2021 Intercontinental Exchange — VPN appliance compromise; Regulation SCI notification delays; $10M SEC settlement (2024)
Data compromised
Regulatory materials emphasized procedural reporting violations; ICE characterized market-impacting data theft as minimal or unproven in public enforcement summaries
Technical writeup
Parent company of the NYSE and related market utilities, Intercontinental Exchange (ICE), learned in April 2021 that a threat actor had exploited a zero-day-class VPN flaw—trade press commonly mapped the timeline to the Pulse Secure crisis—to plant malicious code on a VPN concentrator used for remote access to ICE’s corporate network. ICE maintained the follow-on intrusion was contained and unsuccessful relative to trading systems, but the SEC later fined the firm $10 million because ICE allegedly waited several days before cascading notices required under Regulation SCI to nine wholly owned subsidiaries, delaying independent SEC visibility into a critical-market infrastructure event.
Root cause
Edge VPN appliance compromise via zero-day exploitation (per SEC settlement narrative and contemporaneous reporting)