By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
IndebtaIndebta
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Notification Show More
Aa
IndebtaIndebta
Aa
  • Banking
  • Credit Cards
  • Loans
  • Dept Management
  • Mortgage
  • Markets
  • Investing
  • Small Business
  • Videos
  • Home
  • News
  • Banking
  • Credit Cards
  • Loans
  • Mortgage
  • Investing
  • Markets
    • Stocks
    • Commodities
    • Crypto
    • Forex
  • Videos
  • More
    • Finance
    • Dept Management
    • Small Business
Follow US
Indebta > News > SolarWinds faces SEC lawsuit after 2020 hack
News

SolarWinds faces SEC lawsuit after 2020 hack

News Room
Last updated: 2023/10/30 at 10:37 PM
By News Room
Share
4 Min Read
SHARE

Stay informed with free updates

Simply sign up to the Cyber Security myFT Digest — delivered directly to your inbox.

SolarWinds, the IT company breached by Russian hackers as part of a sprawling espionage campaign in 2020, has been sued by the US Securities and Exchange Commission.

The SEC on Monday filed a complaint accusing the company and chief information security officer Tim Brown of misleading investors by not disclosing “known risks” and not accurately representing its cyber security measures.

“We allege that, for years, SolarWinds and Brown ignored repeated red flags about SolarWinds’ cyber risks, which were well known throughout the company and led one of Brown’s subordinates to conclude: ‘We’re so far from being a security minded company,’” Gurbir Grewal, director of the SEC’s enforcement division, said in a statement.

The alleged wrongdoing occurred from at least the company’s initial public offering in October 2018 to December 2020, when one of the biggest cyber attacks in recent history put a spotlight on what until then had been a little-known Austin-based supply chain company. Hackers backed by Russian intelligence exploited a SolarWinds software product in order to spy on businesses and government organisations globally, including the US commerce and Treasury departments.

A SolarWinds spokesperson said the company was “disappointed by the SEC’s unfounded charges”. Lawyers representing Brown said he had “performed his responsibilities at SolarWinds . . . with diligence, integrity, and distinction” and said they looked forward to “defending his reputation”.

The SEC’s action is the first time it has attempted to hold a chief information security officer personally liable for cyber security failures. Gary Gensler, SEC chair, has turned his focus to cyber risks, including proposing rules to broaden companies’ disclosures.

According to the complaint, Brown wrote in an internal presentation in 2018 that SolarWinds’ “current state of security leaves us in a very vulnerable state for our critical assets”. The deal’s IPO registration documents, however, had only mentioned “generic and hypothetical cyber security risk disclosures”, the SEC said.

A SolarWinds engineer told Brown in 2020 that he was “spooked” by activity at one of their customers, to which the executive replied saying the matter was “very concerning”, according to the complaint. “As you guys know our backends are not that resilient and we should definitely make them better,” he added, according to the complaint.

The complaint also quoted internal communications warning in 2020 that “[t]he volume of security issues being identified over the last month have outstripped the capacity of engineering teams to resolve”. 

The SEC alleged that these shortcomings were exploited in what it called “one of the worst cyber security incidents in history”, which unfolded between January 2019 and December 2020, according to the complaint.

A SolarWinds manager in November 2020 wrote in an instant message: “[E]very time I hear about our head geeks talking about security I want to throw up.”

Read the full article here

News Room October 30, 2023 October 30, 2023
Share this Article
Facebook Twitter Copy Link Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Finance Weekly Newsletter

Join now for the latest news, tips, and analysis about personal finance, credit cards, dept management, and many more from our experts.
Join Now
Jamie Dimon gets real at Davos.

Watch full video on YouTube

How The Iran War Is Impacting Travel

Watch full video on YouTube

President Trump speaks at the World Economic Forum

Watch full video on YouTube

Home Relistings Are Rocketing But Housing Supply Is Still Low

Watch full video on YouTube

Harbor Diversified International All Cap Fund Q4 2025 Commentary (HAIDX)

Harbor Capital is an asset manager focused on curating an intentionally select…

- Advertisement -
Ad imageAd image

You Might Also Like

News

Harbor Diversified International All Cap Fund Q4 2025 Commentary (HAIDX)

By News Room
News

RPV: This Pure Value ETF Is A Reliable Player For Uncertain Conditions And Long Term

By News Room
News

Intel shareholder claims board gave US an equity stake to avoid Trump’s social media attacks

By News Room
News

Oracle shares rally on strong revenue forecast from AI data centres

By News Room
News

There is no easy exit to Trump’s war

By News Room
News

The thing that everyone expected to happen has happened

By News Room
News

Lego chief hits out at Danish wealth tax proposal

By News Room
News

Iran hardliners cast slain supreme leader as martyr to rally regional allies

By News Room
Facebook Twitter Pinterest Youtube Instagram
Company
  • Privacy Policy
  • Terms & Conditions
  • Press Release
  • Contact
  • Advertisement
More Info
  • Newsletter
  • Market Data
  • Credit Cards
  • Videos

Sign Up For Free

Subscribe to our newsletter and don't miss out on our programs, webinars and trainings.

I have read and agree to the terms & conditions
Join Community

2023 © Indepta.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?