• About
    • Site Profile
    • Pam Agnew, ABC (editor)
    • Dominic Jones (editor)
    • Richard Ketchen (contributor)
    • Ezra Marbach (contributor)
    • Vanessa Schoenthaler (contributor)
  • Contacts
  • Advertise
  • Premium Services
IR Web Report
  • Latest Posts
  • Categories
    • Web Disclosure
    • Annual Reports
    • Quarterly Reporting
    • Presentations
    • Social Media
    • IR Law
    • Governance
    • Shareholder Services
    • Video
    • Mobile
  • Book Store
  • Jobs
  • Vendor Directory
Browse: Home / NASDAQ hack has “state sponsorship” hallmarks: expert

NASDAQ hack has “state sponsorship” hallmarks: expert

By Dominic Jones on February 7, 2011

  • Tweet

A RECOGNIZED authority on cyber security says the hacking activity against NASDAQ OMX’s Directors Desk board portal, used by 10,000 directors and many Fortune 500 companies, has hallmarks of state-sponsored corporate espionage.

directorsdesk2NASDAQ OMX confirmed in a statement on Saturday that it had discovered “suspicious files” on the US servers of its Directors Desk board portal, used by directors and management to share sensitive company documents online. The exchange said that “at this stage” there was no evidence that the hackers had obtained any of its clients’ information.

The exchange company was forced to issue the statement and begin informing clients about the security breach after the Wall Street Journal reported late Friday night that the case had been reported to White House officials and was being investigated by the FBI, the Secret Service, the US Department of Justice, the US Securities and Exchange Commission, the Department of Homeland Security and leading cyber security experts.

Investigation began “more than a year ago”

Initial media reports portrayed the threat as a potential attack on the exchange’s trading systems and therefore a matter of national security, but Directors Desk is an altogether separate product from the exchange’s trading engine.

However, the nature of the information stored on Directors Desk – confidential corporate financial and strategy information shared with board directors  – makes the incident potentially extremely serious and helps explain the high level interest in the case and the large number of agencies involved in the investigation.

It also emerged last night that investigations into the hacking have been ongoing for longer than first disclosed. The Wall Street Journal reported that the Secret Service began its investigation more than a year ago, but the investigation ramped up after NASDAQ OMX reported finding malware on its servers in October or November.

It’s not clear if NASDAQ OMX has ever notified Directors Desk clients of potential security threats prior to doing so on Saturday. It’s likely that the current revelations will undermine companies’ confidence in using board portals.

State-Sponsorship, Advanced Persistent Threat

Jeffrey Carr, CEO of cyber security firm Taia Global and author of the 2009 book Inside Cyber Warfare, said in a post on Forbes.com that the length of time involved in the hacking activity “strongly suggests State-sponsorship because it takes skill to continually persist within a network for that long and skill costs money.”

jeffrey carr

Jeffrey Carr

He says the nature of the threat falls within the scope of an Advanced Persistent Threat (APT) attack, a term often used to describe deliberate and sustained attacks by paid state-sponsored operatives who have advanced skills. And he says the Directors Desk security measures are inadequate against such an attack.

“The security measures advertised on the Directors Desk website like compliance with ISO27001, firewalls, IDS, and strong passwords are useless against APT because attacks are specifically designed to bypass everything that the target has put in place; even encryption,” Carr writes, adding that an “entirely different security posture is needed” considering the rich pool of business intelligence available on Directors Desk.

“If it hasn’t already done so, NASDAQ needs to consult with security experts who understand and work APT attacks as soon as possible. If you’re a Directors Desk LLC customer, you should probably do the same,” writes Carr, who also revealed that Directors Desk LLC settled a deceptive practices case brought by the Federal Trade Commission in 2009, after it was acquired by NASDAQ OMX in 2007.

The Wall Street Journal and AOL Daily Finance speculated last night that the New York Stock Exchange’s egovdirect.com service had been taken offline in connection with the incident at NASDAQ.

However, that seems unlikely since the NYSE’s service is not a board portal and is used by companies primarily to file corporate governance information with the exchange and to compare their governance practices with those of peers.

In a press release last August, NASDAQ OMX said Directors Desk serves “more than 10,000 directors representing more than 230 organizations worldwide, including many Fortune 500 companies.”


Dominic Jones

Dominic (bio & disclosures) is IR Web Report‘s founder and an online investor relations consultant. He advises leading public companies and investor relations service providers worldwide on using the web for disclosure, engagement and profile building. You can contact him via the contacts page.

Posted in Corporate Governance, IR News | Tagged board communications, board portals, corporate governance | Leave a response

« Previous Next »

Search the Site

About IR Web Report

Founded in 2001, we are the world's leading source of information about online investor relations communications. Our core philosophy is that investors' needs must come first or companies' online communications efforts will fail to be effective. More about us

Get Our Free Email Newsletter

Close
Note: We don't sell or rent our email list. Unsubscribe instructions come with each email.

Latest Stories

  • This week in Investor Relations
  • This week in Investor Relations
  • This week in Investor Relations
  • This week in Investor Relations
  • This week in Investor Relations
Investor relations jobs by IR Web Report
Visit the IR services directory

  • African Is Cool online IR
  • Pristine Advisers
  • InsuranceIR LLC
  • Morningstar Investor Relations Services

Full Disclosure

All articles on IR Web Report are unpaid editorial. We do not charge a fee to outside contributors. Sponsors or advertisers are not automatically entitled to become contributors or receive editorial coverage. We accept contributors based on their individual expertise and experience. Contributors are required to disclose when they write about or refer to any company with which they have a business relationship, either directly or indirectly. If you believe that any contributor or IR Web Report is not living up this policy, please contact us or leave a comment on the relevant post. Editorial integrity is important to us and we take all complaints seriously.

Site Map

  • Home
  • Terms of Use
  • Be visible on IR Web Report
  • Investis Online IR Rankings
  • About the Rankings
  • IR Web Report’s Book Store
  • IR News
  • About
  • Contacts

Archives

  • 2012
  • 2011
  • 2010
  • 2009
  • 2008
  • 2007
  • 2006
  • 2005
  • 2004
  • 2003
  • 2002
  • 2001

About IR Web Report

Founded in 2001, we are the world's leading source of information about online investor relations communications. Our core philosophy is that investors' needs must come first or companies' online communications efforts will fail to be effective. More about us


Follow @irwebreport
Feed Subscribe to feed

Copyright © 2001 - 2012 IR Web Reporting International Inc. By using this site you agree to the Terms of Use and our Privacy Policy.