SEC Charges Four Companies With Misleading Cyber Disclosures
The SEC charged Unisys, Avaya, Check Point, and Mimecast with misleading disclosures regarding SolarWinds-related cyberattacks, resulting in combined civil penalties of nearly $7 million.
Unisys, Avaya, Check Point, and Mimecast settled SEC charges for making materially misleading disclosures about cybersecurity intrusions linked to the SolarWinds Orion hack. The companies face penalties of $4 million, $1 million, $995,000, and $990,000 respectively, with Unisys also charged with disclosure control violations. These enforcement actions address violations of the Securities Act of 1933 and the Securities Exchange Act of 1934.
The SEC charged four companies—Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited—with making materially misleading disclosures regarding cybersecurity breaches related to the SolarWinds Orion hack. While Unisys, Avaya, and Check Point learned of their intrusions in 2020 and Mimecast in 2021, each company negligently minimized the scope of the unauthorized access in public filings. Unisys was additionally charged with disclosure control violations for framing realized risks as hypothetical despite significant data exfiltration. To settle the charges, Unisys will pay $4 million, Avaya $1 million, Check Point $995,000, and Mimecast $990,000. Each company agreed to cease and desist from future violations without admitting or denying the findings. All four firms cooperated during the investigation and took steps to enhance their cybersecurity controls.
Exhibits & Attached Documents (4)
Extracted insights
- $4.00M $4 million $1M–$10M
- $1.00M $1 million $1M–$10M
- $995K $995,000 $100K–$1M
- $990K $990,000 $100K–$1M
- person check point
- agency civil penalties to settle the sec’s charges
- company each company
- person Jorge G. Tenreiro
- person Sanjay Wadhwa
- agency the sec’s investigation involving the four companies
- agency the sec’s order against avaya
- agency the sec’s order against check point
- agency the sec’s order against unisys
- agency the sec’s orders
- agency the securities and exchange commission
- The Securities and Exchange Commission charged four current and former public companies
- The Securities and Exchange Commission charged Unisys with disclosure controls and procedures violations
- The companies agreed to pay civil penalties to settle the SEC’s charges
- Unisys will pay a $4 million civil penalty
- Avaya will pay a $1 million civil penalty
- Check Point will pay a $995,000 civil penalty
- Mimecast will pay a $990,000 civil penalty
- The charges against the four companies result from an investigation involving public companies potentially impacted by the compromise of SolarWinds’ Orion software and by other related activity
- Sanjay Wadhwa said As today’s enforcement actions reflect, while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered
- The SEC’s orders find these companies provided misleading disclosures about the incidents at issue, leaving investors in the dark about the true scope of the incidents
- Unisys, Avaya, and Check Point learned in 2020
- Mimecast learned in 2021
- The SEC’s order against Unisys finds the company described its risks from cybersecurity events as hypothetical despite knowing that it had experienced two SolarWinds-related intrusions involving exfiltration of gigabytes of data
- The order finds these materially misleading disclosures resulted in part from Unisys’ deficient disclosure controls
- The SEC’s order against Avaya finds it stated that the threat actor had accessed a “limited number of [the] Company’s email messages,” when Avaya knew the threat actor had also accessed at least 145 files in its cloud file sharing environment
- The SEC’s order against Check Point finds it knew of the intrusion but described cyber intrusions and risks from them in generic terms
- The order charging Mimecast finds the company minimized the attack by failing to disclose the nature of the code the threat actor exfiltrated and the quantity of encrypted credentials the threat actor accessed
- Jorge G. Tenreiro said Downplaying the extent of a material cybersecurity breach is a bad strategy
- The SEC’s orders find each company violated certain applicable provisions of the Securities Act of 1933, the Securities Exchange Act of 1934, and related rules thereunder
- Each company agreed to cease and desist from future violations of the charged provisions
- Each company agreed to pay the penalties described above
- Each company cooperated during the investigation, including by voluntarily providing analyses or presentations that helped expedite the staff’s investigation and by voluntarily taking steps to enhance its cybersecurity controls
- The SEC’s investigation involving the four companies was conducted by Arsen Ablaev and Michael Baker of the Crypto Assets and Cyber Unit (CACU) and David D’Addio in the Boston Regional Office
- It was supervised by Amy Flaherty Hartman and Mr. Tenreiro of the CACU and Kathryn A. Pyszka of the Chicag
The Securities and Exchange Commission today charged four current and former public companies – Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited – with making materially misleading disclosures regarding cybersecurity risks and intrusions. The SEC also charged Unisys with disclosure controls and procedures violations. The companies agreed to pay the following civil penalties to settle the SEC’s charges: Unisys will pay a $4 million civil penalty; Avaya. will pay a $1 million civil penalty; Check Point will pay a $995,000 civil penalty; and Mimecast will pay a $990,000 civil penalty. The charges against the four companies result from an investigation involving public companies potentially impacted by the compromise of SolarWinds’ Orion software and by other related activity. “As today’s enforcement actions reflect, while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered,” said Sanjay Wadhwa, Acting Director of the SEC’s Division of Enforcement. “Here, the SEC’s orders find that these companies provided misleading disclosures about the incidents at issue, leaving investors in the dark about the true scope of the incidents.” According to the SEC’s orders, Unisys, Avaya, and Check Point learned in 2020, and Mimecast learned in 2021, that the threat actor likely behind the SolarWinds Orion hack had accessed their systems without authorization, but each negligently minimized its cybersecurity incident in its public disclosures. The SEC’s order against Unisys finds that the company described its risks from cybersecurity events as hypothetical despite knowing that it had experienced two SolarWinds-related intrusions involving exfiltration of gigabytes of data. The order also finds that these materially misleading disclosures resulted in part from Unisys’ deficient disclosure controls. The SEC’s order against Avaya finds that it stated that the threat actor had accessed a “limited number of [the] Company’s email messages,” when Avaya knew the threat actor had also accessed at least 145 files in its cloud file sharing environment. The SEC’s order against Check Point finds that it knew of the intrusion but described cyber intrusions and risks from them in generic terms. The order charging Mimecast finds that the company minimized the attack by failing to disclose the nature of the code the threat actor exfiltrated and the quantity of encrypted credentials the threat actor accessed. “Downplaying the extent of a material cybersecurity breach is a bad strategy,” said Jorge G. Tenreiro, Acting Chief of the Crypto Assets and Cyber Unit. “In two of these cases, the relevant cybersecurity risk factors were framed hypothetically or generically when the companies knew the warned of risks had already materialized. The federal securities laws prohibit half-truths, and there is no exception for statements in risk-factor disclosures.” The SEC’s orders find that each company violated certain applicable provisions of the Securities Act of 1933, the Securities Exchange Act of 1934, and related rules thereunder. Without admitting or denying the SEC’s findings, each company agreed to cease and desist from future violations of the charged provisions and to pay the penalties described above. Each company cooperated during the investigation, including by voluntarily providing analyses or presentations that helped expedite the staff’s investigation and by voluntarily taking steps to enhance its cybersecurity controls. The SEC’s investigation involving the four companies was conducted by Arsen Ablaev and Michael Baker of the Crypto Assets and Cyber Unit (CACU) and David D’Addio in the Boston Regional Office. It was supervised by Amy Flaherty Hartman and Mr. Tenreiro of the CACU and Kathryn A. Pyszka of the Chicago Regional Office.
The Securities and Exchange Commission today charged four current and former public companies – Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited – with making materially misleading disclosures regarding cybersecurity risks and intrusions. The SEC also charged Unisys with disclosure controls and procedures violations. The companies agreed to pay the following civil penalties to settle the SEC’s charges: Unisys will pay a $4 million civil penalty; Avaya. will pay a $1 million civil penalty; Check Point will pay a $995,000 civil penalty; and Mimecast will pay a $990,000 civil penalty. The charges against the four companies result from an investigation involving public companies potentially impacted by the compromise of SolarWinds’ Orion software and by other related activity. “As today’s enforcement actions reflect, while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered,” said Sanjay Wadhwa, Acting Director of the SEC’s Division of Enforcement. “Here, the SEC’s orders find that these companies provided misleading disclosures about the incidents at issue, leaving investors in the dark about the true scope of the incidents.” According to the SEC’s orders, Unisys, Avaya, and Check Point learned in 2020, and Mimecast learned in 2021, that the threat actor likely behind the SolarWinds Orion hack had accessed their systems without authorization, but each negligently minimized its cybersecurity incident in its public disclosures. The SEC’s order against Unisys finds that the company described its risks from cybersecurity events as hypothetical despite knowing that it had experienced two SolarWinds-related intrusions involving exfiltration of gigabytes of data. The order also finds that these materially misleading disclosures resulted in part from Unisys’ deficient disclosure controls. The SEC’s order against Avaya finds that it stated that the threat actor had accessed a “limited number of [the] Company’s email messages,” when Avaya knew the threat actor had also accessed at least 145 files in its cloud file sharing environment. The SEC’s order against Check Point finds that it knew of the intrusion but described cyber intrusions and risks from them in generic terms. The order charging Mimecast finds that the company minimized the attack by failing to disclose the nature of the code the threat actor exfiltrated and the quantity of encrypted credentials the threat actor accessed. “Downplaying the extent of a material cybersecurity breach is a bad strategy,” said Jorge G. Tenreiro, Acting Chief of the Crypto Assets and Cyber Unit. “In two of these cases, the relevant cybersecurity risk factors were framed hypothetically or generically when the companies knew the warned of risks had already materialized. The federal securities laws prohibit half-truths, and there is no exception for statements in risk-factor disclosures.” The SEC’s orders find that each company violated certain applicable provisions of the Securities Act of 1933, the Securities Exchange Act of 1934, and related rules thereunder. Without admitting or denying the SEC’s findings, each company agreed to cease and desist from future violations of the charged provisions and to pay the penalties described above. Each company cooperated during the investigation, including by voluntarily providing analyses or presentations that helped expedite the staff’s investigation and by voluntarily taking steps to enhance its cybersecurity controls. The SEC’s investigation involving the four companies was conducted by Arsen Ablaev and Michael Baker of the Crypto Assets and Cyber Unit (CACU) and David D’Addio in the Boston Regional Office. It was supervised by Amy Flaherty Hartman and Mr. Tenreiro of the CACU and Kathryn A. Pyszka of the Chicago Regional Office.