Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Equiniti Agrees to $850,000 SEC Penalty After Intrusions Cause More Than $6.6 Million in Client-Fund Losses

By TheFinanceBase Team5 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Equiniti Trust Company LLC agreed to an $850,000 SEC civil penalty after two cyber-related fraud incidents caused more than $6.6 million in temporary losses from client funds. The SEC said the transfer agent’s safeguards were inadequate to prevent or detect unauthorized share issuance, account creation, liquidation and transfers. Affected clients were fully reimbursed, and Equiniti also accepted a cease-and-desist order and censure.

The SEC announced the settled administrative proceeding on August 20, 2024. The agency did not accuse Equiniti of stealing the money or of being the attacker. Its findings focused on the company’s controls for protecting client securities and funds.

What Equiniti does

Equiniti is a registered securities transfer agent. Its U.S. entity in the SEC proceeding was Equiniti Trust Company LLC, formerly American Stock Transfer & Trust Company LLC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A transfer agent generally maintains an issuer’s registered-shareholder records and processes transactions such as share issuances, cancellations, transfers and ownership changes. Depending on the arrangement, it may also handle dividend payments, direct-registration accounts, corporate actions and shareholder correspondence.

That is different from being a retail brokerage. A brokerage typically holds or facilitates trading in customer accounts. Not every investor who owns shares through a broker has an account directly maintained by Equiniti. Equiniti describes its shareholder-services role on its company website.

What happened in the two incidents

The SEC’s action involved two separate attack paths. They were not simply the same type of database breach repeated twice.

September 2022: hijacked email chain and unauthorized share issuance

According to the SEC, a threat actor entered an existing email conversation between American Stock Transfer and a U.S. public-company issuer. The actor impersonated an employee of the issuer and instructed the transfer agent to issue millions of new shares.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The shares were then liquidated, and approximately $4.78 million in proceeds was sent to bank accounts in Hong Kong. About $1 million was recovered from that incident.

The important control issue was not merely that someone sent a fraudulent email. The attacker exploited confidence in an existing business conversation and the process used to accept issuer instructions. A request involving new share issuance, liquidation and overseas payment should be treated as a high-risk asset movement requiring independent verification, even when it appears inside a familiar email thread.

Around April 2023: fraudulent accounts linked through Social Security numbers

In the second incident, the SEC said an attacker used stolen Social Security numbers to create fraudulent accounts. Equiniti’s system automatically linked those accounts to legitimate client accounts solely because the Social Security numbers matched.

The names and other personal information did not match, but those discrepancies did not prevent the account links. The attacker then liquidated securities and transferred approximately $1.9 million externally. Approximately $1.6 million was recovered.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This incident illustrates why a Social Security number should not function as a standalone identity credential. A matching identifier can be useful, but contradictory names, addresses or other information should trigger additional verification and manual review rather than automatic account access or linkage.

How the money adds up

Item Amount
Total temporary losses across both incidents More than $6.6 million
Recovered across both incidents Approximately $2.6 million
Recovered from the 2022 incident Approximately $1 million
Recovered from the 2023 incident Approximately $1.6 million
SEC civil penalty $850,000
Client reimbursement Affected clients were fully reimbursed

The figures describe different things. The approximately $2.6 million was money recovered from the incidents, while the $850,000 was a regulatory civil penalty. The SEC did not describe the penalty as restitution or as money distributed directly to investors.

Why the SEC charged Equiniti

The SEC said Equiniti violated Section 17A(d) of the Securities Exchange Act of 1934 and Rule 17Ad-12. At a high level, the rule requires transfer agents to maintain safeguards designed to protect securities and funds in their possession or control from theft or misuse.

That makes cybersecurity an asset-protection issue for a transfer agent, not merely an internal technology concern. Controls around email authentication, identity verification, account linking, share issuance, liquidation and external payments can determine whether an attacker can convert a fraudulent instruction into a real loss.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The SEC’s announcement and administrative order are the controlling sources for the allegations and settlement terms.

What penalties did Equiniti accept?

The settlement included:

  • an $850,000 civil penalty;
  • a cease-and-desist order; and
  • a censure.

This was an SEC administrative settlement, not a criminal prosecution or criminal conviction. Equiniti consented to the proceeding without admitting or denying the SEC’s findings, except as to jurisdictional facts.

The SEC’s action also does not say that every Equiniti customer was affected. It identifies losses involving affected clients connected to the two incidents.

What the case means for shareholders

The fact that Equiniti is a transfer agent does not mean every person who owns shares through a brokerage has an Equiniti account. Investors should first determine where their shares are actually registered or held.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If you see an unauthorized transaction in a directly registered or transfer-agent account, contact the transfer agent and the issuer promptly. If the assets are held through a brokerage account, contact the broker or financial institution instead. Preserve account statements, transaction confirmations, emails and other records.

Where personal information or credentials may have been exposed, general precautions can include changing affected passwords, enabling multifactor authentication where available, placing fraud alerts or security freezes with the nationwide credit bureaus, and reporting suspected identity theft through appropriate government channels. The SEC’s investor guidance on account security and identity theft provides general safety information; it is not a case-specific remediation order for Equiniti customers.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What transfer agents and issuers should learn

Verify high-risk instructions outside the compromised channel

An email thread can look trustworthy while being controlled by an impersonator. Instructions to issue shares, sell securities, change payment details or send proceeds overseas should be confirmed through a pre-established, independent channel. Callback procedures should use known contact information, not a phone number supplied in the suspicious message.

Do not let one identifier override contradictions

The second incident shows the danger of automatically linking accounts based only on a Social Security number. A safer process would compare multiple identity attributes and escalate mismatches. Multifactor authentication, manual review and anomaly detection may be appropriate controls, although the SEC order does not prescribe a particular technology or specific remedy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Apply extra controls to asset movement

Share issuance, liquidation and external transfers are especially sensitive because they change the form or location of an asset and can make recovery harder. Dual authorization, transaction limits, cooling-off periods, destination-account verification and real-time alerts can help separate legitimate activity from an unusual request.

Distinguish recovery from prevention

Recovering approximately $2.6 million and reimbursing affected clients were important outcomes, but they do not erase the underlying control failure. Recovery is a response objective. Preventing unauthorized activity and detecting it before funds leave are separate objectives.

Timeline

  • September 2022: A hijacked email chain led to unauthorized share issuance, liquidation and transfers to Hong Kong accounts.
  • Around April 2023: Stolen Social Security numbers were used to create fraudulent accounts that were linked to legitimate accounts despite mismatched personal details.
  • August 20, 2024: The SEC announced the settled charges and related administrative order.

Bottom line

Equiniti was not accused of being the hacker or of intentionally stealing client money. The SEC found that its safeguards were inadequate to prevent or detect two fraud schemes involving client securities and funds. The affected clients were fully reimbursed, but the $850,000 penalty, cease-and-desist order and censure show that transfer-agent cybersecurity controls are part of the regulated protection of investor assets.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.