When federal investigators began noticing suspicious trading ahead of major corporate acquisitions, they initially suspected something that had become familiar territory in white-collar enforcement: foreign hackers had likely penetrated elite American law firms.
The trades were too accurate. The timing was too precise. Again and again, confidential merger activity inside some of the country’s most prestigious firms appeared to leak into the market shortly before public announcements. According to The Wall Street Journal, investigators first believed the pattern resembled earlier cases involving overseas cybercriminals who targeted law firms to steal sensitive M&A intelligence.
That assumption made sense. Law firms sit at the center of the modern financial system. They possess advance knowledge of acquisitions, tender offers, restructurings, activist campaigns, and billion-dollar negotiations long before investors or regulators ever see them. A successful breach of even one major firm can produce information capable of generating enormous profits.
But prosecutors now allege the source of the leak was not a foreign hacking operation at all.
According to the SEC and federal prosecutors, the information was allegedly coming from inside the firms themselves.
At the center of the case is Nicolo Nourafchan, a Yale Law School graduate and former associate at Sidley Austin, Latham & Watkins, and Goodwin Procter. Prosecutors allege Nourafchan spent years exploiting access to confidential deal information and feeding it into an expanding network of traders spread across New York, Florida, California, Russia, and Israel.
What separates this case from ordinary insider-trading prosecutions are the details now emerging from the SEC complaint and the Journal’s reporting.
According to the SEC filing, Nourafchan allegedly described to another lawyer how he searched internal document-management systems using keywords tied to mergers and acquisitions and then viewed files in “preview” or “read-only” mode to reduce the likelihood of creating an electronic trail. Prosecutors allege he accessed signing checklists, merger agreements, board materials, SEC drafts, diligence trackers, and transaction timelines connected to deals he was never assigned to handle.
If true, it represents a very different kind of threat than the one investigators initially feared.
This was not an outsider forcing his way into the system. It was allegedly someone already inside the building, using legitimate credentials and institutional trust as the mechanism of access.
The Wall Street Journal added another revealing detail that had not previously surfaced publicly: investigators allegedly came to believe Nourafchan’s movement between elite firms may itself have been strategic. One participant allegedly remarked that Nourafchan “just only works in these types of firms,” while another responded: “Genius.”
The Journal also reported that after leaving Goodwin, Nourafchan allegedly attempted to secure employment at a public-relations firm that worked on mergers, supposedly hoping to continue accessing transaction intelligence from another corner of the deal ecosystem.
That allegation changes the character of the story. Prosecutors are not describing isolated misconduct or a few bad trades. They are describing what they believe was a long-running intelligence operation built around access to confidential corporate information.
The SEC complaint reconstructs the alleged information flow in extraordinary detail.
In one example involving Johnson & Johnson’s planned acquisition of Momenta Pharmaceuticals, prosecutors allege Nourafchan accessed confidential files related to “Project Mars,” including merger agreements and board materials. Soon afterward, prosecutors allege a series of calls and coded messages spread through the network, followed by highly suspicious options trading.
The communications themselves sound less like Wall Street jargon and more like coded operational language.
Deals were allegedly referred to as “flights.” Sharing information became “learning.” Pending announcements were discussed as whether a “rabbi” was scheduled for “surgery.” In one exchange involving Amazon’s planned acquisition of iRobot, traders allegedly panicked because the deal announcement had not yet occurred. One participant allegedly asked whether they should tell people to “pull out” because there was “no movement on the situation.”
There are also moments in the complaint that prosecutors will almost certainly use to show awareness of wrongdoing.
In July 2022, according to the SEC filing, Brian Fensterszaub allegedly forwarded a news article about insider-trading prosecutions to his brother Mark. Mark allegedly responded by sending Google search results for the phrase “insider trading definition.”
The government further alleges participants used prepaid phones, encrypted messaging apps, in-person meetings, and coded terminology to avoid detection. Some payments were allegedly disguised as business loans. Prosecutors also allege trades were routed through shell entities in the British Virgin Islands and Panama.

The most important detail in the entire story may still be the first one: investigators initially believed they were dealing with foreign hackers.
That fact alone illustrates how unusual the trading activity allegedly appeared. The patterns were reportedly so consistent and so closely tied to elite law firms that investigators assumed someone had penetrated the firms from the outside.
Instead, prosecutors now allege the compromise may have come from lawyers already trusted to guard the information.
If the allegations are true, the lesson is uncomfortable. The greatest vulnerability inside elite institutions may not always be the outsider trying to break through the perimeter.
Sometimes it is the insider who already has the keys.
