TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The redacted lawsuit: Solarwinds board of directors sued by shareholders

117 pointsby jollofricepeasover 3 years ago

8 comments

schappimover 3 years ago
Refresher: SolarWinds is that company that develops IT management software. The hack (suspected to be carried out by the Russians[1]) involving SolarWinds&#x27; systems and software penetrated thousands of organizations globally including multiple parts of the United States federal government, leading to a series of data breaches.<p>[1] <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20220101181934&#x2F;https:&#x2F;&#x2F;www.nytimes.com&#x2F;2020&#x2F;12&#x2F;14&#x2F;us&#x2F;politics&#x2F;russia-hack-nsa-homeland-security-pentagon.html" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20220101181934&#x2F;https:&#x2F;&#x2F;www.nytim...</a>
评论 #29805844 未加载
lucasyvasover 3 years ago
&gt; SolarWinds:<p>&gt; (i) used weak passwords for its software download webpages such as “solarwinds123”<p>&gt; (ii) did not properly segment its IT network<p>&gt; (iii) directed its clients to disable antivirus scanning and firewall protection on its Orion software<p>&gt; (iv) cut investments in cybersecurity<p>&gt; (v) listed its sensitive and high-value clients on its webpage for anyone to see.<p>I, for one, am shocked!<p>I think (hope) the importance of secure software may finally become better respected by companies. Seems ransomware is now only the beginning, since you&#x27;ll later be sued as well!
评论 #29805883 未加载
评论 #29806107 未加载
评论 #29811087 未加载
评论 #29805848 未加载
评论 #29810234 未加载
adrrover 3 years ago
Harm for solarwinds is a lot more than the 24% decline in revenue. When we signed our cyberinsurance policy they made us attest that we had no solarwinds software running in our network or on company assets.
评论 #29808790 未加载
Shankover 3 years ago
The really interesting things are the apparent areas for redaction in the original lawsuit [0] pdf. For example:<p>1. This action asserts derivative claims on behalf of SolarWinds against current and former members of the Company’s board of directors (the “Board”), for their utter failure to implement or oversee any reasonable monitoring system concerning [redacted] cybersecurity risks fundamental to SolarWinds’ only line of business. [entire sentence redacted]<p>2. Paragraph 5 is redacted entirely, but paragraph 6 states &quot;these warnings underscored the specific and heightened risk.&quot; Does that mean that paragraph 5 contained notes from previous warnings that were ignored? If so, that&#x27;s very interesting.<p>3. Paragraph 7&#x27;s last sentence on warnings is redacted, and paragraphs 8, 9, and 10 are redacted. Paragraph 11 starts by saying that oversight failures were at play. Perhaps people inside were both warned and ignored warnings prior to the attack taking place?<p>The rest of the complaint contains a very similar pattern: large swathes of redactions in and around failures to monitor the situation and failures to account for risk exposure.<p>Paragraph 79: &quot;By utterly failing to implement or oversee any reasonable monitoring system concerning the Company’s cybersecurity risks, SolarWinds’ Board disabled itself from being informed of mission critical risks at the Company and breached its fiduciary duties to the Company and its shareholders.&quot;<p>Yikes.<p>[0]: <a href="https:&#x2F;&#x2F;github.com&#x2F;jaybobo&#x2F;jaybobo&#x2F;blob&#x2F;main&#x2F;docs&#x2F;solarwinds-complaint&#x2F;20211104-shareholders-vs-solarwinds-board-filing.pdf" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;jaybobo&#x2F;jaybobo&#x2F;blob&#x2F;main&#x2F;docs&#x2F;solarwinds...</a>
评论 #29806368 未加载
评论 #29810731 未加载
rrdharanover 3 years ago
“Everything everywhere is securities fraud”<p><a href="https:&#x2F;&#x2F;www.bloomberg.com&#x2F;opinion&#x2F;articles&#x2F;2019-06-26&#x2F;everything-everywhere-is-securities-fraud" rel="nofollow">https:&#x2F;&#x2F;www.bloomberg.com&#x2F;opinion&#x2F;articles&#x2F;2019-06-26&#x2F;everyt...</a>
评论 #29806684 未加载
imglorpover 3 years ago
I&#x27;m curious about the general effect of breaches on public corps&#x27; stock prices.<p>This one took a dive after their breach and kept going down. Experian, as a different example, has been on a tear for 10+ years with only smaller transient dips, despite millions of consumers injured.
ahuppover 3 years ago
Is there precedent for holding the board personally liable for something like this? That seems both morally questionable, and with lots significant negative effects to how organizations run.
评论 #29809901 未加载
评论 #29810123 未加载
评论 #29810576 未加载
olliejover 3 years ago
So for once this seems to be shareholders targeting the directors personally, rather than the company, is that right?
评论 #29813758 未加载