Sources detail a Ukraine-based hacking scheme that stole press releases from three US newswires over at least five years and made $100M+ via insider trading
At a Kiev nightclub in the spring of 2012, 24-year-old Ivan Turchynov made a fateful drunken boast to some fellow hackers.
Context & Ripple Effects
This feature adds detail to a case that was already public record: the SEC's 2015 charges against nine traders and hackers alleged Business Wire, PR Newswire and other services were breached for five years, and one Ukrainian hacker later admitted in court to stealing some 150,000 releases for the network's benefit. What the new reporting contributes is the origin story — Ivan Turchynov's boast at a Kiev nightclub in 2012 — and an upgraded damage estimate: sources now put the take above $100M, well past the ~$30M figure cited when the hacker's guilty plea was reported in 2016.
The piece lands between two enforcement waves: the original indictments, and the 2019 charges against Turchynov and others, which kept the prosecution alive years after the initial sweep.
First-order effects
- The three newswires face renewed scrutiny of their pre-release handling of earnings material, since their embargoed feeds were the direct source of the stolen information.
- US prosecutors gain a fuller evidentiary narrative — the Kiev origin and the $100M-plus scale — to support the pending cases against Turchynov and his co-defendants.
Second-order effects
- Newswire services and their corporate clients are pushed toward tighter controls on embargoed earnings distribution, because the same channel had already been shown to leak at scale.
- The demonstrated profitability of stolen pre-market news invites copycats targeting adjacent disclosure channels — a pattern that later surfaced in DOJ charges against five Russians who hacked two SEC filing agents between 2018 and 2020.
Third-order effects
- If the pattern holds, corporate earnings disclosure becomes a standing target for organized Eastern European hacking groups rather than opportunistic breaches, forcing regulators and issuers to treat the entire pre-announcement supply chain as critical infrastructure.
- Enforcement increasingly reaches into extradition and diplomacy: the later profile of Vladislav Klyushin — a Russian insider-trading hacker released in a 2024 prisoner swap — shows these cases ending in geopolitical bargaining as much as in courtrooms.
The trend: Stolen market-moving information is becoming a repeat business model for Eastern European hacking crews, pulling newswires, SEC filing infrastructure, and even prisoner-swap diplomacy into the enforcement perimeter.