Skip to content

DeviceDaily.com – Technology Highlights

Daily Updates on Technology & Devices

The SEC says its X account was taken over with a SIM swap attack

The regulator confirmed it wasn’t using MFA at the time.

Karissa Bell
Karissa Bell
 
Updated Tue, Jan 23, 2024
The SEC says its X account was taken over with a SIM swap attack | DeviceDaily.com
SOPA Images via Getty Images

The Securities and Exchange Commission has provided more details about how its official X account was compromised earlier this month. In a statement, the regulator confirmed that it had been the victim of a SIM swapping attack and that its X account was not secured with multi-factor authentication (MFA) at the time it was accessed.

“The SEC determined that the unauthorized party obtained control of the SEC cell phone number associated with the account in an apparent ‘SIM swap’ attack,” it said, referring to a common scam in which attackers persuade customer service representatives to transfer phone numbers to new devices. “Once in control of the phone number, the unauthorized party reset the password for the @SECGov account.”

The hack of its X account, which was taken over in order to falsely claim that bitcoin ETFs had been approved, has raised questions about SEC’s security practices. Government-run social media accounts are typically required to have MFA enabled. The fact that one as high-profile and with potentially market-moving abilities like @SECGiv would not be using the extra layer of security has already prompted questions from Congress.

In its statement, the SEC said that it asked X’s support staff to disable MFA last July following “issues” with its account access. “Once access was reestablished, MFA remained disabled until staff reenabled it after the account was compromised on January 9,” it said. “MFA currently is enabled for all SEC social media accounts that offer it.”

While the lack of MFA likely made it much easier to take over the SEC’s account, there are still numerous questions about the exploit, including how those responsible knew which phone was associated with the X account, how the unnamed telecom carrier fell for the scam and, of course, who was behind it. The regulator said it’s investigating these questions, along with the Department of Justice, FBI, Homeland Security and its own Inspector General.

Engadget is a web magazine with obsessive daily coverage of everything new in gadgets and consumer electronics

(18)

Related

Tagged Account, Attack, Over, Says, swap, taken
Author: admin
Device Daily Photo

Post navigation

Apple’s Mac turns 40: How its revolutionary user experience forever changed computers →
← New AI tech could make video-game NPCs a lot more interesting
  • Home
  • Advertisement and Publishing
  • Boards Settings
  • Contact Us
  • Desktops
    • 10 Craziest PC Case Mods
    • Toshiba Launches Qosmio X305-Q708 Gaming Laptop
  • Everything
  • Following
  • Gadgets
    • Deus ex-machina The Wearable Motorcycle
    • Pico Usb Flash Drive is The Tiniest Usb-Drive Out There
    • Timex Thumbnail Watch
  • Laptops
    • Rugged Tablet PC – Duros 8404 Daylight-Viewable LCD
  • Link Building Tools
    • Link Building Tools
  • Login
  • Lost Your Password?
  • MSIC – MISCELLANEOUS
    • Microsoft Bing Makes a Bang
    • NASA Scientists Make Magnetic Fields Visible, Beautiful
    • Scientists Create Ball Lightings For The Energy Of The Future – Quantum Energy
    • ZIGGURAT: Dubai’s Carbon Neutral Pyramid Will House 1 Million
  • Pins Settings
  • Popular
  • Privacy Policy
  • Register
  • Settings
  • Source
  • Terms of use
  • XML Sitemaps

Copyright © 2025 DeviceDaily.com - Technology Highlights

Design by ThemesDNA.com