The US Securities and Exchange Commission (SEC) spoke about the recent breach of its account on the social network X and said that it was done through a SIM-swapping attack on the mobile phone number that was linked to the account.

Recently, the SEC's X account was compromised and posted a fake announcement about an alleged approval of Bitcoin ETFs on securities exchanges.
It was not clear how the account was compromised, with the SEC stating at the time that an investigation is underway and that it will provide an update on its findings.
The update has now come, with the SEC saying it all started with a SIM-swapping attack.
See also: SIM swapping attacks: What are they and how to protect yourself?
“ Two days after the incident, in consultation with the SEC’s telecommunications provider, it was determined that the unauthorized party had gained control of the mobile phone number associated with the SEC account, in an apparent SIM swap attack ,” the SEC statement explains
In SIM swapping attacks, attackers trick the victim's telecom provider into porting the phone number to a device under the attacker's control. This gives the attacker control of the number, which means that all of the victim's calls and messages go to their own device. This means that password reset links and one-time passwords, used for multi-factor authentication (MFA), are also sent to the attacker.
According to the SEC, the hackers did not have access to the agency’s internal systems, data, devices, or other social media accounts. Once they had the number, they reset the password for the @SECGov account on X and created the fake Bitcoin ETF announcement.
The SEC says it continues to work with law enforcement authorities to further investigate the incident.
The SEC also confirmed that multi-factor authentication was not enabled on the account, as they had disabled it when they encountered problems logging in. Of course, in this case, could hackers have compromised SEC X's account even with the verification enabled, since they would have received the one-time code on the number they had stolen.
See also: SIM swapper sentenced to 8 years in prison for account hacking
However, if instead of a message with the one-time code, an authentication app was used, hackers would not be able to log in to the account.
For this reason, it is always recommended to use MFA only with a hardware security key or authentication app and not via SMS.
The SEC account wasn’t the only X account to be compromised for a crypto scam this time around. The accounts of Netgear and Hyundai, as well as cybersecurity firm Mandiant , were also targeted by hackers. In addition, the platform was flooded with malicious ads promoting cryptocurrency scams and crypto drainers. Unfortunately, there doesn’t seem to be an end in sight, with users expressing frustration with the constant stream of malicious ads.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How can companies make it harder to breach their X accounts?
One of the most effective ways to protect against such breaches is to usestrong and unique passwords for each account.
Additionally, using multi-factor authentication can provide extra protection. This means that even if a user's password is compromised, hackers will still need to overcome a second barrier to gain access to the account.
See also: X users frustrated by constant stream of malicious crypto ads
It is also important to regularly update the software and operating system of devices, as updates often include security fixes that can protect against new threats.
Using antivirus software is also a good way to protect yourself. These tools can detect and remove threats before they cause damage.
Finally, educating users about the tactics hackers use to gain access to X accounts can help prevent attacks.
Source: www.bleepingcomputer.com
