...
Skip to content

SEC ramps up SolarWinds hack probe: Bloomberg

(Reuters) — The U.S. Securities and Exchange Commission is asking technology and telecom companies how they handled the SolarWinds cyberattack in 2020, Bloomberg News reported Tuesday, citing people familiar with the matter.

The hack of information technology company SolarWinds, one of the broadest and most sophisticated cyberattacks ever in the U.S., was identified in December 2020. It affected thousands of companies and government offices that used SolarWinds’ products.

Hackers were able to use SolarWinds’ flagship network management software called Orion as a springboard into U.S. government networks and international targets.

The SEC has asked for internal communications of companies about the cyberattack’s impact, probing for gaps in corporate security and for other cyber incidents, the report said, citing people familiar with the matter who did not identify the companies.

The SEC did not immediately respond to a Reuters request for comment on the report.

Last year, the SEC sued SolarWinds and its top information security executive, saying they defrauded investors by hiding cybersecurity weaknesses during the massive hack.