Senators want to know why the SEC’s X account wasn’t secured with MFA

Another lawmaker is pushing the Securities and Exchange Commission for more information about its security practices following the hack of its verified account on X. In a new letter to the agency’s Inspector general, Senator Ron Wyden, called for an investigation into “the SEC’s apparent failure to follow cybersecurity best practices.”

The letter, which was first reported by Axios, comes days after the SEC’s official X account was taken over in order to post a tweet claiming that spot bitcoin ETFs had been approved by the regulator. The rogue post temporarily juiced the price of bitcoin and forced SEC chair Gary Gensler to chime in from his X account that the approval had not, in fact, happened. (The SEC did approve 11 spot bitcoin ETFs a day later, with Gensler saying in a statement that “bitcoin is primarily a speculative, volatile asset that’s also used for illicit activity.”)

The incident has raised a number of questions about the SEC’s security practices after officials at X said the financial regulator had not been using multi-factor authentication to secure its account. In the letter, Wyden, who chairs the Senate’s finance committee, said it would be "inexcusable" for the agency to not use additional layers of security to lock down its social media accounts.

“Given the obvious potential for market manipulation, if X’s statement is correct, the SEC’s social media accounts should have been secured using industry best practices,” Wyden wrote. “Not only should the agency have enabled MFA, but it should have secured its accounts with phishing-resistant hardware tokens, commonly known as security keys, which are the gold standard for account cybersecurity. The SEC’s failure to follow cybersecurity best practices is inexcusable, particularly given the agency’s new requirements for cybersecurity disclosure”

Wyden isn’t the only lawmaker who has pushed the SEC for more details about the hack. Senators J. D. Vance and Thom Tillis sent a letter of their own, addressed to Gensler, immediately following the incident. They asked for a briefing about the agency’s security policies and investigation into the hack by January 23.

The SEC didn’t immediately respond to a request for comment. The agency said in an earlier statement that it was working with the FBI and the Inspector General to investigate the matter.

This article originally appeared on Engadget at https://www.engadget.com/senators-want-to-know-why-the-secs-x-account-wasnt-secured-with-mfa-203614701.html?src=rss https://www.engadget.com/senators-want-to-know-why-the-secs-x-account-wasnt-secured-with-mfa-203614701.html?src=rss
Creato 1y | 12 gen 2024, 20:40:25


Accedi per aggiungere un commento

Altri post in questo gruppo

23andMe founder Anne Wojcicki will regain control of embattled DNA company after all

In a surprise twist, 23andMe founder and former CEO Anne Wojcicki is set to regain control of the DNA company's assets,

13 giu 2025, 22:20:12 | Engadget
A Minecraft Movie is coming exclusively to HBO Max on June 20

Don’t throw all your popcorn at the screen, but A Minecraft Movie

13 giu 2025, 19:50:15 | Engadget
The spiritual sequel to the Pebble smartwatch is on track to ship in July

Eric Migicovsky, the creator of Pebble who's

13 giu 2025, 19:50:14 | Engadget
The Internet Archive modernizes its GeoCities GIF search engine

The Internet Archive made it easier to search for '90s-era GIFs. GifCities

13 giu 2025, 19:50:13 | Engadget
Get a free Amazon gift card when you sign up for a discounted NordVPN plan

While it didn’t quite make the cut in our guide to the best virtual private networ

13 giu 2025, 17:40:13 | Engadget
Spotify is adding the ability to remotely download playlists to secondary devices

Spotify is rolling out a new feature that lets Premium subscribers remotely download playlists to additional devices. For instance, a user could initiate a download on an iPhone for an iPad or for

13 giu 2025, 17:40:12 | Engadget
Wikipedia cancels plan to test AI summaries after editors skewer the idea

Wikipedia is backing off a plan to test AI article summaries. Earlier this month, the platform announced plans to trial the feature for about 10 percent of mobile web visitors. To say they weren't

13 giu 2025, 17:40:11 | Engadget