Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

Cyber Attacks Against Stock Exchanges Threaten Financial Markets: Report

Cyber Attacks Hitting Global Stock Exchanges are Putting Financial Markets At Risk, According to a New Idustry Report 

A “significant” number of stock exchanges have been hit by cyber-attacks over the past year, according to a recent study from a group representing global stock exchanges.

Cyber Attacks Hitting Global Stock Exchanges are Putting Financial Markets At Risk, According to a New Idustry Report 

A “significant” number of stock exchanges have been hit by cyber-attacks over the past year, according to a recent study from a group representing global stock exchanges.

About 53 percent of exchanges surveyed by the International Organization of Securities Commissions and the World Federation of Exchanges had been hit by a cyber-attack, according to a study released Tuesday. Of the 46 exchanges around the world included in the survey, nearly a quarter of the exchanges who had been attacked were in the Asia-Pacific region.

“While there is uncertainty around the size of the cyber-crime threat in securities markets, there are clear signs that it is a growing threat to the financial sector, with potential for large costs,” wrote the study’s co-authors, Iosco’s Rohini Tendulkar and WFE’s Gregoire Naacke.

Cyber Attacks on Stock ExchangesThe most common attacks against exchanges were malware and denial-of-service (DoS) attacks, where Websites and servers are overwhelmed trying to handle excessive volumes of Internet traffic. Other attacks included laptop and data thefts, Website scanning, and insider information theft. None of the exchanges reported financial theft as part of cyber-attacks.

“Attacks tend to be disruptive in nature, rather than motivated by financial gain,” the report said.

So far, the attacks appear to have focused on non-trading-related online services and Websites. Back in February 2011, NASDAQ OMX Group discovered unknown adversaries had placed suspicious files on one of its applications which facilitated director communication. Trading platforms were not impacted, in that attack. NASDAQ and BATS Global Markets said in February last year that they were targeted with denial of service attacks.

“Cyber-crime also appears to be increasing in terms of sophistication and complexity, widening the potential for infiltration and large-scale damage,” the report (PDF) said.

About 46 percent of the exchanges in the survey said there was no impact from cyber-attacks on the organization “because of preventative and detection mechanisms.” About 21 percent said there was some disruption or unavailability of production and Web servers.

Advertisement. Scroll to continue reading.

Even so, the increased attacks are worrisome because the markets are interconnected, which means there is a potential of a single attack having a widespread impact, the paper said. About 89 percent of the exchanges said cyber-attacks represents a systemic risk to markets.

“A number of respondents could envision a large-scale, coordinated and successful cyber-attack on financial markets having a substantial impact on market integrity and efficiency,” the study said. When asked to describe such an attack, the majority of the respondents suggested attack scenarios “with more far-reaching consequences,” such as halting trading, manipulating data, targeting telecommunication networks, and affecting the functions of a clearing house, the authors wrote.

At least the senior executives in charge appear to be paying attention, as 93 percent of the exchanges said “cyber-threats are discussed and understood by senior management.” Even more positive, 93 percent of respondents have disaster recovery protocols or measures in place to deal with the fallout of a cyber-attack.

All the organizations in the survey said they are able to identify an attack within 48 hours of it occurring. However, it is a little worrying that a quarter of the exchanges in the report said that current measures may not be sufficient to withstand a large-scale and coordinated attack.

While there wasn’t a lot of information available on the costs of cyber-crime to securities markets, the exchanges in the survey said the monetary impact—both direct and indirect costs—of the attacks in 2012 were less than $1 million.

The majority of the exchanges said they share information about both attempted and successful cyber-attacks with securities regulatory, supervisory commissions, and other authorities. Only three organizations out of the whole survey said they share information with “peer institutions.” Organizations felt the effective regulation and legislation, improved information sharing, and stronger internal measures would improve their security posture.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Kim Larsen is new Chief Information Security Officer at Keepit

Professional services company Slalom has appointed Christopher Burger as its first CISO.

Allied Universal announced that Deanna Steele has joined the company as CIO for North America.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Malware & Threats

The NSA and FBI warn that a Chinese state-sponsored APT called BlackTech is hacking into network edge devices and using firmware implants to silently...

Cybersecurity Funding

2022 Cybersecurity Year in Review: Top news headlines and trends that impacted the security ecosystem

Endpoint Security

Today, on January 10, 2023, Windows 7 Extended Security Updates (ESU) and Windows 8.1 have reached their end of support dates.

Artificial Intelligence

ChatGPT is increasingly integrated into cybersecurity products and services as the industry is testing its capabilities and limitations.

Cybersecurity Funding

Network security provider Corsa Security last week announced that it has raised $10 million from Roadmap Capital. To date, the company has raised $50...