SEC Charges Firm With Deficient Cybersecurity Procedures
Voya Financial Advisors Inc. agreed to pay a $1 million penalty to settle SEC charges for cybersecurity failures that allowed intruders to impersonate contractors in 2016, compromising 5,600 customers' personal data and exploiting known vulnerabilities, particularly the failure to apply security policies to independent contractors.
Voya Financial Advisors Inc. (VFA) was charged by the SEC with violating the Safeguards Rule and the Identity Theft Red Flags Rule after a 2016 cyber intrusion compromised the personal information of 5,600 customers. Intruders impersonated VFA contractors to reset passwords, gaining access to customer accounts and creating fraudulent profiles, exploiting systemic weaknesses—including VFA’s failure to apply its security protocols to its independent contractors, who made up the majority of its workforce. Without admitting or denying the findings, VFA agreed to pay a $1 million penalty, be censured, and retain an independent consultant to evaluate and remediate its compliance policies.
Voya Financial Advisors Inc. (VFA), a Des Moines-based broker-dealer and investment adviser, agreed to pay a $1 million penalty to settle SEC charges stemming from cybersecurity failures that enabled a 2016 cyber intrusion compromising the personal data of 5,600 customers. Intruders impersonated VFA contractors over a six-day period by calling the company’s support line to request password resets, then used the new credentials to access confidential customer information and create unauthorized online profiles for three clients. The SEC found that VFA’s cybersecurity procedures were deficient, particularly in failing to apply its protocols to independent contractors—who constituted the largest portion of its workforce—and had not addressed known vulnerabilities exposed in prior similar incidents. This marked the first-ever SEC enforcement action for violating the Identity Theft Red Flags Rule, underscoring the agency’s emphasis on firms adapting cybersecurity measures to their specific business models. VFA did not admit or deny the allegations but agreed to be censured and to retain an independent consultant to review and improve its compliance with the Safeguards Rule and related regulations. The investigation was led by the SEC’s Cyber Unit and Chicago Regional Office, with support from the National Examination Program, highlighting the regulatory focus on protecting customer data in the financial sector. The case serves as a warning to broker-dealers and investment advisers that robust, regularly updated cybersecurity policies are not optional but a regulatory imperative.
Exhibits & Attached Documents (1)
Extracted insights
- $1.00M $1 million $1M–$10M
- person cyber intruders
- person examination team
- agency sec’s investigation
- agency Securities and Exchange Commission
- person stephanie avakian
- Securities and Exchange Commission announced a Des Moines-based broker-dealer and investment adviser has agreed to pay $1 million to settle charges related to its failures in cybersecurity policies and procedures surrounding a cyber intrusion that compromised personal information of thousands of customers
- SEC charged Voya Financial Advisors Inc. (VFA) with violating the Safeguards Rule and the Identity Theft Red Flags Rule
- SEC took enforcement action charging violations of the Identity Theft Red Flags Rule
- Cyber intruders impersonated VFA contractors over a six-day period in 2016 by calling VFA’s support line and requesting that the contractors’ passwords be reset
- Intruders used passwords to gain access to the personal information of 5,600 VFA customers
- Intruders created new online customer profiles and obtain unauthorized access to account documents for three customers
- VFA’s failure stemmed from weaknesses in its cybersecurity procedures, some of which had been exposed during prior similar fraudulent activity
- VFA failed to apply its procedures to the systems used by its independent contractors, who make up the largest part of VFA’s workforce
- Stephanie Avakian said "Customers entrust both their money and their personal information to their brokers and investment advisers. VFA failed in its obligations when its deficiencies made it vulnerable to cyber intruders accessing the confidential information of thousands of its customers."
- Robert A. Cohen said "This case is a reminder to brokers and investment advisers that cybersecurity procedures must be reasonably designed to fit their specific business models. They also must review and update the procedures regularly to respond to changes in the risks they face."
- VFA agreed to be censured and pay a $1 million penalty, and will retain an independent consultant to evaluate its policies and procedures for compliance with the Safeguards Rule and Identity Theft Red Flags Rule and related regulations
- SEC’s investigation was conducted by Arsen Ablaev of the Cyber Unit and Paul Montoya in the Chicago Regional Office
- Case was supervised by Kathryn Pyszka in the Chicago Regional Office and Mr. Cohen
- Examination was conducted by the Chicago Regional Office with the assistance of the National Examination Program
- Examination team included Kristine Baker, Stacey Gohl, Thu Bao Ta, David Mueller, Daniel Dewaal and Emilie Abate
The Securities and Exchange Commission today announced that a Des Moines-based broker-dealer and investment adviser has agreed to pay $1 million to settle charges related to its failures in cybersecurity policies and procedures surrounding a cyber intrusion that compromised personal information of thousands of customers. The SEC charged Voya Financial Advisors Inc. (VFA) with violating the Safeguards Rule and the Identity Theft Red Flags Rule, which are designed to protect confidential customer information and protect customers from the risk of identity theft. This is the first SEC enforcement action charging violations of the Identity Theft Red Flags Rule. According to the SEC’s order, cyber intruders impersonated VFA contractors over a six-day period in 2016 by calling VFA’s support line and requesting that the contractors’ passwords be reset. The intruders used the new passwords to gain access to the personal information of 5,600 VFA customers. The SEC’s order finds that the intruders then used the customer information to create new online customer profiles and obtain unauthorized access to account documents for three customers. The order also finds that VFA’s failure to terminate the intruders’ access stemmed from weaknesses in its cybersecurity procedures, some of which had been exposed during prior similar fraudulent activity. According to the order, VFA also failed to apply its procedures to the systems used by its independent contractors, who make up the largest part of VFA’s workforce. “Customers entrust both their money and their personal information to their brokers and investment advisers,” said Stephanie Avakian, Co-Director of the SEC Enforcement Division. “VFA failed in its obligations when its deficiencies made it vulnerable to cyber intruders accessing the confidential information of thousands of its customers.” “This case is a reminder to brokers and investment advisers that cybersecurity procedures must be reasonably designed to fit their specific business models,” said Robert A. Cohen, Chief of the SEC Enforcement Division’s Cyber Unit. “They also must review and update the procedures regularly to respond to changes in the risks they face.” Without admitting or denying the SEC’s findings, VFA agreed to be censured and pay a $1 million penalty, and will retain an independent consultant to evaluate its policies and procedures for compliance with the Safeguards Rule and Identity Theft Red Flags Rule and related regulations. The SEC’s investigation was conducted by Arsen Ablaev of the Cyber Unit and Paul Montoya in the Chicago Regional Office. The case was supervised by Kathryn Pyszka in the Chicago Regional Office and Mr. Cohen. The examination that led to the investigation was conducted by the Chicago Regional Office with the assistance of the National Examination Program. The examination team included Kristine Baker, Stacey Gohl, Thu Bao Ta, David Mueller, Daniel Dewaal and Emilie Abate.
The Securities and Exchange Commission today announced that a Des Moines-based broker-dealer and investment adviser has agreed to pay $1 million to settle charges related to its failures in cybersecurity policies and procedures surrounding a cyber intrusion that compromised personal information of thousands of customers. The SEC charged Voya Financial Advisors Inc. (VFA) with violating the Safeguards Rule and the Identity Theft Red Flags Rule, which are designed to protect confidential customer information and protect customers from the risk of identity theft. This is the first SEC enforcement action charging violations of the Identity Theft Red Flags Rule. According to the SEC’s order, cyber intruders impersonated VFA contractors over a six-day period in 2016 by calling VFA’s support line and requesting that the contractors’ passwords be reset. The intruders used the new passwords to gain access to the personal information of 5,600 VFA customers. The SEC’s order finds that the intruders then used the customer information to create new online customer profiles and obtain unauthorized access to account documents for three customers. The order also finds that VFA’s failure to terminate the intruders’ access stemmed from weaknesses in its cybersecurity procedures, some of which had been exposed during prior similar fraudulent activity. According to the order, VFA also failed to apply its procedures to the systems used by its independent contractors, who make up the largest part of VFA’s workforce. “Customers entrust both their money and their personal information to their brokers and investment advisers,” said Stephanie Avakian, Co-Director of the SEC Enforcement Division. “VFA failed in its obligations when its deficiencies made it vulnerable to cyber intruders accessing the confidential information of thousands of its customers.” “This case is a reminder to brokers and investment advisers that cybersecurity procedures must be reasonably designed to fit their specific business models,” said Robert A. Cohen, Chief of the SEC Enforcement Division’s Cyber Unit. “They also must review and update the procedures regularly to respond to changes in the risks they face.” Without admitting or denying the SEC’s findings, VFA agreed to be censured and pay a $1 million penalty, and will retain an independent consultant to evaluate its policies and procedures for compliance with the Safeguards Rule and Identity Theft Red Flags Rule and related regulations. The SEC’s investigation was conducted by Arsen Ablaev of the Cyber Unit and Paul Montoya in the Chicago Regional Office. The case was supervised by Kathryn Pyszka in the Chicago Regional Office and Mr. Cohen. The examination that led to the investigation was conducted by the Chicago Regional Office with the assistance of the National Examination Program. The examination team included Kristine Baker, Stacey Gohl, Thu Bao Ta, David Mueller, Daniel Dewaal and Emilie Abate.