2022-01-01 SEC Press press_release 64 KB 4,339 chars

SEC Charges 18 Defendants in International Scheme to Manipulate Stocks Using Hacked US Brokerage Accounts

Release
2022-145
Caption
Securities and Exchange Commission v. Amy Flaherty Hartman, et al.
summary

The SEC charged 18 individuals and entities, including Rahim Mohamed of Canada, for orchestrating a cyber-enabled microcap stock manipulation scheme that netted over $1 million in illicit proceeds.

paragraph

The scheme involved hackers compromising at least 31 U.S. retail brokerage accounts to purchase shares of Lotus Bio-Technology and Good Gaming, artificially inflating prices. The defendants, who already controlled large blocks of these stocks, sold at inflated values and netted over $1 million in illicit proceeds. The SEC filed charges under the Securities Act of 1933 and Securities Exchange Act of 1934, seeking disgorgement of ill-gotten gains, interest, penalties, and trading bars.

narrative

The Securities and Exchange Commission (SEC) charged 18 individuals and entities for their roles in a cyber-enabled microcap stock manipulation scheme that occurred between late 2017 and early 2018. The scheme involved hackers compromising at least 31 U.S. retail brokerage accounts to purchase shares of Lotus Bio-Technology and Good Gaming, artificially inflating prices and trading volumes. The defendants, who already controlled large blocks of these stocks, sold at inflated values and netted over $1 million in illicit proceeds. Rahim Mohamed of Canada was alleged to have coordinated the hacking attacks, while Davies Wong and Glenn Laken of Canada and Illinois, respectively, controlled the majority of the Lotus Bio-Tech and Good Gaming stock that was sold. Richard Tang of Canada was also implicated in both schemes, with Mohamed leveraging international accounts and dummy holders to conceal the fraud.

Enriched metadata

Scheme
market-manipulation (95%)
Victim loss
$1,000,000
Classified market-manipulation(confidence 95%). EDGAR detection: forms SC 13D/G/13F· recall 53% / precision 9%. detection rule →
Parties
Amy Flaherty Hartmanandrew mcfallCarolyn Welshhansdavies wongglenn b. lakenhacking attacksJoseph Sansonejoshua dickmanjustin jeffrieslucy graetzm. graham loomisnatalie brunsonpatrick mccluskeyrahim mohamedrichard tangRobert GordonSecurities and Exchange Commissionsecurities of lotus bio-technology development corp. and good gaming, inc.william hicks
Keywords
secsecuritiescommissionaccountsbrokerage accountsgood gamingatlanta regionalsecurities commissionlotus bio-techbio-tech goodbritish columbiaschemeusingregionalinternational

Exhibits & Attached Documents (1)

Extracted insights

Dollar amounts 1
  • $1.00M $1 million $1M–$10M
Entities 19
  • person Amy Flaherty Hartman
  • person andrew mcfall
  • person Carolyn Welshhans
  • person davies wong
  • person glenn b. laken
  • person hacking attacks
  • person Joseph Sansone
  • person joshua dickman
  • person justin jeffries
  • person lucy graetz
  • person m. graham loomis
  • person natalie brunson
  • person patrick mccluskey
  • person rahim mohamed
  • person richard tang
  • person Robert Gordon
  • agency Securities and Exchange Commission
  • company securities of lotus bio-technology development corp. and good gaming, inc.
  • person william hicks
Triples 20
  • Securities And Exchange Commission charged 18 Individuals And Entities
  • Rahim Mohamed coordinated Hacking Attacks
  • Hackers accessed 31 U.S. Retail Brokerage Accounts
  • Hackers purchased Securities Of Lotus Bio-Technology Development Corp. And Good Gaming, Inc.
  • Davies Wong controlled Majority Of Lotus Bio-Tech Stock
  • Glenn B. Laken controlled Majority Of Good Gaming Stock
  • Richard Tang was involved with Lotus Bio-Tech And Good Gaming Schemes
  • Securities And Exchange Commission seeks Return Of Ill-Gotten Gains Plus Interest, Penalties, Bars, And Other Equitable Relief
  • Joshua Dickman conducted Investigation
  • Lucy Graetz conducted Investigation
  • Andrew McFall conducted Investigation
  • Patrick McCluskey conducted Investigation
  • Carolyn Welshhans supervised Case
  • Joseph Sansone supervised Case
  • Justin Jeffries supervised Case
  • Natalie Brunson supervised Case
  • Amy Flaherty Hartman supervised Case
  • Robert Gordon will lead Securities And Exchange Commission's Litigation
  • William Hicks will lead Securities And Exchange Commission's Litigation
  • M. Graham Loomis supervised Litigation
PDF (from attached: complaint)
Text layers
Extracted body text (4,339c)
The Securities and Exchange Commission today charged 18 individuals and entities for their roles in a fraudulent scheme in which dozens of online retail brokerage accounts were hacked and improperly used to purchase microcap stocks to manipulate the price and trading volume of those stocks. Those charged include Rahim Mohamed of Alberta, Canada, who is alleged to have coordinated the hacking attacks, and several others in and outside the U.S. who allegedly benefited from or participated in the scheme. According to the SEC’s complaint, in late 2017 and early 2018, hackers accessed at least 31 U.S. retail brokerage accounts and used them to purchase the securities of Lotus Bio-Technology Development Corp. and Good Gaming, Inc. The unauthorized purchases allegedly enabled fraudsters, who already controlled large blocks of Lotus Bio-Tech and Good Gaming stock, to sell their holdings at artificially high prices and reap more than $1 million in illicit proceeds. According to the complaint, Davies Wong of British Columbia, Canada, and Glenn B. Laken of Illinois, respectively, controlled the majority of the Lotus Bio-Tech and Good Gaming stock that was sold while the hacking attacks were being carried out, and Mohamed coordinated with Wong, Laken, and others to orchestrate the attacks. The complaint also alleges that Richard Tang of British Columbia, Canada, was involved with both the Lotus Bio-Tech and Good Gaming schemes. “This case illustrates the critical importance of cybersecurity and of our ongoing efforts to protect retail investors from cyber fraud,” said Gurbir S. Grewal, Director of the SEC’s Division of Enforcement. “The SEC remains committed to rooting out this type of wrongdoing. Investors should also take precautions, including choosing strong passwords, using different passwords for different accounts, and using two-factor authentication when available.” “Our complaint details a brazen and sophisticated scheme, with hackers using international accounts and dummy accountholders to hide their tracks,” said Nekia Hackworth Jones, Director of the SEC’s Atlanta Regional Office. “As this case demonstrates, the Division can uncover misconduct even when it crosses borders and is concealed behind multiple layers of obfuscation.” The SEC’s complaint charges violations of the antifraud and beneficial ownership reporting provisions of the Securities Act of 1933 and the Securities Exchange Act of 1934 and names two relief defendants who received proceeds from the hacks. The SEC seeks the return of ill-gotten gains plus interest, penalties, bars, and other equitable relief. The SEC’s investigation is continuing. The SEC’s investigation has been conducted by Joshua Dickman and Lucy Graetz of the Atlanta Regional Office, Andrew McFall of the Washington, D.C. Office, and Patrick McCluskey of the Philadelphia Regional Office, with the assistance of Marlee Miller and Owen Granke of the SEC’s Office of International Affairs. The case is being supervised by Acting Chief of the Crypto Assets and Cyber Unit Carolyn Welshhans, Market Abuse Unit Chief Joseph Sansone, Justin Jeffries and Natalie Brunson of the Atlanta Regional Office, and Amy Flaherty Hartman of the Chicago Regional Office. Robert Gordon and William Hicks of the Atlanta Regional Office will lead the SEC’s litigation, supervised by M. Graham Loomis. The SEC appreciates the assistance of the Financial Industry Regulatory Authority, the Alberta Securities Commission, the Australia Securities and Investments Commission, the British Columbia Securities Commission, the Calgary Police Service, the Cayman Islands Monetary Authority, the Dubai Financial Services Authority, the French Autorité des Marchés Financiers, the Hong Kong Securities and Futures Commission, the Mauritius Financial Services Commission, the Ontario Securities Commission, the Quebec Autorité des Marchés Financiers, the Royal Canadian Mounted Police, the Securities Commission of the Bahamas, the Sûreté du Québec, the Superintendencia del Mercado de Valores de la República Dominicana, the Swiss Financial Market Supervisory Authority, and the United Kingdom Financial Conduct Authority. To learn more about how to protect your online investment accounts from fraud, please visit the SEC’s Office of Investor Education and Advocacy investor alerts webpage.
OCR text (4,339c · html-text · 99% conf)
The Securities and Exchange Commission today charged 18 individuals and entities for their roles in a fraudulent scheme in which dozens of online retail brokerage accounts were hacked and improperly used to purchase microcap stocks to manipulate the price and trading volume of those stocks. Those charged include Rahim Mohamed of Alberta, Canada, who is alleged to have coordinated the hacking attacks, and several others in and outside the U.S. who allegedly benefited from or participated in the scheme. According to the SEC’s complaint, in late 2017 and early 2018, hackers accessed at least 31 U.S. retail brokerage accounts and used them to purchase the securities of Lotus Bio-Technology Development Corp. and Good Gaming, Inc. The unauthorized purchases allegedly enabled fraudsters, who already controlled large blocks of Lotus Bio-Tech and Good Gaming stock, to sell their holdings at artificially high prices and reap more than $1 million in illicit proceeds. According to the complaint, Davies Wong of British Columbia, Canada, and Glenn B. Laken of Illinois, respectively, controlled the majority of the Lotus Bio-Tech and Good Gaming stock that was sold while the hacking attacks were being carried out, and Mohamed coordinated with Wong, Laken, and others to orchestrate the attacks. The complaint also alleges that Richard Tang of British Columbia, Canada, was involved with both the Lotus Bio-Tech and Good Gaming schemes. “This case illustrates the critical importance of cybersecurity and of our ongoing efforts to protect retail investors from cyber fraud,” said Gurbir S. Grewal, Director of the SEC’s Division of Enforcement. “The SEC remains committed to rooting out this type of wrongdoing. Investors should also take precautions, including choosing strong passwords, using different passwords for different accounts, and using two-factor authentication when available.” “Our complaint details a brazen and sophisticated scheme, with hackers using international accounts and dummy accountholders to hide their tracks,” said Nekia Hackworth Jones, Director of the SEC’s Atlanta Regional Office. “As this case demonstrates, the Division can uncover misconduct even when it crosses borders and is concealed behind multiple layers of obfuscation.” The SEC’s complaint charges violations of the antifraud and beneficial ownership reporting provisions of the Securities Act of 1933 and the Securities Exchange Act of 1934 and names two relief defendants who received proceeds from the hacks. The SEC seeks the return of ill-gotten gains plus interest, penalties, bars, and other equitable relief. The SEC’s investigation is continuing. The SEC’s investigation has been conducted by Joshua Dickman and Lucy Graetz of the Atlanta Regional Office, Andrew McFall of the Washington, D.C. Office, and Patrick McCluskey of the Philadelphia Regional Office, with the assistance of Marlee Miller and Owen Granke of the SEC’s Office of International Affairs. The case is being supervised by Acting Chief of the Crypto Assets and Cyber Unit Carolyn Welshhans, Market Abuse Unit Chief Joseph Sansone, Justin Jeffries and Natalie Brunson of the Atlanta Regional Office, and Amy Flaherty Hartman of the Chicago Regional Office. Robert Gordon and William Hicks of the Atlanta Regional Office will lead the SEC’s litigation, supervised by M. Graham Loomis. The SEC appreciates the assistance of the Financial Industry Regulatory Authority, the Alberta Securities Commission, the Australia Securities and Investments Commission, the British Columbia Securities Commission, the Calgary Police Service, the Cayman Islands Monetary Authority, the Dubai Financial Services Authority, the French Autorité des Marchés Financiers, the Hong Kong Securities and Futures Commission, the Mauritius Financial Services Commission, the Ontario Securities Commission, the Quebec Autorité des Marchés Financiers, the Royal Canadian Mounted Police, the Securities Commission of the Bahamas, the Sûreté du Québec, the Superintendencia del Mercado de Valores de la República Dominicana, the Swiss Financial Market Supervisory Authority, and the United Kingdom Financial Conduct Authority. To learn more about how to protect your online investment accounts from fraud, please visit the SEC’s Office of Investor Education and Advocacy investor alerts webpage.