Intelligence · Cyber · Trade

“The breach and the trade are the same event.
Nobody watches both.”

InCyTrade dynamically focuses on your exposure and the assets that truly matter in the current window, and correlates market-abuse signals against thousands of internal daily alerts to find your breach before it is too late, closing the one gap no SOC tool and no market-surveillance tool covers alone.

Cybercrime has always gone hand in hand with financial crime.

HTD Hack-to-Trade Detection

The Shift

Cybercrime went quiet.

Cybercrime has always run as a business: steal the database, sell the access, deploy ransomware, name a price. The most sophisticated threat actors have stopped playing it that way. They're staying below the radar - holding access instead of spending it, and converting an intrusion into a financial trade the victim never learns occurred.

This is the shape cyberattacks are taking next. InCyTrade exists to catch it.

The Activity

No ransom note. No negotiation. No victim ever knows.

The new play is quiet. The actor doesn't encrypt the estate - they sit on the CFO's mailbox, the M&A data room, the quarter-close file share, or a draft press release sitting with Investor Relations, and they trade the information. The information monetizes itself in a liquid market, and the access is never burned - it can be worked again next quarter, next catalyst, indefinitely.

The behavior is established. The detection layer does not exist.

The Blind Spot

Two teams, two tickets, zero shared visibility.

Market side

Regulators, exchanges, and compliance vendors see the market - anomalous flow, catalyst timing, cluster behavior. They have zero visibility into whether the issuer was compromised that week.

Enterprise side

The SOC sees the estate - EDR, SIEM, identity, DLP, file audit. They have zero visibility into whether the options chain moved two days after they quietly closed the ticket.

An access anomaly on the deal folder and an options anomaly 48 hours later are, today, two unrelated tickets, in two unrelated systems, owned by two teams that never speak. InCyTrade is the join.

The Precedent

Hack-to-trade - the prosecuted record.

  1. 2010 – 2015

    Newswires

    Three wire services breached. Roughly 150,000 pre-release announcements accessed, about 800 traded.

    >$100M32 charged · SEC 2015-163

  2. 2013 – 2015

    FIN4

    Executive, legal, and compliance mailboxes targeted at more than 100 companies.

    ~2/3healthcare & pharma · FireEye, 2014

  3. 2016

    SEC EDGAR

    Non-public test filings extracted directly from the filing system itself.

    $4.1M157 earnings · charged 2019 · SEC 2019-1

  4. 2018 – 2020

    Filing agents

    Two SEC filing agents breached. Prosecutors described trading around more than 2,000 earnings events.

    ~$9M → ~$90Mconvicted 2023 · DOJ

  5. 2019 – 2020

    Issuers, directly

    Five public companies. Senior executives' account passwords reset to obtain pre-release earnings information.

    $3.75M14 earnings · charged 2024 · SEC LR-26141

Regulatory convergence

Dec 2023
Material cyber incidents disclosable within four business days of the materiality determination (SEC Item 1.05). Final rule.
Since 2024
Incidents now surface as dated 8-K filings, creating a public, timestamped record that can be placed alongside market activity.
Feb 2025
SEC stands up its Cyber and Emerging Technologies Unit. Hacking to obtain material nonpublic information is a named priority. Announcement.

Named actors

FIN4
Hack-to-trade specialist. Executive mailboxes, 2013–2015.
Cl0p
Mass document theft via managed file-transfer platforms.
ALPHV / BlackCat
Filed an SEC complaint against its own victim, 2023.

Independent research

25%
Of 1,859 U.S. takeovers studied, about a quarter showed abnormal equity-options volume in the 30 days before announcement. Management Science, 2019.
8%
The share of those same deals the SEC litigated. The gap between the two numbers is the detection problem, measured by someone else.
Breaches
Options activity before a corporate data-breach announcement carries statistical predictive power for the announcement itself. Peer-reviewed study, 2022.

Enforcement record

Dec 2023
In the twelve months after the rule took effect, 54 issuers disclosed 55 cyber incidents on Form 8-K. Filing survey.
Jul 2024
SEC staff ran a sweep review of Item 1.05 filings and issued 14 comment letters, most of them about how materiality was described. Review.
2023 - 2024
Six issuers settled charges over cyber disclosure or the controls behind it, for about $12.1M in civil penalties in total: $3M in 2023, $2.125M in June 2024, and roughly $7M across four issuers in October 2024.

Figures above are drawn from the linked SEC and Department of Justice releases, from FireEye's 2014 report Hacking the Street? FIN4 Likely Playing the Market, and from the peer-reviewed and filing-survey sources linked in each row. Charging documents describe allegations. Convictions are noted where they occurred. Affected companies are not named here because they are not named in the public charging documents.

Actors have traded on what they steal for years, under the perfect cover of the market - and everyone looks away. No product watches both sides at once.

The Platform · HTD · AI

One platform. Two engines. Four cylinders.

Agentless security AI platform. The collection layer runs in its own cloud. The mapping and correlation layers run on-prem, inside your estate, reading directly from the tools you already run.

Modules 01 + 02 · Prevention

Coverage & Focus

Narrow the estate to what actually matters in the current catalyst window. The window shifts month to month - earnings, then M&A, then a filing - and the scope shifts with it.

  • External MNPI exposure, surfaced only when a leak carries real, asset-specific impact.
  • Catalyst-tuned attack-path mapping - the identities that can actually reach this window's crown jewels, not just the finance team.
  • The narrowest, highest-sensitivity assets get temporary, logging-only telemetry hardening for the duration of the window.

Modules 03 + 04 · Correlation

Probability & Materiality

Correlate a real cyber event with the market. This is the layer built to help prioritise which incident to assess first against the SEC's four-business-day disclosure clock.

  • Live correlation: does an internal access anomaly explain a suspected transaction on a known, scheduled catalyst?
  • Retroactive correlation: does a prior cyber or access event explain an unexplained market move on a surprise catalyst?
  • A scored, time-bounded finding with its supporting timeline attached - intended to support a disclosure decision, not to replace the judgement behind it.

The Team

Built by operators who've sat on both sides of this problem.

Raphael Cohen

Co-Founder & CEO

Formerly Unit 8200 and the Israeli Prime Minister's Office.

Yaron Golfand

Co-Founder & CTO

Formerly Unit 8200 and the Israeli Prime Minister's Office.

Get in touch

Let's talk.

If you run security, compliance, or legal for a public company, we want to hear from you.