{
  "id": "case-sec-v-solarwinds-ciso",
  "slug": "sec-v-solarwinds-ciso-brown",
  "title": "SEC v. SolarWinds Corp. & CISO Timothy G. Brown (Securities Fraud)",
  "summary": "Landmark civil enforcement action brought by the SEC charging SolarWinds and its Chief Information Security Officer with securities fraud and internal accounting control failures, alleging company statements to investors overstated cyber defenses while internal executive communications conceded critical password and perimeter vulnerabilities.",
  "case_number": "1:23-cv-09518-PAE",
  "court": "U.S. District Court for the Southern District of New York",
  "district": "S.D.N.Y.",
  "country": "United States",
  "opened_at": "2023-10-30",
  "status": "charged",
  "victim_sector": "Public Markets & Corporate Governance",
  "victim_country": "United States",
  "loss_amount_usd": 26000000,
  "loss_amount_note": "Consolidated securities litigation settlement and ongoing legal defense costs.",
  "first_seen_at": "2018-01-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "apt29",
  "defendant_slugs": [
    "timothy-brown"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "SEC Complaint alleged SolarWinds maintained insecure credential management practices, including solarwinds123 password on public GitHub repos.",
      "evidence_locator": "SEC Complaint \u00b6 41, Page 16",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Complaint: SEC v. SolarWinds & Timothy G. Brown",
      "source_url": "https://www.sec.gov/litigation/complaints/2023/comp-pr2023-227.pdf",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "complaint",
      "event_date": "2023-10-30",
      "description": "SEC files federal enforcement action alleging Section 10(b) securities fraud against company and CISO."
    },
    {
      "event_type": "ruling",
      "event_date": "2024-07-18",
      "description": "SDNY Judge Paul Engelmayer dismisses internal controls claims but sustains core securities fraud claims based on public Security Statement."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Public Markets & Corporate Governance networks. Landmark civil enforcement action brought by the SEC charging SolarWinds and its Chief Information Security Officer with securities fraud and internal accounting control failures, alleging company statements to investors overstated cyber defenses while internal executive communications conceded critical password and perimeter vulnerabilities.",
    "blast_radius": "Consolidated securities litigation settlement and ongoing legal defense costs. Impacted Public Markets & Corporate Governance infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "SEC Complaint alleged SolarWinds maintained insecure credential management practices, including solarwinds123 password on public GitHub repos.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}