Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Equiniti Trust Company LLC agreed to an $850,000 SEC civil penalty after two cyber-related fraud incidents caused more than $6.6 million in temporary losses from client funds. The SEC said the transfer agent’s safeguards were inadequate to prevent or detect unauthorized share issuance, account creation, liquidation and transfers. Affected clients were fully reimbursed, and Equiniti also accepted a cease-and-desist order and censure.
The SEC announced the settled administrative proceeding on August 20, 2024. The agency did not accuse Equiniti of stealing the money or of being the attacker. Its findings focused on the company’s controls for protecting client securities and funds.
What Equiniti does
Equiniti is a registered securities transfer agent. Its U.S. entity in the SEC proceeding was Equiniti Trust Company LLC, formerly American Stock Transfer & Trust Company LLC.
A transfer agent generally maintains an issuer’s registered-shareholder records and processes transactions such as share issuances, cancellations, transfers and ownership changes. Depending on the arrangement, it may also handle dividend payments, direct-registration accounts, corporate actions and shareholder correspondence.
#1 Best Overall
That is different from being a retail brokerage. A brokerage typically holds or facilitates trading in customer accounts. Not every investor who owns shares through a broker has an account directly maintained by Equiniti. Equiniti describes its shareholder-services role on its company website.
What happened in the two incidents
The SEC’s action involved two separate attack paths. They were not simply the same type of database breach repeated twice.
September 2022: hijacked email chain and unauthorized share issuance
According to the SEC, a threat actor entered an existing email conversation between American Stock Transfer and a U.S. public-company issuer. The actor impersonated an employee of the issuer and instructed the transfer agent to issue millions of new shares.
The shares were then liquidated, and approximately $4.78 million in proceeds was sent to bank accounts in Hong Kong. About $1 million was recovered from that incident.
The important control issue was not merely that someone sent a fraudulent email. The attacker exploited confidence in an existing business conversation and the process used to accept issuer instructions. A request involving new share issuance, liquidation and overseas payment should be treated as a high-risk asset movement requiring independent verification, even when it appears inside a familiar email thread.
Around April 2023: fraudulent accounts linked through Social Security numbers
In the second incident, the SEC said an attacker used stolen Social Security numbers to create fraudulent accounts. Equiniti’s system automatically linked those accounts to legitimate client accounts solely because the Social Security numbers matched.
The names and other personal information did not match, but those discrepancies did not prevent the account links. The attacker then liquidated securities and transferred approximately $1.9 million externally. Approximately $1.6 million was recovered.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThis incident illustrates why a Social Security number should not function as a standalone identity credential. A matching identifier can be useful, but contradictory names, addresses or other information should trigger additional verification and manual review rather than automatic account access or linkage.
Rank #3
How the money adds up
| Item | Amount |
|---|---|
| Total temporary losses across both incidents | More than $6.6 million |
| Recovered across both incidents | Approximately $2.6 million |
| Recovered from the 2022 incident | Approximately $1 million |
| Recovered from the 2023 incident | Approximately $1.6 million |
| SEC civil penalty | $850,000 |
| Client reimbursement | Affected clients were fully reimbursed |
The figures describe different things. The approximately $2.6 million was money recovered from the incidents, while the $850,000 was a regulatory civil penalty. The SEC did not describe the penalty as restitution or as money distributed directly to investors.
Why the SEC charged Equiniti
The SEC said Equiniti violated Section 17A(d) of the Securities Exchange Act of 1934 and Rule 17Ad-12. At a high level, the rule requires transfer agents to maintain safeguards designed to protect securities and funds in their possession or control from theft or misuse.
That makes cybersecurity an asset-protection issue for a transfer agent, not merely an internal technology concern. Controls around email authentication, identity verification, account linking, share issuance, liquidation and external payments can determine whether an attacker can convert a fraudulent instruction into a real loss.
Recommended Free Tools
The SEC’s announcement and administrative order are the controlling sources for the allegations and settlement terms.
Rank #4
What penalties did Equiniti accept?
The settlement included:
- an $850,000 civil penalty;
- a cease-and-desist order; and
- a censure.
This was an SEC administrative settlement, not a criminal prosecution or criminal conviction. Equiniti consented to the proceeding without admitting or denying the SEC’s findings, except as to jurisdictional facts.
The SEC’s action also does not say that every Equiniti customer was affected. It identifies losses involving affected clients connected to the two incidents.
What the case means for shareholders
The fact that Equiniti is a transfer agent does not mean every person who owns shares through a brokerage has an Equiniti account. Investors should first determine where their shares are actually registered or held.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsIf you see an unauthorized transaction in a directly registered or transfer-agent account, contact the transfer agent and the issuer promptly. If the assets are held through a brokerage account, contact the broker or financial institution instead. Preserve account statements, transaction confirmations, emails and other records.
Best Value
Where personal information or credentials may have been exposed, general precautions can include changing affected passwords, enabling multifactor authentication where available, placing fraud alerts or security freezes with the nationwide credit bureaus, and reporting suspected identity theft through appropriate government channels. The SEC’s investor guidance on account security and identity theft provides general safety information; it is not a case-specific remediation order for Equiniti customers.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What transfer agents and issuers should learn
Verify high-risk instructions outside the compromised channel
An email thread can look trustworthy while being controlled by an impersonator. Instructions to issue shares, sell securities, change payment details or send proceeds overseas should be confirmed through a pre-established, independent channel. Callback procedures should use known contact information, not a phone number supplied in the suspicious message.
Do not let one identifier override contradictions
The second incident shows the danger of automatically linking accounts based only on a Social Security number. A safer process would compare multiple identity attributes and escalate mismatches. Multifactor authentication, manual review and anomaly detection may be appropriate controls, although the SEC order does not prescribe a particular technology or specific remedy.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Apply extra controls to asset movement
Share issuance, liquidation and external transfers are especially sensitive because they change the form or location of an asset and can make recovery harder. Dual authorization, transaction limits, cooling-off periods, destination-account verification and real-time alerts can help separate legitimate activity from an unusual request.
Distinguish recovery from prevention
Recovering approximately $2.6 million and reimbursing affected clients were important outcomes, but they do not erase the underlying control failure. Recovery is a response objective. Preventing unauthorized activity and detecting it before funds leave are separate objectives.
Timeline
- September 2022: A hijacked email chain led to unauthorized share issuance, liquidation and transfers to Hong Kong accounts.
- Around April 2023: Stolen Social Security numbers were used to create fraudulent accounts that were linked to legitimate accounts despite mismatched personal details.
- August 20, 2024: The SEC announced the settled charges and related administrative order.
Bottom line
Equiniti was not accused of being the hacker or of intentionally stealing client money. The SEC found that its safeguards were inadequate to prevent or detect two fraud schemes involving client securities and funds. The affected clients were fully reimbursed, but the $850,000 penalty, cease-and-desist order and censure show that transfer-agent cybersecurity controls are part of the regulated protection of investor assets.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

