{
  "id": "case-radchenko-sec-edgar-hack",
  "slug": "us-v-radchenko-sec-edgar-intrusion",
  "title": "U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)",
  "summary": "Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly traded companies before their official release to generate $4.1 million in illegal insider trades.",
  "case_number": "2:19-cr-00040",
  "court": "U.S. District Court for the District of New Jersey",
  "district": "D.N.J.",
  "country": "United States",
  "opened_at": "2019-01-15",
  "status": "fugitive",
  "victim_sector": "Regulatory Agencies, Securities Markets, Public Corporations",
  "victim_country": "United States",
  "loss_amount_usd": 4100000,
  "loss_amount_note": "Generated $4.1 million in illegal trading profits using stolen corporate filings.",
  "first_seen_at": "2016-05-01T00:00:00Z",
  "last_updated_at": "2026-07-05T11:00:00Z",
  "actor_slug": "edgar-hack-syndicate",
  "defendant_slugs": [
    "artem-radchenko"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.",
      "evidence_locator": "Indictment \u00b6 14, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Radchenko",
      "source_url": "https://www.justice.gov/opa/pr/two-ukrainian-nationals-indicted-computer-hacking-and-securities-fraud-scheme",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    }
  ],
  "events": [
    {
      "event_type": "indictment",
      "event_date": "2019-01-15",
      "description": "Grand jury in Newark, New Jersey, indicts Radchenko and Oleksandr Ieremenko for computer fraud and wire fraud."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary breached the target network via Exploit Public-Facing Application. Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.",
    "blast_radius": "Generated $4.1 million in illegal trading profits using stolen corporate filings. Impacted Regulatory Agencies, Securities Markets, Public Corporations infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Initial Access",
        "title": "Initial Perimeter Infiltration",
        "description": "Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.",
        "technical_artifacts": [
          "T1190",
          "Exploit Public-Facing Application"
        ],
        "mitre_technique_id": "T1190"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}