> Hackers used targeted social engineering to gain access to accounts of legitimate users, then emailed bosses promoting certain stocks.
> There was at least one instance when one firm noticed something was a bit amiss - but wasn't able to stop it.
> When info-security staff at the firm noticed the odd sign-in location, it locked Mr Aaron's account. Good security practice.