U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)
Key Facts
- Legal Status: FUGITIVE in U.S. District Court for the District of New Jersey.
- Primary Target Sector: Regulatory Agencies, Securities Markets, Public Corporations.
- Documented Financial Loss: $4.1 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary breached the target network via Exploit Public-Facing Application. Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.
Operational & Financial Fallout
Generated $4.1 million in illegal trading profits using stolen corporate filings. Impacted Regulatory Agencies, Securities Markets, Public Corporations infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary breached the target network via Exploit Public-Facing Application. Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.
Adversary Kill Chain Flow
1 Documented PhasesRadchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.
Generated $4.1 million in illegal trading profits using stolen corporate filings. Impacted Regulatory Agencies, Securities Markets, Public Corporations infrastructure and associated victim operations.
Procedural & Incident Timeline
Grand jury in Newark, New Jersey, indicts Radchenko and Oleksandr Ieremenko for computer fraud and wire fraud.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Artem Radchenko | Ukraine | fugitive | Pending | None | Perpetrator of SEC EDGAR test filing system hack for securities insider trading. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports." | Indictment ¶ 14, Page 8 | reviewed |