2021-01-01 SEC Press press_release 64 KB 4,621 chars

SEC Announces Three Actions Charging Deficient Cybersecurity Procedures

Release
2021-169
summary

The SEC sanctioned eight registered firms—Cetera Entities, Cambridge, and KMS—for cybersecurity failures that led to email account takeovers exposing over 11,000 customers' personal information, with Cetera also issuing misleading breach notifications, resulting in combined penalties of $750,000 and cease-and-desist orders without admission of guilt.

paragraph

The SEC charged Cetera Entities, Cambridge Investment Research, and KMS Financial Services with violating Rule 30(a) of Regulation S-P due to inadequate cybersecurity measures that enabled email account takeovers, exposing the personally identifying information of at least 11,465 customers. Cetera Entities faced additional charges under the Advisers Act for deceptive breach notifications, while Cambridge delayed firm-wide security upgrades for over three years after its first breach, and KMS failed to implement policies until over a year after discovering attacks. All firms agreed to cease-and-desist orders, censure, and penalties totaling $750,000—$300,000 for Cetera, $250,000 for Cambridge, and $200,000 for KMS—without admitting or denying the findings.

narrative

The Securities and Exchange Commission sanctioned eight registered broker-dealers and investment advisers—Cetera Advisor Networks, Cetera Investment Services, Cetera Financial Specialists, Cetera Advisors, Cetera Investment Advisers (collectively the Cetera Entities), Cambridge Investment Research and Cambridge Investment Research Advisors, and KMS Financial Services—for systemic cybersecurity failures that resulted in email account takeovers exposing the personal information of thousands of clients. Between November 2017 and June 2020, over 60 Cetera personnel’s cloud-based email accounts were compromised, exposing at least 4,388 customers, with Cetera Advisors and Cetera Investment Advisers also issuing misleading breach notifications that falsely implied timely disclosure. Cambridge suffered breaches from January 2018 to July 2021 affecting 2,177 clients, despite knowing of the first incident in 2018 and failing to implement enhanced security until 2021. KMS experienced breaches from September 2018 to December 2019 impacting approximately 4,900 clients, and did not adopt written security policies until May 2020 or fully implement them until August 2020. All firms violated Rule 30(a) of Regulation S-P, and the Cetera Entities additionally violated Section 206(4) of the Advisers Act and Rule 206(4)-7. Without admitting or denying the allegations, each firm agreed to cease-and-desist orders, censure, and monetary penalties: $300,000 for the Cetera Entities, $250,000 for Cambridge, and $200,000 for KMS, totaling $750,000 in combined fines.

Enriched metadata

Scheme
cyber-fraud (95%)
Outcome
settled
Victims
4,388
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
cambridge investment research inc.cetera advisor networks llccetera advisors llccetera entitieseach firmkms financial services inc.Securities and Exchange Commission
Keywords
ceterasec's ordersec'sllcinvestmentcambridgecustomers clientscetera investmentinvestment adviserscetera entitiesorder againstcloud-based emailemail accountstaken oversecurity measures

Exhibits & Attached Documents (3)

Extracted insights

Dollar amounts 3
  • $300K $300,000 $100K–$1M
  • $250K $250,000 $100K–$1M
  • $200K $200,000 $100K–$1M
Entities 7
  • company cambridge investment research inc.
  • company cetera advisor networks llc
  • company cetera advisors llc
  • person cetera entities
  • person each firm
  • company kms financial services inc.
  • agency Securities and Exchange Commission
Triples 14
  • Securities And Exchange Commission Sanctioned Eight Firms In Three Actions
  • Eight Firms Agreed To Settle The Charges
  • Cetera Advisor Networks Llc Failed To Protect Email Accounts Of Personnel Consistent With Policies
  • Cetera Advisors Llc Sent Breach Notifications To Clients With Misleading Language
  • Cambridge Investment Research Inc. Failed To Implement Firm-Wide Enhanced Security Measures Until 2021
  • Kms Financial Services Inc. Failed To Adopt Written Policies And Procedures Requiring Additional Security Measures Until May 2020
  • Kms Financial Services Inc. Did Not Fully Implement Additional Security Measures Firm-Wide Until August 2020
  • Securities And Exchange Commission Found Violations Of Rule 30(A) Of Regulation S-P
  • Cetera Advisors Llc Violated Section 206(4) Of The Advisers Act And Rule 206(4)-7
  • Each Firm Agreed To Cease And Desist From Future Violations Of The Charged Provisions
  • Cetera Entities Will Pay Penalty Of $300,000
  • Cambridge Will Pay Penalty Of $250,000
  • Kms Will Pay Penalty Of $200,000
  • Securities And Exchange Commission Conducted Investigations By Arsen Ablaev, Christine Jeon, Peter Senechalle, And Stephanie Reinhart
PDF (from attached: pdf)
Text layers
Extracted body text (4,621c)
The Securities and Exchange Commission today sanctioned eight firms in three actions for failures in their cybersecurity policies and procedures that resulted in email account takeovers exposing the personal information of thousands of customers and clients at each firm. The eight firms, which have agreed to settle the charges, are: Cetera Advisor Networks LLC, Cetera Investment Services LLC, Cetera Financial Specialists LLC, Cetera Advisors LLC, and Cetera Investment Advisers LLC (collectively, the Cetera Entities); Cambridge Investment Research Inc. and Cambridge Investment Research Advisors Inc. (collectively, Cambridge); and KMS Financial Services Inc. (KMS). All were Commission-registered as broker dealers, investment advisory firms, or both. According to the SEC's order against the Cetera Entities, between November 2017 and June 2020, cloud-based email accounts of over 60 Cetera Entities' personnel were taken over by unauthorized third parties, resulting in the exposure of personally identifying information (PII) of at least 4,388 customers and clients. None of the taken over accounts were protected in a manner consistent with the Cetera Entities' policies. The SEC's order also finds that Cetera Advisors LLC and Cetera Investment Advisers LLC sent breach notifications to the firms' clients that included misleading language suggesting that the notifications were issued much sooner than they actually were after discovery of the incidents. According to the SEC's order against Cambridge, between January 2018 and July 2021, cloud-based email accounts of over 121 Cambridge representatives were taken over by unauthorized third parties, resulting in the PII exposure of at least 2,177 Cambridge customers and clients. The SEC's order finds that although Cambridge discovered the first email account takeover in January 2018, it failed to adopt and implement firm-wide enhanced security measures for cloud-based email accounts of its representatives until 2021, resulting in the exposure and potential exposure of additional customer and client records and information. According to the SEC's order against KMS, between September 2018 and December 2019, cloud-based email accounts of 15 KMS financial advisers or their assistants were taken over by unauthorized third parties, resulting in the PII exposure of approximately 4,900 KMS customers and clients. The SEC's order further finds that KMS failed to adopt written policies and procedures requiring additional firm-wide security measures until May 2020, and did not fully implement those additional security measures firm-wide until August 2020, placing additional customer and client records and information at risk. "Investment advisers and broker dealers must fulfill their obligations concerning the protection of customer information," said Kristina Littman, Chief of the SEC Enforcement Division's Cyber Unit. "It is not enough to write a policy requiring enhanced security measures if those requirements are not implemented or are only partially implemented, especially in the face of known attacks." The SEC's orders against each of the firms finds that they violated Rule 30(a) of Regulation S-P, also known as the Safeguards Rule, which is designed to protect confidential customer information. The SEC's order against the Cetera Entities also finds that Cetera Advisors LLC and Cetera Investment Advisers LLC violated Section 206(4) of the Advisers Act and Rule 206(4)-7 in connection with their breach notifications to clients. Without admitting or denying the SEC's findings, each firm agreed to cease and desist from future violations of the charged provisions, to be censured and to pay a penalty. The Cetera Entities will pay a $300,000 penalty, Cambridge will pay a $250,000 penalty, and KMS will pay a $200,000 penalty. The SEC's investigations were conducted by Arsen Ablaev, Christine Jeon, and Peter Senechalle of the Cyber Unit and Stephanie Reinhart of the Complex Financial Instruments Unit in the Chicago Regional Office, and supervised by Amy Flaherty Hartman and Ms. Littman of the Cyber Unit. The examinations that led to the investigations were conducted by the Chicago Regional Office and the New York Regional Office with the assistance of the National Examination Program. The examination teams included Joseph Atatsi, Kristine Baker, Daniel Dewaal, Mark Fearer, Richard Hannibal, Donald Hirata, Bradley Kartholl, Steve Lika, Thomas Meier, Paul Mensheha, Salvatore Montemarano, David Mueller, Edward Schmidt, Atif Shameem, Jennifer Spicher, Molly Thompson, Timothy Trainor, Mathew Varghese, and Michael Wells.
OCR text (4,621c · html-text · 99% conf)
The Securities and Exchange Commission today sanctioned eight firms in three actions for failures in their cybersecurity policies and procedures that resulted in email account takeovers exposing the personal information of thousands of customers and clients at each firm. The eight firms, which have agreed to settle the charges, are: Cetera Advisor Networks LLC, Cetera Investment Services LLC, Cetera Financial Specialists LLC, Cetera Advisors LLC, and Cetera Investment Advisers LLC (collectively, the Cetera Entities); Cambridge Investment Research Inc. and Cambridge Investment Research Advisors Inc. (collectively, Cambridge); and KMS Financial Services Inc. (KMS). All were Commission-registered as broker dealers, investment advisory firms, or both. According to the SEC's order against the Cetera Entities, between November 2017 and June 2020, cloud-based email accounts of over 60 Cetera Entities' personnel were taken over by unauthorized third parties, resulting in the exposure of personally identifying information (PII) of at least 4,388 customers and clients. None of the taken over accounts were protected in a manner consistent with the Cetera Entities' policies. The SEC's order also finds that Cetera Advisors LLC and Cetera Investment Advisers LLC sent breach notifications to the firms' clients that included misleading language suggesting that the notifications were issued much sooner than they actually were after discovery of the incidents. According to the SEC's order against Cambridge, between January 2018 and July 2021, cloud-based email accounts of over 121 Cambridge representatives were taken over by unauthorized third parties, resulting in the PII exposure of at least 2,177 Cambridge customers and clients. The SEC's order finds that although Cambridge discovered the first email account takeover in January 2018, it failed to adopt and implement firm-wide enhanced security measures for cloud-based email accounts of its representatives until 2021, resulting in the exposure and potential exposure of additional customer and client records and information. According to the SEC's order against KMS, between September 2018 and December 2019, cloud-based email accounts of 15 KMS financial advisers or their assistants were taken over by unauthorized third parties, resulting in the PII exposure of approximately 4,900 KMS customers and clients. The SEC's order further finds that KMS failed to adopt written policies and procedures requiring additional firm-wide security measures until May 2020, and did not fully implement those additional security measures firm-wide until August 2020, placing additional customer and client records and information at risk. "Investment advisers and broker dealers must fulfill their obligations concerning the protection of customer information," said Kristina Littman, Chief of the SEC Enforcement Division's Cyber Unit. "It is not enough to write a policy requiring enhanced security measures if those requirements are not implemented or are only partially implemented, especially in the face of known attacks." The SEC's orders against each of the firms finds that they violated Rule 30(a) of Regulation S-P, also known as the Safeguards Rule, which is designed to protect confidential customer information. The SEC's order against the Cetera Entities also finds that Cetera Advisors LLC and Cetera Investment Advisers LLC violated Section 206(4) of the Advisers Act and Rule 206(4)-7 in connection with their breach notifications to clients. Without admitting or denying the SEC's findings, each firm agreed to cease and desist from future violations of the charged provisions, to be censured and to pay a penalty. The Cetera Entities will pay a $300,000 penalty, Cambridge will pay a $250,000 penalty, and KMS will pay a $200,000 penalty. The SEC's investigations were conducted by Arsen Ablaev, Christine Jeon, and Peter Senechalle of the Cyber Unit and Stephanie Reinhart of the Complex Financial Instruments Unit in the Chicago Regional Office, and supervised by Amy Flaherty Hartman and Ms. Littman of the Cyber Unit. The examinations that led to the investigations were conducted by the Chicago Regional Office and the New York Regional Office with the assistance of the National Examination Program. The examination teams included Joseph Atatsi, Kristine Baker, Daniel Dewaal, Mark Fearer, Richard Hannibal, Donald Hirata, Bradley Kartholl, Steve Lika, Thomas Meier, Paul Mensheha, Salvatore Montemarano, David Mueller, Edward Schmidt, Atif Shameem, Jennifer Spicher, Molly Thompson, Timothy Trainor, Mathew Varghese, and Michael Wells.