SEC Investigative Report: Public Companies Should Consider Cyber Threats When Implementing Internal Accounting Controls
The SEC issued a report cautioning nine public companies that fell victim to business email compromise frauds, losing nearly $100 million collectively—with two losing over $30 million and one over $45 million—without filing charges, but emphasizing their legal obligation under Section 13(b)(2)(B) to maintain cyber-aware internal accounting controls.
The SEC investigated nine public companies that lost nearly $100 million due to business email compromise (BEC) frauds, in which perpetrators impersonated executives or vendors to trick employees into wiring funds to fraudulent accounts. Two companies lost more than $30 million each, and one lost over $45 million, with most funds unrecoverable and the frauds often undetected for months. Although no charges were brought against the companies or individuals, the SEC stressed that all public issuers are legally required under Section 13(b)(2)(B) of the Securities Exchange Act to calibrate internal accounting controls to current cyber risks.
The SEC issued an investigative report warning public companies about the growing threat of business email compromise (BEC) frauds, based on its examination of nine firms that collectively lost nearly $100 million. In each case, perpetrators impersonated company executives or vendors via email, deceiving employees into wiring large sums to accounts controlled by fraudsters; the schemes often persisted for months and were typically uncovered only after law enforcement intervention. Two companies lost more than $30 million, one exceeded $45 million, and the vast majority of the stolen funds were unrecoverable. Despite the massive losses, the SEC chose not to bring charges against any of the companies or their personnel, noting that the frauds exploited weaknesses in internal controls rather than intentional misconduct. The report emphasized that all public issuers subject to Section 13(b)(2)(B) of the Securities Exchange Act of 1934 are legally obligated to maintain and regularly update internal accounting controls that account for evolving cyber threats. The SEC highlighted the FBI’s estimate that BEC frauds have cost businesses over $5 billion since 2013, underscoring the systemic nature of the risk. Released during National Cybersecurity Awareness Month, the report serves as a regulatory alert, urging companies across sectors—including technology, energy, real estate, and consumer goods—to proactively assess and strengthen their defenses to protect investor confidence.
Exhibits & Attached Documents (1)
Extracted insights
- $5.00B $5 billion ≥$1B
- $100.00M $100 million $100M–$1B
- $45.00M $45 million $10M–$100M
- $30.00M $30 million $10M–$100M
- $1.00M $1 million $1M–$10M
- agency Federal Bureau of Investigation
- company one company
- agency sec chairman jay clayton
- agency sec enforcement division
- agency Securities and Exchange Commission
- person stephanie avakian
- Securities And Exchange Commission issued an investigative report
- SEC Enforcement Division investigated nine public companies
- perpetrators posed as company executives or vendors
- perpetrators used emails to dupe company personnel
- companies lost at least $1 million
- two companies lost more than $30 million
- one company lost more than $45 million
- nine companies wired nearly $100 million
- FBI estimates fraud involving BECs has cost companies more than $5 billion since 2013
- SEC Chairman Jay Clayton said cyber frauds are a pervasive, significant, and growing threat to all companies
- Stephanie Avakian said we did not charge the nine companies we investigated
- SEC conducted investigations by Brent Wilner, Creighton Papier, and Maria Rodriguez
- SEC supervised investigations by Diana Tani, John Berry, and Michele Layne
The Securities and Exchange Commission today issued an investigative report cautioning that public companies should consider cyber threats when implementing internal accounting controls. The report is based on the SEC Enforcement Division's investigations of nine public companies that fell victim to cyber fraud, losing millions of dollars in the process. The SEC's investigations focused on "business email compromises" (BECs) in which perpetrators posed as company executives or vendors and used emails to dupe company personnel into sending large sums to bank accounts controlled by the perpetrators. The frauds in some instances lasted months and often were detected only after intervention by law enforcement or other third parties. Each of the companies lost at least $1 million, two lost more than $30 million, and one lost more than $45 million. In total, the nine companies wired nearly $100 million as a result of the frauds, most of which was unrecoverable. No charges were brought against the companies or their personnel. The companies, which each had securities listed on a national stock exchange, covered a range of sectors including technology, machinery, real estate, energy, financial, and consumer goods. Public issuers subject to the internal accounting controls requirements of Section 13(b)(2)(B) of the Securities Exchange Act of 1934 must calibrate their internal accounting controls to the current risk environment and assess and adjust policies and procedures accordingly. The FBI estimates fraud involving BECs has cost companies more than $5 billion since 2013. "Cyber frauds are a pervasive, significant, and growing threat to all companies, including our public companies," said SEC Chairman Jay Clayton. "Investors rely on our public issuers to put in place, monitor, and update internal accounting controls that appropriately address these threats." Stephanie Avakian, Co-Director of the SEC Enforcement Division, said, "In light of the facts and circumstances, we did not charge the nine companies we investigated, but our report emphasizes that all public companies have obligations to maintain sufficient internal accounting controls and should consider cyber threats when fulfilling those obligations." The issuance of the SEC's report coincides with National Cybersecurity Awareness Month. In consultation with the Division of Corporation Finance and the Office of the Chief Accountant, the SEC's investigations were conducted by Brent Wilner, Creighton Papier, and Maria Rodriguez, and supervised by Diana Tani, John Berry, and Michele Layne of the Los Angeles Regional Office.
The Securities and Exchange Commission today issued an investigative report cautioning that public companies should consider cyber threats when implementing internal accounting controls. The report is based on the SEC Enforcement Division's investigations of nine public companies that fell victim to cyber fraud, losing millions of dollars in the process. The SEC's investigations focused on "business email compromises" (BECs) in which perpetrators posed as company executives or vendors and used emails to dupe company personnel into sending large sums to bank accounts controlled by the perpetrators. The frauds in some instances lasted months and often were detected only after intervention by law enforcement or other third parties. Each of the companies lost at least $1 million, two lost more than $30 million, and one lost more than $45 million. In total, the nine companies wired nearly $100 million as a result of the frauds, most of which was unrecoverable. No charges were brought against the companies or their personnel. The companies, which each had securities listed on a national stock exchange, covered a range of sectors including technology, machinery, real estate, energy, financial, and consumer goods. Public issuers subject to the internal accounting controls requirements of Section 13(b)(2)(B) of the Securities Exchange Act of 1934 must calibrate their internal accounting controls to the current risk environment and assess and adjust policies and procedures accordingly. The FBI estimates fraud involving BECs has cost companies more than $5 billion since 2013. "Cyber frauds are a pervasive, significant, and growing threat to all companies, including our public companies," said SEC Chairman Jay Clayton. "Investors rely on our public issuers to put in place, monitor, and update internal accounting controls that appropriately address these threats." Stephanie Avakian, Co-Director of the SEC Enforcement Division, said, "In light of the facts and circumstances, we did not charge the nine companies we investigated, but our report emphasizes that all public companies have obligations to maintain sufficient internal accounting controls and should consider cyber threats when fulfilling those obligations." The issuance of the SEC's report coincides with National Cybersecurity Awareness Month. In consultation with the Division of Corporation Finance and the Office of the Chief Accountant, the SEC's investigations were conducted by Brent Wilner, Creighton Papier, and Maria Rodriguez, and supervised by Diana Tani, John Berry, and Michele Layne of the Los Angeles Regional Office.