The U.S. Securities and Exchange Commission (SEC) has officially dropped its high-profile lawsuit against SolarWinds and its Chief Information Security Officer, Timothy Brown, which alleged that the company misled investors about its cybersecurity practices prior to the 2020 SUNBURST supply chain attack. The SEC, SolarWinds, and Brown jointly requested the court to dismiss the civil enforcement action, with the SEC stating the dismissal was at its discretion and not indicative of its stance on other cases. The lawsuit, filed in 2023, accused SolarWinds and its CISO of failing to disclose cybersecurity weaknesses between the company's IPO in 2018 and the discovery of the SUNBURST attack in December 2020, which allowed Russian state actors to compromise the Orion IT management software and breach numerous high-profile organizations and U.S. government agencies.
SolarWinds expressed relief and satisfaction with the outcome, emphasizing that the facts demonstrated appropriate conduct by its security team and hoping the resolution would alleviate concerns among CISOs about personal liability in similar cases. The SEC's action had previously sparked significant debate within the cybersecurity community, with many leaders warning of a potential chilling effect on security disclosures. The SUNBURST attack, attributed to Russia's Cozy Bear, resulted in approximately 18,000 organizations downloading compromised software, with about 100 suffering further breaches, including major corporations and several U.S. federal departments. The conclusion of the lawsuit marks a significant moment in the ongoing discussion about corporate cybersecurity accountability and regulatory oversight.

See the reporting duties and controls this puts on the clock.
8 events from the most recent confirmed update back to the earliest known activity.
SolarWinds previously agreed to settle a related investor class-action lawsuit for $26 million. Coverage described the amount as less than 1% of the company's market capitalization.
After the SEC dropped the case, SolarWinds publicly welcomed the decision and said the outcome vindicated the company and its security personnel. Company leadership also said SolarWinds had become stronger and better prepared since the 2020 attack.
On or before November 20, 2025, the SEC voluntarily dismissed its 2023 lawsuit against SolarWinds and Timothy Brown, saying it did so in the exercise of its discretion. The dismissal ended a closely watched case that many CISOs feared could expand personal liability for security leaders.
Near the end of the Biden administration, the SEC fined four companies for inadequate or misleading disclosures connected to the SolarWinds incident. The enforcement actions showed the agency continued pursuing cyber disclosure cases beyond SolarWinds itself.
In July 2024, the U.S. District Court for the Southern District of New York threw out most of the SEC's claims against SolarWinds and Brown. The court found key parts of the SEC's case relied improperly on hindsight and speculation.
In 2023, the SEC filed a lawsuit against SolarWinds and its chief information security officer, Timothy G. Brown, alleging they misled investors about the company's cybersecurity practices and risks tied to the 2020 breach. The complaint included fraud and internal controls allegations.
Reporting and later legal coverage attributed the 2020 SolarWinds breach to Russian state-sponsored actors, including APT29 and the Russian Foreign Intelligence Service. This attribution became a central part of the incident's public understanding.
A major supply-chain attack involving malicious code inserted into SolarWinds' Orion software was discovered in 2020. The campaign enabled intrusions into numerous large companies and U.S. federal agencies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
9 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcetherecord.media
Open sourcescworld.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcethehackernews.com
Open sourcego.theregister.com
Open sourcenextgov.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.