Skip to Primary Navigation

SEC charges four companies for underreporting Sunburst data breach damage

Image of a man looking at lines of code on a laptop.
Photo: Adam Berry/Getty Images

The four settlements come nearly one year after the SEC sued SolarWinds for misleading investors about its cybersecurity controls.

Four US companies, Avaya, Unisys, Mimecast and Check Point Software Technologies Ltd were each charged by the SEC for downplaying the extent to which their data had been compromised in the massive 2020-2021 SolarWinds “Sunburst” hack.

In September 2019, Russian state-affiliated hackers launched an attack on Orion, a network management

After

Get full access, free for a month

This is a Premium article. Start your 28-day free trial to continue reading and access all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience