US government sues SolarWinds for security failings

Security attack
(Image credit: Shutterstock / ozrimoz)

Three years after the major cyber-incident at SolarWinds, the US Securities and Exchange Commission (SEC) is suing the firm. 

In the lawsuit, the government agency alleges that the company and its executive staff knew their systems’ security was an utter disaster for months, if not years before the data breach incident.

However, instead of notifying investors and users, they kept the information for themselves and even tried to convince everyone the firm’s assets were secure.

Worries over Orion

"We allege that, for years, SolarWinds and Brown (SolarWinds CISO Timothy G. Brown), ignored repeated red flags about SolarWinds' cyber risks, which were well known throughout the company and led one of Brown's subordinates to conclude: 'We're so far from being a security minded company,'" said Gurbir S. Grewal, the head of SEC's Division of Enforcement.

"Rather than address these vulnerabilities, SolarWinds and Brown engaged in a campaign to paint a false picture of the company's cyber controls environment, thereby depriving investors of accurate material information."

Brown also worried that someone could use Orion in future attacks, because the organization’s backend systems weren’t resilient, the SEC claims. In an ironic twist of fate, it was exactly Orion that was used to deliver highly destructive malware to numerous organizations around the world. 

Back in 2020, a Russian hacking organization known as APT29 breached SolarWinds, discovered a patch for Orion that was in the works, and compromised it with malicious code. Once SolarWinds pushed the update to its clients, most of them were infected. 

According to a BleepingComputer report, APT29 is linked to the Russian Foreign Intelligence Service (SVR) hacking division. 

Commenting on the news, the company’s President and CEO, Sudhakar Ramakrishna, said the lawsuit is “alarming”, and that the SEC’s behavior is “misguided” and an “improper enforcement action”.

"We made a deliberate choice to speak—candidly and frequently—with the goal of sharing what we learned to help others become more secure. We partnered closely with the government and encouraged other companies to be more open about security by sharing information and best practices,” he was cited as saying.

"Unfounded" accusations

"The SEC's charges now risk the open information-sharing across the industry that cybersecurity experts agree is needed for our collective security."

A subsequent company statement added that the charges are “unfounded” and that they’ll put American national security at risk. 

“The SEC’s determination to manufacture a claim against us and our CISO is another example of the agency’s overreach and should alarm all public companies and committed cybersecurity professionals across the country. We look forward to clarifying the truth in court and continuing to support our customers through our Secure by Design commitments.”

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A wall of data on a large screen.
“It's the same doors that the good guys use, that the bad guys can walk through” - former White House tech advisor on data-centric security in the wake of Salt Typhoon
Eu
Is your business ready for DORA? Cisco ThousandEyes outlines the "three pillars" everyone needs to have in place to be resilient
EU
“Rehearse, rehearse, rehearse” - is your business doing enough on DORA compliance?
An illustration of a silhouetted thief in motion running while carrying a stolen fingerprint
The 5 worst cyberattacks of 2024
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Meta warns of worrying security flaw hitting open source type software
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Data leak
Hacked Tata Technologies data leaked by ransomware gang
Latest in News
The Google Gemini logo against a black background.
I tried Gemini's new AI image generation tool - here are 5 ways to get the best art from Google's upcoming Flash 2.0 built-in image upgrade
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Samsung Galaxy S26 Ultra could resurrect an intriguing camera feature
Eurocom Raptor X18
At $15,000, this massive 256GB RAM laptop makes Apple's MacBook Pro look affordable, tiny and very, very slow
Cristin Milioti in Black Mirror season 7
Netflix launches trailer for Black Mirror season 7, giving us a look at its first-ever sequel episode and an unexpected returning character
A graphic of the PC Gaming Show
Get ready for a bounty of PC games on June 8, as the PC Gaming show is back
A close up of The Daily podcast from Pocket Casts' web page
‘Podcasting shouldn’t be locked behind walled gardens’: Pocket Casts slams Spotify and makes its web player free to all