2023-01-12 sec-litreleases litigation_release 66 KB 2,775 chars

SEC v. Covington & Burling LLP, No. LR-25612, District of Columbia (Jan. 12, 2023) — Press Release

raw: Covington & Burling LLP

Covington & Burling LLP, No. 1:23-mc-00002 (D.D.C. Jan. 12, 2023)

Caption
SEC v. Covington & Burling LLP
summary

The SEC has filed a subpoena enforcement action against Covington & Burling LLP to compel the disclosure of client names accessed during the 2020 Microsoft Hafnium cyberattack.

paragraph

The SEC is investigating potential federal securities law violations, including illegal trading and disclosure failures, following a 2020 cyberattack on Covington & Burling LLP. Threat actors accessed the non-public files of nearly 300 SEC-regulated clients, prompting the agency to seek the names of those impacted. While Covington has only provided names for two consenting clients, the SEC is seeking a court order to compel full compliance with its investigative subpoena.

narrative

The Securities and Exchange Commission (SEC) has filed a subpoena enforcement action against the law firm Covington & Burling LLP to compel the disclosure of client identities. In November 2020, threat actors associated with the Microsoft Hafnium cyberattack unlawfully accessed Covington's network and individual devices. This breach exposed the non-public files of approximately 300 SEC-regulated clients. The SEC is investigating potential violations of federal securities laws, specifically looking for illegal trading based on material non-public information and failures to disclose material cybersecurity events. To date, Covington has refused to provide names for most affected entities, releasing only two clients who consented to the disclosure. The SEC's application seeks a court order to force compliance with its investigative subpoena to identify suspicious trading activity.

Enriched metadata

Scheme
cyber-fraud (80%)
Court
District of Columbia
Case No.
1:23-mc-00002
Entity
Covington & Burling LLP
Classified cyber-fraud(confidence 80%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
Securities and Exchange CommissionCovington & Burling LLP
Keywords
covingtonseccovington burlingthreat actorssubpoenacyberattackburlingllpthreatactorssecuritiesapplicationclientsnamesinformation

Exhibits & Attached Documents (1)

Extracted insights

Entities 3
  • company covington & burling llp
  • agency Securities and Exchange Commission
  • person threat actors
Triples 10
  • Securities And Exchange Commission filed an application seeking an order directing the law firm Covington & Burling LLP to comply with a narrow subpart of an investigative subpoena for documents
  • Threat actors obtained access to Covington's computer network and certain individual devices, including non-public files of nearly 300 Covington clients regulated by the SEC
  • Securities And Exchange Commission learned of the cyberattack on Covington in early 2022
  • Securities And Exchange Commission issued a subpoena soon after learning of the cyberattack
  • Securities And Exchange Commission is seeking the names of clients whose files were viewed, copied, modified, or exfiltrated by threat actors
  • Securities And Exchange Commission seeks this information to assist in identifying suspicious trading by threat actors or others in clients' securities and determining if such trading was illegal based on material non-public information
  • Securities And Exchange Commission will assist in determining whether impacted clients made all required disclosures about material cybersecurity events related to the cyberattack
  • Covington & Burling LLP has refused to provide the names of all but two of the clients
  • Securities And Exchange Commission seeks an order directing Covington to show cause why the court should not compel it to produce the documents as required by the subpoena
  • Securities And Exchange Commission seeks an order directing Covington to comply with the subpoena following the court's ruling on the order to show cause
Text layers
Extracted body text (2,775c)
SEC Files Subpoena Enforcement Action Against Law Firm Covington & Burling LLP Seeking the Names of Entities Whose Non-Public Information Was Accessed by Threat Actors Who Accessed Covington's Computer Network Litigation Release No. 25612 / January 12, 2023 Securities and Exchange Commission v. Covington & Burling LLP, No. 1:23-mc-00002 (D.D.C. filed Jan. 10, 2023) The Securities and Exchange Commission ("SEC") announced that it has filed an application seeking an order directing the law firm Covington & Burling LLP ("Covington") to comply with a narrow subpart of an investigative subpoena for documents. According to the SEC's filing in U.S. District Court for the District of Columbia, the SEC is investigating potential violations of the federal securities laws arising from the Microsoft Hafnium cyberattack, including among other things potential illegal trading and disclosure violations arising from the cyberattack. According to the filing, in or around November 2020, threat actors associated with the Microsoft Hafnium cyberattack maliciously and unlawfully obtained access to Covington's computer network and certain individual devices, including access to non-public files of nearly 300 Covington clients that are regulated by the SEC. The SEC learned of the cyberattack on Covington in early 2022 and issued the subpoena soon thereafter. Through its subpoena enforcement action, the SEC is seeking only the names of those clients whose files were viewed, copied, modified or exfiltrated by the threat actors. According to the filing, the SEC seeks this information to assist it in identifying any suspicious trading by the threat actors or others in those clients' securities, and whether such trading was illegal based on material non-public information that the threat actors viewed or exfiltrated as part of the cyberattack. In addition, the information will assist the SEC in determining whether the impacted clients made all required disclosures to the investing public about any material cybersecurity events in connection with the cyberattack. To date, Covington has refused to provide the names of all but two of the clients, and those two clients consented to providing their names to the SEC. The SEC's application seeks an order from the court directing Covington to show cause as to why the court should not compel it to produce the documents as required by the subpoena. The application further seeks an order from the court, following its ruling on the order to show cause, directing Covington to comply with the subpoena. The application is subject to the court's ruling. The SEC is continuing its fact-finding investigation and, to date, has not concluded that any individual or entity has violated the federal securities laws. Application
OCR text (2,775c · html-text · 99% conf)
SEC Files Subpoena Enforcement Action Against Law Firm Covington & Burling LLP Seeking the Names of Entities Whose Non-Public Information Was Accessed by Threat Actors Who Accessed Covington's Computer Network Litigation Release No. 25612 / January 12, 2023 Securities and Exchange Commission v. Covington & Burling LLP, No. 1:23-mc-00002 (D.D.C. filed Jan. 10, 2023) The Securities and Exchange Commission ("SEC") announced that it has filed an application seeking an order directing the law firm Covington & Burling LLP ("Covington") to comply with a narrow subpart of an investigative subpoena for documents. According to the SEC's filing in U.S. District Court for the District of Columbia, the SEC is investigating potential violations of the federal securities laws arising from the Microsoft Hafnium cyberattack, including among other things potential illegal trading and disclosure violations arising from the cyberattack. According to the filing, in or around November 2020, threat actors associated with the Microsoft Hafnium cyberattack maliciously and unlawfully obtained access to Covington's computer network and certain individual devices, including access to non-public files of nearly 300 Covington clients that are regulated by the SEC. The SEC learned of the cyberattack on Covington in early 2022 and issued the subpoena soon thereafter. Through its subpoena enforcement action, the SEC is seeking only the names of those clients whose files were viewed, copied, modified or exfiltrated by the threat actors. According to the filing, the SEC seeks this information to assist it in identifying any suspicious trading by the threat actors or others in those clients' securities, and whether such trading was illegal based on material non-public information that the threat actors viewed or exfiltrated as part of the cyberattack. In addition, the information will assist the SEC in determining whether the impacted clients made all required disclosures to the investing public about any material cybersecurity events in connection with the cyberattack. To date, Covington has refused to provide the names of all but two of the clients, and those two clients consented to providing their names to the SEC. The SEC's application seeks an order from the court directing Covington to show cause as to why the court should not compel it to produce the documents as required by the subpoena. The application further seeks an order from the court, following its ruling on the order to show cause, directing Covington to comply with the subpoena. The application is subject to the court's ruling. The SEC is continuing its fact-finding investigation and, to date, has not concluded that any individual or entity has violated the federal securities laws. Application