
Background
Alarum is a web data collection services provider. The company’s American Depositary Shares (ADSs) trade on Nasdaq. The company operates a subsidiary called NetNut that manages a web data collection service. The complaint alleges that during the class period, Alarum detailed NetNut’s and Alarum’s “competitive advantages,” including, among other things, the security and safety of the company’s services.
On July 2, 2026, Reuters published an article entitled “Google disrupts NetNut proxy network used in malware operations,” (here), which stated, among other things, that Google had weakened a network of internet-connected devices being used to conceal and route malicious online traffic, acting against the NetNut residential proxy operator.” The article stated that the proxy networks were being used to mask the origin of the traffic and to bypass security defenses, in a way that is “frequently exploited for cybercrime.”
Another media story published the same day, entitled “FBI Probes whether Alarum Unit is Behind Co-Opted Home Devices,” stated that for more than a year, the FBI had been investigating whether the NetNut unit’s network “had a role in linking customers’ home internet devices without their consent into a network that people can use to disguise their locations.” The article quoted one commentator as saying that “most users may not even notice the uninvited proxy internet squatters until the police come to their door investigating cybercrime coming from the home.”
In response to these reports, the company paused traffic through the relevant networks, in a way that significantly reduced the company’s services and that the company said was likely to have a material adverse impact on the company’s operations and financial results. According to the securities complaint, the price of the company’s ADSs declined by more than half on this news.
The Lawsuit
The complaint alleges that during the class period, the defendants made false or misleading statements or failed to disclose that: “(1) an Alarum Technologies subsidiary, NetNut, was engaging in illegal activity by linking customer home internet devices into another network without the customer’s consent; (2) this activity allows cyber criminals to conceal their locations; (3) the foregoing materially highlighted Alarum Technologies’ legal exposure and materially threatened its business prospects; and (4) as a result, Defendants’ statements about Alarum Technologies’ business, operations, and prospects were materially false and misleading and/or lacked a reasonable basis at all times.”
The complaint alleges that the defendants violated Sections 10(b) and 20(a) of the Securities Exchange Act of 1934 and Rule 10b-5 thereunder. The complaint seeks to recover damages on behalf of the class.
Discussion
As I noted at the outset, this new lawsuit is a reminder that cybersecurity-related issues remain an important potential source of D&O claims and liability. At the same time, however, this new lawsuit is quite a bit different from the kind of cybersecurity lawsuits filed in the past.
The typical allegations in prior cybersecurity-related securities suits would involve allegations that a bad actor had, unknown to the defendant company, infiltrated the company’s networks and systems, and accessed private or confidential data. This new complaint alleges that the company’s own allegedly improper actions created an environment that facilitated misuse of the company’s proxy networks in a way that allowed third parties to mask their locations and potentially engage in cybercrime. The new lawsuit is, however, similar to prior suits in at least one way, in that it involves allegations that cybersecurity vulnerabilities facilitated the activities of third-party bad actors.
The lawsuit has only just been filed, and it remains to be seen how it will fare. It is worth noting that the complaint quotes extensively from the company’s risk factor disclosures, in which the company repeatedly emphasized that the company’s operations and financial performance would suffer if the company were to experience network security issues or regulatory concerns. It also seems plausible that the company was as blindsided by the apparent misuse of its proxy network as anyone was, which would certainly undermine the plaintiffs’ allegations that the company acted with scienter to mislead investors.
In any event, this new complaint is a reminder that, even amidst ongoing discussion of the current securities litigation hot topics such as AI and geopolitics, cybersecurity issues remain an important potential source of D&O liability and claims.