22 June 2021

SolarWinds clients are facing probe from US SEC over cyber-breach disclosures


SolarWinds clients are facing probe from US SEC over cyber-breach disclosures

The U.S. Securities and Exchange Commission (SEC) has opened an investigation into last year's SolarWinds hack to determine whether some companies failed to disclose that they had been affected by the breach, Reuters reported, citing people familiar with the investigation.

According to the sources, the SEC sent investigative letters last week to a number of public issuers and investment firms seeking voluntary information on whether they had been victims of the hack and failed to disclose it.

In addition, the agency is seeking information on whether the affected companies had experienced a lapse of internal controls, and related information on insider trading. It also looks at the policies at certain companies to assess whether they are designed to protect customer information, according to Reuters.

U.S. securities law requires companies to disclose material information that could affect their share prices, including cyber breaches.

Companies that have provided details about the breaches would not face enforcement actions related to historical failures, including internal accounting control failures, the sources said.

While the letters are focused on the SolarWinds breach, the SEC may develop future policies on the impact of cyber security issues on the markets and on investors, the sources told Reuters.

Back to the list

Latest Posts

Cyber Security Week in Review: May 10, 2024

Cyber Security Week in Review: May 10, 2024

In brief: Google fixes yet another Chrome 0Day, Dell suffers a data breach, the LockBit leader identified, and more.
10 May 2024
Massive BogusBazaar fraud ring steals credit cards from thousands of victims

Massive BogusBazaar fraud ring steals credit cards from thousands of victims

As of April 2024, approximately 22,500 domains were active.
9 May 2024
Poland’s government institutions targeted in Russian cyberespionage campaign

Poland’s government institutions targeted in Russian cyberespionage campaign

The incident marks the latest in a string of Russian cyberattacks aimed at NATO-allied nations supporting Ukraine.
9 May 2024