The U.S. Securities and Exchange Commission has levied civil penalties totaling nearly $7 million against four companies it alleges misled investors about their cybersecurity risks and downplayed intrusions into their systems by the same hackers behind the SolarWinds attack.

In an order Tuesday, the SEC said Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies and Mimecast all filed public disclosures that "minimized" cybersecurity incidents likely related to SolarWinds.