SEC Falls Victim to SIM Swap Attack: Hacker Takes Control of SEC’s X Account

The U.S. Securities and Exchange Commission (SEC) has recently revealed that its X account was compromised in a SIM swap attack. This attack involved the unauthorized party gaining control of the SEC's cell phone number associated with the account, leading to a fake announcement being posted about the approval of spot bitcoin exchange-traded funds (ETFs).

SEC Acknowledges Being Targeted in SIM Swap Attack

The SEC provided an update on Monday regarding the unauthorized access of its @SECGov account on the social media platform X. The attack, which took place on January 9, involved the use of the SEC's X account to post a false message claiming that the agency had approved spot bitcoin ETFs. It is important to note that the agency had not approved any spot bitcoin ETFs at that time.

The securities regulator provided further details, stating that two days after the incident, in consultation with the SEC's telecom carrier, it was determined that the unauthorized party had gained control of the SEC's cell phone number through a SIM swap attack.

The SEC explained that once in control of the phone number, the unauthorized party reset the password for the @SECGov account. However, the regulator emphasized that access to the phone number was obtained via the telecom carrier and not through SEC systems. The SEC's staff have found no evidence to suggest that the unauthorized party gained access to SEC systems, data, devices, or other social media accounts.

In July 2023, multi-factor authentication (MFA) had been enabled on the @SECGov X account. However, due to issues accessing the account, X Support disabled MFA at the staff's request. The SEC reinstated MFA after the account was compromised on January 9. Currently, MFA is enabled for all SEC social media accounts that offer this feature.

The SEC's staff is actively collaborating with various law enforcement and federal oversight entities, including the Federal Bureau of Investigation (FBI), the Department of Homeland Security (DHS), the Commodity Futures Trading Commission (CFTC), the Department of Justice (DOJ), and the SEC's own Division of Enforcement.

The SEC highlighted that the ongoing investigation aims to determine how the unauthorized party persuaded the carrier to change the SIM card associated with the account and how they knew which phone number was linked to the account.

A significant number of SIM swap attacks have targeted cryptocurrency investors. In addition to the SEC, other notable victims include Vitalik Buterin, the co-founder of Ethereum. To learn how to protect yourself and your crypto assets from SIM swap attacks, refer to our comprehensive guide.

We value your opinion: What do you think about the SEC's SIM swap incident? Share your thoughts in the comments section below.

