Call it ultra-insider trading, perhaps – a group of hackers has been infiltrating the email of more than 100 companies, most of which in the biotech and healthcare arenas, to siphon off information that could impact the global financial markets.
The New York Times reports:
The group’s activities, detailed in a report released Monday morning by FireEye, the Silicon Valley security company, shed light on a new breed of criminals intent on using their hacking skills to gain a market edge in the pharmaceutical industry, where news of clinical trials, regulatory decisions or safety or legal issues can affect a company’s stock price.
Though FireEye won’t disclose which companies have been impacted, the Wall Street Journal says the cybercriminals in one case targeted employees who tracked government reimbursement rates, and others involved in M&A activity. Three are U.S. publicly traded companies, and breakdown of victims is as such, according to the NYT:
Half of these companies fall into the biotechnology sector; 13 percent sell medical devices; 12 percent sell medical instruments and equipment; 10 percent manufacture drugs; and a small minority of targets include medical diagnostics and research organizations, health care providers and organizations that offer health care planning services.
The NYT continues:
The attackers, whom FireEye named “Fin4” because of their focus on the financial sector, appear to be native English speakers, based in North America or Western Europe, who are well-versed in the Wall Street vernacular. Their email lures are precisely tailored toward each victim, written in flawless English and carefully worded to sound as if they were sent by someone with an extensive background in investment banking and with knowledge of the terms those in the industry employ.
The hackers’ approach has been tailored to the individual and the organization, making it difficult to detect malfeasance for a long while.
The Fin4 attackers maintain a light footprint. Unlike other well-documented attacks originating in China or Russia, the attackers do not use malware to crawl further and further into an organization’s computer servers and infrastructure. They simply read a person’s emails, and set rules for the infiltrated inboxes to automatically delete any email that contains words such as “hacked,” “phished,” or “malware,” to increase the time before their victims learn their accounts have been compromised.