chief security officer
  • fig. beginning
  • macropolicy
  • Industrial Development
  • CSO·Insight
  • Threat intelligence
  • Data Security
  • privacy protection
  • Cloud security
  • EN
    • CN
    • DE
    • RU
    • JP
    • KR
Sign in Sign up
Creation Center
  1. chief security officerHome
  2. intelligence gathering

X (formerly twitter) security team confirms theft of SEC account

chief security officer • January 11, 2024 at 7:42 pm • intelligence gathering • 12643 views

The U.S. Securities and Exchange Commission compromised the X (formerly twitter) account after unidentified individuals took control of the X (formerly twitter) account cell phone number. Approval for the Bitcoin ETF to be listed on all registered national stock exchanges was posted through the account, which did not have two-factor authentication enabled at the time of the theft.The X security team recommends that all users enable two-factor authentication to secure their accounts.

The SEC posted on its X (formerly twitter) account on Tuesday that the agency has "approved the listing of bitcoin ETFs on all registered national securities exchanges" and that "approved bitcoin ETFs will be subject to ongoing oversight and compliance measures to ensure continued investment "protection."

X (formerly twitter) security team confirms theft of SEC account

The post received more than 35,000 likes and more than 26,000 retweets in just 18 minutes before it was deleted, and SEC Chairman Gary Gensler later declared that the agency's accounts had been hacked via X Explained.

Company X's security team today confirmed that its Twitter account @SECGov has been compromised. The company has completed its initial investigation and determined that the compromise was not due to a breach of its systems, but rather to an unidentified individual taking control of X-related phone numbers. @SECGov via a third-party account.

X (formerly twitter) security team confirms theft of SEC account

Company X can also confirm that the account was not enabled at the time of the thefttwo-factor authentication. Two-factor authentication is an extra strong account security measure that helps protect accounts from unauthorized access.

Company X encourages all users to enable two-factor authentication. For more information on how to do this, please visit Company X's Help Center: https://help.x.com/en/safety-and-security/account-security-tips

leakparticulars

According to Company X's investigation, unidentified individuals were able to take control of the phone numbers associated with X. @SECGov through a third party account. This allowed them to reset the account's password and gain access to the account.

The account did not have two-factor authentication enabled at the time of the theft. Two-factor authentication requires the user to provide two different authentication factors in order to log into the account. This typically includes a username, password, and a one-time code from a cell phone or other security device.

Response from Company X

Company X has taken steps to protect its systems from future attacks. The company has also updated its security policy to require two-factor authentication (2FA) to be enabled for all accounts.

Users' recommendations

Company X encourages all users to take steps to protect theirAccount Security. This includes:

  • Use strong passwords and change them regularly
  • Enable two-factor authentication
  • Monitor their account activity and note any anomalies

Users may also take the following measures to protect their personal information:

  • Be cautious about sharing personal information
  • Use a secure browser andcyber securityhardware
  • Keep your operating system and software up to date

Original article by Chief Security Officer, if reproduced, please credit https://www.cncso.com/en/us-sec-twitter-account-hacked.html

2FA Security VerificationSEC account theft Twitter securitytwo-factor authenticationAccount Securitycell phone number hijackingleakloopholescyber securityhacking attack
Like (0)
0 0
Generate poster

About the author

chief security officer

chief security officer

137 posts
4 comments
1 questions
3 answers
8 followers
Chief Security Officer (cncso.com)
Windows & Edge Browser Patch:Microsoft Security Update Fixes 48 New Vulnerabilities Windows & Edge Browser Patch:Microsoft Security Update Fixes 48 New Vulnerabilities
Previous January 10, 2024 9:30 pm
Five years of safe operation practice summary and future thinking Five years of safe operation practice summary and future thinking
Next January 12, 2024 at 9:25 pm

related suggestion

  • National security: cyberwarfare methodology and case studies CSO·Insight

    National security: cyberwarfare methodology and case studies

    018.4K060
    chief security officer chief security officer
    February 10, 2024
  • Malvertising on Google targets Chinese users with fake spoofing apps intelligence gathering

    Malvertising on Google targets Chinese users with fake spoofing apps

    011.9K00
    chief security officer chief security officer
    January 29, 2024
  • Google security report reveals more than 60 0day used for commercial spyware intelligence gathering

    Google security report reveals more than 60 0day used for commercial spyware

    011.9K00
    chief security officer chief security officer
    February 7, 2024
  • The Cyberspace Administration of China imposes penalties on CNKI for illegally handling personal information intelligence gathering

    The Cyberspace Administration of China imposes penalties on CNKI for illegally handling personal information

    012.2K01
    SnowFlake SnowFlake
    September 6, 2023
  • Crypto wallet Ledger supply chain vulnerability led to the theft of $600,000 in virtual assets intelligence gathering

    Crypto wallet Ledger supply chain vulnerability led to the theft of $600,000 in virtual assets

    014.2K00
    chief security officer chief security officer
    December 16, 2023
  • Critical Remote Code Execution (RCE) Vulnerability Found in Juniper SRX Firewalls and EX Switches intelligence gathering

    Critical Remote Code Execution (RCE) Vulnerability Found in Juniper SRX Firewalls and EX Switches

    013.4K00
    chief security officer chief security officer
    January 14, 2024
chief security officer
chief security officer
chief security officer

Chief Security Officer (cncso.com)

137 posts
4 comments
1 questions
3 answers
8 followers

Popular Recommendations

  • Google Zero Trust Architecture Practice
    278.6K

    Google Zero Trust Architecture Practice

  • StripChat adult video website vulnerability leaks sensitive data of tens of millions of users

    StripChat adult video website vulnerability leaks sensitive data of tens of millions of users

    64.7K
  • WPS Office for windows is dealing with a certain OLE mechanism remote code vulnerability

    WPS Office for windows is dealing with a certain OLE mechanism remote code vulnerability

    64.5K
  • Alibaba Cloud Zero Trust Practice: Identity and Network Micro-Isolation in Production Networks

    Alibaba Cloud Zero Trust Practice: Identity and Network Micro-Isolation in Production Networks

    37.4K
  • Practice and exploration of consumer personal information protection in takeaway business scenarios

    Practice and exploration of consumer personal information protection in takeaway business scenarios

    31.4K
  • AIGC Artificial Intelligence Safety Report 2024

    AIGC Artificial Intelligence Safety Report 2024

    30.7K
  • New secure infrastructure: Alibaba data asset blueprint

    New secure infrastructure: Alibaba data asset blueprint

    27.7K
  • Security Parallel: Next Generation Native Security Infrastructure

    Security Parallel: Next Generation Native Security Infrastructure

    27.6K
  • China's new development in the digital era, network security has entered a new era

    China's new development in the digital era, network security has entered a new era

    25.4K
  • [Critical] Remote code execution vulnerability in open source Apache Log4j

    [Critical] Remote code execution vulnerability in open source Apache Log4j

    24.4K
chief security officer
  • fig. beginning
  • Creation Center
  • Privacy Policy
  • Personal center
  • about Us
  • Sitemap
  • CN
  • EN
  • DE

Copyright © 2020 Chief Security Officer. All Rights Reserved.
浙ICP备2023041448号 | Zhejiang Public Network Security No. 33011002017423