How a female Ukrainian hacker exposed a botched – Business News
A Ukrainian hacker who was held at gunpoint by a gang of cocaine-sniffing cybercriminals helped the Securities and Exchange Commission blow the lid of of a high-profile breach case that had wrongly accused American day merchants, in response to a report.
Olga Kuprina, recognized by her online persona “Ghost in the Shell,” turned a whistleblower for the federal company within the stunning cyberattack that infiltrated the SEC’s Edgar submitting system in 2016, Bloomberg News reported on Monday.
Surrounded by cocaine, laptops and armed males, Kuprina was trapped by a native crime boss, Artem Radchenko, in her Kyiv house and ordered to hack maybe the world’s greatest repository of company filings, in response to the outlet.
Radchenko allegedly hoped to sell unpublished filings for $200,000 apiece.
Kuprina was recognized by her online persona “Ghost in the Shell.” Instagram/sky31337
But because the doped-up Radchenko barked instructions at Kuprina, she plotted her escape — determined to return to her 7-year-old daughter and expose the cybercrime, in response to Bloomberg News.
When she demanded fee for the hack, Radchenko allegedly broke her nostril and refused to permit her to go away, in response to Bloomberg News.
Kuprina, 34, later fled, contacted US authorities, and turned over onerous drives and handwritten notes proving how she had accessed the SEC knowledge.
“There were so many vulnerabilities there you cannot f–king imagine,” she informed investigators. Edgar, she mentioned, was an outdated, patched-together system that hadn’t been correctly secured in years.
Kuprina, who had additionally hacked Citigroup, Nasdaq, Dow Jones and NASA, signed a plea deal with the feds and fled to the US in 2018, leaving her mom and daughter behind.
Olga Kuprina is a Ukrainian hacker who turned whistleblower. Instagram/sky31337
In 2019, the SEC wrongfully scapegoated American day merchants who have been accused of pocketing $4.1 million from insider trades linked to the large cyberattack that breached the Edgar submitting system.
It seems these Americans might have merely been guilty of making sensible, fortunate bets.
“Today’s action shows the SEC’s commitment and ability to unravel these schemes and identify the perpetrators even when they operate from outside our borders,” the company’s head of enforcement mentioned in a press release.
Sungjin Cho, a Los Angeles-based day trader, was startled to seek out federal brokers banging on his door earlier than daybreak. They confiscated his gadgets, grilled him about overseas hackers, and accused him of profiting off stolen knowledge.
“I don’t know what we were expecting to find, but he didn’t seem like a high-rolling criminal at all,” one FBI agent informed Bloomberg News.
Kuprina’s cooperation with US authorities would reveal a months-long breach of the SEC’s core system — and upend the company’s narrative.
What the SEC didn’t say in its official model of occasions was that the breach of Edgar had lasted far longer than publicly acknowledged — and had been exposed not by company sleuthing however by Kuprina.
Despite her central function in exposing the breach — and persevering with to obtain paperwork as late as March 2017 — Kuprina wasn’t talked about within the SEC’s grievance.
In 2019, the SEC introduced prices towards US merchants over a hack that was perpetrated by Ukrainian cybercriminals, in response to a report. Christopher Sadowski
Instead, the commission zeroed in on Cho and his associates: David Kwon, a good friend who traded by way of Cho’s accounts, and Ivan Olefir, a Ukrainian consumer linked to Cho’s trading firm.
While the three made trades that aligned with earnings bulletins, investigators discovered no direct proof they’d been involved with the hackers, nor that they ever knowingly acquired stolen paperwork.
Still, the SEC charged them, citing high win charges on earnings trades and circumstantial connections.
The Department of Justice, which was conducting a parallel legal probe, in the end declined to prosecute the merchants — a transfer that signaled doubts concerning the power of the case, Bloomberg News reported.
Cho maintained that he and his colleagues have been merely monitoring uncommon trading exercise — in search of indicators that others had inside info, then piggybacking on their bets.
“Any earnings or any market-moving announcement…there will always be some leak,” Cho informed investigators.
Gorodenkoff – stock.adobe.com
“And if you could detect that movement, that’s the strategy.”
Critics say the SEC needed a win — and selected simple targets. The company confronted strain to reply after being hacked itself, and somewhat than deal with the Ukrainian masterminds nonetheless at giant, it skilled its firepower on merchants who have been within attain.
In the top, Cho settled for $175,000 — a fraction of what the SEC claimed he made. He didn’t admit wrongdoing, however underneath SEC guidelines, he’s not allowed to publicly say he’s harmless both.
“I’m not allowed to say I’m innocent, but I’ll give you all the facts and people can decide for themselves,” he later mentioned.
In 2020, Kuprina pleaded guilty to federal prices associated to Edgar and 5 different hacks, in response to Bloomberg. She served a short jail stint earlier than being launched as she cooperated with investigators.
A decide sentenced her to time served in 2023 in recognition of her cooperation, in response to Bloomberg.
The expert hacker now works for cybersecurity company Recorded Future Inc. — and was reunited together with her mom and daughter, who have been flown out of war-torn Ukraine by the US authorities.
Meanwhile, hackers like Radchenko are nonetheless at giant. And the SEC’s Edgar system, although up to date in elements, stays susceptible in response to cybersecurity consultants.
The Post has sought remark from the SEC, Kuprina, Cho and Kwon.
