Hackers use a new SEC rule to snitch on the company they infiltrated

A hacking group deployed a surprising tactic after infiltrating a financial software company’s network. They reported the breach to the US Securities and Exchange Commission (SEC).

DataBreaches.net initially reported on the incident, which was conducted by ALPHV / BlackCat, a group known for breaching entities as diverse as MGM Resorts and Reddit. The hackers reportedly breached the servers of fintech company MeridianLink on November 7, stealing company data without encrypting it. However, when the business neglected to negotiate directly, the hackers increased the pressure by filing a report with the SEC.

They did so citing a new rule the SEC passed this summer, which requires companies falling victim to “material cybersecurity incidents” to report them to the agency within four business days.

However, the four-day requirement may not have taken effect yet. At least one official form claims the rule kicked in 90 days after the date of publication in the Federal Register (they appear to have been published on August 4, making that alleged effective date November 2) or December 18. But the Federal Register document says, “With respect to compliance with the incident disclosure requirements in Item 1.05 of Form 8–K and in Form 6–K [the part referring to the four-day requirement], all registrants other than smaller reporting companies must begin complying on December 18, 2023.” Adding to the confusion, Reuters reported in October that the rule takes effect on December 15.

Engadget reached out to the SEC to clarify whether the rule is active yet. We’ll update this article if we hear back.

MeridianLink told BleepingComputer that it quickly worked to contain the threat. “Based on our investigation to date, we have identified no evidence of unauthorized access to our production platforms, and the incident has caused minimal business interruption,” the company wrote. The company says it’s still trying to determine if any consumer personal information was breached, promising to notify affected parties if it was.

Whether the SEC has any teeth (or desire) to do anything about MeridianLink’s failure to report the incident in four business days, the rule could, ironically, serve as a new tool for cyber attackers. Rather than contacting customers or making calls to tighten the grip and pressure companies to comply with their demands, perhaps they can now simply rat them out to Uncle Sam.

This article originally appeared on Engadget at https://www.engadget.com/hackers-use-a-new-sec-rule-to-snitch-on-the-company-they-infiltrated-201242292.html?src=rss https://www.engadget.com https://www.engadget.com/hackers-use-a-new-sec-rule-to-snitch-on-the-company-they-infiltrated-201242292.html?src=rss
созданный 1y | 16 нояб. 2023 г., 21:20:25


Войдите, чтобы добавить комментарий

Другие сообщения в этой группе

Here are the coolest cars at New York International Auto Show 2025

This year marks the 125th anniversary of the New York International Auto Show (NYIAS), and despite concerns over tariffs, there are still a lot of manufacturers here showing off new models includin

18 апр. 2025 г., 21:40:18 | Engadget
Google is trying to get college students hooked on AI with a free year of Gemini Advanced

Under no circumstances should you let AI do your schoolwork for you, but Google has decided to make that option a little bit easier for the next year. The company is

18 апр. 2025 г., 21:40:17 | Engadget
Blizzard explains hero bans ahead of their introduction in competitive Overwatch

Blizzard has finally shared

18 апр. 2025 г., 21:40:16 | Engadget
The Apple Sports app now lets users create and share game cards

The Apple Sports app just introduced a new feature called Game Card Sharing. This lets users generate digital game cards that carry information about a specific match. The cards can be generated fo

18 апр. 2025 г., 19:20:15 | Engadget
Celebrate the 35th anniversary of the Hubble Space Telescope with a gigantic tower of gas and dust

As part of their ongoing celebration of the Hubble Space Telescope's

18 апр. 2025 г., 19:20:14 | Engadget
The rhythm-infused adventure Unbeatable has a new demo for PC and PS5

In the latest evidence that indie games are often where you find the boldest creative choices, look no further than Unbeatable. The hand‑drawn rhythm adventure title — announced in 2020 an

18 апр. 2025 г., 19:20:12 | Engadget
The Kia EV4 makes its US debut at the 2025 New York Auto Show

Kia's first all-electric sedan, the 2026 EV4, is making its official debut in the US at the

18 апр. 2025 г., 17:10:15 | Engadget