the release. The material taken is typically an earnings announcement, or in the law-firm case confidential merger information in emails, before its scheduled publication.
  3. Pass it to traders. In the newswire case the SEC alleged the hackers built a secret web location to give traders the stolen releases, in return sometimes for a share of the profits. Prosecutors described “wish lists” in which traders named the releases they wanted.
  4. Trade in the window. The window can be short. In one 2013 instance described in the SEC’s first complaint release, traders acted in the 36 minutes between a newswire receiving a release and publishing it. Trading was often in stock, options and contracts for difference, which give leveraged exposure to a price move without owning the shares.
  5. Wait for publication. The owner publishes the news on its normal schedule.
  6. Close out and share. The traders take the move and sometimes pass part of the profit back to the source.

Why did the law need a court to say it was fraud?

Section 10(b) of the Securities Exchange Act reaches a “manipulative or deceptive device”. A hacker’s trades are not manipulative in the Supreme Court’s sense, because they do not artificially affect market activity. The SEC therefore had to show the conduct was deceptive.

The obstacle was the Supreme Court’s insider trading line of cases, in which silence is deceptive only where a duty to speak exists. A stranger who breaks in has no such duty. In SEC v. Dorozhko the district court held on that basis that hacking was not deceptive without a breach of fiduciary duty.

The Second Circuit disagreed in 2009. It held that the fiduciary-duty requirement in those cases belongs to fraud by silence, and that an affirmative misrepresentation is a different kind of fraud that needs no such duty. It said that misrepresenting one’s identity to reach off-limits information and then stealing it is “plainly deceptive”. It was less sure about a hacker who merely exploits a flaw in code, which it said might be “mere theft”, and it sent the case back to the district court to decide how that hack was done.

Twelve years later, in United States v. Korchevsky, the same court upheld convictions arising from the newswire case. It treated stolen-credential log-ins as deceptive because each one misrepresents the user as authorised, and said the deception need not target investors. It did not decide the pure-exploit question, because the hackers there had used stolen credentials after their initial entry.

The point for readers: the question is settled for hacks that impersonate a user in the Second Circuit. It is not settled everywhere, and not for every method.

What law applies?

Provisions most often charged
ProvisionCitationPrimary text
Securities Exchange Act — general antifraud15 U.S.C. § 78j(b) Read the text
SEC Rule 10b-517 C.F.R. § 240.10b-5 Read the text
Securities Act — fraudulent interstate transactions15 U.S.C. § 77q(a) Read the text
Computer fraud and abuse18 U.S.C. § 1030 Read the text
Wire fraud18 U.S.C. § 1343 Read the text
Securities and commodities fraud18 U.S.C. § 1348 Read the text

The SEC’s civil cases in this library charge Section 10(b), Rule 10b-5 and Section 17(a) of the Securities Act. In some matters it also charged defendants under section 20(b) of the Exchange Act, which covers doing through another person what one may not do directly. The parallel criminal cases described in the Justice Department’s releases involved wire fraud conspiracy, securities fraud, computer fraud and money laundering conspiracy counts. Wire fraud does not depend on the section 10(b) deception analysis, and several individuals in the newswire matter pleaded to conspiracy to commit wire fraud.

Which real cases are there?

Which real enforcement actions have alleged hack to trade?

This library holds 13 enforcement actions tagged hack to trade. The table shows the largest by civil penalty together with the most recently filed. Every row links to a page carrying the regulator's own release and, where one was published, the complaint.

Selected hack to trade actions
Action Agency Filed Penalty Status
SEC v. Ieremenko et al.: settlements with Cho, Olefir and Capyield (hack to trade, 2020) SEC 2020-11-05 $425k settled
SEC v. Ieremenko et al.: settlements with Kwon and Sabodakha (hack to trade, 2020) SEC 2020-04-09 $149k settled
SEC v. Robert B. Westbrook (hack to trade, 2024) SEC 2024-09-27 filed
SEC v. Vladislav Kliushin, Nikolai Rumiantcev, Mikhail Irzak, Igor Sladkov, and Ivan Yermakov (hack to trade, 2021) SEC 2021-12-22 judgment

All 13hack to tradeactions →

Read the table with care. The library holds 13 records as of 2026-09-20. They span five underlying schemes (newswires, two law firms, the SEC’s EDGAR system, two filing agents, and executives’ email accounts), but for the newswire case they are follow-up announcements, not the opening one: the SEC’s first release of 13 August 2015, against 32 defendants (later 34), is not among them. The count is not a measure of how common the conduct is.

What the record shows.

What the record does not show. It does not show how many such schemes exist, how many go undetected, or whether the schemes it describes are typical. Every case here was found because the hack or the trading left a trace. Nor does it show how any unresolved matter ended.

How is it detected?

Two routes appear in the records. One begins at the market: a broker flagged unusual trading in the Dorozhko matter and referred it to the SEC, which then traced the trades to the hack. The other begins at the victim: the newswires cooperated with prosecutors in the newswire case, and the SEC’s own systems were the source of the EDGAR case.

The links between hackers and traders are usually found in communications and payments, since the trading itself looks like a run of well-timed bets.

What penalties have followed?

What penalties does hack to trade actually attract?

The numbers below are computed from this site's own case records at build time, not quoted from a secondary source. They change whenever a new action is added to the library.

Actions recorded
13
Median penalty
$287k
Largest penalty
$425k
Criminal parallel
85%
Median sentence

Computed from 13enforcement actions in our own case library tagged hack-to-trade , filed between 2015 and 2024. Median penalty covers the 2actions where a civil monetary penalty was disclosed; median sentence covers the 0 defendants who received a custodial term. Penalties exclude disgorgement and prejudgment interest, which are reported separately on each case page.

Largest single penalty: SEC v. Ieremenko et al.: settlements with Cho, Olefir and Capyield (hack to trade, 2020) .

The library’s monetary fields for these records are extracted mechanically and are incomplete for multi-defendant settlements, so treat the totals shown as a floor, not a complete figure. In the newswire case, the SEC said some judgments against individuals convicted criminally were deemed satisfied by criminal restitution and forfeiture orders, so civil and criminal amounts overlap and should not be added together.

What are the red flags?

How do the records for hack to trade end?

This describes the 13records in this library tagged hack to trade, not how such cases end in the world. "Settled" is not a finding of guilt. Many records are filings whose outcome this library does not track: 5 of 13 are marked filed or unknown.

Recorded status of 13 hack to trade records in this libraryCount of hack to trade records by recorded status: filed 5, settled 5, judgment 3, dismissed 0, appealed 0, unknown 0.filed 5 38%settled 5 38%judgment 3 23%dismissed 0 0%appealed 0 0%unknown 0 0%
Other recorded outcomes, records in this library only
MeasureRecordsValue
Share with a criminal parallel1385% (11 of 13)
Median civil penalty, where recorded2Too few records to show
Median months from filing to resolution60.0 months

Penalty and timing rows count only records where the figure or both dates are recorded; the count is shown beside each. Figures are computed at build time.

Frequently asked questions about hack to trade

Is hack to trade market manipulation?
No. Manipulation puts a false signal into the price. In hack to trade the news that is eventually published is true and the price moves to where it belongs; the trader simply got there first. The wrong lies in how the information was obtained, which is why this library files it under conduct that is routinely confused with manipulation.
Is it the same as insider trading?
It is a close relative but rests on a different theory. Insider trading liability turns on a breach of a duty owed to the source of the information. A hacker or a trader who receives hacked material owes no such duty to the newswire or the issuer, so the case has to be built on deception in how the information was obtained.
What did SEC v. Dorozhko decide?
In 2009 the Second Circuit held that a fraud built on an affirmative misrepresentation does not need a breach of fiduciary duty to count as deceptive under section 10(b), and that misrepresenting your identity to get into a system and steal information is plainly deceptive. It left open whether merely exploiting a flaw in code is deceptive, and sent the case back to the district court.
Does the deception have to be aimed at investors?
Not according to the Second Circuit in United States v. Korchevsky (2021). It rejected the argument that the deception must target investors, because Rule 10b-5 requires only that the deceptive conduct be in connection with the purchase or sale of a security. The hacking that prompted and enabled the trading met that test.
Can the recipients of hacked information be liable if they never hacked anything?
The records in this library say yes. The SEC charged traders who received hacked news releases with the same antifraud provisions as the hackers, and in the 2021 filing-agent case it also charged traders under the provision on acting through another person. Whether an individual is liable turns on what they knew and did, and each matter has its own record.
Do the profit figures in different documents agree?
Not always. In the newswire case the SEC alleged more than $100 million in illegal profits, while the Justice Department's announcements describe about $30 million and the Second Circuit refers to more than $18 million from the two defendants it reviewed. The documents describe different defendants, periods and measures, and the figures should not be added or swapped.
Where does hack to trade differ from hijacked-account ramping?
Hack to trade steals information and trades on it. Hijacked-account ramping steals control of other people's brokerage accounts and uses the orders they place to move a price. The first exploits a true signal; the second manufactures a false one, so only the second is manipulation.
Why does this library hold so few hack-to-trade records, and does the count mean anything?
The library reflects what regulators announced, and partly what has been cached. The 13 records it holds come from five underlying schemes. The count says nothing about how common the conduct is; the opening 2015 newswire announcement is not among them.

Terms defined on this page

Material Non Public Information · Misappropriation Theory · Insider Trading Term · Rule 10b 5 · Section 10b · Wire Fraud · EDGAR · Deception · Disgorgement · Hack To Trade Term · Newswire · Contract For Difference

Sources

  1. SEC v. Dorozhko, 574 F.3d 42 (2d Cir. 2009) — U.S. Court of Appeals for the Second Circuit (via CourtListener)
  2. United States v. Korchevsky, Nos. 19-197 and 19-780 (2d Cir. July 19, 2021) — U.S. Court of Appeals for the Second Circuit
  3. SEC Litigation Release 23319: 32 defendants charged in a scheme to trade on hacked news releases (August 13, 2015) — U.S. Securities and Exchange Commission
  4. Nine People Charged in Largest Known Computer Hacking and Securities Fraud Scheme (August 11, 2015) — U.S. Attorney's Office, District of New Jersey
  5. SEC Litigation Release 25295: five Russian nationals charged over hacked filing agents (December 22, 2021) — U.S. Securities and Exchange Commission
  6. SEC Litigation Release 21465: judgment against Oleksandr Dorozhko (March 29, 2010) — U.S. Securities and Exchange Commission

Reviewed September 20, 2026. Every statute link points at the primary text. If something here is wrong, tell us — corrections are logged in public.