2025-01-13 sec-litreleases litigation_release 65 KB 2,588 chars

SEC v. Ashford Inc., No. LR-26215, Northern District of Texas (Jan. 13, 2025) — Press Release

raw: Ashford Inc

Ashford Inc, No. 3:25-cv-00082 (Jan. 13, 2025)

Caption
U.S. Securities and Exchange Commission v. Ashford, Inc.
summary

Ashford Inc. settled SEC charges for making misleading disclosures regarding a 2023 ransomware attack by paying a $115,231 civil penalty.

paragraph

Ashford Inc. faced charges for violating the Securities Act of 1933 and the Exchange Act of 1934 due to false disclosures about a major cyberattack. The company failed to accurately report that a ransomware attack had exfiltrated over 12 terabytes of sensitive guest data. To settle the matter, Ashford agreed to a $115,231 civil penalty and a court injunction without admitting or denying the allegations.

narrative

The SEC filed charges against Ashford Inc. for making materially false and misleading disclosures regarding a 2023 cybersecurity attack. A foreign-based threat actor had exfiltrated over 12 terabytes of data, including sensitive guest financial and personally identifiable information. Despite this, Ashford's regulatory filings in late 2023 claimed that no customer information had been exposed. The company was charged with violating Section 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Exchange Act of 1934. Ashford agreed to settle the negligence-based charges by consenting to an injunction and a $115,231 civil penalty. This penalty amount reflects Ashford's assistance to the SEC during the investigation. The settlement remains subject to court approval.

Enriched metadata

Scheme
cyber-fraud (95%)
Court
Northern District of Texas
Case No.
3:25-cv-00082
Outcome
settled
Civil penalty
$115,231
Entity
Ashford Inc.
CIK
0001604738
Classified cyber-fraud(confidence 95%). No EDGAR filing fingerprint (criminal/DOJ-side scheme). detection rule →
Parties
Securities and Exchange CommissionAshford, Inc.
Keywords
ashfordsecurities exchangesecexchange commissionincsecuritiesexchangeinvestors regardingregarding cybercyber incidentasset managementthreat actorfort worthworth regionalinformation

Exhibits & Attached Documents (1)

Extracted insights

Dollar amounts 1
  • $115K $115,231 $100K–$1M
Entities 14
  • company an alternative asset management company
  • person arsen ablaev
  • company ashford inc.
  • person Derek Kleinmann
  • person Jorge Tenreiro
  • person keefe bernstein
  • person kristin pauley
  • person patrick disbennett
  • agency Securities and Exchange Commission
  • company settled charges against ashford inc.
  • agency the securities and exchange commission's charges
  • agency the securities and exchange commission's investigation
  • agency the securities and exchange commission's litigation
  • person threat actor
Triples 15
  • Securities And Exchange Commission filed settled charges against Ashford Inc.
  • Ashford Inc. is an alternative asset management company
  • Ashford Inc. learned it had been subjected to a cybersecurity attack
  • threat actor exfiltrated more than 12 terabytes of data
  • Ashford Inc. indicated it had completed an investigation
  • Securities And Exchange Commission charged Ashford Inc. with violating Section 17(a)(3) of the Securities Act of 1933
  • Securities And Exchange Commission charged Ashford Inc. with violating Section 13(a) of the Exchange Act of 1934
  • Ashford Inc. agreed to settle the Securities And Exchange Commission's charges
  • Ashford Inc. consented to an injunction and an order to pay a civil penalty of $115,231
  • Derek Kleinmann conducted the Securities And Exchange Commission's investigation
  • Arsen Ablaev conducted the Securities And Exchange Commission's investigation
  • Kristin Pauley supervised the Securities And Exchange Commission's investigation
  • Jorge Tenreiro supervised the Securities And Exchange Commission's investigation
  • Patrick Disbennett will lead the Securities And Exchange Commission's litigation
  • Keefe Bernstein will supervise the Securities And Exchange Commission's litigation
PDF (from attached: complaint)
Text layers
Extracted body text (2,588c)
U.S. SECURITIES AND EXCHANGE COMMISSION Litigation Release No. 26215 / January 13, 2025 Securities and Exchange Commission v. Ashford Inc., No. 3:25-cv-00082 (N.D. Tex. filed Jan. 13, 2025) Ashford Inc. To Settle Negligence-Based Charges for Misleading Investors Regarding a Cyber Incident The Securities and Exchange Commission filed settled charges against Ashford Inc. for materially false and misleading disclosures to investors regarding a cyber incident. Ashford, a formerly registered issuer based in Dallas, Texas, is an alternative asset management company with a portfolio of strategic operating businesses that provides global asset management, investment management, and related services to the real estate and hospitality sectors. According to the SEC’s complaint, Ashford learned in September 2023 that it had been subjected to a cybersecurity attack and ransomware demand by a foreign-based threat actor. As part of the attack the threat actor gained access to Ashford’s servers and exfiltrated more than 12 terabytes of data which was stored on Ashford’s internal computer systems and which contained, among other things, sensitive hotel guest information. In a quarterly report filed with the SEC in November 2023, Ashford indicated that it had “completed an investigation” and had “not identified that any customer information was exposed.” Ashford made similar disclosures in two additional quarterly reports, along with Ashford’s annual report filed with the SEC for the period ended December 31, 2023. However, Ashford knew or should have known that the exfiltrated data contained sensitive personally identifiable information and financial information related to guests. The SEC's complaint, filed in the U.S. District Court for the Northern District of Texas, charges Ashford with violating Section 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Exchange Act of 1934 and Rules 12b-20, 13a-1, and 13a-13 thereunder. Without admitting or denying the SEC's allegations, Ashford agreed to settle the SEC’s charges, consenting to an injunction and an order to pay a civil penalty of $115,231, which takes into account Ashford’s assistance to the SEC staff in its investigation. The settlement is subject to court approval. The SEC's investigation was conducted by Derek Kleinmann of the Fort Worth Regional Office and Arsen Ablaev of the SEC’s Crypto Assets and Cyber Unit and was supervised by Kristin Pauley and Jorge Tenreiro. The SEC’s litigation will be led by Patrick Disbennett and supervised by Keefe Bernstein of the Fort Worth Regional Office.
OCR text (2,588c · html-text · 99% conf)
U.S. SECURITIES AND EXCHANGE COMMISSION Litigation Release No. 26215 / January 13, 2025 Securities and Exchange Commission v. Ashford Inc., No. 3:25-cv-00082 (N.D. Tex. filed Jan. 13, 2025) Ashford Inc. To Settle Negligence-Based Charges for Misleading Investors Regarding a Cyber Incident The Securities and Exchange Commission filed settled charges against Ashford Inc. for materially false and misleading disclosures to investors regarding a cyber incident. Ashford, a formerly registered issuer based in Dallas, Texas, is an alternative asset management company with a portfolio of strategic operating businesses that provides global asset management, investment management, and related services to the real estate and hospitality sectors. According to the SEC’s complaint, Ashford learned in September 2023 that it had been subjected to a cybersecurity attack and ransomware demand by a foreign-based threat actor. As part of the attack the threat actor gained access to Ashford’s servers and exfiltrated more than 12 terabytes of data which was stored on Ashford’s internal computer systems and which contained, among other things, sensitive hotel guest information. In a quarterly report filed with the SEC in November 2023, Ashford indicated that it had “completed an investigation” and had “not identified that any customer information was exposed.” Ashford made similar disclosures in two additional quarterly reports, along with Ashford’s annual report filed with the SEC for the period ended December 31, 2023. However, Ashford knew or should have known that the exfiltrated data contained sensitive personally identifiable information and financial information related to guests. The SEC's complaint, filed in the U.S. District Court for the Northern District of Texas, charges Ashford with violating Section 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Exchange Act of 1934 and Rules 12b-20, 13a-1, and 13a-13 thereunder. Without admitting or denying the SEC's allegations, Ashford agreed to settle the SEC’s charges, consenting to an injunction and an order to pay a civil penalty of $115,231, which takes into account Ashford’s assistance to the SEC staff in its investigation. The settlement is subject to court approval. The SEC's investigation was conducted by Derek Kleinmann of the Fort Worth Regional Office and Arsen Ablaev of the SEC’s Crypto Assets and Cyber Unit and was supervised by Kristin Pauley and Jorge Tenreiro. The SEC’s litigation will be led by Patrick Disbennett and supervised by Keefe Bernstein of the Fort Worth Regional Office.