{"id":23005,"date":"2024-01-23T20:36:15","date_gmt":"2024-01-24T02:36:15","guid":{"rendered":"https:\/\/ustower.net\/?p=23005"},"modified":"2024-01-23T20:36:23","modified_gmt":"2024-01-24T02:36:23","slug":"sec-account-hack-result-of-sim-swap-attack-agency-says","status":"publish","type":"post","link":"https:\/\/ustower.net\/?p=23005","title":{"rendered":"SEC account hack result of \u2018SIM swap\u2019 attack, agency says"},"content":{"rendered":"\n<p class=\"has-medium-font-size\">The hack of the Securities and Exchange Commission\u2019s (SEC) account on X, the platform formerly known as Twitter, earlier this month was the result of a \u201cSIM swap\u201d attack, an agency spokesperson said Tuesday.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">An \u201cunauthorized party\u201d used SIM swapping to obtain control of the phone number associated with the SEC\u2019s X account and reset the password, the spokesperson said.&nbsp;<\/p>\n\n\n\n<p class=\"has-medium-font-size\">SIM swapping allows scammers to receive voice and SMS communications associated with a phone number by transferring the number to an unauthorized device.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">The SEC spokesperson said access to the phone number occurred via the agency\u2019s telecom carrier, noting there is no evidence the unauthorized party \u201cgained access to SEC systems, data, devices, or other social media accounts.\u201d<\/p>\n\n\n\n<p class=\"has-medium-font-size\">\u201cAmong other things, law enforcement is currently investigating how the unauthorized party got the carrier to change the SIM for the account and how the party knew which phone number was associated with the account,\u201d the spokesperson added.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">Multifactor authentication for the SEC\u2019s account had also been disabled at the request of the agency\u2019s staff last July \u201cdue to issues accessing the account\u201d and remained disabled until the hack on Jan. 9, the spokesperson said.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">\u201cMFA currently is enabled for all SEC social media accounts that offer it,\u201d they added.<\/p>\n\n\n\n<p class=\"has-medium-font-size\">The SEC revealed its X account had been hacked earlier this month, after it appeared to approve several highly anticipated bitcoin investment funds.&nbsp;<\/p>\n\n\n\n<p class=\"has-medium-font-size\">While the agency quickly took down the fake announcement and replaced it with a disavowal, the breach prompted criticism and calls for investigation from lawmakers on both sides of the aisle, particularly after X revealed the SEC\u2019s account did not have two-factor authentication enabled.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><a href=\"https:\/\/thehill.com\/policy\/technology\/4424007-sec-account-hack-result-of-sim-swap-attack-agency-says\/\">thehill<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The hack of the Securities and Exchange Commission\u2019s (SEC) account on X, the platform formerly known as Twitter, earlier this month was the result of a \u201cSIM swap\u201d attack, an agency spokesperson said Tuesday. An \u201cunauthorized party\u201d used SIM swapping to obtain control of the phone number associated with the SEC\u2019s X account and reset [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":23006,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5783],"tags":[26101,24364,1226,2539,4754,1211],"class_list":["post-23005","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sci-tech","tag-sim-exchange","tag-accounts","tag-attack","tag-sec","tag-stolen","tag-twitter"],"_links":{"self":[{"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts\/23005","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23005"}],"version-history":[{"count":1,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts\/23005\/revisions"}],"predecessor-version":[{"id":23007,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/posts\/23005\/revisions\/23007"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=\/wp\/v2\/media\/23006"}],"wp:attachment":[{"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23005"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23005"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ustower.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23005"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}