SEC Twitter account hacked, apparently didn't have 2FA enabled

Twitter
Twitter combats hate speech bans racism (Image credit: Shutterstock)

The US Security and Exchange Commission (SEC) has confirmed that its X account was compromised to send out unauthorized tweets. 

The agency is currently deliberating on whether to allow Bitcoin Exchange Traded Funds (ETFs), but a tweet from its official X account suggested that it had now approved them.

A spokesperson from the SEC clarified to CoinDesk that its "@SECGov X/Twitter account has been compromised," adding that, "the unauthorized tweet regarding Bitcoin ETFs was not made by the SEC or its staff."

No 2FA

In a further statement, the SEC also said it "will work with law enforcement and our partners across government to investigate the matter and determine appropriate next steps relating to both the unauthorized access and any related misconduct."

SEC Chair Gary Gensler also issued a statement on his own X account, confirming, "the SEC has not approved the listing and trading of spot bitcoin exchange-traded products."

Another spokesperson also told CoinDesk that decisions of this nature would not be announced via X, but rather on its official website and published in the Federal Register.

The safety team at X also tweeted explaining that there was no issue on its end; rather, an "unidentified individual" had managed to gain control of a phone number associated with the @SECGov account. 

It also added that the account had no two-factor authentication (2FA) in place at the time of the compromise, urging every user on its platform to "enable this extra layer of security." This usually involves receiving a code via text or an authenticator app on a device associated with the account in question, for the user to approve if a login attempt is made. 

It means that if hackers manage to obtain your username and password for one of your accounts, they will still not be able to gain access without the 2FA code to authenticate.

In response to the original fake tweet approving bitcoin ETFs, the cryptocurrency rose to $48,000, then swiftly dropped by 6% when the tweet was confirmed false. 

“This proves that accounts on X continue to be targeted and if an official account is compromised then serious consequences can follow. Cryptocurrency scams remain the focal point and with social pressure on X, they can still reap huge gains," Jake Moore, Global Cybersecurity Advisor at ESET told TechRadar Pro.

"Legitimate third party access compromise or targeted social engineering are still the most common ways to obtain access to an account which leaves the security onus very much on individuals. Therefore, even more significance should be directed at training staff and account owners especially when dealing with high profile accounts.”

MORE FROM TECHRADAR PRO

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
An American flag flying outside the US Capitol building against a blue sky
US government reveals new cybercrime unit targeting AI fraud, crypto and other scams
Ethereum
Hackers steal over $1bn in one of the biggest crypto thefts ever
An American flag flying outside the US Capitol building against a blue sky
More alleged Chinese intrusions into the US Treasury revealed
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
North Korean flag with a hooded hacker
FBI says North Korean Lazarus hackers were behind $1.5 billion Bybit crypto hack
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight
Finger Presses Orange Button Domain Name Registration on Black Keyboard Background. Closeup View
I visited the world’s first registered .com domain – and you won’t believe what it’s offering today
Image showing detail of the Leica D-Lux 8
Still can't get a Fujifilm X100VI? This premium Leica compact costs less, and it's in stock