Security

CSO

SEC drops 42 cases after staff bungle data protection

Corporate watchdog fouled its info-separation regime, let the wrong people read sensitive docs


The US Securities and Exchange Commission (SEC) has dismissed proceedings against 42 companies and individuals after admitting that its enforcement staff accessed documents that were supposed to be for judges' eyes only.

All 42 [PDF] of the now-dismissed cases were slated to be heard by the watchdog agency's in-house court – which is supposed to remain strictly separate from the SEC's enforcement staff.

"The 'Chinese Wall' between adjudication and enforcement is a sacrosanct tenet of the SEC and of internal control policy," said Digital Brand Media and Marketing Group (DBMM), one of the 42 entities involved, in a press release about the dismissals.

The decision follows a review of enforcement staff's access to records. That effort commenced in April 2022 after the SEC disclosed two earlier cases in which "agency enforcement staff had access to certain adjudicatory memoranda," in a way that broke legal rules.

The improper access saw the enforcement side of the SEC download databases they weren't supposed to be able to see, before sending memos to other staff members who also barred from seeing those documents - among them "attorneys investigating and prosecuting the enforcement matters," according to the SEC's April 2022 statement.

In the investigation that followed, during which the watchdog agency brought in external consultants Berkeley Research Group, the review team found that the data mishandling was far worse than previously disclosed by the SEC.

"We deeply regret that the agency's internal systems lacked sufficient safeguards surrounding access to Adjudication memoranda, and we are continuing our work to ensure that, going forward, work product from the Adjudication staff is appropriately safeguarded," the Friday statement read. 

The dismissals include several years-old cases, including one against Michelle Cochran – an accountant who in 2016 successfully challenged the legality of the SEC's in-house court before the US Supreme Court. 

Cochran's case against the SEC had been consolidated with a similar lawsuit challenging the US Federal Trade Commission's tribunal, Axon Enterprise v. FTC. In ruling in favor of Cochran last month, the Supreme Court's decision "foreshadows hard days to come" for in-house courts, William E. Kovacic, a law professor at George Washington University and former FTC chairman, told the Wall Street Journal

According to the SEC, the investigation into the data breach found "no evidence that the control deficiency resulted in harm to any respondent or affected the Commission's adjudication in any proceeding."

Still, the agency acknowledged its data handling wasn't up to snuff, and committed to do better in the future.

"We take this lapse in controls very seriously and are committed to both informing the public about the scope of this issue and preventing any similar lapses in the future," it added. ®

Send us news
2 Comments

Senate bill aims to stop Uncle Sam using facial recognition at airports

Legislation would eliminate TSA permission to use the tech, require database purge in 90 days

Meta goes to war with FTC over right to profit from kids' personal data

Awkward hill to die on, but OK

Plex gives fans a privacy complex after sharing viewing habits with friends by default

Grandma is watching what?!

Meta sued by privacy group over pay up or click OK model

Scrolling through endless humblebrags without targeted ads is a fundamental right, according to privacy expert

Boffins fool AI chatbot into revealing harmful content – with 98 percent success rate

This one weird trick works every time, most of the time

Proposed US surveillance regime would enlist more businesses

Expanded service provider definition could force cafes and hotels to spy for the feds

Musk takes SEC 'Twitter sitter' consent decree appeal to US Supreme Court

Same old argument about free speech – let's see if it sticks this time

GitLab admits IT ineptitude in finance reporting is ongoing

Code shack has had two years since auditor's 'adverse opinion' to get house in order

US senator claims Google and Apple reveal push notification data to foreign govs

Cupertino promises to reveal its data deliveries, ending silence on the matter

Amazon on the hook for predictably revolting use of concealed clothes hook spy cam

Judge finds plaintiff's claim – that Amazon knew about illicit usage – credible enough for case to proceed

Researcher claims Harvard nixed social media research after getting Zuck bucks

University says ties to Meta execs and a $500 million donation played no role

Interpol makes first border arrest using Biometric Hub to ID suspect

Global database of faces and fingerprints proves its worth