HomeSecurityIntercontinental Exchange pays fine for late breach disclosure

Intercontinental Exchange pays fine for late breach disclosure

Intercontinental Exchange (ICE) will pay a $10 million finefor delaying the disclosure of a VPN breach. Specifically, the fine was imposed by the U.S. Securities and Exchange Commission (SEC) because the company did not immediately notify its subsidiaries and thus did not promptly report a security in April 2021.

Intercontinental Exchange VPN breach fine

Under the Systems Compliance and Integrity (SCI Regulation), companies must immediately notify the SEC of security breaches and provide an update within 24 hours, unless they determine that the impact on their operations or the market is negligible.

The SEC says that in the case of the breach , it was not notified of the incident as required. Instead, Commission staff contacted the subsidiaries.

See also: OmniVision reveals data breach

“It reportedly took them four days to assess its impact and internally conclude that it was a de minimis event. When it comes to cybersecurity ,especially for incidents at critical market players, every second counts and four days can be an eternity.“.

Intercontinental Exchange discovered the incident on April 15, 2021, after being notified by a third party of a possible system intrusion linked to an unknown virtual private network (VPN) vulnerability.

State hackers behind the breach?

Subsequent investigation revealed that the attackers deployed a malicious payload on a compromised VPN device, which was used for remote access to the corporate network.

“Sophisticated threat actors, believed to be government hackers, installed a webshell code on a compromised VPN device in an attempt to collect information passing through that device, including employee name, password, and multi-factor authentication codes. This data could allow the attacker to gain access to internal corporate networks,” the SEC reveals.

See also: Hacker says he exposed 70,000 National Parent Teacher Association files

However, the Intercontinental Exchange security team found that access was limited to a single compromised VPN device, even though there was evidence that the attacker stole “data and some ICE user meta-data.”

The SEC says ICE staff failed to notify legal and compliance officials at the company’s subsidiaries for several days, violating both Reg SCI rules and subsidiaries ICE’s ownfailed to properly assess the intrusion and failed to meet their Reg SCI disclosure obligations.

Intercontinental Exchange pays fine for late breach disclosure

Intercontinental Exchange and its subsidiaries agreed to the SEC order, acknowledging that the subsidiaries violated the reporting provisions of the SCI regulation. ICE is responsible for the violation of the provisions.

This settlement serves as a reminder to companies of the importance of promptly reporting cybersecurity incidents and implementing robust policies and procedures to mitigate risks . It also highlights the increasing scrutiny from regulatory bodies regarding companies’ cybersecurity practices

In recent years, there has been a significant increase in cyber attacks targeting businesses, with hackers constantly finding new ways to exploit vulnerabilities. This makes it essential for companies to have strong systems for preventing and dealing with cyber threats.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Panda Restaurant reveals data breach

In addition to regulatory sanctions, companies also face reputational and financial damage from security. Customers may lose confidence in a company's ability to protect their data, leading to reduced business and potential lawsuits.

Therefore, it is vital for companies to prioritize cybersecurity and invest in measures such as regular risk assessments, employee training, and incident response plans.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS