SEC fines three companies over hacked employee email accounts
Full article414 words · extracted from therecord.media · click to collapse
The US Securities and Exchange Commission has fined three brokerage firms on Monday for neglecting to secure employee accounts, incidents that led to the exposure of their customers' data. Cetera Advisor Networks LLC, Cetera Investment Services LLC, Cetera Financial Specialists LLC, Cetera Advisors LLC, and Cetera Investment Advisers LLC (collectively, the Cetera entities); Cambridge Investment Research Inc. and Cambridge Investment Research Advisors Inc. (collectively, Cambridge); and KMS Financial Services Inc. (KMS) all settled with the SEC in three separate lawsuits [PDF: Cetera, Cambridge, KMS], the agency announced this week. According to court documents, the three companies were hacked multiple times between 2017 and 2020, hid the intrusions, and failed to properly notify customers. Cetera: Cambridge: KMS: The SEC said the three companies broke Rule 30(a) of Regulation S-P, also known as the Safeguards Rule, which requires companies to protect confidential customer information from hacks or accidental data leaks. "Investment advisers and broker dealers must fulfill their obligations concerning the protection of customer information," said Kristina Littman, Chief of the SEC Enforcement Division's Cyber Unit. "It is not enough to write a policy requiring enhanced security measures if those requirements are not implemented or are only partially implemented, especially in the face of known attacks." According to the settlements, the three companies also agreed to pay fines. Cetera will pay $300,000, Cambridge will pay $250,000, and KMS will pay $200,000, the SEC said.
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/sec-fines-three-companies-over-hacked-employee-email-accounts