https://www.securityweek.com/ransomware-group-files-sec-complaint-over-victims-failure-to-disclose-data-breach/ SECURITYWEEK NETWORK: * Cybersecurity News * Webcasts * Virtual Events ICS: * ICS Cybersecurity Conference SecurityWeek * Malware & Threats + Cyberwarfare + Cybercrime + Data Breaches + Fraud & Identity Theft + Nation-State + Ransomware + Vulnerabilities * Security Operations + Threat Intelligence + Incident Response + Tracking & Law Enforcement * Security Architecture + Application Security + Cloud Security + Endpoint Security + Identity & Access + IoT Security + Mobile & Wireless + Network Security * Risk Management + Cyber Insurance + Data Protection + Privacy & Compliance + Supply Chain Security * CISO Strategy + Cyber Insurance + CISO Conversations + CISO Forum * ICS/OT + Industrial Cybersecurity + ICS Cybersecurity Conference * Funding/M&A + Cybersecurity Funding + M&A Tracker * Cybersecurity News * Webcasts * Virtual Events * ICS Cybersecurity Conference Connect with us * * * Hi, what are you looking for? [Search ] [Search] SecurityWeekSecurityWeek SecurityWeekSecurityWeek SecurityWeek * Malware & Threats + Cyberwarfare + Cybercrime + Data Breaches + Fraud & Identity Theft + Nation-State + Ransomware + Vulnerabilities * Security Operations + Threat Intelligence + Incident Response + Tracking & Law Enforcement * Security Architecture + Application Security + Cloud Security + Endpoint Security + Identity & Access + IoT Security + Mobile & Wireless + Network Security * Risk Management + Cyber Insurance + Data Protection + Privacy & Compliance + Supply Chain Security * CISO Strategy + Cyber Insurance + CISO Conversations + CISO Forum * ICS/OT + Industrial Cybersecurity + ICS Cybersecurity Conference * Funding/M&A + Cybersecurity Funding + M&A Tracker Ransomware Ransomware Group Files SEC Complaint Over Victim's Failure to Disclose Data Breach Alphv/BlackCat ransomware group files SEC complaint against MeridianLink over its failure to disclose an alleged data breach caused by the hackers. [Ed-Kovacs] By Eduard Kovacs November 16, 2023 * * * * + Flipboard + Reddit + Whatsapp + Whatsapp + Email Ransomware Attack SEC complaint A notorious ransomware group has filed a complaint with the US Securities and Exchange Commission (SEC) over the failure of a victim to disclose an alleged data breach resulting from an attack conducted by the cybercrime gang itself. The ransomware group known as Alphv and BlackCat claims to have breached the systems of MeridianLink, a California-based company that provides digital lending solutions for financial institutions and data verification solutions for consumers. The cybercriminals claim to have stolen a significant amount of customer data and operational information belonging to MeridianLink, and they are threatening to leak it unless a ransom is paid. In an apparent effort to increase its chances of getting paid, the malicious hackers claim to have filed a complaint with the SEC against MeridianLink, accusing the company of failing to disclose the breach within four business days, as required by rules announced by the agency in July. BlackCat published screenshots on its leak website on November 15 to show that the complaint has been filed and received by the SEC. Complaint filed with the SEC against MeridianLinkScreenshot showing the complaint filed with the SEC against MeridianLink This appears to be the first time a ransomware group has filed an SEC complaint against one of its victims. The hackers told DataBreaches.net that the attack against MeridianLink -- which allegedly did not involve file-encrypting ransomware, only data theft -- was conducted on November 7 and it was discovered the same day. However, MeridianLink told DataBreaches.net that the intrusion occurred on November 10. "Upon discovery on the same day, we acted immediately to contain the threat and engaged a team of third-party experts to investigate the incident. Based on our investigation to date, we have identified no evidence of unauthorized access to our production platforms, and the incident has caused minimal business interruption," the company said, adding that it cannot share further details due to its ongoing investigation. Advertisement. Scroll to continue reading. It's worth pointing out that the new SEC data breach disclosure rules will only go into effect in mid-December 2023. In addition, companies will be required to notify the SEC within four business days of determining that a cybersecurity incident is material to investors, which, based on MeridianLink's statement, has yet to happen. Contacted by SecurityWeek, an SEC spokesperson declined to comment. BlackCat has been one of the most active ransomware operations and it's not uncommon for the group to try new methods for convincing targets to pay up, including by setting up dedicated leak websites for individual victims. *updated to say that the SEC declined to comment Related: BlackCat Ransomware Targets Industrial Companies Related: Western Digital Confirms Ransomware Group Stole Customer Information [Ed-Kovacs] Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia's security news reporter. Eduard holds a bachelor's degree in industrial informatics and a master's degree in computer techniques applied in electrical engineering. More from Eduard Kovacs * Google Adds Passkey Support to New Titan Security Key * Zimbra Zero-Day Exploited to Hack Government Emails * Administrator of Darkode Hacking Forum Sentenced to Prison * Ransomware Group Files SEC Complaint Over Victim's Failure to Disclose Data Breach * US Announces IPStorm Botnet Takedown and Its Creator's Guilty Plea * Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities * New Intel CPU Vulnerability 'Reptar' Can Allow DoS Attacks, Privilege Escalation * Protected Virtual Machines Exposed to New 'CacheWarp' AMD CPU Attack Latest News * Google Adds Passkey Support to New Titan Security Key * Biden Campaign Looking for CISO * Zimbra Zero-Day Exploited to Hack Government Emails * State-Sponsored Online Spies Likely to Target Australian Submarine Program, Spy Agency Says * Bad Bots Account for 73% of Internet Traffic: Analysis * Administrator of Darkode Hacking Forum Sentenced to Prison * Threat Intel: To Share or Not to Share is Not the Question * Ransomware Group Files SEC Complaint Over Victim's Failure to Disclose Data Breach [SecurityWe] Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. [ ] [Subscribe] Webinar Beyond VPN Replacement: Other ZTNA superpowers CISOs Should Know Tuesday, August 22, 2023 Join security experts as they discuss ZTNA's untapped potential to both reduce cyber risk and empower the business. Register Webinar: Scaling Software Supply Chain Security: Driving Actionable SBOM Management with the OpenSSF S2C2F OSS Specification Thursday, September 7, 2023 Join Microsoft and Finite State for a webinar that will introduce a new strategy for securing the software supply chain. Register Expert Insights Threat Intel: To Share or Not to Share is Not the Question [Marc-Solomon_Bio] To share or not to share threat intelligence isn't the question. It's how to share, what to share, where and with whom. (Marc Solomon) Addressing the State of AI's Impact on Cyber Disinformation/ Misinformation [Rik-Ferguson] By embracing a strategy that combines technological advancements with critical thinking skills, collaboration, and a culture of continuous learning, organizations can safeguard against AI's disruptive effects. (Rik Ferguson) Offense Intended: How Adversarial Emulation Went From State Secret To Board Bullet Point [Tom-Eston-Bishop] Offensive Security does not focus on discreet attacks, singular actors, or Indicators of compromise, but understands the entirety of both sides of the battlefield. (Tom Eston) Narrowing the Focus of AI in Security [Matt-Honea] AI can truly disrupt all elements of the SOC and provide an analyst with 10x more data and save 10x more time than what currently exists. (Matt Honea) DPI: Still Effective for the Modern SOC? [Matt-Wilson_Neto] There has been an ongoing debate in the security industry over the last decade or so about whether or not deep packet inspection (DPI) is dead. (Matt Wilson) * * * * + Flipboard + Reddit + Whatsapp + Whatsapp + Email Related Content Ransomware Alerts Ransomware Alerts Cybercrime Cyber Insights 2023 | Ransomware The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions. Kevin TownsendFebruary 2, 2023 Dish Network Dish Network Cybercrime Dish Network Says Outage Caused by Ransomware Attack Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen. Eduard KovacsMarch 1, 2023 SharePoint Online (Office 365) Ransomware Attach SharePoint Online (Office 365) Ransomware Attach Ransomware SaaS Ransomware Attack Hit Sharepoint Online Without Using a Compromised Endpoint A SaaS ransomware attack against a company's Sharepoint Online was done without using a compromised endpoint. Kevin TownsendJune 9, 2023 IPStorm takedown IPStorm takedown Ransomware GoAnywhere Zero-Day Attack Hits Major Orgs Several major organizations are confirming impact from the latest zero-day exploits hitting Fortra's GoAnywhere software. Ionut ArghireMarch 27, 2023 Feedback Friday on SEC SolarWinds charges Feedback Friday on SEC SolarWinds charges Management & Strategy Industry Reactions to Hive Ransomware Takedown: Feedback Friday Industry professionals comment on the recent disruption of the Hive ransomware operation and its hacking by law enforcement. Eduard KovacsJanuary 27, 2023 Yum Brands Discloses Data Breach Following Ransomware Attack Data Breaches Yum Brands Discloses Data Breach Following Ransomware Attack KFC and Taco Bell parent company Yum Brands says personal information was compromised in a January 2023 ransomware attack. Ionut ArghireApril 11, 2023 Ransomware Ransomware Ransomware Payments Giant NCR Hit by Ransomware US payments giant NCR has confirmed being targeted in a ransomware attack for which the BlackCat/Alphv group has taken credit. Eduard KovacsApril 17, 2023 VMware zero-day CVE-2023-20867 exploited VMware zero-day CVE-2023-20867 exploited Malware & Threats VMware ESXi Servers Targeted in Ransomware Attack via Old Vulnerability Unpatched and unprotected VMware ESXi servers worldwide have been targeted in a ransomware attack exploiting a vulnerability patched in 2021. Eduard KovacsFebruary 6, 2023 SecurityWeek * * * Popular Topics * Cybersecurity News * Industrial Cybersecurity Security Community * Virtual Cybersecurity Events * Webcast Library * CISO Forum * ICS Cybersecurity Conference * Cybersecurity Newsletters Stay Intouch * Cyber Weapon Discussion Group * RSS Feed * Security Intelligence Group * Follow SecurityWeek on LinkedIn About SecurityWeek * Advertising * Event Sponsorships * Writing Opportunities * Feedback/Contact Us News Tips Got a confidential news tip? We want to hear from you. Submit Tip Advertising Reach a large audience of enterprise cybersecurity professionals Contact Us Daily Briefing Newsletter Subscribe to the SecurityWeek Daily Briefing and get the latest content delivered to your inbox. [ ] [Subscribe] * Privacy Policy Copyright (c) 2023 SecurityWeek (r), a Wired Business Media Publication. All Rights Reserved. Close