SEC Press press_release 5 KB 1,809 chars

SEC Urges Investors to Protect Their Online Brokerage Accounts from Identity Thieves

Release
2005-158
summary

The SEC issued a public advisory in November 2005 warning that identity thieves were using malware and keyloggers to steal login credentials from online brokerage accounts and siphon funds, urging investors to adopt security measures like firewalls and security tokens, with no individuals charged and no dollar amounts disclosed.

paragraph

In November 2005, the SEC issued an investor alert warning of widespread identity theft targeting online brokerage accounts, where fraudsters used malicious software—including keyloggers—to steal usernames and passwords and transfer funds to external accounts. Although no specific perpetrators, cases, or dollar losses were identified, the SEC confirmed numerous incidents of unauthorized access and fund theft. The agency responded with an educational guide recommending protective steps such as installing firewalls, using security tokens, and ignoring phishing emails, emphasizing prevention over enforcement with no charges filed.

narrative

In November 2005, the U.S. Securities and Exchange Commission (SEC) issued a public advisory warning investors about a growing threat of identity theft targeting online brokerage accounts. Regulators reported numerous incidents in which unauthorized individuals gained access to investor accounts using malicious software, particularly keylogging programs that captured login credentials, enabling thieves to transfer funds to external accounts. The SEC did not disclose specific victims, dollar amounts, or named perpetrators, as the alert was purely preventative rather than an enforcement action. To combat the threat, the agency recommended practical safeguards, including installing personal firewalls and security software, using security tokens for authentication, and avoiding emails that request sensitive information. The SEC emphasized that many investors were not taking adequate precautions, increasing their vulnerability to cyber intrusions. The advisory was accompanied by a publicly available guide on the SEC’s website to help investors protect their accounts. No legal charges, investigations, or financial penalties were announced as part of this release, underscoring its focus on education and risk mitigation rather than prosecution.

Enriched metadata

Scheme
cyber-fraud (95%)
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
identity thievesmalicious software programsonline brokerage accountssec investor education directorSecurities and Exchange Commissionsoftware programssusan f. wyderkounauthorized individuals
Keywords
online brokeragebrokerage accountsidentity thievesonlineaccountsinvestors protectbrokeragesecinvestorsidentitythievesprotect onlineprotecturges investorsaccounts identity

Extracted insights

Entities 8
  • person identity thieves
  • person malicious software programs
  • person online brokerage accounts
  • agency sec investor education director
  • agency Securities and Exchange Commission
  • person software programs
  • person susan f. wyderko
  • person unauthorized individuals
Triples 10
  • SEC issued investor guide designed to inform Americans about steps to protect online brokerage accounts
  • Identity Thieves targeting online brokerage accounts
  • Unauthorized Individuals gained access to other people's online brokerage accounts
  • Fraudsters stolen money from investors by transferring funds from online brokerage accounts
  • Identity Thieves use malicious software programs to attack vulnerable computers
  • Malicious Software Programs monitor computer activity and send information back to thief's computer
  • Software Programs keep track of key strokes to obtain username and password information
  • Susan F. Wyderko is SEC Investor Education Director
  • SEC offers tips on how online investors can protect personal information from intruders
  • Investors can protect themselves by installing personal firewall, security software, using security token, ignoring suspicious emails
View original SEC press releasesec.gov
Extracted body text (1,809c)
SEC Urges Investors to Protect Their Online Brokerage Accounts from Identity Thieves FOR IMMEDIATE RELEASE 2005-158 Washington, D.C., Nov. 3, 2005 - The Securities and Exchange Commission today issued an investor guide designed to inform Americans about steps they can take to protect their online brokerage accounts from unauthorized activity by intruders. Regulators believe that some identity thieves are targeting online brokerage accounts for intrusion. Over the past few months, the SEC has become aware of numerous situations in which unauthorized individuals have gained access to other people's online brokerage accounts. Some of these fraudsters have stolen money from investors by transferring funds from the online brokerage accounts to outside accounts. Many identity thieves use malicious software programs to attack vulnerable computers of online users. These software programs can monitor computer activity and send information back to the thief's computer. Sometimes, these programs will keep track of key strokes, which then allows identity thieves to easily obtain username and password information. "We are concerned that many investors aren't taking appropriate precautions when accessing their online brokerage accounts," said SEC Investor Education Director Susan F. Wyderko. "In our guide, we offer tips on how online investors can protect their personal information from intruders." Installing a personal firewall and security software package, using a security token, and ignoring emails requesting confidential or sensitive information are among the ways investors can protect themselves from identity thieves. The SEC's investor guide is available at www.sec.gov/investor/pubs/onlinebrokerage.htm. http://www.sec.gov/news/press/2005-158.htm Home | Previous Page Modified: 11/3/2005
OCR text (1,809c · plain-text · 99% conf)
SEC Urges Investors to Protect Their Online Brokerage Accounts from Identity Thieves FOR IMMEDIATE RELEASE 2005-158 Washington, D.C., Nov. 3, 2005 - The Securities and Exchange Commission today issued an investor guide designed to inform Americans about steps they can take to protect their online brokerage accounts from unauthorized activity by intruders. Regulators believe that some identity thieves are targeting online brokerage accounts for intrusion. Over the past few months, the SEC has become aware of numerous situations in which unauthorized individuals have gained access to other people's online brokerage accounts. Some of these fraudsters have stolen money from investors by transferring funds from the online brokerage accounts to outside accounts. Many identity thieves use malicious software programs to attack vulnerable computers of online users. These software programs can monitor computer activity and send information back to the thief's computer. Sometimes, these programs will keep track of key strokes, which then allows identity thieves to easily obtain username and password information. "We are concerned that many investors aren't taking appropriate precautions when accessing their online brokerage accounts," said SEC Investor Education Director Susan F. Wyderko. "In our guide, we offer tips on how online investors can protect their personal information from intruders." Installing a personal firewall and security software package, using a security token, and ignoring emails requesting confidential or sensitive information are among the ways investors can protect themselves from identity thieves. The SEC's investor guide is available at www.sec.gov/investor/pubs/onlinebrokerage.htm. http://www.sec.gov/news/press/2005-158.htm Home | Previous Page Modified: 11/3/2005