# Exclusive: Wide-ranging SolarWinds probe sparks fear in Corporate America
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2021-09-10
Category: BUSINESS
Category URL: https://financedigest.com/category/business
Meta Title: SEC Investigation Into SolarWinds Russian Hacking Operation
Meta Description: Discover the SEC investigation uncovering corporate executives&#039; fear of liability. Turn over records of data breaches to avoid penalties. Stay informed.
URL: https://financedigest.com/exclusive-wide-ranging-solarwinds-probe-sparks-fear-in-corporate-americahtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/2021-09-10t050942z1lynxmpeh8905mrtroptp4global-cyber-microsoft-1736837909669-compressed.jpg)

By Christopher Bing, Chris Prentice and Joseph Menn

(Reuters) – A U.S. Securities and Exchange Commission investigation into the SolarWinds [Russian hacking operation has dozens of corporate executives fearful](https://www.financedigest.com/eastern-ukraine-town-empties-as-residents-fear-new-russian-assault.html "Eastern Ukraine town empties as residents fear new Russian assault") information unearthed in the expanding probe will expose them to liability, according to six people familiar with the inquiry.

The SEC is asking companies to turn over records into “any other” [data breach](https://www.financedigest.com/10-steps-to-stop-lateral-movement-in-data-breaches.html "10 Steps to Stop Lateral Movement in Data Breaches") or ransomware attack dating back to October 2019 if they downloaded a bugged network-management software update from SolarWinds Corp, which delivers products used across corporate America, according to details of the letters shared with Reuters.

People familiar with the inquiry [say the requests may reveal numerous unreported cyber incidents unrelated to the Russian](https://www.financedigest.com/eu-says-full-russian-gas-halt-would-slash-gdp.html "EU says full Russian gas halt would slash GDP") espionage campaign, giving the SEC a rare level of insight into previously unknown incidents that the companies likely never intended to disclose.

I’ve never seen anything like this,” said a consultant who [works with dozens of publicly](https://www.financedigest.com/the-new-fangled-normal-of-working-from-home-to-push-the-public-cloud-service-market.html "The “New-Fangled” Normal of “Working from Home” to Push the Public Cloud Service Market") traded companies that recently received the request. “What companies are concerned about is they don’t know how the SEC will use this information. And most companies have had unreported breaches since then.” The consultant spoke on condition of anonymity to discuss his experience.

An SEC official said the request’s intent was to find other breaches relevant to the SolarWinds incident.

The SEC told companies they would not be penalized if they [shared data](https://www.financedigest.com/shares-slip-yields-rise-as-u-s-data-sparks-rate-hike-concerns.html "Shares slip, yields rise as U.S. data sparks rate hike concerns") about the SolarWinds hack voluntarily, but did not offer that amnesty for other compromises.

Cyberattacks have grown in both frequency and impact, prompting deep concern in the White House over the [last year](https://www.financedigest.com/most-uk-smes-spent-600-hours-over-the-last-year-preparing-for-new-gdpr-legislation.html "Most UK SMEs spent 600 hours over the last year preparing for new GDPR legislation"). U.S. [officials have faulted companies for failing to disclose such events](https://www.financedigest.com/leading-blockchain-firm-to-unveil-decentral-project-at-official-consensus-industry-closing-event.html "Leading Blockchain Firm to Unveil Decentral Project at Official Consensus Industry Closing Event"), arguing that it conceals the extent of the problem from shareholders, policymakers and law enforcement looking for the worst offenders.

People familiar with the SEC investigation told Reuters the letters went to hundreds of companies, including many in the technology, [finance and energy sectors](https://www.financedigest.com/finance-is-the-next-big-sector-to-be-ubered.html "Finance is the next big sector to be Uber’ed"), thought to be potentially affected by the SolarWinds attacks. That [number exceeds](https://www.financedigest.com/number-of-emv-card-present-transactions-exceeds-42-globally.html "Number of EMV Card – Present Transactions exceeds 42% globally") the 100 that the Department of Homeland Security said had downloaded the bad SolarWinds software and then had it exploited.

Since last year, only about two [dozen firms](https://www.financedigest.com/over-a-dozen-chinese-based-firms-say-they-have-minimal-exposure-to-svb.html "Over a dozen Chinese-based firms say they have minimal exposure to SVB") have been publicly identified as impacted, including Microsoft Corp, Cisco Systems, FireEye Inc and Intel Corp. Of those contacted for this story only Cisco confirmed receiving the SEC letter. A Cisco spokesperson said it has responded to the SEC’s request.

Cybersecurity research has also suggested https://www.netresec.com/?page=Blog&month=2021-01&post=Twenty-three-SUNBURST-Targets-Identified software maker Qualys Inc and oil energy [company Chevron Corp were among those targeted](https://www.financedigest.com/britain-toughens-up-diversity-targets-for-uk-companies.html "Britain toughens up diversity targets for UK companies") in the Russian cyber operation. Both declined to comment on the SEC investigation.

About 18,000 [clients of SolarWinds downloaded](https://www.financedigest.com/accountants-can-add-even-value-offering-clients-new-breakeven-cis-calculators-downloadable-app.html "Accountants Can Add Even More Value by Offering Clients New Breakeven and CIS Calculators from Their Own Downloadable App") a hacked version of its software, which the cyber criminals manipulated for potential future access. Yet only a small subset of those customers saw follow-on hacking activity, suggesting the attackers infected far more [companies than they ultimately](https://www.financedigest.com/ultimate-growth-for-sme-finance-company.html "Ultimate growth for SME finance company") victimized.

The SEC sent letters last month to [companies believed to have been affected](https://www.financedigest.com/factbox-companies-potentially-affected-by-italys-election.html "Factbox: Companies potentially affected by Italy’s election"), following an initial https://www.reuters.com/technology/us-sec-official-says-agency-has-begun-probe-cyber-breach-by-solarwinds-2021-06-21 round sent in June, according to six sources who have seen the letters.

The [second wave of requests were addressed to recipients at companies from the first round](https://www.financedigest.com/meta-to-cut-10000-jobs-in-second-round-of-layoffs.html "Meta to cut 10,000 jobs in second round of layoffs") who had not responded. The exact number of recipients is unclear.

The current probe is “unprecedented” in terms of the lack of clarity over the SEC’s goal in such a large sweep, said Jina Choi, a partner at Morrison & Foerster LLP and former SEC director who has worked on [cybersecurity cases](https://www.financedigest.com/making-the-case-for-cybersecurity-investment.html "Making the case for cybersecurity investment").

Though the SEC [issued guidance a decade ago calling](https://www.financedigest.com/uk-issues-call-to-arms-for-omicron-booster-drive.html "UK issues call to arms for Omicron booster drive") for companies to disclose hacks that could be material, then updated that guidance in 2018, most admissions have been vague.

Gary Gensler, who took the helm at the SEC in April, has tasked the agency with issuing new disclosure requirements ranging from cybersecurity to [climate risk](https://www.financedigest.com/financial-risks-of-climate-change-overplayed-senior-hsbc-banker-says.html "Financial risks of climate change overplayed, senior HSBC banker says").

While the hack was first reported by Reuters https://www.reuters.com/article/us-usa-cyber-treasury-exclusive-idUSKBN28N0PG more than nine months ago, the actual impact of the wide-scale [digital spying operation](https://www.financedigest.com/digital-marketing-trends-that-will-change-how-brands-operate-in-2021.html "Digital Marketing Trends that will change how brands operate in 2021"), which U.S. officials say came from a Russian [intelligence service](https://www.financedigest.com/artificial-intelligence-and-financial-services-the-perfect-match.html "Artificial intelligence and financial services – the perfect match?"), remains largely unknown.

Government officials have shied [away from sharing](https://www.financedigest.com/britain-chips-away-at-natwest-stake-with-1-6-billion-share-sale.html "Britain chips away at NatWest stake with .6 billion share sale") a comprehensive account of what was stolen or what the Russians were after, but described it as traditional government espionage.

Scores of companies have referred to the hacks in SEC filings, but many cite the events only as an example of the sort of intrusion they might one day experience. Most that say they had SolarWinds [software installed add that they do not believe their most sensitive data](https://www.financedigest.com/auriga-announces-new-analytics-software-module-to-help-banks-turn-data-into-results.html "Auriga announces new analytics software module to help banks turn data into results") was taken.

John Reed Stark, [former head](https://www.financedigest.com/italy-names-former-treasury-official-to-head-ita-airways.html "Italy names former Treasury official to head ITA Airways") of the SEC’s office of internet enforcement, said “companies will struggle to answer these questions – not just because these are broad, sweeping and all-encompassing requests, but also because the SEC is bound to discover some sort of mistake” in what they’ve previously disclosed.

(Reporting by Christopher Bing, Chris Prentice and Joseph Menn; Editing by Chris Sanders and Edward Tobin)


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

