Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

SEC and SolarWinds to settle lawsuit over 2020 breach | Computer Weekly

By Computer Weekly by By Computer Weekly
July 8, 2025
Home Uncategorized
Share on FacebookShare on Twitter


The United States’ Securities and Exchange Commission (SEC) has reached a settlement in principle with SolarWinds in an ongoing case against the organisation and its chief information security officer, Tim Brown, over failings that led to the compromise of its IT performance management platform Orion by the Russian state hacking group known as Cozy Bear.

The so-called Sunburst/Solorigate supply chain incident that came to light in December 2020 saw malicious code introduced into the SolarWinds’ platform by the Russians, which was then unknowingly pushed to downstream targets as a legitimate update.

Almost 20,000 SolarWinds customers downloaded and installed the malicious updates, among them the likely true targets of the cyber attack, American government bodies, such as the Department of Energy (DoE) and the National Nuclear Safety Administration (NNSA) that maintains the US nuclear weapons stock.

In a letter to presiding judge Paul Engelmayer of the US District Court for the Southern District of New York, SEC and SolarWinds representatives said they had reached a settlement in principle “that would completely resolve this litigation”, subject to review and approval by the SEC’s commissioners. They requested all pending dates in the case be stayed ahead of a planned filing date for the final settlement, set for 12 September.

Engelmayer congratulated both parties on a “productive development” and has subsequently stayed all deadlines in the case, as well as adjourning oral arguments set for later this month.

A SolarWinds spokesperson said: “The settlement is subject to approval by the Commission and we cannot therefore discuss the terms at this time. We are pleased with the potential resolution and happy to focus on driving our business forward without distraction.”

Charges dropped

Last year, Engelmayer tossed out most of the SEC’s claims against SolarWinds and Brown, which had alleged that they had knowingly defrauded investors in overstating the resilience of the organisation’s security practices, and understating or not disclosing known risks.

Among other things, the SEC claimed that the defendants ignored, covered up or even outright lied to customers about links between different cyber attacks on various Orion users that were taking place over the course of 2020.

Engelmayer’s initial dismissal of many of the charges, including those that stemmed from SolarWinds disclosures made after news of the incident broke, was made on the basis that they relied on hindsight and speculation.

However, he did sustain a number of charges, including parts of the SEC’s complaints that alleged public misrepresentations about the resilience of SolarWinds’ access controls.

Given the SEC’s much-publicised and well-dissected rules on security incident reporting, which came into force at the end of 2023 and put the spotlight firmly on the actions security leaders take following an incident, the reasons why it has chosen to try to reach a full settlement will likely bear some analysis.

Computer Weekly’s sister title Cybersecurity Dive suggested that the Republican majority now in control at the SEC may have had some bearing on the regulator’s willingness to compromise – the initial case was brought by the Democrat-led body under former president Joe Biden.

Lending weight to the theory that the dramatic change in the US political landscape is behind the SolarWinds settlement, the SEC has also recently dropped a number of enforcement cases involving cryptocurrency firms including the likes of Binance, Coinbase and Crypto.com. This came following a 23 January Executive Order (EO) from president Trump’s White House, designed to support the crypto sector.



Source link

By Computer Weekly

By Computer Weekly

Next Post
Industries prioritize AI investments as uncertainty looms

Industries prioritize AI investments as uncertainty looms

Recommended.

Cisco & Wells Fargo to Host Silicon One Tech Talk

Cisco & Wells Fargo to Host Silicon One Tech Talk

June 30, 2025
Zillow launches messaging, a new way for home shoppers to collaborate within the Zillow app

Zillow launches messaging, a new way for home shoppers to collaborate within the Zillow app

October 28, 2025

Trending.

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

July 18, 2025
Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

September 4, 2025
Wesco Declares Quarterly Dividend on Common Stock

Wesco Declares Quarterly Dividend on Common Stock

December 1, 2025
HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

October 24, 2025
⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

March 10, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio