SEC fines four companies $7 million for “downplaying” cyberattack

24 October 2024

Elizabeth Pfeuti

Latest News

Australia narrows climate reporting scope mid‑rollout

Minerva Proxy Update

Follow This challenges Shell days before key vote

SRD III is Europe’s chance to fix proxy plumbing

SEC Steps Closer to Unwinding Climate Disclosure Rules

Minerva Proxy Update

Featured Briefings

Australia Proxy Season Review 2025

2026 Proxy Season Preview

Diversity Divergence: Shareholders Steadfast Amid Pervasive Political Posturing

SEC fines four companies $7 million for “downplaying” cyberattack

October 23, 2024

An American regulator has charged and imposed penalties totalling $7 million on four companies for making misleading disclosures linked to the 2019 SolarWinds data breach.

The Securities and Exchange Commission (SEC) fined cybersecurity firms Check Point and Mimecast $995,000 and $999,000, respectively. Tech companies Unisys and Avaya faced larger fines, with Unisys paying $4 million and Avaya $1 million.

These companies were all victims of a cybersecurity breach of SolarWinds’ software, which the SEC said was one of the most widespread and sophisticated hacking campaigns ever conducted against the federal government and private sector.

According to the SEC, each company committed different violations that negligently downplayed and minimised the impact of the breaches.

It said that Unisys, Avaya, and Check Point learned in 2020, while Mimecast learned in 2021, that the threat actor likely responsible for the SolarWinds Orion hack had gained unauthorised access to their system, but each downplayed the severity of the incident in their public disclosures.

In particular, the regulator ruled that Avaya and Mimecast disclosed information about the cyberattack, but the disclosures left out certain material information.

Meanwhile, Check Point and Unisys failed to update an existing risk factor in response to the breach. The SEC said without acknowledging the compromise of their networks, these risk factors became materially misleading.

The SEC noted that all companies cooperated with its investigation and agreed to pay the penalties and to cease and desist from future violations of the charged provisions, without admitting or denying the findings.

Sanjay Wadhwa, acting director of the SEC’s Division of Enforcement, said: “As today’s enforcement actions reflect, while public companies may become targets of cyberattacks, it is incumbent upon them to not further victimize their shareholders or other members of the investing public by providing misleading disclosures about the cybersecurity incidents they have encountered.”

Minerva’s blog focuses on the latest developments in ESG investing and stewardship. Minerva is a global provider of sustainable stewardship solutions with over 25 years of expertise. Minerva empowers investors by providing essential tools, including ESG research and data, enabling them to navigate the intricate landscape of stewardship and proxy voting, whilst ensuring their decisions are well-informed and aligned with sustainable principles.

Related Stories

SEC Steps Closer to Unwinding Climate Disclosure Rules

May 13, 2026
Read More
fiduciary squeeze

The fiduciary squeeze is timed for when trustees can’t look up

April 23, 2026
Read More

Texas Climate Investing Blacklist Stays on Ice

April 17, 2026
Read More

Regulating the Raters: The FCA’s ESG Regulatory Proposals, Minerva’s Response, and What the Market Should Watch

April 16, 2026
Read More

FCA Sustainability Disclosure Proposals: A Turning Point for UK Market Transparency

April 10, 2026
Read More

Why Switzerland’s Proposed Sustainability Bill Matters for Investors

April 9, 2026
Read More