In last week’s installment of our Navigating DOJ Cybersecurity Enforcement Series, we discuss the Department of Justice (“DOJ”) vigorous pursuit of enforcement actions related to Cybersecurity Fraud under a variety of new and developing regulations, including the Cybersecurity Maturity Model Certification rule. So, what is the impetus behind the DOJ’s Civil Cyber-Fraud Initiative? Enter SolarWinds, a highly publicized cybersecurity attack that came to light in 2020. The initial breach began over a year before it was ultimately discovered by an external entity. During the attack, hackers gained access to SolarWinds’ Orion network, which interfaced with the internal network of several federal agencies, including the U.S. Treasury, the Department of Homeland Security, the Department of State, the Department of Commerce, the National Institutes for Health, and the DOJ. Hackers exploited vulnerabilities in SolarWinds’ network, creating a backdoor and granting hackers unfettered access to sensitive government information. This attack placed national security at risk and underscored the rise of cyber espionage. The stark reality of that risk highlighted the importance of ensuring the strength and integrity of cybersecurity systems protecting sensitive Government data.
SolarWinds provides IT management software to organizations worldwide. The Orion platform, which is its flagship product, offers network monitoring and management capabilities utilized by over 32,000 customers, including Government agencies, Fortune 500 companies, and critical infrastructure operators. As a monitoring software, Orion maintained privileges to monitor the network traffic of its customers, including open access to those organizations’ infrastructures. Therefore, compromising Orion would grant hackers access to the internal systems and data of all SolarWinds’ customers.
Starting in September 2019, remote hackers, later determined to be a group associated with Russian foreign intelligence, gained access to SolarWinds’ internal development environment, and began inserting innocuous test codes into the Orion Platform. These were designed to test whether the hackers would be able to modify the Orion program and access data throughout SolarWinds customer networks without being detected. They were successful. The malicious code, known as Sunburst, was deployed in February 2020. It was sophisticated enough to avoid detection by systems running automatic security tools to randomize its communications to blend with normal network traffic. The effect of Sunburst was compounded by SolarWinds’ distribution of compromised software updates to nearly 18,000 of its customers throughout the Spring of 2020.
From March through December 2020, Sunburst ran rampant through targeted networks, using supposedly legitimate credentials to access email systems and exfiltrate sensitive data. The breach was not uncovered until one of SolarWinds’ customers detected unauthorized access to its own systems. By then, the attack had already imposed substantial costs on affected organizations, including agencies of the United States government.
The U.S. Securities and Exchange Commission (“SEC”) ultimately pursued a large-scale enforcement action against SolarWinds. Following the discovery and investigation of the hack, the SEC filed a lawsuit in the Southern District of New York against SolarWinds in 2023 alleging that the company and its CISO, Timothy Brown, misled investors by overstating its cybersecurity practices and failing to disclose known vulnerabilities. The lawsuit further alleged that SolarWinds concealed critical information regarding its security risks and identified incidents from its IPO in 2018 to the public disclosure of the breach in December 2020, and that its disclosures contained material and false and misleading statements. While the matter was ultimately dismissed through a joint motion by the parties in November 2025 under undisclosed terms, the intensity of the SEC’s investigation accentuates the risks companies face in the Government’s recalibration of cybersecurity enforcement efforts. Further updates on the SEC’s regulations and enforcement efforts will be detailed in a subsequent alert.
The SolarWinds attack exposed vulnerabilities in cybersecurity systems, specifically ones that run automated programs to detect breaches. Industry leaders reacted by touting safeguards, including implementing security information and event management systems, active directory monitoring systems, penetration testing, and data loss prevention systems. This ultimately spurred the Government to strengthen cybersecurity regulations and impose strict requirements on any company with access to Government data of any kind, shifting industry best practices into legal imperatives. Those imperatives in turn have resulted in a sweeping crackdown through cybersecurity fraud investigations.
This alert is part of an ongoing series through which Leech Tishman will track developments in the DOJ’s Cybersecurity Fraud Enforcement program and issue continuing legal updates addressing compliance obligations, impacted industries, and the relevant regulatory requirements. View the first alert in this series here.
Leech Tishman’s Labor & Employment attorneys regularly counsel clients on compliance with statutory and common law requirements. Our team is prepared to assist your company in understanding and implementing the obligations and compliance measures required under the DOJ’s Cybersecurity Fraud Enforcement program. For assistance or additional information, please contact Lydia A. Pappas at lpappas@leechtishman.com, attorney in Leech Tishman’s Labor & Employment Practice Group.