SEC just hit four companies with big fines for downplaying the SolarWinds hack

The Securities and Exchange Commission fined four companies on Tuesday with misleading investors about the impact the 2020 hack of SolarWinds had on their own systems.

Unisys, Avaya, Check Point, and Mimecast will each pay civil penalties to settle the agency’s charges that they downplayed the impacts of the hack through their respective public disclosures.

“While public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered,” Acting Director of the SEC’s Division of Enforcement Sanjay Wadhwa said in a statement.

In 2020, a Russian backed group planted malware in the SolarWinds system that sent out updates to SolarWinds’s Orion software. When several thousand of the company’s clients installed the update, they also unknowingly installed the malware. It ended up becoming one of the most destructive and costly cyberattacks in history, as NPR put it.

According to the SEC, Unisys, Avaya, and Check Point learned in 2020, and Mimecast learned in 2021, that the actor behind the hack had accessed their systems without authorization. Still, the SEC argued, each minimized the incident in public disclosures. The SEC said that Unisys also described its risk as hypothetical, when it already knew it had been breached twice.

Unisys will pay a $4 million civil penalty. Avaya will pay $1 million, Check Point will pay $995,000, and Mimecast will pay $990,000.

A Check Point spokesperson said: “As mentioned in the SEC’s order, Check Point investigated the SolarWinds incident and did not find evidence that any customer data, code, or other sensitive information was accessed. Nevertheless, Check Point decided that cooperating and settling the dispute with the SEC was in its best interest and allows the company to maintain its focus on helping its customers defend against cyberattacks throughout the world.”

An Avaya spokesperson made a similar comment. “We are pleased to have resolved with the SEC this disclosure matter related to historical cybersecurity issues dating back to late 2020, and that the agency recognized Avaya’s voluntary cooperation and that we took certain steps to enhance the company’s cybersecurity controls,” the spokesperson said. “Avaya continues to focus on strengthening its cybersecurity program, both in designing and providing our products and services to our valued customers, as well as in our internal operations.”

Spokespeople for Unisys and Mimecast did not immediately return Fast Company‘s requests for comment.

https://www.fastcompany.com/91215136/sec-just-hit-four-companies-with-big-fines-for-downplaying-the-solarwinds-hack?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Létrehozva 7mo | 2024. okt. 23. 19:20:03


Jelentkezéshez jelentkezzen be

EGYÉB POSTS Ebben a csoportban

TikTok wants to help people unplug, but not everyone wants a digital detox

Feeling like you’ve overdone it on the scrolling? Now you can take a break from TikTok to meditate—without ever leaving the app.

TikTok’s new in-app meditation feature,

2025. máj. 16. 23:50:03 | Fast company - tech
OpenAI launches Codex, an AI agent for coding

OpenAI launched a research preview on Friday of what it’s calling its most capable AI coding agent yet.

Codex, a cloud-based sof

2025. máj. 16. 19:20:04 | Fast company - tech
How NFL teams turn schedule reveals into viral social media moments

For NFL teams’ social media departments, May 14 is the Super Bowl.

NFL Schedule Release Day has become an unofficial holiday on the league calendar. All 32 teams unveil their season sche

2025. máj. 16. 19:20:03 | Fast company - tech
Meet the startup taking on Nintendo, Xbox, and PlayStation

Switch, PS5, and XBox might be the biggest names in video games, but David Lee and a group of entrepreneurial alums from companies like Apple, Google, Microsoft, and Meta are carving out a niche m

2025. máj. 16. 14:40:04 | Fast company - tech
Who invented Facebook’s Like button? It’s complicated, say the authors of this new book

The internet wouldn’t be the same without the Like button, the thumbs-

2025. máj. 16. 14:40:03 | Fast company - tech
For this CVS Health developer, making tech more accessible is personal

Cory Joseph has been blind since birth. So he’s among the people Apple aims to serve with an addition to its App Store called “Accessibility Nutrition Labels,” one of a raft of features the compan

2025. máj. 16. 12:20:05 | Fast company - tech