Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

SEC Continues its Cybersecurity Focus, Settles with Company over Lax Security Measures

By Julia Kadish & Samantha Davis on August 28, 2024
Email this postTweet this postLike this postShare this post on LinkedIn
Chained
Jose Fontano, Unsplash

The SEC recently issued an order and settlement against a company from a pair of cyberattacks in which millions of dollars of client funds were stolen. While the company was able to recover a portion of the funds and ultimately reimbursed clients for the money lost, the SEC still fined the company $850,000 for failure to provide the necessary safeguards to protect its clients’ funds.

In both attacks, cyber criminals were able to transfer of large sums of money to external bank accounts. The first incident stemmed from a threat actor hijacking an existing email chain and pretending to be a client. The attacker then requested the issuance and liquidation of new shares to an external account. In the second incident, an attacker used stolen Social Security Numbers from an unknown source to create fake accounts and link to legitimate accounts even though other personal information attached to the accounts didn’t match. In both instances, the attacker transferred funds out to external accounts.

The order highlights what the SEC expects when it comes to employee training and security protocols. Although the company had sent employees alerts about fraud and guidance on the importance of call-backs to verify requests and to pay attention to requesters’ email addresses, the SEC found this to be insufficient. The SEC said that the company should’ve taken additional steps such as confirming that the warning email was read by employees, that training was provided, and to otherwise confirm that call-backs were in-fact being performed.

Putting it Into Practice: This case servers as a reminder of the types of monitoring and measuring criteria regulators may expect when it comes to demonstrating that employees have been adequately trained. Copies of training materials or warning newsletters may no longer be enough. Regulators are more and more interested in how a company evaluates whether its cyber training is effective and how they are monitoring employee compliance. 

Photo of Julia Kadish Julia Kadish

Julia Kadish is a partner in the Intellectual Property Practice Group in the firm’s Chicago office and a member of the Privacy and Cybersecurity Team.

Read more about Julia KadishEmail
Photo of Samantha Davis Samantha Davis

Samantha Davis is an associate in the Intellectual Property Practice Group in the firm’s New York office and a member of the Privacy & Cybersecurity Team.

Read more about Samantha DavisEmail
  • Posted in:
    Banking, Finance and Securities, Privacy and Cybersecurity
  • Blog:
    Eye On Privacy
  • Organization:
    Sheppard, Mullin, Richter & Hampton LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo