The SEC says its X account was taken over with a SIM swap attack

The Securities and Exchange Commission has provided more details about how its official X account was compromised earlier this month. In a statement, the regulator confirmed that it had been the victim of a SIM swapping attack and that its X account was not secured with multi-factor authentication (MFA) at the time it was accessed.

“The SEC determined that the unauthorized party obtained control of the SEC cell phone number associated with the account in an apparent 'SIM swap' attack," it said, referring to a common scam in which attackers persuade customer service representatives to transfer phone numbers to new devices. “Once in control of the phone number, the unauthorized party reset the password for the @SECGov account.”

The hack of its X account, which was taken over in order to falsely claim that bitcoin ETFs had been approved, has raised questions about SEC’s security practices. Government-run social media accounts are typically required to have MFA enabled. The fact that one as high-profile and with potentially market-moving abilities like @SECGiv would not be using the extra layer of security has already prompted questions from Congress.

In its statement, the SEC said that it asked X’s support staff to disable MFA last July following “issues” with its account access. “Once access was reestablished, MFA remained disabled until staff reenabled it after the account was compromised on January 9,” it said. “MFA currently is enabled for all SEC social media accounts that offer it.”

While the lack of MFA likely made it much easier to take over the SEC’s account, there are still numerous questions about the exploit, including how those responsible knew which phone was associated with the X account, how the unnamed telecom carrier fell for the scam and, of course, who was behind it. The regulator said it’s investigating these questions, along with the Department of Justice, FBI, Homeland Security and its own Inspector General.

This article originally appeared on Engadget at https://www.engadget.com/the-sec-says-its-x-account-was-taken-over-with-a-sim-swap-attack-004542771.html?src=rss https://www.engadget.com/the-sec-says-its-x-account-was-taken-over-with-a-sim-swap-attack-004542771.html?src=rss
Vytvořeno 1y | 23. 1. 2024 1:40:12


Chcete-li přidat komentář, přihlaste se

Ostatní příspěvky v této skupině

Wyze adds major security update to its security cameras after numerous security lapses

Wyze, the Seattle-based tech company that specializes in smart home products and wireless cameras, has

18. 6. 2025 20:30:16 | Engadget
Waymo will start testing its autonomous cars in New York again

Waymo's autonomous cars are heading back to New York City in July, the company

18. 6. 2025 20:30:14 | Engadget
Animated Death Stranding movie gets its screenwriter

Hideo Kojima said in an interview with Vogue Japan earlier this year that an

18. 6. 2025 20:30:12 | Engadget
Google is adding the Veo 3 video generator to YouTube to slopify Shorts

Google will integrate the Veo 3 video generation tool into YouTube Shorts later this summer. This was revealed by YouTube CEO Neal Mohan at a keynote during the Cannes Lions film festival that was

18. 6. 2025 18:10:31 | Engadget
Google's AI-powered Search Live feature is here to further cannibalize the internet

Google's Search Live feature with voice input is now available on its app for iOS and Android in the US. You'll have to opt in to

18. 6. 2025 18:10:29 | Engadget
Devil May Cry and the early Mortal Kombat games join GOG’s Preservation Program

GOG’s Preservation Program launched in

18. 6. 2025 18:10:28 | Engadget