Hacker-Hedge Funds, Hiding in Plain Sight
Pairing cyber with insider trading is a nasty business, and apparently not always a profitable one.

Earlier this year, Waters published an entire issue dedicated to cyber crime — and with the US government considering sanctions against China for a recent uptick in breaches, the subject is worth revisiting once again.
Reporting in the last month has also shown that a number of hedge fund traders, using illicit means to gain non-public data on listed companies, traded on inside information using contracts-for-difference (CFDs), instruments that would potentially obscure the crime ... or so they thought.
The US Securities and Exchange Commission announced this week the results of an investigation into the matter, with punitive fines (relative to profits) in the millions levied against a number of small hedge funds found to be executing that new classic trick: the hack-and-trade.
I point this out for a couple reasons. First, these weren't bankers or sales traders who are usually in the enforcement crosshairs; nor are the crimes of the typical white-collar, headline-making variety, like the botched SAC Capital insider trading case.
Instead, they're murky hedge funds — several of which possess connections to one of hacking's great meccas, Ukraine.
This year we've heard multiple times that trading algorithms are being hacked and either manipulated or lifted for ransom ... so it's not too difficult to imagine a hacker of that sophistication breaking into a company's files (or its private equity parent's systems) undetected, looking for quarterly performance numbers a day or two early.
Second, Waters has organized a special cyber briefing next week. Investment management representation for this one is strong, with mainstay firms Lazard, Pine River Capital, New York Life, Mackay Shields, and Blackstone all joining us for the discussion. Evidence enough, then, that cyber is an issue on the buy side as much as it is anywhere else in financial services. [Other end-users are still welcome to register if they're interested.]
Raising the Stakes
Why is this particular case important?
Well, to start with, it demonstrates the evolution of cyber — and not just in the sense that investment managers are now aware of it, whether as targets or (these days) participating in it.
For our dedicated issue this spring, I profiled Blackstone CISO Jay Leek, and one of his strongest points was around the changing nature of the threat his firm faces.
It's not an enemy looking to make a political point with a disruption or ruin some hardware, so much as one stealthily trolling around for actionable information.
Indeed, this year we've heard multiple times that trading algorithms are being hacked and either manipulated or lifted for ransom ... so it's not too difficult to imagine a hacker of that sophistication breaking into a company's files (or its private equity parent's systems) undetected, looking for quarterly performance numbers a day or two early.
So far as the CFDs are concerned, the case also illustrates the lengths traders are willing to go in their attempts at masking these crimes.
Insider trading, of course, has long been a securities law violation in search of genuine definition — the SAC case demonstrated that.
But once it is detected, stealing information electronically (as opposed to, say, overhearing a CFO whispering to a colleague) is a fairly black-and-white case. While the hackers had no problem heisting the information, it seems that this time around, sloppiness on the part of hedge fund owners and their method of actually procuring the information broke the investigation open.
Mild Relief ... For Now
The contour of this case will do nothing to dissuade CISOs of the need to modernize their cyber defenses. Hopefully another finance-meets-cyber headline gets their board members' attention. Meanwhile, for those who worry about the regulators' ability to uncover these kinds of crimes, it comes as perhaps is a mild relief.
But ultimately, it leaves me wondering: if these are the lengths bad actors are willing to go — combining not one but two lurid activities in an attempt at securing a windfall, what's next?
To what extent is cyber going to be at the heart of financial crime of all kinds in 2020, and should we be thinking about ways of dealing with it now, rather than waiting for the other shoe to drop?
Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.
To access these options, along with all other subscription benefits, please contact info@waterstechnology.com or view our subscription options here: http://subscriptions.waterstechnology.com/subscribe
You are currently unable to print this content. Please contact info@waterstechnology.com to find out more.
You are currently unable to copy this content. Please contact info@waterstechnology.com to find out more.
Copyright Infopro Digital Limited. All rights reserved.
As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (point 2.4), printing is limited to a single copy.
If you would like to purchase additional rights please email info@waterstechnology.com
Copyright Infopro Digital Limited. All rights reserved.
You may share this content using our article tools. As outlined in our terms and conditions, https://www.infopro-digital.com/terms-and-conditions/subscriptions/ (clause 2.4), an Authorised User may only make one copy of the materials for their own personal use. You must also comply with the restrictions in clause 2.5.
If you would like to purchase additional rights please email info@waterstechnology.com
More on Emerging Technologies
Standard Chartered goes from spectator to player in digital asset game
The bank’s digital assets custody offering is underpinned by an open API and modular infrastructure, allowing it to potentially add a secondary back-end system provider.
Saugata Saha pilots S&P’s way through data interoperability, AI
Saha, who was named president of S&P Global Market Intelligence last year, details how the company is looking at enterprise data and the success of its early investments in AI.
Data partnerships, outsourced trading, developer wins, Studio Ghibli, and more
The Waters Cooler: CME and Google Cloud reach second base, Visible Alpha settles in at S&P, and another overnight trading venue is approved in this week’s news round-up.
Are we really moving on from GenAI already?
Waters Wrap: Agentic AI is becoming an increasingly hot topic, but Anthony says that shouldn’t come at the expense of generative AI.
Cloud infrastructure’s role in agentic AI
The financial services industry’s AI-driven future will require even greater reliance on cloud. A well-architected framework is key, write IBM’s Gautam Kumar and Raja Basu.
Waters Wavelength Ep. 310: SigTech’s Bin Ren
This week, SigTech’s CEO Bin Ren joins Eliot to discuss GenAI’s progress since ChatGPT’s emergence in 2022, agentic AI, and challenges with regulating AI.
Microsoft exec: ‘Generative AI is completely passé. This is the year of agentic AI’
Microsoft’s Symon Garfield said that AI advancements are prompting financial services firms to change their approach to integrating AI-powered solutions.
Inside the company that helped build China’s equity options market
Fintech firm Bachelier Technology on the challenges of creating a trading platform for China’s unique OTC derivatives market.