CASE DOSSIER fugitive

U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack)

Docket: 2:19-cr-00040 Court: U.S. District Court for the District of New Jersey Opened: 2019-01-15 Sector: Regulatory Agencies, Securities Markets, Public Corporations

Key Facts

Status
FUGITIVE
Legal disposition
Loss Amount
$4.1 million
Generated $4.1 million in illegal trading profits using stolen corporate filings.
Techniques
1
Verified mappings
Defendants
1
Named in charges
  • Legal Status: FUGITIVE in U.S. District Court for the District of New Jersey.
  • Primary Target Sector: Regulatory Agencies, Securities Markets, Public Corporations.
  • Documented Financial Loss: $4.1 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Ukrainian cybercriminals who hacked into the SEC EDGAR corporate filing test system, exfiltrating non-public quarterly earnings reports for hundreds of publicly traded companies before their official release to generate $4.1 million in illegal insider trades.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary breached the target network via Exploit Public-Facing Application. Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.

Operational & Financial Fallout

Generated $4.1 million in illegal trading profits using stolen corporate filings. Impacted Regulatory Agencies, Securities Markets, Public Corporations infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: FUGITIVE
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary breached the target network via Exploit Public-Facing Application. Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Initial Access Initial Perimeter Infiltration
MITRE ATT&CK T1190 →

Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports.

Artifacts & Tooling: T1190 Exploit Public-Facing Application
Real-World Blast Radius & Operational Fallout

Generated $4.1 million in illegal trading profits using stolen corporate filings. Impacted Regulatory Agencies, Securities Markets, Public Corporations infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2019-01-15 indictment

Grand jury in Newark, New Jersey, indicts Radchenko and Oleksandr Ieremenko for computer fraud and wire fraud.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Artem Radchenko Ukraine fugitive Pending None Perpetrator of SEC EDGAR test filing system hack for securities insider trading.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1190 Exploit Public-Facing Application
Initial Access
"Radchenko exploited a software vulnerability in the SEC EDGAR test server software to extract unpublished draft 8-K and 10-Q reports." Indictment ¶ 14, Page 8 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Artem Radchenko (SEC EDGAR Insider Trading Hack), No. 2:19-cr-00040 (U.S. District Court for the District of New Jersey 2019), https://cybercaselibrary.com/cases/us-v-radchenko-sec-edgar-intrusion/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/us-v-radchenko-sec-edgar-intrusion" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>