SEC fines tech companies for misleading SolarWinds disclosures

Teilen:

The Securities and Exchange Commission charged four current and former public companies – Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited – with making materially misleading disclosures regarding cybersecurity risks and intrusions. The SEC also charged Unisys with disclosure controls and procedures violations.

The charges against the four companies result from an investigation involving public companies potentially impacted by the compromise of SolarWinds’ Orion software and by other related activity.

The companies agreed to pay the following civil penalties to settle the SEC’s charges:

  • Unisys will pay a $4 million civil penalty;
  • Avaya. will pay a $1 million civil penalty;
  • Check Point will pay a $995,000 civil penalty; and
  • Mimecast will pay a $990,000 civil penalty.

The charges

According to the SEC’s orders, Unisys, Avaya, and Check Point learned in 2020, and Mimecast learned in 2021, that the threat actor likely behind the SolarWinds Orion hack had accessed their systems without authorization, but each negligently minimized its cybersecurity incident in its public disclosures.

The SEC’s order against Unisys finds that the company described its risks from cybersecurity events as hypothetical despite knowing that it had experienced two SolarWinds-related intrusions involving exfiltration of gigabytes of data. The order also finds that these materially misleading disclosures resulted in part from Unisys’ deficient disclosure controls.

The SEC’s order against Avaya finds that it stated that the threat actor had accessed a “limited number of [the] Company’s email messages,” when Avaya knew the threat actor had also accessed at least 145 files in its cloud file sharing environment.

The SEC’s order against Check Point finds that it knew of the intrusion but described cyber intrusions and risks from them in generic terms.

The order charging Mimecast finds that the company minimized the attack by failing to disclose the nature of the code the threat actor exfiltrated and the quantity of encrypted credentials the threat actor accessed.

“Downplaying the extent of a material cybersecurity breach is a bad strategy,” said Jorge G. Tenreiro, Acting Chief of the Crypto Assets and Cyber Unit. “In two of these cases, the relevant cybersecurity risk factors were framed hypothetically or generically when the companies knew the warned of risks had already materialized. The federal securities laws prohibit half-truths, and there is no exception for statements in risk-factor disclosures.”

The SEC’s orders find that each company violated certain applicable provisions of the Securities Act of 1933, the Securities Exchange Act of 1934, and related rules thereunder. Without admitting or denying the SEC’s findings, each company agreed to cease and desist from future violations of the charged provisions and to pay the penalties described above. Each company cooperated during the investigation, including by voluntarily providing analyses or presentations that helped expedite the staff’s investigation and by voluntarily taking steps to enhance its cybersecurity controls.

The SEC previously announced charges against SolarWinds and its CISO for overstating the company’s cybersecurity practices and understating or failing to disclose known cybersecurity risks, as well as failing to address those risks.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:29 am, Juni 26, 2025
Wetter-Symbol 21°C
L: 19° | H: 22°
broken clouds
Luftfeuchtigkeit: 73 %
Druck: 1010 mb
Wind: 16 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:44 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 22°°C 0.24 mm 24% 17 mph 73 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 13 mph 61 % 1021 mb 0 mm/h
Sa. Juni 28 10:00 pm
Wetter-Symbol
17° | 28°°C 0.2 mm 20% 10 mph 88 % 1025 mb 0 mm/h
So. Juni 29 10:00 pm
Wetter-Symbol
19° | 32°°C 0 mm 0% 6 mph 82 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 34°°C 0.2 mm 20% 12 mph 59 % 1019 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 13 mph 73 % 1010 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
20° | 21°°C 0.2 mm 20% 12 mph 73 % 1010 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
22° | 23°°C 0.24 mm 24% 17 mph 45 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 13 mph 35 % 1015 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 47 % 1018 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 57 % 1020 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 6 mph 61 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
17° | 17°°C 0 mm 0% 8 mph 59 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,454.41
1.30%
Ethereum(ETH)
€2,136.92
2.40%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.87
0.43%
Solana(SOL)
€124.55
-0.82%
USDC(USDC)
€0.86
-0.01%
Dogecoin(DOGE)
€0.141427
-0.63%
Shiba Inu(SHIB)
€0.000010
-0.23%
Pepe(PEPE)
€0.000009
-5.06%
Nach oben scrollen