Ah, right on time: Hacker-slammed SolarWinds sued by angry shareholders
- Reference: 1609887811
- News link: https://www.theregister.co.uk/2021/01/05/solarwinds_sued/
- Source link:
Last month, it emerged the update server used by SolarWinds to distribute its Orion software had [1]been subverted by miscreants to secretly inject a backdoor into the code so that hackers could infiltrate the computers of customers who installed the product. Said customers included tons of government organizations and corporations worldwide. And in a statement on Tuesday, the US government's National Security Council task force probing the tampering said it was highly likely those miscreants were Russian spies seeking out confidential and vital information.
"This work indicates that an Advanced Persistent Threat (APT) actor, likely Russian in origin, is responsible for most or all of the recently discovered, ongoing cyber compromises of both government and non-governmental networks," the council's statement [2]reads .
This work indicates that an Advanced Persistent Threat (APT) actor, likely Russian in origin, is responsible for most or all of the recently discovered, ongoing cyber compromises of both government and non-governmental networks
"At this time, we believe this was, and continues to be, an intelligence gathering effort. We are taking all necessary steps to understand the full scope of this campaign and respond accordingly."
The task force reckons 18,000 public and private sector orgs downloaded the tainted Orion builds, but that "a much smaller number" suffered further network intrusions via the implanted backdoor. In other words: plenty of IT departments installed the software but the hackers only sneaked into a few places through the hidden security hole. Nevertheless the damage to SolarWinds' reputation and share price has been great and its stockholders are furious.
Their [3]lawsuit [PDF], filed in Texas and seeking class-action status, alleges SolarWinds’ president Kevin Thompson and its CFO Barton Kalsu violated America's securities law after they “misrepresented and failed to disclose” critical facts.
Well, on the bright side, the SolarWinds Sunburst attack will spur the cybersecurity field to evolve all over again [4]READ MORE
The legal challenge points out that when the world [5]learned of the backdooring, it led to a "precipitous decline in the market value of the company’s securities," which led to "significant losses and damages.” In other words, they lost money when the company’s shares dropped sharply in December when the hack was revealed. The picture has since [6]worsened .
The lawsuit alleges that the software biz had failed to warn shareholders in a timely manner that a backdoor had been planted in its Orion monitoring products from the middle of 2020, which opened up systems used by the US federal government and corporations. Microsoft, for example, [7]said it installed the tainted suite though not on production networks.
The lawsuit also points out that SolarWinds’ update server was at one time only protected by the [8]insanely bad password solarwinds123, which was not a great indication of security being taken seriously.
A little knowledge is a dangerous thing
It further alleges that execs had "actual knowledge of the material omissions and/or the falsity of the material statements" and intended to "deceive plaintiff… or, in the alternative, acted with reckless disregard for the truth when they failed to ascertain and disclose the true facts in the statements made by them." The argument is that by failing to disclose its true security situation, the company’s share price was being “artificially inflated.”
In its quarterly filings with the SEC, SolarWinds included the standard boilerplate warning to investors about its cybersecurity efforts: that there was an increase in the "number, intensity and sophistication of attempted hacks and intrusions from around the world," and that as a result it "may be unable to anticipate these techniques or to implement adequate preventative measures." As a result, SolarWinds’ software could be breached and lead to a "severe reputational damage adversely affecting customer or investor confidence."
SolarWinds releases known attack timeline, new data suggests hackers may have done a dummy run last year [9]READ MORE
The question that the lawsuit is likely to dig into is whether that warning was sufficient or whether execs knew things were potential far worse and failed to relay that information properly.
The lawsuit references reports three days after the hack became public in which security researcher Vinoth Kumar said he had “alerted the company that anyone could access SolarWinds’ update server by using the password ‘solarwinds123.’” The lawsuit also notes that days after the hack was revealed, the compromised Orion software updates were still on SolarWinds’ website, though we note they were no longer directly linked from any webpages.
The lawsuit wants damages for "reasonable costs and expenses incurred" as well as lawyers’ fees and any fines a court may put on the company though doesn’t put a dollar figure on it. ®
Get our [10]Tech Resources
[1] https://www.theregister.com/2020/12/14/solarwinds_fireeye_cozybear_us_government/
[2] https://www.cisa.gov/news/2021/01/05/joint-statement-federal-bureau-investigation-fbi-cybersecurity-and-infrastructure
[3] https://regmedia.co.uk/2021/01/05/solarwinds.pdf
[4] https://www.theregister.com/2020/12/21/solarwinds_sunburst_evolve/
[5] https://www.theregister.com/2020/12/14/solarwinds_fireeye_cozybear_us_government/
[6] https://www.theregister.com/2021/01/04/solarwinds_malware_confirmed/
[7] https://www.theregister.com/2020/12/18/solarwinds_nnsa_microsoft_cisa/
[8] https://www.theregister.com/2020/12/16/solarwinds_github_password/
[9] https://www.theregister.com/2020/12/21/in_brief_security/
[10] https://whitepapers.theregister.com/
You gambled, you lost. Deal with it.
You sit down at a casino table, drop your money on a random blob, & spin the wheel, throw the dice, take your cards, whatever. You agree to the risks when you sat down & told the table master to include you. You spun the wheel, threw the dice, accepted the cards & the wheel came up a different blob, the dice came up snake eyes, the cards were crap. You lost. Too bad. That's gambling.
What makes you think playing the stock market is any different? Sure the company is supposed to remind you that you're gambling, they did remind you, so if they did their due dilligence then you're shit out of luck. You gambled, you lost, deal with it.
Having said that, IF the company did NOT do it's due diligence THEN you have a case, but as far as TFA indicates they did & you're screwed. It sucks but you need to put your Adult Pants on & deal with it like one.
Re: You gambled, you lost. Deal with it.
Considering there's already circumstantial evidence and cover-ups are very common in these circumstances it looks like they're making another value bet that the discovery will turn up something. That's plenty grown up and it's their money to throw at lawyers if they want to.
Re: You gambled, you lost. Deal with it.
The 'tell' was that insiders dropped a whole lot of the stock at a decent price before the news hit. The timeline started with the disclosure of the screwup by a security researcher who, if I recall correctly, communicated privately to the company. This happened at least six weeks before the announcement and during that time -- in fact just before the annoucement -- several insiders dropped a considerable amount of stock on the market that was picked up by a Canadian pension fund.
The SEC not only takes a really dim view of insider trading but the pension fund is correct to feel duped. There was ample time to disclose the potential risk to what was a major investor but somehow this got lost in the wash. Investors are used to risk, they just don't like being conned.
The operation is not over
Whilst there may be a whole host of other companies to step in to take over this lost business and, yes, SolarWinds may have screwed up with some fundamentals OpSec, I'm not sure suing them out of existence is going to do the world any good.
There would have likely been a reason many of these huge customers chose to use them and not some alternative. At a guess, maybe because they tick more boxes than the competition making them the "best".
Whilst there definitely should be a review of what happened (and i willingly prepare to eat my words), they were the target of a state level attack, there's very little they could probably do to have prevented the attack. What should be happening is learning lessons to make sure that a repeat can't ever happen again and to move on.
To use analogy, it would be like West Bromwich Albion firing Sam Johnstone (according to stats, he is best goalkeeper in Premier league) because they lost 4-0 to Arsenal (also Google it yourself). Maybe, there was nothing in his power he could have done to be better Arsenal were happily dancing around a laughable defense. The team itself should reflect on the situation, not just blame the goaly
Re: The operation is not over
Oh, gimme a break! "Maybe, there was nothing in his power he could have done..."? With "solarwinds123" password (1FA) on an update server?
Microsoft and others should drop SolarWinds as a hot potato, immediately. The guys are just plain incompetent.
That's the problem with using third-party software, and by proxy that's the problem with cloud computing in general: you rely on somebody else's competence, which you know nothing about.
Re: The operation is not over
> I'm not sure suing them out of existence is going to do the world any good.
Oh yes, it would.
For one, it would discourage anyone thinking about it from using their Certified Piece Of Shit software. For two, any time C-level execs do a massive stock dump before major negative news hits, they inadvertently answer any questions one may have had about securities fraud. For three, SolarWinds had no intentions of disclosing any of this. The disclosure was forced by FireEye, who, as user of SolarWinds' software, was massively penetrated .
Very few details are available - as of yet - about how any of this may have happened, but from the few tidbits that have been made public thus far there is plenty of evidence of negligence and outright reckless incompetence. Hint: setting up development shop in Poland because it's cheap. Cheap it may be, but it's also full of [1]SVR .
[1] https://en.wikipedia.org/wiki/Foreign_Intelligence_Service_(Russia)
In their defence
They could always try quoting this; https://off-guardian.org/2021/01/04/the-russian-hacking-nato-psyop-has-finally-been-solved/
But I am not too sure it would do them any good.