• About
    • Site Profile
    • Pam Agnew, ABC (editor)
    • Dominic Jones (editor)
    • Richard Ketchen (contributor)
    • Ezra Marbach (contributor)
    • Vanessa Schoenthaler (contributor)
  • Contacts
  • Advertise
  • Premium Services
IR Web Report
  • Latest Posts
  • Categories
    • Web Disclosure
    • Annual Reports
    • Quarterly Reporting
    • Presentations
    • Social Media
    • IR Law
    • Governance
    • Shareholder Services
    • Video
    • Mobile
  • Book Store
  • Jobs
  • Vendor Directory
Browse: Home / Bloomberg grabs NetApp’s earnings early, second case in a week

Bloomberg grabs NetApp’s earnings early, second case in a week

By Dominic Jones on November 18, 2010

  • Tweet

NETAPP Inc. (NASDAQ:NTAP) has become the second company in less than a week to have earnings information leaked from an unsecured area of its corporate website.

Bloomberg confirmed to Dow Jones that it retrieved unpublished financial data from the company’s website more than an hour before its scheduled release.

NASDAQ officials halted NetApp’s stock at 3:11 pm ET after the stock had dropped 6.5% on the leaked news, which hit trading desks around 2:45 pm ET.

The storage and data management company hurriedly issued its earnings release via Market Wire at 3:31 pm and filed the same information in an 8-K on EDGAR at 3:34 pm.

The company, based in Sunnyvale, CA,  told Dow Jones that someone had obtained financial tables that it attaches to its earnings releases from “a restricted area of the company’s website.”

However, a Bloomberg spokesperson said they found NetApp’s financial tables posted on the company’s website without any required password or firewall and that the company had failed to respond to multiple calls to verify the information before the story was published.

Same slack practices as Disney

As we first reported Nov. 12 when The Walt Disney Company’s (NYSE:DIS) earnings release was leaked from its website, Bloomberg uses a sophisticated software program called a spider to crawl key websites for news.

The software is similar to the search software that Google and other search engines use to crawl the web. There is nothing illegal of underhanded in what Bloomberg is doing. Its software can only access information that is publicly accessible.

And as with Disney, it looks to us that NetApp’s own slack security measures and predictable document naming practices allowed either a Bloomberg reporter or their search bot to access the PDF document containing NetApp’s financial statements, which were uploaded to the company’s server in preparation for publishing its earnings release after regular market hours.

URL of pending PDF financials easy to guess

According to the PDF metadata, someone at NetApp yesterday created the PDF of its financial tables at 2:08 pm ET from an Excel spreadsheet. This file was named  financial-fy11-q2.pdf and uploaded to an unsecured folder on NetApp’s self-hosted website.

While the PDF document was not linked to any public page on NetApp’s website, anyone with knowledge of NetApp’s prior news release naming and posting practices could have easily guessed the file’s URL.

Here is a list of the URLs for NetApp’s financial statements for the past few quarters:

  • http://media.netapp.com/documents/financial-fy11-q2.pdf
  • http://media.netapp.com/documents/financial-q1-fy11.pdf
  • http://media.netapp.com/documents/financial-10-q4.pdf
  • http://media.netapp.com/documents/financial-q3-10.pdf
  • http://media.netapp.com/documents/q2-10-financialb.pdf

While they are not all exactly the same, a reporter or a search bot wouldn’t have to try too many permutations to predict the URL of yesterday’s file. This is exactly the same thing that tripped up Disney last week.

In essence, Bloomberg merely stumbled across the document by typing in a few different URLs. It didn’t hack the server or steal the information.

Companies have obligation to safeguard info

It is every public company’s obligation to secure material disclosure documents prior to making the information public. This is cheap and easy to do and often is a standard feature in off-the-shelf web content management software.

That two companies should be caught out like this in a week raises serious questions about companies’ disclosure controls and web security.  Unfortunately, IR departments and their executives almost universally pay little attention to their websites. Situations like this are a consequence of that neglect.

Hopefully, these incidents will prompt IR leaders, executives and directors to conduct audits of their website infrastructure and publishing procedures.

(Hat tip to Mike O’Brien)


Dominic Jones

Dominic (bio & disclosures) is IR Web Report‘s founder and an online investor relations consultant. He advises leading public companies and investor relations service providers worldwide on using the web for disclosure, engagement and profile building. You can contact him via the contacts page.

Posted in Issues, Online IR | Tagged Bloomberg, Disclosure, Disclosure leaks, Quarterly Reporting, security breaches | 7 Responses

  • http://blogs.dix-eaton.com/streettalk/ Rob Berick

    Another day, another slip… at the very least, it’s (another) reminder that IR departments need to look before they leap into web disclosure protocols as nothing’s risk free.

  • Pingback: In Defense of IR Departments « InsuranceIR's Blog

  • http://irwebreport.com Dominic Jones

    Rob,

    Neither Disney nor NetApp were trying to do web disclosure. If they had, they likely would have looked at the SEC’s guidance, assessed their websites’ ability to meet the requirements, and then realized they needed improvements.

    Securing unpublished content isn’t rocket science or expensive. I do it here every day, on a free blog CMS and a budget of $0. What’s wrong with these companies?

  • Pingback: 5 things that make BASF’s online IR great | IR Web Report

  • Pingback: Meet the company that broke Microsoft’s earnings 70 minutes early | IR Web Report

  • Pingback: Disclosure leaks: Can companies take legal action? | IR Web Report

  • Pingback: Reuters leaks FirstRand’s earnings, web firm in spotlight | IR Web Report

« Previous Next »

Search the Site

About IR Web Report

Founded in 2001, we are the world's leading source of information about online investor relations communications. Our core philosophy is that investors' needs must come first or companies' online communications efforts will fail to be effective. More about us

Get Our Free Email Newsletter

Close
Note: We don't sell or rent our email list. Unsubscribe instructions come with each email.

Latest Stories

  • This week in Investor Relations
  • This week in Investor Relations
  • This week in Investor Relations
  • This week in Investor Relations
  • This week in Investor Relations
Investor relations jobs by IR Web Report
Visit the IR services directory

  • Morningstar Investor Relations Services
  • Pristine Advisers
  • b2i Technologies, Inc.
  • InsuranceIR LLC

Full Disclosure

All articles on IR Web Report are unpaid editorial. We do not charge a fee to outside contributors. Sponsors or advertisers are not automatically entitled to become contributors or receive editorial coverage. We accept contributors based on their individual expertise and experience. Contributors are required to disclose when they write about or refer to any company with which they have a business relationship, either directly or indirectly. If you believe that any contributor or IR Web Report is not living up this policy, please contact us or leave a comment on the relevant post. Editorial integrity is important to us and we take all complaints seriously.

Site Map

  • Home
  • Terms of Use
  • Be visible on IR Web Report
  • Investis Online IR Rankings
  • About the Rankings
  • IR Web Report’s Book Store
  • IR News
  • About
  • Contacts

Archives

  • 2012
  • 2011
  • 2010
  • 2009
  • 2008
  • 2007
  • 2006
  • 2005
  • 2004
  • 2003
  • 2002
  • 2001

About IR Web Report

Founded in 2001, we are the world's leading source of information about online investor relations communications. Our core philosophy is that investors' needs must come first or companies' online communications efforts will fail to be effective. More about us


Follow @irwebreport
Feed Subscribe to feed

Copyright © 2001 - 2012 IR Web Reporting International Inc. By using this site you agree to the Terms of Use and our Privacy Policy.