Who's watching the watchdog? SEC admits to possible data breach
At the same time that the Securities and Exchange Commission (SEC) was preparing corporate guidelines for cybersecurity risk disclosure, the securities market watchdog was informing its employees that their personal brokerage account information may have been compromised by a contractor.
In an October 7 letter to SEC employees, Chief Information Officer Thomas Bayer said a contractor that runs the computer system for the staff ethics compliance program shared names and account numbers with a subcontractor without the SEC’s permission, in violation of the contractor’s agreement, according to a report by Reuters.
The ethics compliance program was put in place to guard against insider trading by SEC employees after the agency’s inspector general raised concerns about the issue, the report noted. "We are not aware of any actual misuse of the data. Nevertheless, it is the SEC's policy to provide notification of any incident that presents the potential for unauthorized access to personal information”, Bayer wrote in the letter quoted by Reuters.
