The Securities and Exchange Commission fined four companies on Tuesday with misleading investors about the impact the 2020 hack of SolarWinds had on their own systems.
Unisys, Avaya, Check Point, and Mimecast will each pay civil penalties to settle the agency’s charges that they downplayed the impacts of the hack through their respective public disclosures.
“While public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered,” Acting Director of the SEC’s Division of Enforcement Sanjay Wadhwa said in a statement.
In 2020, a Russian backed group planted malware in the SolarWinds system that sent out updates to SolarWinds’s Orion software. When several thousand of the company’s clients installed the update, they also unknowingly installed the malware. It ended up becoming one of the most destructive and costly cyberattacks in history, as NPR put it.
According to the SEC, Unisys, Avaya, and Check Point learned in 2020, and Mimecast learned in 2021, that the actor behind the hack had accessed their systems without authorization. Still, the SEC argued, each minimized the incident in public disclosures. The SEC said that Unisys also described its risk as hypothetical, when it already knew it had been breached twice.
Unisys will pay a $4 million civil penalty. Avaya will pay $1 million, Check Point will pay $995,000, and Mimecast will pay $990,000.
A Check Point spokesperson said: “As mentioned in the SEC’s order, Check Point investigated the SolarWinds incident and did not find evidence that any customer data, code, or other sensitive information was accessed. Nevertheless, Check Point decided that cooperating and settling the dispute with the SEC was in its best interest and allows the company to maintain its focus on helping its customers defend against cyberattacks throughout the world.”
An Avaya spokesperson made a similar comment. “We are pleased to have resolved with the SEC this disclosure matter related to historical cybersecurity issues dating back to late 2020, and that the agency recognized Avaya’s voluntary cooperation and that we took certain steps to enhance the company’s cybersecurity controls,” the spokesperson said. “Avaya continues to focus on strengthening its cybersecurity program, both in designing and providing our products and services to our valued customers, as well as in our internal operations.”
Spokespeople for Unisys and Mimecast did not immediately return Fast Company‘s requests for comment.
Login to add comment
Other posts in this group
![The destruction going on at U.S. government sites is bad news for us all](https://www.cdn5.niftycent.com/a/k/8/y/4/G/n/the-destruction-going-on-at-u-s-government-sites-is-bad-news-for-us-all.webp)
Earlier this week, a doctor friend told me about a frustrating new obstacle he’s facing at work. In normal times, he’s relied on websites operated by the U.S. federal government for practical info
![Why this cybersecurity startup wants to watermark everything](https://www.cdn5.niftycent.com/a/k/o/6/K/W/5/why-this-cybersecurity-startup-wants-to-watermark-everything.webp)
Cybersecurity startup EchoMark is releasing a new application programming interface (API) to allow for its novel digital watermarking tool to integrate with virtually any existing communications s
![LinkedIn’s big bet on TikTok-style video is paying off in a big way](https://www.cdn5.niftycent.com/a/1/x/K/z/B/v/linkedin-s-big-bet-on-tiktok-style-video-is-paying-off-in-a-big-way.webp)
Is LinkedIn the new TikTok?
Short-form video is now the fastest-growing category on LinkedIn, growing at twice the rate of other post formats on the platform. According to LinkedIn
![Robinhood halts Super Bowl betting contracts after CFTC request](https://www.cdn5.niftycent.com/a/e/b/9/r/V/v/robinhood-halts-super-bowl-betting-contracts-after-cftc-request.webp)
Robinhood said on Tuesday it is rolling back the event contracts that would let users bet on the result of the
![The value of Trump’s memecoin has dropped more than 75% since inauguration](https://www.cdn5.niftycent.com/a/e/7/v/N/q/z/the-value-of-trump-s-memecoin-has-dropped-more-than-75-since-inauguration.webp)
Donald Trump drew plenty of criticism by launching his own branded memecoin three days before his
![You can try DeepSeek’s R1 through Perplexity—without the security risk](https://www.cdn5.niftycent.com/a/1/Y/r/A/R/9/you-can-try-deepseek-s-r1-through-perplexity-without-the-security-risk.webp)
The AI search firm Perplexity routinely lets users try out state-of-the-art large language models on its site, but the company moved quickly to put Chinese company DeepSeek’s new R1 model front an
![What’s behind Nintendo’s 42% drop in profits?](https://www.cdn5.niftycent.com/a/D/P/d/9/Y/b/what-s-behind-nintendo-s-42-drop-in-profits.webp)
Nintendo’s profits tumbled as sales of its Switch console lost momentum, prompting the