SEC Charges 4 Companies Over Misleading SolarWinds Cyber Attack Disclosures

Share:

The U.S. Securities and Exchange Commission (SEC) has charged four current and former public companies for making “materially misleading disclosures” related to the large-scale cyber attack that stemmed from the hack of SolarWinds in 2020.

The SEC said the companies – Avaya, Check Point, Mimecast, and Unisys – are being penalized for how they handled the disclosure process in the aftermath of the SolarWinds Orion software supply chain incident and downplaying the extent of the breach, thereby infringing the Securities Act of 1933, the Securities Exchange Act of 1934, and related rules under them.

To that end, Avaya will pay a fine of $1 million, Check Point will pay $995,000, Mimecast will pay $990,000, and Unisys will pay $4 million to settle the charges. In addition, the SEC has charged Unisys with disclosure controls and procedures violations.

“While public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered,” said Sanjay Wadhwa, acting director of the SEC’s Division of Enforcement.

“Here, the SEC’s orders find that these companies provided misleading disclosures about the incidents at issue, leaving investors in the dark about the true scope of the incidents.”

According to the SEC, all four companies learned the Russian threat actors behind the SolarWinds Orion hack had accessed their systems in an unauthorized manner, but chose to minimize the scope of the incident in their public disclosures.

Unisys, the independent federal agency said, chose to describe the risks arising as a result of the intrusion as “hypothetical” despite being aware of the fact that the cybersecurity events led to the exfiltration of more than 33 GB of data on two different occasions.

The investigation also found that Avaya stated the threat actor had accessed a “limited number” of the company’s email messages, when, in reality, it was aware that the attackers had also accessed at least 145 files in its cloud environment.

As for Check Point and Mimecast, the SEC took issue with how they painted the risks from the breach in broad strokes, with the latter also failing to disclose the nature of the code the threat actor exfiltrated and the number of encrypted credentials the threat actor accessed.

“In two of these cases, the relevant cybersecurity risk factors were framed hypothetically or generically when the companies knew the warned of risks had already materialized,” Jorge G. Tenreiro, acting chief of the Crypto Assets and Cyber Unit, said. “The federal securities laws prohibit half-truths, and there is no exception for statements in risk-factor disclosures.”

Ravie Lakshmanan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:49 pm, Feb 3, 2025
weather icon 8°C
L: 7° | H: 9°
overcast clouds
Humidity: 81 %
Pressure: 1024 mb
Wind: 7 mph SSE
Wind Gust: 9 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
7° | 9°°C 0 mm 0% 8 mph 97 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 9°°C 0.2 mm 20% 14 mph 98 % 1027 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 89 % 1044 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
3° | 8°°C 0 mm 0% 10 mph 86 % 1045 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
3° | 6°°C 0 mm 0% 14 mph 91 % 1039 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 8°°C 0 mm 0% 8 mph 86 % 1025 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 7°°C 0 mm 0% 5 mph 91 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 97 % 1024 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 5 mph 98 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 7°°C 0 mm 0% 7 mph 91 % 1023 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 95 % 1022 mb 0 mm/h
Tomorrow 9:00 am
weather icon
7° | 7°°C 0 mm 0% 11 mph 90 % 1023 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 13 mph 79 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€93,056.33
-3.53%
Ethereum(ETH)
€2,556.14
-14.59%
Tether(USDT)
€0.98
0.13%
XRP(XRP)
€2.36
-13.19%
Solana(SOL)
€193.14
-5.81%
USDC(USDC)
€0.98
0.00%
Dogecoin(DOGE)
€0.250408
-12.58%
Shiba Inu(SHIB)
€0.000015
-13.05%
Pepe(PEPE)
€0.000010
-19.54%
Scroll to Top