Hack to trade: press releases stolen before they were published
Nothing false is said to the market in a hack-to-trade case, so it is not manipulation. That is exactly why courts had to decide what "deceptive" means in section 10(b). In 2009 the Second Circuit held in SEC v. Dorozhko that impersonating a user to steal information is plainly deceptive, with no breach of duty needed; in 2021 it applied that to stolen log-ins at newswires.
On 17 October 2007, an anonymous hacker tried to get into a secure server at Thomson Financial, which hosted the earnings release of IMS Health, at 8:06 in the morning. At 2:15 in the afternoon, minutes after Thomson received the data, the hacker found it and downloaded it. At 2:52 a trader who had never used his brokerage account before began buying put options on IMS. The company published at 4:33. The next morning the stock fell about 28 per cent and, within six minutes of the open, he had sold everything.
Those are the facts as the Second Circuit recited them in SEC v. Dorozhko. The SEC alleged the trader was the hacker. What the SEC did not allege is the interesting part: it did not argue that he had broken any duty to Thomson or to IMS. He was a stranger to both.
That single fact turned a plain theft into a question about the meaning of a word in the securities statute. This post follows that question through the cases in this library, and tests a simple claim: because nothing false is ever said to the market, hack to trade is not market manipulation, but for the same reason it forced a court to decide what counts as deception.
Why is it not manipulation?
Manipulation puts a false picture into the price. A spoofed order signals demand that is not there. Hack to trade signals nothing. The releases the traders were reading were genuine. When they came out the market reacted to them, and the price moved to where accurate news put it. The traders did not distort that price; they got to it first.
The technique page sets out the boundaries in full. The short version is that this is a wrong done to the holder of the information and to the fairness of the race, and not a falsification of the market’s message.
What did the schemes look like?
The largest in this library concerned newswires. In August 2015 the SEC charged 32 defendants, later 34, in a scheme it alleged had run for five years. Two men in Ukraine, it said, hacked at least two newswire services and stole hundreds of earnings announcements before release. It said they passed them to traders in Russia, Ukraine, Malta, Cyprus, France and three US states, and sometimes took a share of the profits.
The Justice Department’s parallel announcement named three victims: Marketwired, PR Newswire and Business Wire. It described about 150,000 press releases taken from the newswires’ servers, with intrusions between February 2010 and August 2015, and trading ahead of more than 800 of them. The SEC’s first release gives one example. On 1 May 2013, it said, traders had 36 minutes between a newswire receiving an announcement that a company was cutting its forecasts and publishing it. Ten minutes after the company sent the release, it alleged, they began selling the stock short, and made $511,000 when the price fell.
Prosecutors described how the traders gave the hackers “wish lists” of releases they wanted, and how trading tended to follow. The SEC’s first release adds that traders sometimes gave the hackers access to their brokerage accounts so they could check they were being paid.
The technique has moved between targets. The library also holds an alleged hack of law-firm networks (2016), the SEC’s own EDGAR filing system (2019), filing agents that prepare companies’ quarterly reports (2021) and, in 2024, a UK national accused of resetting passwords on executives’ email accounts to read results before they were published.
What did the court decide?
Section 10(b) prohibits a “manipulative or deceptive device”. The district judge in Dorozhko held that hacking was not deceptive unless it involved a breach of fiduciary duty, since the Supreme Court’s insider trading cases treated silence as deceptive only where a duty to speak existed. Dorozhko had no such duty, so the judge refused the SEC’s request for a preliminary injunction.
The Second Circuit disagreed on 22 July 2009. Its reasoning was that in those Supreme Court cases the fraud was silence, and silence needs a duty; the SEC’s theory was an affirmative misrepresentation, and a misrepresentation is fraudulent without one. It wrote that misrepresenting one’s identity to reach information that is off limits, and then stealing it, is “plainly deceptive”.
Two limits are worth stating. The court was not sure that exploiting a weakness in code, with no false identity, is deception rather than “mere theft”. And it did not decide whether Dorozhko’s own hack involved a misrepresentation. It sent that to the district court. The SEC later obtained summary judgment against him, on 24 March 2010, with about $580,000 ordered in disgorgement, interest and penalty, according to its release.
Did it hold up in the newswire cases?
Twelve years later, in July 2021, the Second Circuit affirmed the convictions of Vitaly Korchevsky and Vladislav Khalupsky in the newswire case. Korchevsky argued that the deception had not been aimed at investors and that hacking is not deceptive. The court rejected the first point because Rule 10b-5 requires only that the deception be in connection with a securities purchase or sale, and the hacking had prompted and enabled the trading.
On the second point the court set aside how the hackers first got into Marketwired, by a method called SQL injection, because they afterwards used stolen employee log-ins. Each such log-in, the court said, misrepresented the hacker as an authorised user. Korchevsky had abandoned his challenge to the count involving spear phishing.
So the settled position, in that circuit, is that impersonation is deception. The pure exploit remains an open question.
Many defendants never had to test any of this. Igor and Arkadiy Dubovoy, Aleksandr Garkusha and Leonid Momotok pleaded guilty to conspiracy to commit wire fraud, a crime that does not rest on section 10(b)‘s deception requirement. The SEC settlements described in this post were entered without admitting or denying the allegations.
What happened to the people charged?
The documents read for this post say the following, and nothing more.
- Korchevsky and Khalupsky: convicted by a jury in July 2018. Khalupsky was sentenced to 48 months in January 2019, and Korchevsky to 60 months in March 2019, with $14.4 million in forfeiture and a $250,000 fine.
- Arkadiy and Igor Dubovoy, Garkusha, Momotok: pleaded guilty. By June 2020 the SEC said Momotok, Garkusha and Khalupsky had been sentenced, and that the two Dubovoys were awaiting sentence. This post reports no later outcome.
- Vadym Iermolovych, a Ukrainian hacker charged separately, pleaded guilty and was sentenced to 30 months in 2017, according to the DOJ.
- Turchynov, Ieremenko and Pavel Dubovoy: indicted in 2015. The 2015 announcement said they remained in Ukraine and that international warrants had been issued. Ieremenko was charged again in 2019 in the EDGAR case. The documents read do not report a later outcome for the criminal charges.
- Vladislav Kliushin (Klyushin): convicted in February 2023 and sentenced to nine years in September 2023. The SEC says his sentence was commuted to time served in July 2024, and that the court entered final judgment against him on 22 May 2025. The DOJ said in 2023 that Ivan Ermakov, Rumiantcev, Irzak and Sladkov remained at large.
The SEC’s action against the nine traders filed in February 2016 is in the library as filed. The record read for this post does not report how it ended. In the law-firm case, the SEC obtained default judgments in May 2017 against Iat Hong, Bo Zheng and Hung Chin, and against Hong’s mother as a relief defendant.
What do the numbers show?
The first thirteen settling defendants agreed to more than $53 million. The SEC said some judgments against the individuals convicted criminally were deemed satisfied by criminal restitution and forfeiture, so the civil and criminal sums overlap.
The profit figures disagree, and the disagreement is instructive. For the newswire case the SEC alleged more than $100 million; the DOJ described about $30 million; the Second Circuit spoke of more than $18 million for the two men whose convictions it reviewed. Different defendants, periods and measures are involved. The figures should not be added or substituted for one another.
What the record does not show
This library holds 13 records for hack to trade as of 2026-09-20. They cover five schemes: the newswires (six records), the SEC’s EDGAR system (three), two law firms (two), two filing agents (one) and executives’ email accounts (one). The SEC’s opening newswire announcement of August 2015 is not among them, and the Zavodchiko record is filed but not resolved in the documents read.
The count says nothing about how many such schemes exist or how many went undetected, or how common they are today. Every case here surfaced because someone saw the trading or the intrusion. For how this differs from stealing control of accounts to push a price, see hijacked-account ramping; for the duty-based version of the same trading, see insider trading.