Practice

What an insider trading case and an FBI advisory imply for deal room access

The SEC has charged 21 individuals in an alleged insider trading scheme built on confidential M&A material misappropriated from multiple global law firms. Separately, the FBI has warned that a criminal group is phoning law firm staff while posing as internal IT in order to obtain remote access. The two are unrelated, but both come down to how much confidential material a single ordinary account can reach, which is a question about how deal rooms are compartmented.

By the CogniSuite team

What the SEC alleges about how deal material was reached

The SEC announced charges on 6 May 2026 against 21 individuals over an alleged insider trading scheme, filed in the U.S. District Court for the District of Massachusetts. The complaint alleges that an M&A attorney misappropriated material nonpublic information belonging to his firm's clients, relating to more than twelve pending corporate transactions, and that he or a co-defendant passed it to others who kicked back a share of their trading profits or tipped further people who traded. The SEC says the alleged conduct produced millions of dollars in illicit profits, and the U.S. Attorney's Office for the same district brought parallel criminal charges.

These are allegations and nothing has been proven. The lead defendant has pleaded not guilty, and every defendant is entitled to contest the charges.

For anyone running a transaction, the route of access matters more than the trading. Reporting on the complaint has focused on the document management systems at the firms where he worked, including material relating to matters he was allegedly not staffed on. Nothing there requires a technical compromise. It describes valid credentials reaching confidential matters that were not the holder's to see.

What the FBI advisory says about attackers posing as IT support

FLASH-20260526-01, issued 26 May 2026, describes the Silent Ransom Group, also tracked as Luna Moth, Chatty Spider and UNC3753. The FBI says the group calls staff directly, or sends phishing emails designed to make the recipient call back, and then poses as internal IT support. While on the phone, the actor directs the employee to grant access to a remote desktop session. Where that fails, the FBI says the group has sent someone to the victim's location to insert a storage device, telling the employee the device needs to be imaged or backed up to address the effects of the phishing email.

The FBI states the group has consistently targeted US-based law firms since spring 2023 and has been active since at least 2022, with victims also in insurance, finance and healthcare. The operation is data theft and extortion without encryption. Because the actors use legitimate remote administration tools, the advisory notes that conventional antivirus is unlikely to flag the intrusion.

One line matters more than the rest for access design. The FBI says that once the actors obtain access, they minimally escalate privileges and pivot quickly to exfiltration. The attacker does not need to become an administrator, because whatever the person on the phone could already reach is usually enough.

Why both cases point at the reach of a single account

As threats these have little in common. One is an alleged insider, the other an external group running a phone script.

They converge on one variable. The alleged insider trading conduct is described as taking place through valid credentials, reaching matters the holder was allegedly not staffed on. In the FBI advisory, the attacker deliberately stays inside the compromised person's existing privileges. In both, the confidential material at risk is set by how much one ordinary account could reach on an ordinary day. The same control helps in both cases, so you do not have to predict which one you are facing.

What compartmenting deal material looks like in practice

Scope by matter, not by firm. Working at the advisor should not imply reach into every live mandate, and being on one deal team should not imply reach into another.

Separate the internal working set from what the other side sees, and make that the starting position rather than something a person configures under time pressure.

Set an access grade rather than treating access as a single yes or no. Whether someone can read a folder and whether they can take the file away are two different decisions, and treating them as one is a common way material leaves a room.

Scope to the organisation and to the person. With several bidders in a room, one bidder's folder should not be reachable by another.

Make the result checkable before documents go in, and keep a record of access that someone will read.

How CogniSuite scopes access to a deal, a folder and a party

Each deal is a separate database served from its own subdomain, with its own users, sessions, access grants and audit trail. A session on one deal is not a session on another. Document reads and AI retrieval are scoped to that deal's database, so reaching across deals is a property of the layout rather than a rule that has to hold.

Within a deal, every folder resolves to one of four grades for a given person: full, watermark, view or none, plus a separate right to upload. A per-user setting overrides a per-organisation setting, which overrides what the parent folder grants, which falls back to the organisation default. A folder scoped to one specific organisation is readable by that organisation alone rather than by every buyer, and if no visibility is set anywhere up the tree it resolves to internal rather than open.

The room also knows which side you represent, so on a buy-side mandate it is the seller who is the counterparty. The counterparty is kept out of the internal room by default. That is a default rather than a hard block, so a deal team can still open a particular internal folder to the other side on purpose.

Download is enforced separately from reading. A view-only folder opens in the viewer, but its bytes are not exported through a file download, through the raw stream the viewer uses, or inside a bulk ZIP. Watermarks are applied when a file is served rather than stored, and carry the viewer's name, organisation and a UTC timestamp.

The AI features use the same permission check. Retrieval applies the folder rules before a document can enter an answer, so the assistant cannot surface something the person asking is not cleared to read. Where a draft will be shown to the other side, grounding is restricted to what every counterparty organisation that can see that request list may read. A team member can also view the room as a specific counterparty organisation, with the permission engine resolving against that organisation rather than hiding things in the interface. See /security for detail.

What a permission model does not solve

It does not stop authorised access. Someone staffed on a matter can read that matter. Compartmenting reduces how many people can reach a given deal, but it will not tell you that a properly credentialed person is reading something for the wrong reason. That remains a supervision problem.

It does not authenticate. The FBI advisory describes someone being talked into handing over a live session. After that the platform sees an authorised user doing authorised things. Scoping limits how much that session reaches, but defending the phone call, the endpoint and the help desk is work that happens at your firm, not in a data room.

Records are only worth what you do with them. An access trail nobody reviews changes nothing after the fact, and the value of any log depends on how well it is protected against alteration. Watermarking is similar. It shows who was served a copy, but it does not survive a photograph, a screenshot or retyping, and coverage varies by file format.

Defaults decide most of this in practice. Broad permissions are convenient during setup, and a room run entirely on defaults has all of the scoping above available and none of it in effect.

One limit is worth stating plainly. AI retrieval admits any folder the person can read at all, including the view-only and watermark tiers. A verbatim quote can therefore appear in an answer drawn from a document that person may view but not download. If that distinction matters for a folder, set that party's access to none rather than view.

None of this makes a compromise impossible. What it changes is how much of a transaction one ordinary account can reach when a compromise happens.

This article is general information, not legal, tax, or financial advice. For how CogniSuite handles security and access, see Security.

← All articles