SEC v. Ashford Inc. — U.S. Securities and Exchange Commission Litigation Release No. 26215, dated January 13, 2025.
Ashford Inc. settled charges with the SEC for misleading investors about a cybersecurity incident. The company falsely stated that no customer information was exposed, when in reality, sensitive guest data was exfiltrated during a ransomware attack. Ashford agreed to pay a civil penalty of $115,231.
In Plain English
Imagine a company's computer system gets hacked, and a bad guy steals a lot of private customer information. The company tells everyone, 'Don't worry, nothing important was taken.' But they actually knew that private customer details were stolen. The SEC stepped in because the company wasn't honest with its investors about the security breach.
Disclaimer: all facts are drawn from the SEC's own filings; the claims described are allegations unless and until a court rules or the parties settle, and some cases end in dismissal.
How the Alleged Scheme Worked
- Cyberattack Occurs In September 2023, Ashford Inc. discovered it was the target of a cybersecurity attack by a foreign threat actor. The attackers gained access to Ashford's servers and exfiltrated approximately 12 terabytes of data.
- Sensitive Data Exfiltrated The exfiltrated data contained sensitive hotel guest information, including personally identifiable information (PII) and financial details, which Ashford knew or should have known.
- Initial Misleading Disclosure In its Form 10-Q filed on November 13, 2023, for the quarter ending September 30, 2023, Ashford stated it had 'completed an investigation' and 'not identified that any customer information was exposed.'
- Repeated Misleading Statements Ashford made similar misleading disclosures in two additional quarterly reports and its annual report filed on March 27, 2024, for the period ending December 31, 2023.
- Further Misleading Disclosure In its Form 10-Q filed on May 13, 2024, for the quarter ending March 31, 2024, Ashford again made the materially misleading disclosure that it had not identified any exposed customer information.
- Violation of Securities Laws These false and misleading disclosures violated Section 17(a)(3) of the Securities Act of 1933 and Section 13(a) of the Exchange Act of 1934, along with associated rules.
The Enforcement Action
The SEC filed settled charges against Ashford Inc. for materially false and misleading disclosures to investors regarding a cyber incident. Ashford agreed to settle the SEC’s charges, consenting to an injunction and an order to pay a civil penalty of $115,231. The settlement is subject to court approval.
Named in this action: Ashford Inc..