ResourcesArticles

A small profit, a big lesson: the Bidstack insider dealing case

Bidstack's interim CFO leaked and traded on inside information about a video-game deal. The FCA fined him and his associate £108,731. Here is what compliance teams should take from the case.

11 August 2026

4 minutes

bidstack-insider-trading

A leak from the top

Bidstack's interim finance chief held the inside information, leaked it, and traded on it through an account in someone else's name. He is now one of two people fined by the FCA, in a case that will feel closer to home for anyone whose job is guarding price-sensitive information.

In December 2021, Bhavesh Hirani was the interim Chief Financial Officer of Bidstack Group Plc, an AIM-listed company that placed advertising inside video games. That role handed him inside information about a major deal Bidstack was about to sign with a large video-game publisher. Rather than guard it, he passed it to an associate, Dipesh Kerai, opened a trading account in Kerai's name, and used it to buy 1.3 million Bidstack shares before the deal was public.

When the announcement came, Bidstack's share price rose by more than 125%, and Kerai walked away with just over £9,000. On 10 February 2026 the Financial Conduct Authority (FCA) announced that it had fined the pair a combined £108,731: £56,000 for Hirani and £52,731 for Kerai, the latter figure including £9,260.74 of disgorged profit plus interest. Both breached Article 14 of the UK Market Abuse Regulation (MAR), which prohibits insider dealing and the unlawful disclosure of inside information.

The insider was the one guarding the information

A finance chief sits at the centre of exactly what MAR is built to protect: results, deals, financing, anything price-sensitive that the market has not yet seen. That is the whole reason the persons discharging managerial responsibilities (PDMR) regime exists, and why a CFO's own dealings are fenced in by closed periods and clearance requirements. Hirani did not stumble into a grey area at the edge of the rules. He took information he was trusted to hold, handed it to someone else, and built a way to trade on it without his own name on the account.

Opening the account in Kerai's name is the part that gives away the intent. Putting a layer between himself and the trade is not what someone does if they believe the dealing is allowed; it is what someone does when they understand the rule and try to route around it. Regulators read that distance for what it is, and the FCA treated the concealment as part of the conduct rather than as something to weigh in Hirani's favour.

How it surfaced

Kerai's trades came to light because a firm filed Suspicious Transaction and Order Reports (STORs), the mechanism MAR requires firms and trading venues to use when they spot possible market abuse. A block of 1.3 million shares bought in a small AIM company days before a price-sensitive announcement is precisely the pattern trade surveillance exists to flag, and once flagged it gave the FCA a thread to pull.

Steve Smart, the FCA's executive director of enforcement and market oversight, was direct about where the credit sat. "Big thanks to the firm that reported its suspicions, enabling us to identify the perpetrators and hold them to account," he said, adding that the pair "exploited inside information for their own gain, trading on details other investors couldn't have known." Enforcement rarely starts with the regulator watching a single screen. It starts with a firm's own surveillance flagging something that does not fit and filing the report.

Lessons

Two lessons carry over from a case like this, and neither depends on the size of the fine.

First, controls have to bite hardest on the people closest to the information. Insider lists, PDMR clearances and closed-period checks are not administrative box-ticking for the junior end of the business; they exist because the person with the most access is also the person best placed to misuse it. When the CFO is the insider, the control that matters is the one that records who held what, and when, without relying on that same person to be honest about it.

Second, the record is what gets tested afterwards. A STOR-triggered investigation works backwards: who had access to the inside information, when they were added to the insider list, when they were cleared or refused, what was disclosed and to whom. Keeping that trail current and timestamped is exactly the manual work InsiderList is built to remove, holding access records, clearances and disclosures in one place so the answer to "who knew, and when" is a query rather than an archaeology project.

Bidstack itself left AIM on 23 April 2024, but the obligations were live when the trades happened, and the penalties followed regardless. Inside information does not wait for a convenient moment, and neither does the FCA. The teams that come through these cases cleanly are the ones whose records were already in order before anyone came asking.

Sources: FCA press release, 10 February 2026; Final Notices for Dipesh Kerai and Bhavesh Hirani.

Leading compliance teams use InsiderList.

Schedule a product demo to see why.