CASE DOSSIER charged

SEC v. SolarWinds Corp. & CISO Timothy G. Brown (Securities Fraud)

Docket: 1:23-cv-09518-PAE Court: U.S. District Court for the Southern District of New York Opened: 2023-10-30 Sector: Public Markets & Corporate Governance

Key Facts

Status
CHARGED
Legal disposition
Loss Amount
$26.0 million
Consolidated securities litigation settlement and ongoing legal defense costs.
Techniques
1
Verified mappings
Defendants
0
Named in charges
  • Legal Status: CHARGED in U.S. District Court for the Southern District of New York.
  • Primary Target Sector: Public Markets & Corporate Governance.
  • Documented Financial Loss: $26.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Landmark civil enforcement action brought by the SEC charging SolarWinds and its Chief Information Security Officer with securities fraud and internal accounting control failures, alleging company statements to investors overstated cyber defenses while internal executive communications conceded critical password and perimeter vulnerabilities.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Public Markets & Corporate Governance networks. Landmark civil enforcement action brought by the SEC charging SolarWinds and its Chief Information Security Officer with securities fraud and internal accounting control failures, alleging company statements to investors overstated cyber defenses while internal executive communications conceded critical password and perimeter vulnerabilities.

Operational & Financial Fallout

Consolidated securities litigation settlement and ongoing legal defense costs. Impacted Public Markets & Corporate Governance infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Public Markets & Corporate Governance networks. Landmark civil enforcement action brought by the SEC charging SolarWinds and its Chief Information Security Officer with securities fraud and internal accounting control failures, alleging company statements to investors overstated cyber defenses while internal executive communications conceded critical password and perimeter vulnerabilities.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

SEC Complaint alleged SolarWinds maintained insecure credential management practices, including solarwinds123 password on public GitHub repos.

Artifacts & Tooling: T1078 Valid Accounts
Real-World Blast Radius & Operational Fallout

Consolidated securities litigation settlement and ongoing legal defense costs. Impacted Public Markets & Corporate Governance infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2023-10-30 complaint

SEC files federal enforcement action alleging Section 10(b) securities fraud against company and CISO.

2024-07-18 ruling

SDNY Judge Paul Engelmayer dismisses internal controls claims but sustains core securities fraud claims based on public Security Statement.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"SEC Complaint alleged SolarWinds maintained insecure credential management practices, including solarwinds123 password on public GitHub repos." SEC Complaint ¶ 41, Page 16 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, SEC v. SolarWinds Corp. & CISO Timothy G. Brown (Securities Fraud), No. 1:23-cv-09518-PAE (U.S. District Court for the Southern District of New York 2023), https://cybercaselibrary.com/cases/sec-v-solarwinds-ciso-brown/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/sec-v-solarwinds-ciso-brown" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>