SEC just hit four companies with big fines for downplaying the SolarWinds hack

The Securities and Exchange Commission fined four companies on Tuesday with misleading investors about the impact the 2020 hack of SolarWinds had on their own systems.

Unisys, Avaya, Check Point, and Mimecast will each pay civil penalties to settle the agency’s charges that they downplayed the impacts of the hack through their respective public disclosures.

“While public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered,” Acting Director of the SEC’s Division of Enforcement Sanjay Wadhwa said in a statement.

In 2020, a Russian backed group planted malware in the SolarWinds system that sent out updates to SolarWinds’s Orion software. When several thousand of the company’s clients installed the update, they also unknowingly installed the malware. It ended up becoming one of the most destructive and costly cyberattacks in history, as NPR put it.

According to the SEC, Unisys, Avaya, and Check Point learned in 2020, and Mimecast learned in 2021, that the actor behind the hack had accessed their systems without authorization. Still, the SEC argued, each minimized the incident in public disclosures. The SEC said that Unisys also described its risk as hypothetical, when it already knew it had been breached twice.

Unisys will pay a $4 million civil penalty. Avaya will pay $1 million, Check Point will pay $995,000, and Mimecast will pay $990,000.

A Check Point spokesperson said: “As mentioned in the SEC’s order, Check Point investigated the SolarWinds incident and did not find evidence that any customer data, code, or other sensitive information was accessed. Nevertheless, Check Point decided that cooperating and settling the dispute with the SEC was in its best interest and allows the company to maintain its focus on helping its customers defend against cyberattacks throughout the world.”

An Avaya spokesperson made a similar comment. “We are pleased to have resolved with the SEC this disclosure matter related to historical cybersecurity issues dating back to late 2020, and that the agency recognized Avaya’s voluntary cooperation and that we took certain steps to enhance the company’s cybersecurity controls,” the spokesperson said. “Avaya continues to focus on strengthening its cybersecurity program, both in designing and providing our products and services to our valued customers, as well as in our internal operations.”

Spokespeople for Unisys and Mimecast did not immediately return Fast Company‘s requests for comment.

https://www.fastcompany.com/91215136/sec-just-hit-four-companies-with-big-fines-for-downplaying-the-solarwinds-hack?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Utworzony 7mo | 23 paź 2024, 19:20:03


Zaloguj się, aby dodać komentarz

Inne posty w tej grupie

Four free Coursera courses to jump-start your AI journey

Artificial intelligence: it’s not just for tech experts anymore. Instead, a heaping helping of free online resources has emerged. These classes are specifically designed to welcome beginners into

19 maj 2025, 05:20:03 | Fast company - tech
What the law says about buying property or protecting sites on the Moon

April 2025 was a busy month for space.

Pop icon Katy Perry

18 maj 2025, 08:30:02 | Fast company - tech
Traveling abroad? Skip Apple Maps and Google Maps. Try these apps instead

Americans often receive a lot of grief for being less internationally traveled than citizens of other countries. But in recent years, more Americans are traveling abroad than ever before. Numbers

17 maj 2025, 11:30:05 | Fast company - tech
Treat yourself to a taste of the weird web of yesteryear

The web wasn’t always like it is now. It used to be weirder—in a good way. And it still can be.

After all, we all occasionally need a tranquil break amidst a hectic day—be it a beautiful

17 maj 2025, 11:30:04 | Fast company - tech
TikTok wants to help people unplug, but not everyone wants a digital detox

Feeling like you’ve overdone it on the scrolling? Now you can take a break from TikTok to meditate—without ever leaving the app.

TikTok’s new in-app meditation feature,

16 maj 2025, 23:50:03 | Fast company - tech
OpenAI launches Codex, an AI agent for coding

OpenAI launched a research preview on Friday of what it’s calling its most capable AI coding agent yet.

Codex, a cloud-based sof

16 maj 2025, 19:20:04 | Fast company - tech