Wide-ranging SolarWinds probe sparks fear in Corporate America
Skip to main content
  • Home
  • Economy
  • Stocks
  • Analysis
  • World+Biz
  • Sports
  • Features
  • Epaper
  • More
    • Subscribe
    • COVID-19
    • Bangladesh
    • Splash
    • Videos
    • Games
    • Long Read
    • Infograph
    • Interviews
    • Offbeat
    • Thoughts
    • Podcast
    • Quiz
    • Tech
    • Archive
    • Trial By Trivia
    • Magazine
    • Supplement
  • বাংলা
The Business Standard

Monday
June 27, 2022

Sign In
Subscribe
  • Home
  • Economy
  • Stocks
  • Analysis
  • World+Biz
  • Sports
  • Features
  • Epaper
  • More
    • Subscribe
    • COVID-19
    • Bangladesh
    • Splash
    • Videos
    • Games
    • Long Read
    • Infograph
    • Interviews
    • Offbeat
    • Thoughts
    • Podcast
    • Quiz
    • Tech
    • Archive
    • Trial By Trivia
    • Magazine
    • Supplement
  • বাংলা
MONDAY, JUNE 27, 2022
Wide-ranging SolarWinds probe sparks fear in Corporate America

USA

Reuters
10 September, 2021, 12:30 pm
Last modified: 10 September, 2021, 12:35 pm

Related News

  • Sri Lanka hikes fuel prices as US delegation arrives
  • Chinese military says US plane in Taiwan Strait endangered peace
  • Abortion ruling imperils gay marriage, other freedoms, liberal justices say
  • Where abortion is still legal in the US after the fall of Roe v Wade
  • US ending abortion right a 'huge blow' to human rights : UN

Wide-ranging SolarWinds probe sparks fear in Corporate America

The SEC is asking companies to turn over records into "any other" data breach or ransomware attack dating back to October 2019 if they downloaded a bugged network-management software update from SolarWinds Corp, which delivers products used across corporate America

Reuters
10 September, 2021, 12:30 pm
Last modified: 10 September, 2021, 12:35 pm
The SolarWinds logo is seen outside its headquarters in Austin, Texas, US, December 18, 2020. REUTERS/Sergio Flores/File Photo
The SolarWinds logo is seen outside its headquarters in Austin, Texas, US, December 18, 2020. REUTERS/Sergio Flores/File Photo

A US Securities and Exchange Commission investigation into the SolarWinds Russian hacking operation has dozens of corporate executives fearful information unearthed in the expanding probe will expose them to liability, according to six people familiar with the inquiry.

The SEC is asking companies to turn over records into "any other" data breach or ransomware attack dating back to October 2019 if they downloaded a bugged network-management software update from SolarWinds Corp, which delivers products used across corporate America, according to details of the letters shared with Reuters.

People familiar with the inquiry say the requests may reveal numerous unreported cyber incidents unrelated to the Russian espionage campaign, giving the SEC a rare level of insight into previously unknown incidents that the companies likely never intended to disclose.

"I've never seen anything like this," said a consultant who works with dozens of publicly traded companies that recently received the request. "What companies are concerned about is they don't know how the SEC will use this information. And most companies have had unreported breaches since then." The consultant spoke on condition of anonymity to discuss his experience.

An SEC official said the request's intent was to find other breaches relevant to the SolarWinds incident.

The SEC told companies they would not be penalized if they shared data about the SolarWinds hack voluntarily, but did not offer that amnesty for other compromises.

Cyberattacks have grown in both frequency and impact, prompting deep concern in the White House over the last year. US officials have faulted companies for failing to disclose such events, arguing that it conceals the extent of the problem from shareholders, policymakers and law enforcement looking for the worst offenders.

People familiar with the SEC investigation told Reuters the letters went to hundreds of companies, including many in the technology, finance and energy sectors, thought to be potentially affected by the SolarWinds attacks. That number exceeds the 100 that the Department of Homeland Security said had downloaded the bad SolarWinds software and then had it exploited.

Since last year, only about two dozen firms have been publicly identified as impacted, including Microsoft Corp, Cisco Systems, FireEye Inc and Intel Corp. Of those contacted for this story only Cisco confirmed receiving the SEC letter. A Cisco spokesperson said it has responded to the SEC's request.

Cybersecurity research has also suggested software maker Qualys Inc and oil energy company Chevron Corp were among those targeted in the Russian cyber operation. Both declined to comment on the SEC investigation.

About 18,000 clients of SolarWinds downloaded a hacked version of its software, which the cyber criminals manipulated for potential future access. Yet only a small subset of those customers saw follow-on hacking activity, suggesting the attackers infected far more companies than they ultimately victimized.

The SEC sent letters last month to companies believed to have been affected, following an initial round sent in June, according to six sources who have seen the letters.

The second wave of requests were addressed to recipients at companies from the first round who had not responded. The exact number of recipients is unclear.

The current probe is "unprecedented" in terms of the lack of clarity over the SEC's goal in such a large sweep, said Jina Choi, a partner at Morrison & Foerster LLP and former SEC director who has worked on cybersecurity cases.

Though the SEC issued guidance a decade ago calling for companies to disclose hacks that could be material, then updated that guidance in 2018, most admissions have been vague.

Gary Gensler, who took the helm at the SEC in April, has tasked the agency with issuing new disclosure requirements ranging from cybersecurity to climate risk.

While the hack was first reported by Reuters more than nine months ago, the actual impact of the wide-scale digital spying operation, which US officials say came from a Russian intelligence service, remains largely unknown.

Government officials have shied away from sharing a comprehensive account of what was stolen or what the Russians were after, but described it as traditional government espionage.

Scores of companies have referred to the hacks in SEC filings, but many cite the events only as an example of the sort of intrusion they might one day experience. Most that say they had SolarWinds software installed add that they do not believe their most sensitive data was taken.

John Reed Stark, former head of the SEC's office of internet enforcement, said "companies will struggle to answer these questions – not just because these are broad, sweeping and all-encompassing requests, but also because the SEC is bound to discover some sort of mistake" in what they've previously disclosed.

World+Biz / Global Economy

USA / Corporate America / SolarWinds

Comments

While most comments will be posted if they are on-topic and not abusive, moderation decisions are subjective. Published comments are readers’ own views and The Business Standard does not endorse any of the readers’ comments.

Top Stories

  • Padma Bridge: Photo: Mumit M/TBS
    Sleepy south stirs to new possibilities
  • Photo: Collected
    2 motorcyclists killed in first accident on Padma Bridge
  • Photo: TBS
    Motorcycles banned on Padma Bridge 

MOST VIEWED

  • Abortion rights supporters protest outside the US Supreme Court the day after the United States Supreme Court ruled in the Dobbs v Women's Health Organization abortion case, overturning the landmark Roe v Wade abortion decision, in Washington, US, June 25, 2022. Photo: Reuters
    Legal clashes await US companies covering workers' abortion costs
  • A Spirit Airlines Airbuys A320-200 airplane sits at a gate at the O'Hare Airport in Chicago, Illinois, U.S. October 2, 2014.REUTERS/Jim Young/File Photo
    ISS urges Spirit shareholders to vote for Frontier offer
  • Illustration: Jason Leung/Unsplash
    As US current account gap balloons, new currency war may be a skirmish
  • People protest the Supreme Court decision to overturn Roe v Wade abortion decision in New York City, New York, US on 24 June 2022. Photo: Reuters
    Abortion rights activists face first day of post-Roe v Wade American life
  • US President Joe Biden signs S. 2938: Bipartisan Safer Communities Act into law from the Roosevelt Room at the White House as first lady Jill Biden stands next to him in Washington, US on 25 June 2022. Photo: Reuters
    Biden signs bipartisan gun safety bill into law; takes swipe at Supreme Court
  • Supreme Court Police line up outside the United States Supreme Court as the court rules in the Dobbs v Women's Health Organization abortion case, overturning the landmark Roe v Wade abortion decision in Washington, US on 24 June 2022. Photo: Reuters
    Supreme Court conservatives assert power with abortion, gun rulings

Related News

  • Sri Lanka hikes fuel prices as US delegation arrives
  • Chinese military says US plane in Taiwan Strait endangered peace
  • Abortion ruling imperils gay marriage, other freedoms, liberal justices say
  • Where abortion is still legal in the US after the fall of Roe v Wade
  • US ending abortion right a 'huge blow' to human rights : UN

Features

Photo: Noor A Alam

The reign of oversized pantsuits

12h | Mode
Photo: TBS

A dream dreamt and then delivered

1d | Panorama
In pictures: 2022 Dhaka Motor Show

In pictures: 2022 Dhaka Motor Show

1d | Wheels
Our team full of hope and mettle, before we entered the disaster zone. PHOTO: SWAMIM AHMED

How we survived 4 days in Sunamganj flood

2d | Panorama

More Videos from TBS

Jalamije becomes Georgian citizen to play Wimbledon

Jalamije becomes Georgian citizen to play Wimbledon

2h | Videos
Sievierodonetsk falls to Russia

Sievierodonetsk falls to Russia

6h | Videos
'Anondolok' is a fun field of dance,music and culture

'Anondolok' is a fun field of dance,music and culture

8h | Videos
Learn all about sports in Khelbei Bangladesh

Learn all about sports in Khelbei Bangladesh

12h | Videos

Most Read

1
Padma Bridge from satellite. Photo: Screengrab
Bangladesh

Padma Bridge from satellite 

2
Photo: Prime Minister's Office
Bangladesh

New investment in transports as Padma Bridge set to open

3
Japan cancels financing Matarbari coal project phase 2
Bangladesh

Japan cancels financing Matarbari coal project phase 2

4
Desco wanted to make a bold statement with their new head office building, a physical entity that would be a corporate icon. Photo: Courtesy
Habitat

Desco head office: When commitment to community and environment inspires architecture

5
Photo: TBS
Infrastructure

Gains from Padma Bridge to cross $10b, hope experts

6
20 businesses get nod for $326m foreign loan for expansion
Economy

20 businesses get nod for $326m foreign loan for expansion

EMAIL US
contact@tbsnews.net
FOLLOW US
WHATSAPP
+880 1847416158
The Business Standard
  • About Us
  • Contact us
  • Sitemap
  • Privacy Policy
  • Comment Policy
Copyright © 2022
The Business Standard All rights reserved
Technical Partner: RSI Lab
BENEATH THE SURFACE
Five aircraft of the Bangladesh Air Force performing in an airshow on Saturday. PHOTO: ISPR

Contact Us

The Business Standard

Main Office -4/A, Eskaton Garden, Dhaka- 1000

Phone: +8801847 416158 - 59

Send Opinion articles to - oped.tbs@gmail.com

For advertisement- sales@tbsnews.net