{"id":2064,"date":"2023-11-17T22:35:00","date_gmt":"2023-11-17T22:35:00","guid":{"rendered":"https:\/\/www.darkreading.com\/risk\/alphv-ransomware-group-files-sec-complaint-against-own-victim"},"modified":"2023-11-17T22:35:00","modified_gmt":"2023-11-17T22:35:00","slug":"hackers-weaponize-sec-disclosure-rules-against-corporate-targets","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/11\/17\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets\/","title":{"rendered":"Hackers Weaponize SEC Disclosure Rules Against Corporate Targets"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets-1.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p>The ransomware group ALPHV (aka &#8220;BlackCat&#8221;) has filed a formal complaint with the US Securities and Exchange Commission (SEC), alleging that a recent victim failed to comply with new disclosure regulations.<\/p>\n<p>An ALPHV insider <a href=\"https:\/\/www.databreaches.net\/alphv-files-an-sec-complaint-against-meridianlink-for-not-disclosing-a-breach-to-the-sec\/\" target=\"_blank\" rel=\"noopener\">told databreaches.net<\/a> that, on Nov. 7, the group successfully attacked the digital lending service provider MeridianLink, exfiltrating without encrypting its files. Thereafter, aside from one interaction, <a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/blackcat-alphv-gang-wiper-functionality-ransomware-tactic\" target=\"_blank\" rel=\"noopener\">the prolific threat actor<\/a> failed to engage the company in negotiations over the stolen data.<\/p>\n<p>ALPHV posted that data to its leak site on Wednesday. It also tried out an unprecedented extra extortion tactic, filing a report about its own crime to the SEC, claiming that its victim failed to follow<a href=\"https:\/\/www.darkreading.com\/edge\/steps-to-follow-to-comply-with-the-sec-cybersecurity-disclosure-rule\" target=\"_blank\" rel=\"noopener\"> new SEC guidelines<\/a> for how soon companies have to publicly disclose their breaches.<\/p>\n<p>&#8220;This is yet another warning to security leaders, who must recognize that disclosure decisions and plans are no longer solely guided by security best practices; federal legal liabilities also play an important role,&#8221; says Patrick Tiquet, vice president of security and architecture at Keeper Security.<\/p>\n<h2 class=\"regular-text\">ALPHV Playing Cop and Robber at the Same Time<\/h2>\n<p>On July 26, <a href=\"https:\/\/www.darkreading.com\/edge\/sec-adopts-new-rule-on-cybersecurity-incident-disclosure-requirements\" target=\"_blank\" rel=\"noopener\">the SEC announced new cyber rules<\/a> for public companies. One standout was a requirement that companies disclose &#8220;any cybersecurity incident they determine to be material,&#8221; along with a description of &#8220;the material aspects of the incident&#8217;s nature, scope, and timing, as well as its material impact or reasonably likely material impact on the registrant.&#8221; Such a submission &#8220;will generally be due four business days after a registrant determines that a cybersecurity incident is material.&#8221;<\/p>\n<p>When four days passed with no word from MeridianLink, ALPHV submitted information about the breach through the SEC&#8217;s official website:<\/p>\n<p>&#8220;We want to bring to your attention a concerning issue regarding MeridianLink&#8217;s compliance with the recently adopted cybersecurity incident disclosure rules,&#8221; the group wrote. &#8220;It has come to our attention that MeridianLink, in light of a significant breach compromising customer data and operational information, has failed to file the requisite disclosure under Item 1.05 of Form 8-K within the stipulated four business days, as mandated by the new SEC rules.&#8221;<\/p>\n<p>The source provided databreaches.net with a screenshot of the form, and the automated receipt confirming submission.<\/p>\n<h2 class=\"regular-text\">Nuance in the New SEC Rule<\/h2>\n<p>Putting aside the sheer audacity of the move, ALPHV may be out of luck with the SEC for two reasons.<\/p>\n<p>For one thing, in <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-gang-files-sec-complaint-over-victims-undisclosed-breach\/\" target=\"_blank\" rel=\"noopener\">a statement provided to BleepingComputer<\/a> on Wednesday, MeridianLink stated that it wasn&#8217;t yet sure if any consumer personal information was compromised, adding that &#8220;based on our investigation to date, we have identified no evidence of unauthorized access to our production platforms, and the incident has caused minimal business interruption.&#8221; Exactly what data ALPHV stole and published may affect whether the breach is &#8220;material,&#8221; per SEC language.<\/p>\n<p>Second, as noted in <a href=\"https:\/\/www.sec.gov\/news\/press-release\/2023-139\" target=\"_blank\" rel=\"noopener\">its original press release<\/a>, the new SEC disclosure rule only takes effect on Dec. 18. (Smaller companies will have even more leeway, with an extra 180 days before they have to get on board).<\/p>\n<p>Future victims of similar attacks will have fewer breaks to count on.<\/p>\n<p>&#8220;Using the threat of filing a &#8216;failure to report&#8217; complaint against its own victim to the SEC is a compelling tactic that could weaponize a government regulation for a cybercriminal group&#8217;s benefit,&#8221; Tiquet warns. &#8220;Disciplinary action from the SEC is not to be taken lightly and fines can be very steep.&#8221;<\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/risk\/alphv-ransomware-group-files-sec-complaint-against-own-victim\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The ransomware group ALPHV (aka &#8220;BlackCat&#8221;) has filed a formal<\/p>\n","protected":false},"author":12,"featured_media":2065,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2064","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=881%2C923&ssl=1",881,923,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=286%2C300&ssl=1",286,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=640%2C671&ssl=1",640,671,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=640%2C671&ssl=1",640,671,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=881%2C923&ssl=1",881,923,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=881%2C923&ssl=1",881,923,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=881%2C923&ssl=1",881,923,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/11\/hackers-weaponize-sec-disclosure-rules-against-corporate-targets.jpg?fit=881%2C923&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2064","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2064"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2064\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2065"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2064"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2064"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2064"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}