SEC v. Covington & Burling LLP, No. 1:23-mc-00002, District of Columbia (Jan. 12, 2023)
raw: In re Microsoft Hafnium Cyberattack. The Commission further requests
In re Microsoft Hafnium Cyberattack. The Commission further requests, No. 1:23-mc-00002 (Jan. 12, 2023)
The SEC has filed an application to compel Covington & Burling LLP to comply with a subpoena regarding client names accessed during the Microsoft Hafnium cyberattack.
The SEC is investigating potential securities law violations, including illegal trading and disclosure failures, stemming from the Microsoft Hafnium cyberattack. The investigation involves a breach that compromised Covington & Burling LLP's network and accessed files for approximately 300 clients. The Commission is seeking a court order to force the firm to disclose the names of clients whose information was viewed, copied, or exfiltrated.
The Securities and Exchange Commission (SEC) has filed an application in the U.S. District Court for the District of Columbia to compel Covington & Burling LLP to comply with an administrative subpoena. The subpoena is part of an investigation into the Microsoft Hafnium cyberattack, which occurred between November 2020 and March 2021. During the attack, threat actors gained unauthorized access to Covington’s network and accessed legal files for approximately 300 clients. While the firm has complied with other requests, it has failed to provide the names of clients whose information was viewed, copied, modified, or exfiltrated. The SEC is investigating potential illegal trading and disclosure failures resulting from the breach. Consequently, the Commission is requesting an order to show cause to force the law firm's compliance with the specific subpoena request.
Extracted insights
- person anne scott
- agency Securities and Exchange Commission
- company subpoena on covington & burling llp
- person threat actors
- Securities And Exchange Commission issued formal order of private investigation and examination
- Securities And Exchange Commission is investigating potential violations of the federal securities laws arising out of the Microsoft Hafnium cyberattack
- Threat actors gained unauthorized access to Covington & Burling LLP's computer network and certain individual devices
- Threat actors accessed legal files for approximately 300 of Covington & Burling LLP's clients
- Securities And Exchange Commission served subpoena on Covington & Burling LLP
- Securities And Exchange Commission learned about Covington & Burling LLP's impact from the cyberattack
- Anne Scott acknowledged service of subpoena
UNITED STATES DISTRICT COURT DISTRICT OF COLUMBIA SECURITIES AND EXCHANGE COMMISSION, 100 F Street, NE Washington, DC 20549 Applicant, vs. COVINGTON & BURLING LLP, 850 10th St, NW Washington, DC 20268 Respondent. Case No. _________ SECURITIES AND EXCHANGE COMMISSION’S APPLICATION FOR AN ORDER TO SHOW CAUSE AND FOR AN ORDER REQUIRING COMPLIANCE WITH SUBPOENA The Securities and Exchange Commission (the “Commission”), pursuant to Section 21(c) of the Securities Exchange Act of 1934 (“Exchange Act”) [15 U.S.C. § 78u(c)] and Section 22(b) of the Securities Act of 1933 (“Securities Act”) [15 U.S.C. § 77v(b)], respectfully applies for an order to show cause why Respondent Covington & Burling LLP (“Covington”) should not be directed to comply with an administrative subpoena properly served upon the firm and issued in connection with a Commission investigation styled In the Matter of Microsoft Hafnium Cyberattack. The Commission further requests that, after Covington has had an opportunity to be heard, this Court enter an order directing its compliance with the subpoena, as set forth below. In support of this Application, the Commission states the following: 1.On March 16, 2021, the Commission issued a formal order of private investigation and examination (the “Formal Order”) pursuant to Section 20(a) of the Securities Act [15 U.S.C. § 77t(a)] Case: 1:23−mc−00002 Assigned To : Cooper, Christopher R. Assign. Date : 1/10/2023 Description: Misc. JAN 10 2023 2 and Section 21(a) of the Exchange Act [15 U.S.C. § 78u(a)]. The Formal Order designated certain individuals as officers of the Commission empowered to administer oaths and affirmations, subpoena witnesses, compel their attendance, take evidence, and require the production of any books, papers, correspondence, memoranda, or other records deemed relevant or material to the investigation. 2. The Commission is investigating potential violations of the federal securities laws arising out of the Microsoft Hafnium cyberattack (the “Cyberattack”), which began in or around November 2020 and continued into at least March 2021. Specifically, the Commission is investigating the impact of the Cyberattack on public companies and regulated entities in order to (a) understand the nature and scope of the attack, (b) assess and identify potential illegal trading based on information gathered during the attack, and (c) determine relevant disclosure obligations for public companies impacted by the attack. 3. As part of the Cyberattack, threat actors gained unauthorized access to Covington’s computer network and certain individual devices, and accessed legal files for approximately 300 of its clients. The Commission’s Formal Order focuses more broadly on the Cyberattack, rather than the impact on Covington, which the Commission did not learn about until approximately March 2022, nearly a year after the Commission’s Formal Order. 4. In support of this Application, the Commission submits the accompanying Memorandum of Points and Authorities and Declaration of W. Bradley Ney (“Ney Decl.”). 5. After learning that Covington had been impacted by the Cyberattack, the Commission served a subpoena on Covington (“Subpoena”) to obtain limited information about impacted parties and the extent of that impact. Specifically, and at issue here, is only the Subpoena’s Request No. 3(a), which called for the names of any clients whose information had been viewed, copied, modified or exfiltrated during the attack on Covington. See Ney Decl., Exhibit A, ¶ C.3. The Subpoena’s deadline for production of documents was April 4, 2022. 3 6. The Subpoena was served upon Anne Scott, a Covington attorney, by encrypted electronic mail on March 21, 2022. Ms. Scott acknowledged service of the Subpoena on March 24, 2022. 7. Covington has represented to the Commission that it has fulfilled its obligations for all other Requests under the Subpoena with the exception of Request No. 3. 8. The Commission and Covington have negotiated over the parameters of Request No. 3, which initially called for additional details about impacted clients in subparts (b) and (c). The Commission agreed to limit its request to Covington’s disclosure of the names of clients whose information was viewed, copied, modified or exfiltrated during the cyberattack on Covington as requested in subpart (a). 9. Accordingly, the Commission hereby submits this Application for an Order to Show Cause, in the form attached, requiring Covington to show cause why it should not be ordered to produce the information in Subpoena Request No. 3(a) to the Commission at 100 F Street, N.E., Washington, D.C., 20549. In the event Covington fails to show sufficient cause, the Commission further requests that the Court order Covington to comply with Subpoena Request 3(a). 10. This Court has jurisdiction over this action, and venue properly lies within the District of Columbia, pursuant to Section 21(c) of the Exchange Act [ 15 U.S.C. § 78u(c)] (“In case of contumacy by, or refusal to obey a subpoena issued to, any person, the Commission may invoke the aid of any court of the United States within which the jurisdiction of which such investigation or proceeding is carried on . . . in requiring the attendance and testimony of witnesses and the production of books, papers, correspondence, memoranda, and other records.”) and Section 22(b) of the Securities Act [15 U.S.C. § 77v(b)] (“In case of contumacy or refusal to obey a subpoena issued to any person, any of the said United States courts, within the jurisdiction of which said person guilty of contumacy or refusal to obey 4 is found or resides, upon application by the Commission may issue to such person an order requiring such person . . . to produce documentary evidence . . . or there to give evidence touching the matter in question.”). Further, Section 21(c) of the Exchange Act and Section 22(b) of the Securities Act provide that “any failure to obey such order of the court may be punished by such court as a contempt thereof.” 15 U.S.C. § 78u(c); 15 U.S.C. § 77v(b). WHEREFORE, the Commission respectfully requests that the Court: (A) Order Covington to show cause why this Court should not direct its compliance with Subpoena Request No. 3(a); (B) After Covington has an opportunity to be heard on this matter, order Covington to comply with Subpoena Request No. 3(a), and produce the names of any clients whose information had been viewed, modified, copied or exfiltrated during the cyberattack on Covington; and (C) Order such other and further relief as may be necessary and appropriate to achieve Covington’s compliance with Subpoena Request No. 3(a). Dated: December 10, 2023 Respectfully submitted, /s/ Dean M. Conway Dean M. Conway (DC Bar No. 457433) Securities and Exchange Commission 100 F. Street N.E. Washington, D.C. 20549 Tel. 202.551.4412 Email: [email protected] 5 CERTIFICATE OF SERVICE I hereby certify that on December 10, 2023, I served a copy of the foregoing Securities and Exchange Commission’s Application for an Order to Show Cause together with a Memorandum of Points and Authorities in Support, the Declaration of W. Bradley Ney, a proposed Order to Show Cause Why an Order Compelling Compliance with Subpoena should not be Issued and a proposed Order Compelling Compliance with Investigative Subpoena via email upon: Richard Grime, Esq. Gibson Dunn 1050 Connecticut Avenue, N.W. Washington, D.C. 20036-5306 [email protected] /s/ Dean M. Conway Dean M. Conway
UNITED STATES DISTRICT COURT DISTRICT OF COLUMBIA SECURITIES AND EXCHANGE COMMISSION, 100 F Street, NE Washington, DC 20549 Applicant, vs. COVINGTON & BURLING LLP, 850 10th St, NW Washington, DC 20268 Respondent. Case No. _________ SECURITIES AND EXCHANGE COMMISSION’S APPLICATION FOR AN ORDER TO SHOW CAUSE AND FOR AN ORDER REQUIRING COMPLIANCE WITH SUBPOENA The Securities and Exchange Commission (the “Commission”), pursuant to Section 21(c) of the Securities Exchange Act of 1934 (“Exchange Act”) [15 U.S.C. § 78u(c)] and Section 22(b) of the Securities Act of 1933 (“Securities Act”) [15 U.S.C. § 77v(b)], respectfully applies for an order to show cause why Respondent Covington & Burling LLP (“Covington”) should not be directed to comply with an administrative subpoena properly served upon the firm and issued in connection with a Commission investigation styled In the Matter of Microsoft Hafnium Cyberattack. The Commission further requests that, after Covington has had an opportunity to be heard, this Court enter an order directing its compliance with the subpoena, as set forth below. In support of this Application, the Commission states the following: 1. On March 16, 2021, the Commission issued a formal order of private investigation and examination (the “Formal Order”) pursuant to Section 20(a) of the Securities Act [15 U.S.C. § 77t(a)] Case: 1:23−mc−00002 Assigned To : Cooper, Christopher R. Assign. Date : 1/10/2023 Description: Misc. JAN 10 2023 Case 1:23-mc-00002-APM Document 1 Filed 01/10/23 Page 1 of 5 SIMONEBLOGAN Received Stamp 2 and Section 21(a) of the Exchange Act [15 U.S.C. § 78u(a)]. The Formal Order designated certain individuals as officers of the Commission empowered to administer oaths and affirmations, subpoena witnesses, compel their attendance, take evidence, and require the production of any books, papers, correspondence, memoranda, or other records deemed relevant or material to the investigation. 2. The Commission is investigating potential violations of the federal securities laws arising out of the Microsoft Hafnium cyberattack (the “Cyberattack”), which began in or around November 2020 and continued into at least March 2021. Specifically, the Commission is investigating the impact of the Cyberattack on public companies and regulated entities in order to (a) understand the nature and scope of the attack, (b) assess and identify potential illegal trading based on information gathered during the attack, and (c) determine relevant disclosure obligations for public companies impacted by the attack. 3. As part of the Cyberattack, threat actors gained unauthorized access to Covington’s computer network and certain individual devices, and accessed legal files for approximately 300 of its clients. The Commission’s Formal Order focuses more broadly on the Cyberattack, rather than the impact on Covington, which the Commission did not learn about until approximately March 2022, nearly a year after the Commission’s Formal Order. 4. In support of this Application, the Commission submits the accompanying Memorandum of Points and Authorities and Declaration of W. Bradley Ney (“Ney Decl.”). 5. After learning that Covington had been impacted by the Cyberattack, the Commission served a subpoena on Covington (“Subpoena”) to obtain limited information about impacted parties and the extent of that impact. Specifically, and at issue here, is only the Subpoena’s Request No. 3(a), which called for the names of any clients whose information had been viewed, copied, modified or exfiltrated during the attack on Covington. See Ney Decl., Exhibit A, ¶ C.3. The Subpoena’s deadline for production of documents was April 4, 2022. Case 1:23-mc-00002-APM Document 1 Filed 01/10/23 Page 2 of 5 3 6. The Subpoena was served upon Anne Scott, a Covington attorney, by encrypted electronic mail on March 21, 2022. Ms. Scott acknowledged service of the Subpoena on March 24, 2022. 7. Covington has represented to the Commission that it has fulfilled its obligations for all other Requests under the Subpoena with the exception of Request No. 3. 8. The Commission and Covington have negotiated over the parameters of Request No. 3, which initially called for additional details about impacted clients in subparts (b) and (c). The Commission agreed to limit its request to Covington’s disclosure of the names of clients whose information was viewed, copied, modified or exfiltrated during the cyberattack on Covington as requested in subpart (a). 9. Accordingly, the Commission hereby submits this Application for an Order to Show Cause, in the form attached, requiring Covington to show cause why it should not be ordered to produce the information in Subpoena Request No. 3(a) to the Commission at 100 F Street, N.E., Washington, D.C., 20549. In the event Covington fails to show sufficient cause, the Commission further requests that the Court order Covington to comply with Subpoena Request 3(a). 10. This Court has jurisdiction over this action, and venue properly lies within the District of Columbia, pursuant to Section 21(c) of the Exchange Act [15 U.S.C. § 78u(c)] (“In case of contumacy by, or refusal to obey a subpoena issued to, any person, the Commission may invoke the aid of any court of the United States within which the jurisdiction of which such investigation or proceeding is carried on . . . in requiring the attendance and testimony of witnesses and the production of books, papers, correspondence, memoranda, and other records.”) and Section 22(b) of the Securities Act [15 U.S.C. § 77v(b)] (“In case of contumacy or refusal to obey a subpoena issued to any person, any of the said United States courts, within the jurisdiction of which said person guilty of contumacy or refusal to obey Case 1:23-mc-00002-APM Document 1 Filed 01/10/23 Page 3 of 5 4 is found or resides, upon application by the Commission may issue to such person an order requiring such person . . . to produce documentary evidence . . . or there to give evidence touching the matter in question.”). Further, Section 21(c) of the Exchange Act and Section 22(b) of the Securities Act provide that “any failure to obey such order of the court may be punished by such court as a contempt thereof.” 15 U.S.C. § 78u(c); 15 U.S.C. § 77v(b). WHEREFORE, the Commission respectfully requests that the Court: (A) Order Covington to show cause why this Court should not direct its compliance with Subpoena Request No. 3(a); (B) After Covington has an opportunity to be heard on this matter, order Covington to comply with Subpoena Request No. 3(a), and produce the names of any clients whose information had been viewed, modified, copied or exfiltrated during the cyberattack on Covington; and (C) Order such other and further relief as may be necessary and appropriate to achieve Covington’s compliance with Subpoena Request No. 3(a). Dated: December 10, 2023 Respectfully submitted, /s/ Dean M. Conway Dean M. Conway (DC Bar No. 457433) Securities and Exchange Commission 100 F. Street N.E. Washington, D.C. 20549 Tel. 202.551.4412 Email: [email protected] Case 1:23-mc-00002-APM Document 1 Filed 01/10/23 Page 4 of 5 5 CERTIFICATE OF SERVICE I hereby certify that on December 10, 2023, I served a copy of the foregoing Securities and Exchange Commission’s Application for an Order to Show Cause together with a Memorandum of Points and Authorities in Support, the Declaration of W. Bradley Ney, a proposed Order to Show Cause Why an Order Compelling Compliance with Subpoena should not be Issued and a proposed Order Compelling Compliance with Investigative Subpoena via email upon: Richard Grime, Esq. Gibson Dunn 1050 Connecticut Avenue, N.W. Washington, D.C. 20036-5306 [email protected] /s/ Dean M. Conway Dean M. Conway Case 1:23-mc-00002-APM Document 1 Filed 01/10/23 Page 5 of 5