The U.S. Securities and Exchange Commission (SEC) disclosed on Tuesday that it has reached settlements with four companies regarding charges of misleading disclosures related to the 2020 SolarWinds hacking incident, which has been linked to a nation-state.

The SEC stated that these four companies—Unisys, Avaya Holdings, Check Point Software Technologies, and Mimecast—were all aware that the threat actors behind the SolarWinds hack had breached their systems. The SEC charged that these companies downplayed the actual impact of their respective incidents in public disclosures, with Unisys also being charged with violating disclosure controls and procedures.

Sanjay Wadhwa, Acting Director of the SEC's Division of Enforcement, said: "As reflected in today's enforcement actions, while public companies may become targets of cyberattacks, they have a responsibility not to further harm shareholders or the investing public by providing misleading disclosures about the cybersecurity incidents they encounter."

This is not the first time the SEC has brought charges regarding how companies handled this supply chain attack. The attack, carried out by a threat group known as Nobelium, affected users of the SolarWinds Orion platform. In 2023, the SEC filed fraud charges against SolarWinds and its CISO Tim Brown, alleging they misled investors about the true nature of cyber risks. Although most of that case was dismissed, the core part was allowed to proceed.

For the SEC, the key issue is how companies describe their risks or level of exposure.

According to SEC orders, Unisys in particular described its cyber risks as hypothetical, even though company executives knew that threat actors had stolen several gigabytes of data. Unisys disclosed the settlement in its SEC filing, including a $4 million civil penalty, and stated that the agreement constitutes neither an admission nor a denial of wrongdoing.

Avaya, on the other hand, disclosed that hackers accessed a limited number of emails, but according to SEC orders, hackers actually accessed 145 files in its cloud file-sharing environment. Avaya was fined $1 million in civil penalties, and the company said it was pleased to resolve the matter, noting that the SEC considered its voluntary cooperation. The company said via email that it has taken steps to strengthen network controls.

Check Point Software, according to the orders, described the intrusion in general terms despite knowing the true nature of the breach. Check Point Software had previously disclosed its investigation, stated that the settlement was in the company's best interest, and agreed to pay a $995,000 civil penalty. In an email statement, the company reiterated that it had investigated the SolarWinds incident and found no evidence that customer data, code, or other sensitive information was accessed.

Mimecast, according to the orders, was aware of the attack but did not disclose the nature of the stolen code or the number of encrypted credentials that were stolen. The company agreed to pay a $990,000 civil penalty. Mimecast is no longer publicly traded, and it stated that when it learned of the incident in January 2021, it made extensive disclosures and communicated with customers and partners. In an email statement, the company said: "Based on the regulatory requirements at the time, we believe we complied with our disclosure obligations."