Nasdaq investigation reveals lax cyber security

 

Exchange operator an easy target for hackers, FBI finds.

A federal investigation into last year's cyber attack on US exchange operator Nasdaq OMX found surprisingly lax security practices that made it an easy target for hackers, people with knowledge of the probe said.

The sources did not want to be identified because the matter is classified.

The ongoing probe by the Federal Bureau of Investigation is focused on Nasdaq's Directors Desk collaboration software for corporate boards, where the breach occurred.

The web-based software is used by directors to share confidential information and to collaborate on projects.

Investigators found that Nasdaq's basic computer architecture was sound, which kept its trading systems safe from the hackers, according to four people who were briefed on the FBI probe or had knowledge of Nasdaq's efforts to improve its security with the help of external consultants.

The sources, however, said the investigators were surprised to find some computers with out-of-date software, misconfigured firewalls and uninstalled security patches that could have fixed known "bugs" that hackers could exploit.

Versions of Microsoft Corp's Windows 2003 Server operating system, for example, had not been properly updated.

While Nasdaq is not the first company to allow software updates to lapse inadvertently, investigators were surprised that the exchange operator was not more vigilant about what the industry calls "cyber hygiene" given its importance to financial systems.

"This was easy pickings," said one person familiar with Nasdaq's security practices. "You would have thought they would be like a cyber Fort Knox, but that wasn't the case at all."

Nasdaq defended its security practices and said no data was compromised by the cyber attack, which was detected in October 2010.

Carl-Magnus Hallberg, senior vice president of information technology services for Nasdaq OMX, told Reuters it was unfair to conclude that security practices were lax simply because the Directors Desk program was breached.

He said it would have been virtually impossible to defend against the hackers who used malware that had not been disclosed.

"This was a sophisticated attack," Hallberg said. He declined to comment further on the specifics of the investigation, saying his company does not publicly discuss details of its security practices.

Broader concerns

The Nasdaq attack has sparked concerns about the severity of the threat facing the financial industry and the need for enhanced security at many companies.

Nasdaq's software is used by the Australian Stock Exchange and Singapore's exchange but there was no indication that last year's hack affected the trading platform or software used by the ASX or other exchanges.

Computer security is uneven across industry and many companies, even in the defense sector, are unaware of malware lurking in their networks, cyber experts say.

Sources said the malware found in Nasdaq's network was complex and insidious, but tougher security measures and more vigilance could have helped the company detect the intrusion more quickly.

While declining to comment on that claim, Nasdaq said it invests heavily in network security and has about 1,000 people working on information technology issues worldwide.

Officials at the FBI and the National Security Agency, which is also involved in the investigation, declined comment.

It was not clear how long the malicious software was present on Nasdaq's network before it was found.

Hallberg said Nasdaq detected the breach, took action to mitigate it and notified federal authorities, who are still investigating. Nasdaq also shared the electronic signatures it identified from the attack with other companies to help them avert similar attacks, Hallberg said.

Nasdaq has about 10 companies advising it on security issues, including a major U.S. defence contractor, he added.

Nasdaq disclosed in February the cyber attack on Directors Desk, a service the company sells to corporate boards. Nasdaq bought the privately held Washington-based company in 2007.

Hallberg said Nasdaq was working closely with other companies and government agencies around the world to increase data-sharing on security threats.

He said the company's security systems were heavily regulated in every country where it operates, and especially in the United States, where the Securities and Exchange Commission conducts four audits per year. Any concerns identified through such audits were dealt with immediately, he said.

(Additional reporting by Jonathan Spicer and Basil Katz in New York. Editing by Tiffany Wu)

Copyright Reuters Copyright Reuters. Click for restrictions.



Nasdaq investigation reveals lax cyber security
 
 
 
 
Top Stories
Project management lessons from the QLD Health payroll inquiry
Analysis: How not to run a major IT project.
 
Review: Asus Fonepad
Calling on the Big Phone.
 
Photos: Highlights from SAP Sapphire Now 2013
All the keynote action from one of the world's biggest SAP events.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Bankwest builds continuous delivery capability
Bankwest builds continuous delivery capability
To automatically deploy test/dev sandboxes by mid-year.
Veterans' Affairs sets sights on modernisation
Veterans' Affairs sets sights on modernisation
Data safe with Human Services, CIO says.
Citi Australia drops platform customisations
Citi Australia drops platform customisations
Technology chief shifts focus from building to leveraging systems.
VicRoads restructures IT team
VicRoads restructures IT team
Department moves to align with industry benchmarks.
Zurich Australia extends IT team offshore
Zurich Australia extends IT team offshore
Malaysian staff served from Australian data centres.
Leigh Berrell - Utilities CIO of the Year
Leigh Berrell - Utilities CIO of the Year
Yarra Valley Water CIO Leigh Berrell accepts his Benchmark Award for Utilities CIO of the Year.
Wayne McMahon - Retail CIO of the Year
Wayne McMahon - Retail CIO of the Year
Domino's Pizza CIO Wayne McMahon accepts his Benchmark Award for Retail CIO of the Year.
Inside Perpetual's ongoing IT transformation
Inside Perpetual's ongoing IT transformation
CIO Jenny Levy discusses how outsourcing will help the firm "simplify, refocus and grow".
Managing Complexity - Defence's Daniel McCabe
Managing Complexity - Defence's Daniel McCabe
Daniel McCabe, Assistant Secretary of Australia's Department of Defence, provides the audience at the iTnews Data Centre Strategy Summit with a deep dive into the organisation's data centre consolidation program.
How Facebook designed the data centre from scratch - Marco Magarelli
How Facebook designed the data centre from scratch - Marco Magarelli
The full keynote by Facebook data centre architect Marco Magarelli at the Australian Data Centre Strategy Summit. Magarelli details the design considerations behind the social network's Prineville, Oregon; North Carolina and Luleå, Sweden data centres.
Modernising Legacy Data Centres - Telstra's Jon Curry
Modernising Legacy Data Centres - Telstra's Jon Curry
Telstra general manager of managed data centres Jon Curry guides the audience at the iTnews Australian Data Centre Summit through the build of the telco's Clayton, Victoria data centre.
NSW Government launches NABERS data centre rating tools
NSW Government launches NABERS data centre rating tools
Matthew Clark from the NSW Department of Environment guides facilties managers through the details of the new NABERS data centre energy rating tool at the Australian Data Centre Strategy Summit.
NABERS launch panel: Australian Data Centre Strategy Summit
NABERS launch panel: Australian Data Centre Strategy Summit
Matthew Clark (NSW Dept of Environment), Greg Boorer (Canberra Data Centres), Glenn Allan (National Australia Bank), Mike Andrea (Strategic Directions) and Bob Sharon (Green Global Consulting) discuss the impact of the NABERS data centre rating.
Judges notes: Fortescue Metals [The Benchmark Awards]
Judges notes: Fortescue Metals [The Benchmark Awards]
iTnews' panel of judges discuss Fortescue Metals 'New World of Work" project, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Retail [The Benchmark Awards]
Judges notes: Retail [The Benchmark Awards]
iTnews' panel of judges discuss the shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: Pacific Aluminium [The Benchmark Awards]
Judges notes: Pacific Aluminium [The Benchmark Awards]
iTnews' panel of judges discuss Pacific Aluminium's lightning fast service desk refresh, one of three shortlisted finalists for the Industrials category of the CIO Benchmark Awards.
Judges notes: Domino's Pizza [The Benchmark Awards]
Judges notes: Domino's Pizza [The Benchmark Awards]
iTnews' panel of judges discuss Domino's Pizza's shift to hosted services, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: McDonald's Australia [The Benchmark Awards]
Judges notes: McDonald's Australia [The Benchmark Awards]
iTnews' panel of judges discuss McDonald's Australia's new self-service portal for employees, one of three shortlisted finalists for the Retail category of the CIO Benchmark Awards.
Judges notes: ING Direct [The Benchmark Awards]
Judges notes: ING Direct [The Benchmark Awards]
iTnews' panel of judges discuss ING Direct's 'Bank in a Box', one of three shortlisted finalists for the banking and finance category of the CIO Benchmark Awards.
Judges notes: Yarra Valley Water [The Benchmark Awards]
Judges notes: Yarra Valley Water [The Benchmark Awards]
iTnews' panel of judges discuss Yarra Valley Water's insourcing project, one of three shortlisted finalists for the Utilities category of the CIO Benchmark Awards.
Latest Comments
Polls
Do you prefer the Coalition's NBN policy?

   |   View results
Yes
  19%
 
No
  81%
TOTAL VOTES: 1638

Vote