{"id":23005,"date":"2024-01-23T20:36:15","date_gmt":"2024-01-24T02:36:15","guid":{"rendered":"https:\/\/ustower.net\/?p=23005"},"modified":"2024-01-23T20:36:23","modified_gmt":"2024-01-24T02:36:23","slug":"sec-account-hack-result-of-sim-swap-attack-agency-says","status":"publish","type":"post","link":"https:\/\/ustower.net\/?p=23005","title":{"rendered":"SEC account hack result of \u2018SIM swap\u2019 attack, agency says"},"content":{"rendered":"\n<p class=\"has-medium-font-size wp-block-paragraph\">The hack of the Securities and Exchange Commission\u2019s (SEC) account on X, the platform formerly known as Twitter, earlier this month was the result of a \u201cSIM swap\u201d attack, an agency spokesperson said Tuesday.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">An \u201cunauthorized party\u201d used SIM swapping to obtain control of the phone number associated with the SEC\u2019s X account and reset the password, the spokesperson said.&nbsp;<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">SIM swapping allows scammers to receive voice and SMS communications associated with a phone number by transferring the number to an unauthorized device.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The SEC spokesperson said access to the phone number occurred via the agency\u2019s telecom carrier, noting there is no evidence the unauthorized party \u201cgained access to SEC systems, data, devices, or other social media accounts.\u201d<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">\u201cAmong other things, law enforcement is currently investigating how the unauthorized party got the carrier to change the SIM for the account and how the party knew which phone number was associated with the account,\u201d the spokesperson added.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Multifactor authentication for the SEC\u2019s account had also been disabled at the request of the agency\u2019s staff last July \u201cdue to issues accessing the account\u201d and remained disabled until the hack on Jan. 9, the spokesperson said.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">\u201cMFA currently is enabled for all SEC social media accounts that offer it,\u201d they added.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The SEC revealed its X account had been hacked earlier this month, after it appeared to approve several highly anticipated bitcoin investment funds.&nbsp;<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">While the agency quickly took down the fake announcement and replaced it with a disavowal, the breach prompted criticism and calls for investigation from lawmakers on both sides of the aisle, particularly after X revealed the SEC\u2019s account did not have two-factor authentication enabled.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><a href=\"https:\/\/thehill.com\/policy\/technology\/4424007-sec-account-hack-result-of-sim-swap-attack-agency-says\/\">thehill<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The hack of the Securities and Exchange Commission\u2019s (SEC) account on X, the platform formerly known as Twitter, earlier this month was the result of a \u201cSIM swap\u201d attack, an agency spokesperson said Tuesday. An \u201cunauthorized party\u201d used SIM swapping to obtain control of the phone number associated with the SEC\u2019s X account and reset [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":23006,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5783],"tags":[26101,24364,1226,2539,4754,1211],"class_list":["post-23005","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sci-tech","tag-sim-exchange","tag-accounts","tag-attack","tag-sec","tag-stolen","tag-twitter"],"_links":{"self":[{"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts\/23005","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23005"}],"version-history":[{"count":1,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts\/23005\/revisions"}],"predecessor-version":[{"id":23007,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts\/23005\/revisions\/23007"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/media\/23006"}],"wp:attachment":[{"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23005"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23005"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23005"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}