Retool says the breach is due to the Google Authenticator MFA cloud sync feature.

Software company Retool reports that the accounts of 27 customers in the cloud were breached during an aggressive and multi-layered social engineering attack.
Retool's development platform is used to build enterprise software by companies ranging from startups to Fortune 500 enterprises, including Amazon, Mercedes-Benz, DoorDash, NBC, Stripe, and Lyft.
Snir Kodesh, Head of Engineering at Retool, revealed that all compromised accounts belong to clients in the cryptocurrency industry.
The breach occurred on August 27, after the attackers bypassed many security mechanisms using SMS phishing and social engineering to compromise the IT employee's account in Okta.
The attack used a URL that impersonated Retool's internal identity gateway and was executed during a previously announced migration of login links to Okta.
Even though most employees who had been targeted ignored the scam's identifying text, one of them clicked the embedded link that redirects to a fake login portal with multi-factor authentication (MFA) form.
After logging in, the attacker created a deepfake of an employee's voice and called the target IT team member, tricking them into providing an additional MFA code, which allowed the addition of a device controlled by the attacker to the target employee's Okta account.
See also: BlackCat ransomware: Encrypts Azure Storage with Sphynx
The attack is attributed to the new sync feature of Google Authenticator
Retool attributes the hack's success to a new Google Authenticator feature that allows users to sync their 2FA codes with their Google account.
This was a feature users have been requesting for a long time, as now they can use Google Authenticator 2FA codes on multiple devices, provided they are all linked to the same account.
However, Retool reports that this feature also bears responsibility for the severity of the security breach in August, as it allowed the hacker who successfully carried out a phishing attack on an employee's Google account to access all 2FA codes used for internal services.
As Kodesh explained, initially Retool had enabled MFA, but the codes synchronized from Google Authenticator to the cloud led to an inadvertent shift to single-factor authentication.
This change occurred because the Okta account verification was translated to Google account verification, providing access to all OTP codes (One-Time Passwords) stored in Google Authenticator.
Even though Google Authenticator promotes the cloud sync feature, it is not mandatory. If you have enabled the feature, you can disable it by clicking the account circle in the top right corner of the app and selecting ‘Use Authenticator without an account.’ This will sign you out of the app and delete the synced 2FA codes from your Google account.
Google also recommends transitioning to FIDO-based technology from traditional multi-factor authentication with one-time password (OTP) as a simple way to prevent similar attacks.
“The risks of phishing and social engineering with legacy authentication technologies, such as those based on OTP, are why the industry is investing heavily in these FIDO-based technologies ,” the Google spokesperson said
See also: TikTok: Deepfake videos of Elon Musk promote fake crypto giveaways

There have been no breaches of Retool customers using the on-premise service
After discovering the security incident, Retool revoked all internal authenticated sessions of employees, including those for Okta and G Suite.
Also, access was restricted for all 27 compromised accounts and all affected cloud customers were notified, restoring all compromised accounts to their original settings (according to Retool, on‑premise customers were not affected in the incident).
A Coindesk report linked the leak at Retool to the theft of $15 million from Fortress Trust in early September.
The Retool development platform is used by companies ranging from startups to large Fortune 500 enterprises, including Amazon, Mercedes-Benz, DoorDash, NBC, Stripe and Lyft.
Hackers are increasingly using social engineering attacks against IT specialists or support staff to gain initial access to corporate networks.
The list of companies that were attacked using this tactic includes Cisco, Uber, 2K Games and, more recently, MGM Resorts.
Towards the end of August, Okta informed customers about network breaches that occurred through the services of IT companies, after the reset of multi-factor authentication (MFA) for Super Administrator or Org Administrator accounts.
The US Federal Services also warned this week about cyber threat actors using deepfakes. They recommend using technology that can help detect deepfakes used to access their networks, communications, and sensitive information after successful social engineering attacks.
Information source: bleepingcomputer.com
