iTnews
  • Home
  • News
  • Technology
  • Security

Nasdaq investigation reveals lax cyber security

By Andrea Shalal-Esa and Jim Finkle
Nov 21 2011 11:00AM
Follow google news

Exchange operator an easy target for hackers, FBI finds.

A federal investigation into last year's cyber attack on US exchange operator Nasdaq OMX found surprisingly lax security practices that made it an easy target for hackers, people with knowledge of the probe said.

Nasdaq investigation reveals lax cyber security

The sources did not want to be identified because the matter is classified.

The ongoing probe by the Federal Bureau of Investigation is focused on Nasdaq's Directors Desk collaboration software for corporate boards, where the breach occurred.

The web-based software is used by directors to share confidential information and to collaborate on projects.

Investigators found that Nasdaq's basic computer architecture was sound, which kept its trading systems safe from the hackers, according to four people who were briefed on the FBI probe or had knowledge of Nasdaq's efforts to improve its security with the help of external consultants.

The sources, however, said the investigators were surprised to find some computers with out-of-date software, misconfigured firewalls and uninstalled security patches that could have fixed known "bugs" that hackers could exploit.

Versions of Microsoft Corp's Windows 2003 Server operating system, for example, had not been properly updated.

While Nasdaq is not the first company to allow software updates to lapse inadvertently, investigators were surprised that the exchange operator was not more vigilant about what the industry calls "cyber hygiene" given its importance to financial systems.

"This was easy pickings," said one person familiar with Nasdaq's security practices. "You would have thought they would be like a cyber Fort Knox, but that wasn't the case at all."

Nasdaq defended its security practices and said no data was compromised by the cyber attack, which was detected in October 2010.

Carl-Magnus Hallberg, senior vice president of information technology services for Nasdaq OMX, told Reuters it was unfair to conclude that security practices were lax simply because the Directors Desk program was breached.

He said it would have been virtually impossible to defend against the hackers who used malware that had not been disclosed.

"This was a sophisticated attack," Hallberg said. He declined to comment further on the specifics of the investigation, saying his company does not publicly discuss details of its security practices.

Broader concerns

The Nasdaq attack has sparked concerns about the severity of the threat facing the financial industry and the need for enhanced security at many companies.

Nasdaq's software is used by the Australian Stock Exchange and Singapore's exchange but there was no indication that last year's hack affected the trading platform or software used by the ASX or other exchanges.

Computer security is uneven across industry and many companies, even in the defense sector, are unaware of malware lurking in their networks, cyber experts say.

Sources said the malware found in Nasdaq's network was complex and insidious, but tougher security measures and more vigilance could have helped the company detect the intrusion more quickly.

While declining to comment on that claim, Nasdaq said it invests heavily in network security and has about 1,000 people working on information technology issues worldwide.

Officials at the FBI and the National Security Agency, which is also involved in the investigation, declined comment.

It was not clear how long the malicious software was present on Nasdaq's network before it was found.

Hallberg said Nasdaq detected the breach, took action to mitigate it and notified federal authorities, who are still investigating. Nasdaq also shared the electronic signatures it identified from the attack with other companies to help them avert similar attacks, Hallberg said.

Nasdaq has about 10 companies advising it on security issues, including a major U.S. defence contractor, he added.

Nasdaq disclosed in February the cyber attack on Directors Desk, a service the company sells to corporate boards. Nasdaq bought the privately held Washington-based company in 2007.

Hallberg said Nasdaq was working closely with other companies and government agencies around the world to increase data-sharing on security threats.

He said the company's security systems were heavily regulated in every country where it operates, and especially in the United States, where the Securities and Exchange Commission conducts four audits per year. Any concerns identified through such audits were dealt with immediately, he said.

(Additional reporting by Jonathan Spicer and Basil Katz in New York. Editing by Tiffany Wu)

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright Reuters
© 2019 Thomson Reuters. Click for Restrictions.
Tags:
financehacknasdaqsecurity

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

Scalable AI solutions: secure delivery
Scalable AI solutions: secure delivery
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.