Intercontinental Exchange to pay $10M SEC penalty over VPN breach
ID: 9789d6af-c78e-5ce6-b389-1ffd0a5cf0d9
STIX ID: report--9789d6af-c78e-5ce6-b389-1ffd0a5cf0d9
Feed Name: Bleeping Computer
Threat Score
ICE experienced an April 2021 VPN compromise where a suspected nation-state actor installed a webshell on a remote-access VPN device to harvest credentials, MFA codes and exfiltrate VPN configuration and user metadata; ICE determined access was limited to a single device but failed to timely notify subsidiaries and the SEC, resulting in a consent order and a $10 million SEC penalty for violating Regulation SCI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
