This page has been archived and commenting is disabled.

Nasdaq Letter To Shareholders Explaining System Breach

Tyler Durden's picture




 

No surprise: blame the US government on the information black out. Shareholders, and the investing public of course, learn last. Our question: when did clients learn?

From Nasdaq OMX letter to shareholders

Many of you may have read an article published in today’s Wall Street
Journal which reports that computer hackers have penetrated our network.
Below are facts behind the story:

• Through our normal security
monitoring systems we detected suspicious files on the U.S. servers
unrelated to our trading systems and determined that our web facing
application Directors Desk was potentially affected. We immediately
conducted an investigation, which included outside forensic firms and
U.S. federal law enforcement. The files were immediately removed and at
this point there is no evidence that any Directors Desk customer
information was accessed or acquired by hackers. Our trading platform
architecture operates independently from our web-facing services like
Directors Desk and at no point was any of NASDAQ OMX’s operated or
serviced trading platforms compromised.

• Subsequently, the
U.S. Department of Justice requested that we refrain from providing
notice to our customers until, at the earliest, February 14, 2011, in
order to facilitate the continuing investigation. NASDAQ OMX was
honoring the U.S. Government’s request to delay notification, but when a
story ran in the media on Saturday, February, 5, 2011, regarding a
hacking incident at NASDAQ OMX, we immediately decided, in consultation
with the authorities, that we must inform our constituents.

• We
continue to evaluate and enhance our advanced security controls to
respond to the ever increasing global cyber threat and continue to
devote extensive resources to further secure our systems. Cyber attacks
against corporations and government occur constantly. NASDAQ OMX remains
vigilant against such attacks. We have been working in cooperation with
the Government’s ongoing investigations and have received their
technical advice for which we are appreciative.

As always, please don’t hesitate to contact us if needed.

Adena Friedman
Executive Vice President, Corporate Strategy and Chief Financial Officer
212-401-8730

Vince Palmiere
Vice President, Investor Relations
212-401-8742

 

- advertisements -

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Sat, 02/05/2011 - 15:42 | 937678 bania
bania's picture

"We apologize, but we just can't tell the difference anymore between security breaches and the status quo manipulation we see every day."

Sat, 02/05/2011 - 17:38 | 937871 Malcolm Tucker
Malcolm Tucker's picture

Speaking of "Newspeak" Here is a post comparing Tony Blair (major tool) and George Galloway (consistent thorn in the side of Blair) speeches on Egypt, VIDEOS included:

 

http://fedupmontrealer.blogspot.com/2011/02/tell-what-politicians-really-think.html

Galloway is ^&*%ing AWESOME

 

Sat, 02/05/2011 - 15:43 | 937680 bob_dabolina
bob_dabolina's picture

In line with Obama's campaign promise of being open and transparent. And the saga continues.

Because withholding pertinant information effecting the livelihood and business of your clients is always in their best interest.

Sat, 02/05/2011 - 15:49 | 937685 Cognitive Dissonance
Cognitive Dissonance's picture

http://www.businessweek.com/bwdaily/dnflash/may2006/nf20060523_2210.htm?campaign_id=rss_daily

Intelligence Czar Can Waive SEC Rules

Now, the White House's top spymaster can cite national security to exempt businesses from reporting requirements.

President George W. Bush has bestowed on his intelligence czar, John Negroponte, broad authority, in the name of national security, to excuse publicly traded companies from their usual accounting and securities-disclosure obligations. Notice of the development came in a brief entry in the Federal Register, dated May 5, 2006, that was opaque to the untrained eye.

 

Sat, 02/05/2011 - 16:03 | 937709 Rainman
Rainman's picture

.....and just think, the serfs keep scratching their heads wondering why nobody in the corporati goes to jail for brazen fraud !!

Sat, 02/05/2011 - 15:50 | 937687 Nihilarian
Nihilarian's picture

 We continue to evaluate and enhance our advanced security controls to respond to the ever increasing global cyber threat and continue to devote extensive resources to further secure our systems. We have been working in cooperation with the Government’s ongoing investigations and have received their technical advice for which we are appreciative. As always, please don’t hesitate to contact us if needed.

 

"Our 'advanced security controls' are not secure nor advanced. We will try to continue the status quo by allowing our primariy clientele to rape and pillage the retail investor. We have been working with the government to secure any damaging information about our operations to continue the status quo. As always, please don't hesitate to contact us if needed, our spam folder is still operational."

Sat, 02/05/2011 - 15:55 | 937693 small watcher
small watcher's picture

So was NASDAQ asked to sit on this until Valentine's Day so that the government could figure out how to leverage this event into enough votes for a new "comprehensive trading reform" act?

BTW, what's the emoticon for tinfoil hat? I forget...

Sat, 02/05/2011 - 16:43 | 937789 MsCreant
MsCreant's picture

<];-)

Sat, 02/05/2011 - 16:03 | 937706 tickhound
tickhound's picture

Ok ill say it... Internet kill switch bitchez

Sat, 02/05/2011 - 17:54 | 937903 serotonindumptruck
serotonindumptruck's picture

It all comes down on the 8th or the 14th of Feb?

Sat, 02/05/2011 - 16:05 | 937708 ebworthen
ebworthen's picture

 

They don't say when they were compromised; last week, last month?

And...the files on the "web facing director's desk" were a beach head; once you get access to a computer on the network, you can usually probe any machine on the network.

Imagine what the hackers are doing to your local banks and credit unions.  You don't have to break into a safe anymore. 

Anyone remember the Russian hacker who hacked into Citibank in 1994? 

Guess who pays for the database dollars that are stolen? 

Who bailed out Wall Street in 2008?  Yeah, like that.

http://www.pbs.org/wgbh/pages/frontline/shows/hackers/whoare/notable.html

 

Sun, 02/06/2011 - 14:12 | 938956 sgt_doom
sgt_doom's picture

Your comments, ebworthen, are as silly as they are nonsensical.

The software they've been using for quite some time derives from Sungard, long owned by the Blackstone Group --- ergo, it was compromised long, long ago.

Together with that, they have joined their software to ClearForest, originally from Israel and funded by the same Israeli private equity group behind Narus, now owned by Boeing (CLearForest now resides under Reuters, and an examination of their BoD explains why  --- as well as their interlocking directorships with Hakluyt & Company, where the name Frank Wisner, recently heard to extol the "exemplary virtues" of Hosni Mubarak and urge him to stay on and on in Egypt --- is further explanation).

Now ClearForest software is used at the FBI, various of the top intel contractors now making up the majority of the US intel budget (SAIC, etc.), as well as CIFA, CIA, etc., and was co-mingled with NORA from IBM (NonObvious Relationship Awareness), and is used by the banksters in their fallback plan to Total Information Awareness, now called the Regulatory DataCorp's G.R.I.D. (Global Regulatory Information Database, or Compliance-GRID).

They are usually, and routinely, hacking themselves, and passing it on "cyber threats", ad nauseum, when someone stumbles across it.

(What the bloody hell is this "cyber" stuff anywho?  Wasn't that from the SF '60s????)

Sat, 02/05/2011 - 16:03 | 937710 Cognitive Dissonance
Cognitive Dissonance's picture

Time for the NASDAQ to upgrade to Windows 2000.

Sat, 02/05/2011 - 16:18 | 937736 small watcher
small watcher's picture

They can't, CD. Microsoft never finished porting 2000 to Alpha.

Sat, 02/05/2011 - 17:13 | 937834 Attitude_Check
Attitude_Check's picture

PLEASE don't tell me they are using OLD Alpha systems!  PLEASE tell me you were kidding, right---Right---RIGHT!

Sat, 02/05/2011 - 22:27 | 938280 HAL 9000
HAL 9000's picture

Good afternoon, gentlemen. I am a HAL 9000 computer. I became operational at the H.A.L. plant in Urbana, Illinois on the 12th of January 1992. My instructor was Mr. Langley, and he taught me to sing a song. If you'd like to hear it I can sing it for you.

Sat, 02/05/2011 - 23:00 | 938296 small watcher
small watcher's picture

King: One day, lad, all this will be yours.

Herbert: What? The curtains?

 

[...snip...]

 

Herbert: I just...

King: Yes?

Herbert: I want...

King: Stop! No singing! [King waves hands franticly]

Sorry for the mixed movie references, but I couldn't resist.

Sun, 02/06/2011 - 02:06 | 938463 Seymour Butt
Seymour Butt's picture

CD - please post more often. You are one of my favorites.

I guess NASDAQ's Windows 95 needs an upgrade.

Sat, 02/05/2011 - 16:28 | 937752 sethstorm
sethstorm's picture

And people would be able to tell the difference between a government-derived manipulation versus a computer compromise-based manipulation, how?

 

 

Sat, 02/05/2011 - 17:16 | 937840 Attitude_Check
Attitude_Check's picture

IF the FBI is doing a solid investigation of who done it, then the delay of public notification is a good thing.  Spooking the individuals responsible is probably not a good way to ever figure out who they are.

 

Of course removing their files on the web system probably already knew "the jig was up"

Sun, 02/06/2011 - 14:22 | 938970 sgt_doom
sgt_doom's picture

Taking time off of the busy schedule of examining their own drivers for downloaded porn, and examining the voluminous amount of downloaded porn over at SEC, FDA and the Fed, the FBI is now hot on the trail of the "cyber threat."

Riiiiiiigggggghhhhhhtttt.....

Sat, 02/05/2011 - 17:50 | 937897 gratefultraveller
gratefultraveller's picture

What I find interesting is what they **don't** say - like, "The system is now clean!"...

Sat, 02/05/2011 - 18:06 | 937928 trx
trx's picture

This just raises more questions.

Like; who's servers are those NASDAQ-unrelated were the suspicious files was detected?

Anyway - here's the latest:  NASDAQ Hackers Aimed At Corporate Bonds

 

 

 

 

 

Sat, 02/05/2011 - 18:16 | 937943 sabra1
sabra1's picture

does anyone know how to hack the HFT'S?

Sun, 02/06/2011 - 12:11 | 938741 trx
trx's picture

Depends on what you want to achive. Steal their money? (redirect command). Stop them from trading? (Just cut the electricity supply). Fuck up their algos? (Insert a worm). etc....

You'll find all the tools you need at SurgeForce.net.

But expect a visit by a couple of FBI representatives about two houres later...

Sat, 02/05/2011 - 19:02 | 937991 zhandax
zhandax's picture

the equivalent of someone sneaking into a house and walking around but—apparently, so far—not taking or tampering with anything.

 

"Through our normal security monitoring systems we detected suspicious files on the U.S. servers unrelated to our trading systems and determined that our web facing application Directors Desk was potentially affected."

I realize that these two statements are not mutually exclusive, but doesn't this start to smell?  Won't this make a lovely setup to explain away the next flash crash?

"Subsequently, the U.S. Department of Justice requested that we refrain from providing notice to our customers"

Until the news could be leaked Saturday before the Superbowl?  Transparency, indeed.

Sun, 02/06/2011 - 14:20 | 938969 sgt_doom
sgt_doom's picture

No...no...no...I think the "suspicious files on the U.S. servers" were named, Jada Fire, Jenna Jameson, Capri, etc., etc., and they just weren't familiar with those names.

Nothing really suspicious about them, other than the fact not a single one has ever returned my phone calls.

Sat, 02/05/2011 - 21:55 | 938252 Homeland Security
Homeland Security's picture

This is obviously the work of financial terrorists, who hate us for our financial freedoms. These financial terrorists are from within, or without, and work tirelessly to develop ways and means to attack us. This attempt was thwarted by a massive, highly sophisticated government security apparatus, which must now grow larger and more intrusive at greater expense to the people of this country, for your own protection. We must write and implement new regulations so that the software of our country’s financial system can be monitored to the degree to which every penny from every person can be monitored around the clock. DARPA is currently developing new technology identify the location of every child’s piggy bank and determine its contents and value in case it too needs to be protected from financial terrorists. In the event of another breach of our financial system POTUS can control each and every financial transaction to the degree necessary to protect this great country. Party on.

Sat, 02/05/2011 - 23:08 | 938336 prophet
prophet's picture

Sounds good to me.  Big brother is my friend.

Sun, 02/06/2011 - 14:18 | 938962 sgt_doom
sgt_doom's picture

+1,000 ! ! ! !

Indeed!  One might predict they will next come up with a....let's call it a "securitization process"....shall we....to further the trend in financial liberty for all, along with all those securitzed financial instruments, credit derivatives, and create thousands upon thousands of categories of them, and give anyone the death penalty who dares refer to the entire Ponzi-Tontine scam as peddling securitized debt.

Woe unto them.....and I too, welcome the overlord.

Sun, 02/06/2011 - 00:13 | 938402 slewie the pi-rat
slewie the pi-rat's picture

Dear Adena & Vince:

Love your stuff!  IMHO, your entire sysytem has been roto-routered by the EU.  Perhaps they are thinking about getting some of their capital back, if they can.  Somehow.  See you in the Hague!

Tyler:  if Justice weren't served in the breach, we would have no Justice, at all.

Sun, 02/06/2011 - 02:11 | 938475 Yen Cross
Yen Cross's picture

I'll thouroughy examine this one, before any comment.

Sun, 02/06/2011 - 02:20 | 938479 Yen Cross
Yen Cross's picture

Sorry for the Mis spells. We are in pPort Douglas QLD setting up a SAT link through TelStra into a west coast server(isp) for the Super Bowl tomorrow. The cyclone knocked down a lot of communication temporarily. Enjoy the game everyone.

Sun, 02/06/2011 - 09:59 | 938625 TapeReader
TapeReader's picture

I doubt that Nasdaq is the only exchange that has been penetrated.

What would it take to bribe some system administrators at the CME to open up some back doors and allow some quant shops to get their own sneak peeks?

http://algofutures.com/blog/hackers-hit-nasdaq-everything-old-is-new-again

 

Do NOT follow this link or you will be banned from the site!