2021 R.R. Donnelley — ransomware and extortion; SEC 2024 cybersecurity-controls settlement
Data compromised
Client and personal identifiers described in SEC cease-and-desist summaries—victim accounting not duplicated here
Technical writeup
Printing and supply-chain services giant R.R. Donnelley disclosed a late-2021 ransomware intrusion with tens of gigabytes of exfiltrated material impacting dozens of client data sets, later amplified by SEC enforcement in 2024 penalizing disclosure- and access-control weaknesses tied to managed-security-service alert handling. Legal summaries emphasized governance of third-party SOC workflows as much as the criminal payload.
Root cause
Ransomware deployment with data theft phase (per SEC order narratives)