Cybersecurity

Personal info leaked in SEC breach

Shutterstock image: open lock. 

At least two people had their sensitive, personal data exposed when hackers broke into the Securities and Exchange Commission's public-facing financial filing system, known as EDGAR, in 2016. The update was provided in an SEC press release just one week after Chairman Jay Clayton told the Senate Banking Committee that he did not believe any personally identifying information was stolen during the intrusion.

The agency clarified Oct. 2 that a forensic analysis "has now determined that an EDGAR test filing accessed by third parties as a result of that intrusion contained the names, dates of birth and social security numbers of two individuals." According to the release, SEC staff informed Clayton of this latest revelation on Sept. 29, and the agency has not ruled out the possibility of additional disclosures in the future.

"While our review and remediation efforts are ongoing and may take substantial time to complete, I believe it is important to provide new information regarding the scope of the 2016 intrusion and provide an update on the steps we are taking to assess and improve the cybersecurity risk profile of our EDGAR system and of the agency's systems more broadly," Clayton said in a prepared statement.

The SEC provided additional details on the scope of its response to the breach. The agency will split its investigation up into five areas: a formal investigation by the Office of the Inspector General, a separate investigation by agency staff to determine if illicit trading took place as a result of the compromise, a review of ongoing modernization efforts to EDGAR with an increased focus on cybersecurity, a more general review of the agency's cybersecurity profile and an internal investigation into the hack by agency staff.

About the Author

Derek B. Johnson is a former senior staff writer at FCW.

Featured

  • Image: Shutterstock

    COVID, black swans and gray rhinos

    Steven Kelman suggests we should spend more time planning for the known risks on the horizon.

  • IT Modernization
    businessman dragging old computer monitor (Ollyy/Shutterstock.com)

    Pro-bono technologists look to help cash-strapped states struggling with legacy systems

    As COVID-19 exposed vulnerabilities in state and local government IT systems, the newly formed U.S. Digital Response stepped in to help.

Stay Connected