PhillipCapital, Maybank Kim Eng among brokerages hit by recent DDoS attacks

Published Thu, Oct 31, 2019 · 09:50 PM

Singapore

SPOKESPERSONS from PhillipCapital and Maybank Kim Eng have confirmed with The Business Times that brokers faced disruptions trying to access their trading platforms on the morning of Oct 24.

A third, sources said, is believed to be RHB Securities but it declined to comment on the matter.

A Monetary Authority of Singapore spokesperson told BT: "MAS has been informed that a small number of stock brokers had encountered distributed denial of service (DDoS) attacks on their online systems last week. There was limited disruption to the services of these stock brokers as they had activated their DDoS mitigation services."

Up to five brokerages in Singapore were said to have been hit with DDoS attacks last Thursday, sources said.

Responding to BT's queries, a PhillipCapital spokesperson said that Phillip Securities and Phillip Futures were both affected but "immediate and appropriate actions" were taken upon the occurrence to mitigate its impact.

"We are constantly monitoring our IT infrastructure and network capabilities to facilitate a smooth trading environment for customers," she added.

Meanwhile, Maybank Kim Eng said: "The impact was minimal as we swiftly mitigated the attack. At no point was the security of our clients' information, online trading or Web services compromised."

Following the disruptions, MAS also issued an advisory "to alert financial institutions of a heightened risk of DDoS activities and advised financial institutions to be on alert to monitor their IT environment for suspicious network activities".

The length of the disruptions varied between brokerages, ranging between 30 minutes to almost the entire duration of the Singapore market's early session.

A trader, who declined to be named, said he, along with some colleagues, were not able to access their brokerage's trading platform. Those that were able to faced "patchy or intermittent" connections.

Another recalled: "There was a short breakdown in connections. The IT department did not give us an explanation for the issue but they quickly restored services within an hour. I thought of it as a minor IT issue that can happen from time to time."

DDoS is a type of cyber attack where malicious players attempt to disrupt a server, service or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic.

The result of this is a temporary or indefinite disruption of the services of a host - in the case of last week's attacks, a trading platform - connected to the Internet.

With cyber attacks on the rise globally, MAS has taken steps with financial institutions operating in Singapore to ensure the resilience of the financial sector to cyber threats.

In August, the financial regulatory authority issued a set of legally binding requirements that sets out key measures that financial institutions must take to mitigate cyber threats.

Consumers too have a role to play in staying vigilant against such threats. "To safeguard their devices from being used as bots to launch DDoS attacks, consumers should adopt good cyber hygiene practices such as installing anti-malware software and updating security patches regularly," a MAS spokesman said.