New details emerge about SECs X account hack, including SIM swap
Summary
The U.S. Securities and Exchange Commission said on Monday that a SIM swap attack was to blame for the breach of its official account on X (formerly Twitter) earlier this month. On Jan. 9, an unauthorized party gained access to the @SECGov account and displayed a fake post claiming the agency had approved the first-ever spot bitcoin exchange-traded funds. A SIM swap is when a phone number is transferred to another device without the permission of the owner, allowing the bad actor to receive SMS messages and voice calls intended for the victim. Because the SEC did not have two-factor authentication enabled, the SIM swap and subsequent password change were the only two steps necessary to gain full access to the agencys account. "Once access was reestablished, MFA remained disabled until staff reenabled it after the account was compromised on January 9," the statement continued.