SEC v. SolarWinds Corp. & CISO Timothy G. Brown (Securities Fraud)
Key Facts
- Legal Status: CHARGED in U.S. District Court for the Southern District of New York.
- Primary Target Sector: Public Markets & Corporate Governance.
- Documented Financial Loss: $26.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Public Markets & Corporate Governance networks. Landmark civil enforcement action brought by the SEC charging SolarWinds and its Chief Information Security Officer with securities fraud and internal accounting control failures, alleging company statements to investors overstated cyber defenses while internal executive communications conceded critical password and perimeter vulnerabilities.
Operational & Financial Fallout
Consolidated securities litigation settlement and ongoing legal defense costs. Impacted Public Markets & Corporate Governance infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Public Markets & Corporate Governance networks. Landmark civil enforcement action brought by the SEC charging SolarWinds and its Chief Information Security Officer with securities fraud and internal accounting control failures, alleging company statements to investors overstated cyber defenses while internal executive communications conceded critical password and perimeter vulnerabilities.
Adversary Kill Chain Flow
1 Documented PhasesSEC Complaint alleged SolarWinds maintained insecure credential management practices, including solarwinds123 password on public GitHub repos.
Consolidated securities litigation settlement and ongoing legal defense costs. Impacted Public Markets & Corporate Governance infrastructure and associated victim operations.
Procedural & Incident Timeline
SEC files federal enforcement action alleging Section 10(b) securities fraud against company and CISO.
SDNY Judge Paul Engelmayer dismisses internal controls claims but sustains core securities fraud claims based on public Security Statement.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "SEC Complaint alleged SolarWinds maintained insecure credential management practices, including solarwinds123 password on public GitHub repos." | SEC Complaint ¶ 41, Page 16 | reviewed |