2024-05-22 SEC Press press_release 63 KB 3,767 chars

SEC Charges Intercontinental Exchange and Nine Affiliates Including the New York Stock Exchange With Failing to Inform the Commission of a Cyber Intrusion

Release
2024-63
Caption
Securities and Exchange Commission v. Commission Staff, et al.
summary

The Intercontinental Exchange, Inc. (ICE) agreed to pay a $10 million penalty to settle SEC charges for causing nine subsidiaries to fail in timely reporting a 2021 cyber intrusion.

paragraph

The SEC charged ICE with causing nine subsidiaries, including the New York Stock Exchange, to violate Regulation SCI notification requirements following a 2021 VPN cyber intrusion. ICE failed to notify its subsidiaries of the breach for several days, preventing them from meeting mandatory disclosure obligations. The settlement involves a $10 million penalty and a cease-and-desist order without admitting or denying the findings.

narrative

The Securities and Exchange Commission announced that The Intercontinental Exchange, Inc. (ICE) will pay a $10 million penalty to settle charges regarding a 2021 cyber intrusion. The SEC found that ICE caused nine of its wholly-owned subsidiaries, including the New York Stock Exchange, to fail in timely notifying the Commission of a breach involving malicious code in a VPN device. Due to internal communication failures, ICE personnel did not inform subsidiary officials of the intrusion for several days, violating Regulation SCI. This delay prevented the subsidiaries from fulfilling their independent regulatory obligations to immediately report the event to the SEC. The settlement includes a cease-and-desist order for ICE and its subsidiaries, which include NYSE Arca, NYSE Chicago, and ICE Clear Credit. ICE and its subsidiaries consented to the order without admitting or denying the SEC's findings.

Enriched metadata

Scheme
cyber-fraud (95%)
Outcome
settled
Settlement
$10,000,000
Civil penalty
$10,000,000
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
commission staffentry of the sec’s order finding violations of notification provisionsice personnelsec of the intrusionthe sec’s investigation
Keywords
seciceexchangeintrusionstock exchangecybersubsidiariessciorderintercontinental exchangecyber intrusionstockincincludingnew

Exhibits & Attached Documents (1)

Extracted insights

Dollar amounts 1
  • $10.00M $10 million $10M–$100M
Entities 5
  • person commission staff
  • agency entry of the sec’s order finding violations of notification provisions
  • person ice personnel
  • agency sec of the intrusion
  • agency the sec’s investigation
Triples 9
  • The Intercontinental Exchange, Inc. (ICE) Agreed To Pay $10 Million Penalty
  • A Third Party Informed ICE That ICE Was Potentially Impacted By A System Intrusion
  • ICE Determined Threat Actor Had Inserted Malicious Code Into A VPN Device
  • ICE Personnel Did Not Notify Legal And Compliance Officials At ICE’s Subsidiaries Of The Intrusion
  • The Respondents Failed To Notify SEC Of The Intrusion
  • Commission Staff Contacted Respondents In The Process Of Assessing Reports Of Similar Cyber Vulnerabilities
  • ICE And Its Subsidiaries Consented To Entry Of The SEC’s Order Finding Violations Of Notification Provisions
  • ICE And Its Subsidiaries Agreed To Cease-And-Desist Order In Addition To Monetary Penalty
  • The SEC’s Investigation Was Conducted By Benjamin D. Brutlag And Lory C. Stone
PDF (from attached: pdf)
Text layers
Extracted body text (3,767c)
The Securities and Exchange Commission today announced that The Intercontinental Exchange, Inc. (ICE) agreed to pay a $10 million penalty to settle charges that it caused the failure of nine wholly-owned subsidiaries, including the New York Stock Exchange, to timely inform the SEC of a cyber intrusion as required by Regulation Systems Compliance and Integrity (Regulation SCI). According to the SEC’s order, in April 2021, a third party informed ICE that ICE was potentially impacted by a system intrusion involving a previously unknown vulnerability in ICE’s virtual private network (VPN). ICE investigated and was immediately able to determine that a threat actor had inserted malicious code into a VPN device used to remotely access ICE’s corporate network. However, the SEC’s order finds that ICE personnel did not notify the legal and compliance officials at ICE’s subsidiaries of the intrusion for several days in violation of ICE’s own internal cyber incident reporting procedures. As a result of ICE’s failures, those subsidiaries did not properly assess the intrusion to fulfill their independent regulatory disclosure obligations under Regulation SCI, which required them to immediately contact SEC staff about the intrusion and provide an update within 24 hours unless they immediately concluded or reasonably estimated that the intrusion had or would have no or a de minimis impact on their operations or on market participants. “The respondents in today’s enforcement action include the world’s largest stock exchange and a number of other prominent intermediaries that, given their roles in our markets, are subject to strict reporting requirements when they experience cyber events. Under Reg SCI, they have to immediately notify the SEC of cyber intrusions into relevant systems that they cannot reasonably estimate to be de miminis events right away. The reasoning behind the rule is simple: if the SEC receives multiple reports across a number of these types of entities, then it can take swift steps to protect markets and investors,” said Gurbir S. Grewal, Director of the SEC’s Division of Enforcement. “Here, the respondents subject to Reg SCI failed to notify the SEC of the intrusion at issue as required. Rather, it was Commission staff that contacted the respondents in the process of assessing reports of similar cyber vulnerabilities. As alleged in the order, they instead took four days to assess its impact and internally conclude it was a de minimis event. When it comes to cybersecurity, especially events at critical market intermediaries, every second counts and four days can be an eternity. Today’s order and penalty not only reflect the seriousness of the respondents’ violations, but also that several of them have been the subject of a number of prior SEC enforcement actions, including for violations of Reg SCI.” ICE and its subsidiaries consented to the entry of the SEC’s order finding that the subsidiaries violated the notification provisions of Regulation SCI and that ICE caused those violations. Without admitting or denying the SEC’s findings, ICE and its subsidiaries, consisting of Archipelago Trading Services, Inc.; New York Stock Exchange LLC; NYSE American LLC; NYSE Arca, Inc.; ICE Clear Credit LLC; ICE Clear Europe Ltd.; NYSE Chicago, Inc.; NYSE National, Inc.; and the Securities Industry Automation Corporation agreed to a cease-and-desist order in addition to ICE’s monetary penalty. The SEC’s investigation was conducted by Benjamin D. Brutlag and Lory C. Stone under the supervision of Melissa Hodgman and Carolyn M. Welshhans. The team was assisted by Heidi Pilpel and David Liu of the SEC’s Division of Trading and Markets and by the Technology Controls Program of the SEC’s Division of Examinations.
OCR text (3,767c · html-text · 99% conf)
The Securities and Exchange Commission today announced that The Intercontinental Exchange, Inc. (ICE) agreed to pay a $10 million penalty to settle charges that it caused the failure of nine wholly-owned subsidiaries, including the New York Stock Exchange, to timely inform the SEC of a cyber intrusion as required by Regulation Systems Compliance and Integrity (Regulation SCI). According to the SEC’s order, in April 2021, a third party informed ICE that ICE was potentially impacted by a system intrusion involving a previously unknown vulnerability in ICE’s virtual private network (VPN). ICE investigated and was immediately able to determine that a threat actor had inserted malicious code into a VPN device used to remotely access ICE’s corporate network. However, the SEC’s order finds that ICE personnel did not notify the legal and compliance officials at ICE’s subsidiaries of the intrusion for several days in violation of ICE’s own internal cyber incident reporting procedures. As a result of ICE’s failures, those subsidiaries did not properly assess the intrusion to fulfill their independent regulatory disclosure obligations under Regulation SCI, which required them to immediately contact SEC staff about the intrusion and provide an update within 24 hours unless they immediately concluded or reasonably estimated that the intrusion had or would have no or a de minimis impact on their operations or on market participants. “The respondents in today’s enforcement action include the world’s largest stock exchange and a number of other prominent intermediaries that, given their roles in our markets, are subject to strict reporting requirements when they experience cyber events. Under Reg SCI, they have to immediately notify the SEC of cyber intrusions into relevant systems that they cannot reasonably estimate to be de miminis events right away. The reasoning behind the rule is simple: if the SEC receives multiple reports across a number of these types of entities, then it can take swift steps to protect markets and investors,” said Gurbir S. Grewal, Director of the SEC’s Division of Enforcement. “Here, the respondents subject to Reg SCI failed to notify the SEC of the intrusion at issue as required. Rather, it was Commission staff that contacted the respondents in the process of assessing reports of similar cyber vulnerabilities. As alleged in the order, they instead took four days to assess its impact and internally conclude it was a de minimis event. When it comes to cybersecurity, especially events at critical market intermediaries, every second counts and four days can be an eternity. Today’s order and penalty not only reflect the seriousness of the respondents’ violations, but also that several of them have been the subject of a number of prior SEC enforcement actions, including for violations of Reg SCI.” ICE and its subsidiaries consented to the entry of the SEC’s order finding that the subsidiaries violated the notification provisions of Regulation SCI and that ICE caused those violations. Without admitting or denying the SEC’s findings, ICE and its subsidiaries, consisting of Archipelago Trading Services, Inc.; New York Stock Exchange LLC; NYSE American LLC; NYSE Arca, Inc.; ICE Clear Credit LLC; ICE Clear Europe Ltd.; NYSE Chicago, Inc.; NYSE National, Inc.; and the Securities Industry Automation Corporation agreed to a cease-and-desist order in addition to ICE’s monetary penalty. The SEC’s investigation was conducted by Benjamin D. Brutlag and Lory C. Stone under the supervision of Melissa Hodgman and Carolyn M. Welshhans. The team was assisted by Heidi Pilpel and David Liu of the SEC’s Division of Trading and Markets and by the Technology Controls Program of the SEC’s Division of Examinations.