SEC’s X account fell victim to SIM swap attack

The SEC’s X attack happened after the agency disabled two-factor authentication in July 2023

article-image

Artwork by Crystal Le

share

The US Securities and Exchange Commission admitted that the two-factor authentication on its X account had been disabled since July 2023. 

The SEC’s official X account was compromised earlier this month. An unauthorized person was able to not only access the account itself, but made a fake post announcing the approval of spot bitcoin ETFs. 

The post was left up on the account for roughly 15 minutes before Chair Gary Gensler took to his own account to announce that the SEC’s had been compromised. 

In a follow up statement detailing what happened, the SEC said that X support asked the regulatory agency to disable the multi-factor authentication after the agency had difficulty accessing the account. 

Read more: ‘A real low point’: Congressman calls out SEC bitcoin ETF drama during House hearing

“MFA remained disabled until staff re-enabled it after the account was compromised on Jan. 9. MFA currently is enabled for all SEC social media accounts that offer it,” the statement said. 

The hacker was able to access the account through a SIM swap, which is when a phone number is transferred to another device without authorization. 

“Access to the phone number occurred via the telecom carrier, not via SEC systems. SEC staff have not identified any evidence that the unauthorized party gained access to SEC systems, data, devices or other social media accounts,” the SEC said.  

Read more: SEC should be held accountable for X account compromise: US senator says

The regulatory body is working with the Federal Bureau of Investigations, Homeland Security, the US Department of Justice and its own Division of Enforcement to track down the attacker. The agency previously disclosed that the FBI and Homeland Security’s cybersecurity department were involved in the investigation. 

“Among other things, law enforcement is currently investigating how the unauthorized party got the carrier to change the SIM for the account and how the party knew which phone number was associated with the account,” the statement continued.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Research report HL cover.jpg

Research

It's increasingly apparent that orderbooks represent the most efficient model for perpetual trading, with the primary obstacle being that the most popular blockchains are ill-suited for hosting a fully onchain orderbook. Hyperliquid is a perpetual trading protocol built on its own L1 that aims to replicate the user experience of centralized exchanges while offering a fully onchain orderbook.

article-image

Consensys filed a lawsuit against the SEC in a Texas court on Thursday

article-image

Marathon Digital’s hash rate target of 50 EH/s by the end of 2025 may be achieved a year sooner than expected, CEO says

article-image

The Algorand Foundation touts the network as first to go after pool of 10 million global developers

article-image

Drive-to-earn DePIN project MapMetrics will slowly transition to the peaq blockchain

article-image

The suit, filed in a Texas court, alleges a regulatory overreach by the SEC

article-image

This is the first crypto-centric announcement from Stripe since May of last year