Hack to trade
Hack to trade is obtaining unpublished, market-moving information by breaking into a computer system, such as a newswire, filing agent or law firm, and trading on it before release; it exploits a true signal and injects no false one into the price.
What is hack to trade, and where is the line drawn?
Hack to trade is a two-step scheme. First, someone breaks into a computer system that holds market-moving news before it is published: a newswire, a company’s filing agent, a law firm, a regulator’s filing system. Second, that person, or people they pass the information to, trades on it before the news is released.
The line is drawn by what enters the price. Nothing false does. The earnings figures or merger terms that are eventually published are accurate, and the price moves to where they put it. The traders were simply there first.
That is why this technique sits in the related but distinct section and not with the manipulation techniques. It is not market manipulation. Manipulation falsifies the price signal, as a spoofed order or a wash trade does. Hack to trade exploits a true signal that others cannot yet see.
It is also not insider trading in the classic sense. Insider trading liability turns on a breach of a duty of trust or confidence owed to the source of the information. A hacker owes the newswire no such duty, and neither does a trader who receives what the hacker stole. That gap is what made the legal question hard, and it is the reason this page exists separately.
It is not hijacked-account ramping either: that technique steals control of other people’s accounts to move a price, while this one steals information and leaves the price alone.
How does it work?
The matters in this library follow the same pipeline, though the details differ.
- Break in. An intruder gains access to a system holding unpublished material. In the newswire and SEC filing-system cases the regulators and prosecutors describe stolen log-in credentials and access to areas the intruders were not permitted to see. In the 2021 case the targets were two filing agents that prepare companies’ periodic reports.
- Copy the release. The material taken is typically an earnings announcement, or in the law-firm case confidential merger information in emails, before its scheduled publication.
- Pass it to traders. In the newswire case the SEC alleged the hackers built a secret web location to give traders the stolen releases, in return sometimes for a share of the profits. Prosecutors described “wish lists” in which traders named the releases they wanted.
- Trade in the window. The window can be short. In one 2013 instance described in the SEC’s first complaint release, traders acted in the 36 minutes between a newswire receiving a release and publishing it. Trading was often in stock, options and contracts for difference, which give leveraged exposure to a price move without owning the shares.
- Wait for publication. The owner publishes the news on its normal schedule.
- Close out and share. The traders take the move and sometimes pass part of the profit back to the source.
Why did the law need a court to say it was fraud?
Section 10(b) of the Securities Exchange Act reaches a “manipulative or deceptive device”. A hacker’s trades are not manipulative in the Supreme Court’s sense, because they do not artificially affect market activity. The SEC therefore had to show the conduct was deceptive.
The obstacle was the Supreme Court’s insider trading line of cases, in which silence is deceptive only where a duty to speak exists. A stranger who breaks in has no such duty. In SEC v. Dorozhko the district court held on that basis that hacking was not deceptive without a breach of fiduciary duty.
The Second Circuit disagreed in 2009. It held that the fiduciary-duty requirement in those cases belongs to fraud by silence, and that an affirmative misrepresentation is a different kind of fraud that needs no such duty. It said that misrepresenting one’s identity to reach off-limits information and then stealing it is “plainly deceptive”. It was less sure about a hacker who merely exploits a flaw in code, which it said might be “mere theft”, and it sent the case back to the district court to decide how that hack was done.
Twelve years later, in United States v. Korchevsky, the same court upheld convictions arising from the newswire case. It treated stolen-credential log-ins as deceptive because each one misrepresents the user as authorised, and said the deception need not target investors. It did not decide the pure-exploit question, because the hackers there had used stolen credentials after their initial entry.
The point for readers: the question is settled for hacks that impersonate a user in the Second Circuit. It is not settled everywhere, and not for every method.
What law applies?
| Provision | Citation | Primary text |
|---|---|---|
| Securities Exchange Act — general antifraud | 15 U.S.C. § 78j(b) | Read the text |
| SEC Rule 10b-5 | 17 C.F.R. § 240.10b-5 | Read the text |
| Securities Act — fraudulent interstate transactions | 15 U.S.C. § 77q(a) | Read the text |
| Computer fraud and abuse | 18 U.S.C. § 1030 | Read the text |
| Wire fraud | 18 U.S.C. § 1343 | Read the text |
| Securities and commodities fraud | 18 U.S.C. § 1348 | Read the text |
The SEC’s civil cases in this library charge Section 10(b), Rule 10b-5 and Section 17(a) of the Securities Act. In some matters it also charged defendants under section 20(b) of the Exchange Act, which covers doing through another person what one may not do directly. The parallel criminal cases described in the Justice Department’s releases involved wire fraud conspiracy, securities fraud, computer fraud and money laundering conspiracy counts. Wire fraud does not depend on the section 10(b) deception analysis, and several individuals in the newswire matter pleaded to conspiracy to commit wire fraud.
Which real cases are there?
Which real enforcement actions have alleged hack to trade?
This library holds 13 enforcement actions tagged hack to trade. The table shows the largest by civil penalty together with the most recently filed. Every row links to a page carrying the regulator's own release and, where one was published, the complaint.
| Action | Agency | Filed | Penalty | Status |
|---|---|---|---|---|
| SEC v. Ieremenko et al.: settlements with Cho, Olefir and Capyield (hack to trade, 2020) | SEC | 2020-11-05 | $425k | settled |
| SEC v. Ieremenko et al.: settlements with Kwon and Sabodakha (hack to trade, 2020) | SEC | 2020-04-09 | $149k | settled |
| SEC v. Robert B. Westbrook (hack to trade, 2024) | SEC | 2024-09-27 | — | filed |
| SEC v. Vladislav Kliushin, Nikolai Rumiantcev, Mikhail Irzak, Igor Sladkov, and Ivan Yermakov (hack to trade, 2021) | SEC | 2021-12-22 | — | judgment |
Read the table with care. The library holds 13 records as of 2026-09-20. They span five underlying schemes (newswires, two law firms, the SEC’s EDGAR system, two filing agents, and executives’ email accounts), but for the newswire case they are follow-up announcements, not the opening one: the SEC’s first release of 13 August 2015, against 32 defendants (later 34), is not among them. The count is not a measure of how common the conduct is.
What the record shows.
- Newswires, 2010 to 2015. The SEC alleged two Ukrainian men hacked at least two newswires and stole hundreds of earnings releases over about five years. It alleged traders in several countries used them to make more than $100 million. Prosecutors named Marketwired, PR Newswire and Business Wire as the victims and put the profits at about $30 million. Thirteen defendants had agreed to SEC settlements totalling more than $53 million by November 2016, without admitting or denying the allegations.
- Criminal outcomes. According to the Justice Department and SEC releases, Vitaly Korchevsky and Vladislav Khalupsky were convicted at trial in July 2018. Korchevsky was sentenced to 60 months and Khalupsky to 48. Arkadiy and Igor Dubovoy, Leonid Momotok and Aleksandr Garkusha pleaded guilty to wire fraud conspiracy. Turchynov, Ieremenko and Pavel Dubovoy were charged in the same indictment; the documents read for this page state that arrest warrants were issued in 2015, and do not report a later outcome for them.
- EDGAR, 2016. In 2019 the SEC alleged that Oleksandr Ieremenko obtained non-public test filings from EDGAR and passed the information to traders, who traded ahead of at least 157 earnings releases and made at least $4.1 million. Traders later settled with the SEC.
- Filing agents, 2018 to 2020. In 2021 the SEC alleged that five Russian nationals traded ahead of more than 500 earnings announcements and made at least $82 million. One, Vladislav Kliushin, was convicted at a jury trial, sentenced to nine years in 2023 and later had his sentence commuted, according to the SEC’s 2025 release. The DOJ said in 2023 that the four others remained at large.
What the record does not show. It does not show how many such schemes exist, how many go undetected, or whether the schemes it describes are typical. Every case here was found because the hack or the trading left a trace. Nor does it show how any unresolved matter ended.
How is it detected?
- Trading that clusters in the window between a release reaching its distributor and the public release, repeated across many issuers.
- Accounts whose trading is almost entirely placed just before earnings or deal announcements, with no other visible strategy.
- Sudden first-time, short-dated option positions sized far beyond an account's history, in a name that then announces.
- Trades in the same names placed by accounts in different countries with no stated connection to one another or to the issuers.
- Log-in anomalies at the information holder, such as credentials used from unusual locations, or accounts accessing material they do not normally view.
- Payments passing from traders to third parties with vague descriptions, or third-party access to brokerage accounts.
Two routes appear in the records. One begins at the market: a broker flagged unusual trading in the Dorozhko matter and referred it to the SEC, which then traced the trades to the hack. The other begins at the victim: the newswires cooperated with prosecutors in the newswire case, and the SEC’s own systems were the source of the EDGAR case.
The links between hackers and traders are usually found in communications and payments, since the trading itself looks like a run of well-timed bets.
What penalties have followed?
What penalties does hack to trade actually attract?
The numbers below are computed from this site's own case records at build time, not quoted from a secondary source. They change whenever a new action is added to the library.
- Actions recorded
- 13
- Median penalty
- $287k
- Largest penalty
- $425k
- Criminal parallel
- 85%
- Median sentence
- —
The library’s monetary fields for these records are extracted mechanically and are incomplete for multi-defendant settlements, so treat the totals shown as a floor, not a complete figure. In the newswire case, the SEC said some judgments against individuals convicted criminally were deemed satisfied by criminal restitution and forfeiture orders, so civil and criminal amounts overlap and should not be added together.
What are the red flags?
- An account that trades heavily only in the hours before scheduled announcements, and is right most of the time.
- A large, short-dated options position in an account that has never traded options, placed hours before an earnings release.
- Trading across many unrelated issuers that shares no theme except that each announced results within hours of the trade.
- Money leaving a trading account for unrelated-looking business payments, or someone other than the account holder monitoring the account.
How do the records for hack to trade end?
This describes the 13records in this library tagged hack to trade, not how such cases end in the world. "Settled" is not a finding of guilt. Many records are filings whose outcome this library does not track: 5 of 13 are marked filed or unknown.
| Measure | Records | Value |
|---|---|---|
| Share with a criminal parallel | 13 | 85% (11 of 13) |
| Median civil penalty, where recorded | 2 | Too few records to show |
| Median months from filing to resolution | 6 | 0.0 months |
Frequently asked questions about hack to trade
- Is hack to trade market manipulation?
- No. Manipulation puts a false signal into the price. In hack to trade the news that is eventually published is true and the price moves to where it belongs; the trader simply got there first. The wrong lies in how the information was obtained, which is why this library files it under conduct that is routinely confused with manipulation.
- Is it the same as insider trading?
- It is a close relative but rests on a different theory. Insider trading liability turns on a breach of a duty owed to the source of the information. A hacker or a trader who receives hacked material owes no such duty to the newswire or the issuer, so the case has to be built on deception in how the information was obtained.
- What did SEC v. Dorozhko decide?
- In 2009 the Second Circuit held that a fraud built on an affirmative misrepresentation does not need a breach of fiduciary duty to count as deceptive under section 10(b), and that misrepresenting your identity to get into a system and steal information is plainly deceptive. It left open whether merely exploiting a flaw in code is deceptive, and sent the case back to the district court.
- Does the deception have to be aimed at investors?
- Not according to the Second Circuit in United States v. Korchevsky (2021). It rejected the argument that the deception must target investors, because Rule 10b-5 requires only that the deceptive conduct be in connection with the purchase or sale of a security. The hacking that prompted and enabled the trading met that test.
- Can the recipients of hacked information be liable if they never hacked anything?
- The records in this library say yes. The SEC charged traders who received hacked news releases with the same antifraud provisions as the hackers, and in the 2021 filing-agent case it also charged traders under the provision on acting through another person. Whether an individual is liable turns on what they knew and did, and each matter has its own record.
- Do the profit figures in different documents agree?
- Not always. In the newswire case the SEC alleged more than $100 million in illegal profits, while the Justice Department's announcements describe about $30 million and the Second Circuit refers to more than $18 million from the two defendants it reviewed. The documents describe different defendants, periods and measures, and the figures should not be added or swapped.
- Where does hack to trade differ from hijacked-account ramping?
- Hack to trade steals information and trades on it. Hijacked-account ramping steals control of other people's brokerage accounts and uses the orders they place to move a price. The first exploits a true signal; the second manufactures a false one, so only the second is manipulation.
- Why does this library hold so few hack-to-trade records, and does the count mean anything?
- The library reflects what regulators announced, and partly what has been cached. The 13 records it holds come from five underlying schemes. The count says nothing about how common the conduct is; the opening 2015 newswire announcement is not among them.
What techniques are related to hack to trade?
Terms defined on this page
Sources
- SEC v. Dorozhko, 574 F.3d 42 (2d Cir. 2009) — U.S. Court of Appeals for the Second Circuit (via CourtListener)
- United States v. Korchevsky, Nos. 19-197 and 19-780 (2d Cir. July 19, 2021) — U.S. Court of Appeals for the Second Circuit
- SEC Litigation Release 23319: 32 defendants charged in a scheme to trade on hacked news releases (August 13, 2015) — U.S. Securities and Exchange Commission
- Nine People Charged in Largest Known Computer Hacking and Securities Fraud Scheme (August 11, 2015) — U.S. Attorney's Office, District of New Jersey
- SEC Litigation Release 25295: five Russian nationals charged over hacked filing agents (December 22, 2021) — U.S. Securities and Exchange Commission
- SEC Litigation Release 21465: judgment against Oleksandr Dorozhko (March 29, 2010) — U.S. Securities and Exchange Commission