{"id":23646,"date":"2024-01-13T12:28:22","date_gmt":"2024-01-13T20:28:22","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/01\/13\/news-17376\/"},"modified":"2024-01-13T12:28:22","modified_gmt":"2024-01-13T20:28:22","slug":"news-17376","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2024\/01\/13\/news-17376\/","title":{"rendered":"SEC X account hacked to hawk crypto-scams"},"content":{"rendered":"\n<p>We have seen several high-profile accounts that were taken over on X (formerly Twitter) only to be used for cryptocurrency related promotional activities, like expressing the approval of exchange-traded funds (ETFs).<\/p>\n<p>The latest victim in this line-up is the Securities and Exchange Commission (SEC).<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">The <a href=\"https:\/\/twitter.com\/SECGov?ref_src=twsrc%5Etfw\">@SECGov<\/a> X account was compromised, and an unauthorized post was posted. The SEC has not approved the listing and trading of spot bitcoin exchange-traded products.<\/p>\n<p>&mdash; U.S. Securities and Exchange Commission (@SECGov) <a href=\"https:\/\/twitter.com\/SECGov\/status\/1744837121406349714?ref_src=twsrc%5Etfw\">January 9, 2024<\/a><\/p><\/blockquote><\/div>\n<\/figure>\n<p>The\u00a0unauthorized post (which was removed within 30 minutes) looked like this:<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"464\" height=\"339\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/Hijack-tweet.png\" alt=\"The tweet sent from the account whiel it was hijacked\" class=\"wp-image-101938\" \/><\/figure>\n<p>The post says:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>&#8220;Today the SEC grants approval to Bitcoin ETFs for listing on registered national security exchanges.<\/p>\n<p>The approved Bitcoin ETFs will be subject to ongoing surveillance and compliance measures to ensure continued investor protection.\u201d<\/p>\n<\/blockquote>\n<p>The hack appears to have been designed to take advantage of anticipation around an imminent annoncement by US regulators about Bitcoin Exchange Traded Funds (ETFs). ETFs are financial products that allow investors to buy commodities like gold or Bitcoin as if they are shares. A spot Bitcoin ETF will buy the cryptocurrency directly, &#8220;on the spot&#8221;, at its current price, throughout the day. The approval would mark a key milestone for the cryptocurrency market in gaining acceptance to mainstream financial markets. <\/p>\n<p>Even though the false tweet only had a short life-span it caused a $2,000 spike in Bitcoin exchanges rates. Someone knowing this was going to happen could have made a significant profit.<\/p>\n<p>In a statement the SEC said:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>&#8220;That unauthorized access has been terminated. The SEC will work with law enforcement and our partners across government to investigate the matter and determine appropriate next steps relating to both the unauthorized access and any related misconduct.&#8221;<\/p>\n<\/blockquote>\n<p>Based on a preliminary probe, X confirmed that the SEC account had been compromised and it found that it was not due to a breach of the social media platform&#8217;s systems.<\/p>\n<p>According to X, an unidentified individual was able to obtain control over a phone number associated with the @SECGov account through a third party. This would suggest the compromise was the result of a <a href=\"https:\/\/www.malwarebytes.com\/glossary\/simjacking\">SIM swapping<\/a> attack, where an attacker takes control of a phone number by convincing a mobile carrier to transfer the victim\u2019s phone number to a SIM card they own.<\/p>\n<p>With this control they can intercept messages, two-factor authentication (2FA) codes, and eventually reset passwords of the account the number has control over. Although apparently the SEC did not have 2FA enabled for its X account!<\/p>\n<h3 class=\"wp-block-heading\" id=\"h-secure-your-x-account\">Secure your X account<\/h3>\n<p>Although any form of 2FA is better than none,  all forms of 2FA are not equally secure. SMS-based 2FA is vulnerable to SIM swapping and if you can avoid it, we suggest you do. X offers other options like an authentication app and a security key.<\/p>\n<p>To change your 2FA factor in X click on <strong>More<\/strong><\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"232\" height=\"127\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/More.png\" alt=\"The More button is beneath the Profile button on your X page\" class=\"wp-image-101939\" \/><\/figure>\n<p>Select <strong>Settings and Support<\/strong> &gt; <strong>Settings and Privacy<\/strong> &gt; <strong>Security and Account access<\/strong><\/p>\n<figure data-wp-context=\"{ &quot;core&quot;: \t\t\t\t{ &quot;image&quot;: \t\t\t\t\t{   &quot;imageLoaded&quot;: false, \t\t\t\t\t\t&quot;initialized&quot;: false, \t\t\t\t\t\t&quot;lightboxEnabled&quot;: false, \t\t\t\t\t\t&quot;hideAnimationEnabled&quot;: false, \t\t\t\t\t\t&quot;preloadInitialized&quot;: false, \t\t\t\t\t\t&quot;lightboxAnimation&quot;: &quot;zoom&quot;, \t\t\t\t\t\t&quot;imageUploadedSrc&quot;: &quot;https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/SecuritySettings.png&quot;, \t\t\t\t\t\t&quot;imageCurrentSrc&quot;: &quot;&quot;, \t\t\t\t\t\t&quot;targetWidth&quot;: &quot;1077&quot;, \t\t\t\t\t\t&quot;targetHeight&quot;: &quot;576&quot;, \t\t\t\t\t\t&quot;scaleAttr&quot;: &quot;&quot;, \t\t\t\t\t\t&quot;dialogLabel&quot;: &quot;Enlarged image&quot; \t\t\t\t\t} \t\t\t\t} \t\t\t}\" data-wp-interactive class=\"wp-block-image aligncenter size-large is-resized wp-lightbox-container\"><img decoding=\"async\" loading=\"lazy\" width=\"1077\" height=\"576\" data-wp-effect=\"effects.core.image.setButtonStyles\" data-wp-init=\"effects.core.image.initOriginImage\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/SecuritySettings.png?w=1024\" alt=\"Settings and Security and account access menu\" class=\"wp-image-101940\" style=\"width:700px\" \/><button class=\"lightbox-trigger\" type=\"button\" aria-label=\"Enlarge image: Settings and Security and account access menu\"> \t\t\t \t\t\t\t \t\t\t \t\t<\/button>        <\/p>\n<div data-wp-body=\"\" class=\"wp-lightbox-overlay zoom\" data-wp-effect=\"effects.core.image.initLightbox\">                 <button type=\"button\" aria-label=\"Close\" class=\"close-button\">                                      <\/button>                 <\/p>\n<div class=\"lightbox-image-container\">\n<figure class=\"wp-block-image aligncenter size-large is-resized responsive-image\"><img decoding=\"async\" src=\"\" alt=\"Settings and Security and account access menu\" class=\"wp-image-101940\" style=\"width:700px\" \/><\/figure>\n<\/p><\/div>\n<div class=\"lightbox-image-container\">\n<figure class=\"wp-block-image aligncenter size-large is-resized enlarged-image\"><img decoding=\"async\" src=\"\" alt=\"Settings and Security and account access menu\" class=\"wp-image-101940\" style=\"width:700px\" \/><\/figure>\n<\/p><\/div>\n<div class=\"scrim\" style=\"background-color: #fff\" aria-hidden=\"true\"><\/div>\n<\/p><\/div>\n<\/figure>\n<p>Click <strong>Security<\/strong> &gt; <strong>Two-factor authentication<\/strong> and put a checkmark in your preferred option.<\/p>\n<figure data-wp-context=\"{ &quot;core&quot;: \t\t\t\t{ &quot;image&quot;: \t\t\t\t\t{   &quot;imageLoaded&quot;: false, \t\t\t\t\t\t&quot;initialized&quot;: false, \t\t\t\t\t\t&quot;lightboxEnabled&quot;: false, \t\t\t\t\t\t&quot;hideAnimationEnabled&quot;: false, \t\t\t\t\t\t&quot;preloadInitialized&quot;: false, \t\t\t\t\t\t&quot;lightboxAnimation&quot;: &quot;zoom&quot;, \t\t\t\t\t\t&quot;imageUploadedSrc&quot;: &quot;https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/choices.png&quot;, \t\t\t\t\t\t&quot;imageCurrentSrc&quot;: &quot;&quot;, \t\t\t\t\t\t&quot;targetWidth&quot;: &quot;617&quot;, \t\t\t\t\t\t&quot;targetHeight&quot;: &quot;429&quot;, \t\t\t\t\t\t&quot;scaleAttr&quot;: &quot;&quot;, \t\t\t\t\t\t&quot;dialogLabel&quot;: &quot;Enlarged image&quot; \t\t\t\t\t} \t\t\t\t} \t\t\t}\" data-wp-interactive class=\"wp-block-image aligncenter size-full is-resized wp-lightbox-container\"><img decoding=\"async\" loading=\"lazy\" width=\"617\" height=\"429\" data-wp-effect=\"effects.core.image.setButtonStyles\" data-wp-init=\"effects.core.image.initOriginImage\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/choices.png\" alt=\"Choices are Text message, Authentication app, and Security key\" class=\"wp-image-101941\" style=\"width:700px\" \/><button class=\"lightbox-trigger\" type=\"button\" aria-label=\"Enlarge image: Choices are Text message, Authentication app, and Security key\"> \t\t\t \t\t\t\t \t\t\t \t\t<\/button>        <\/p>\n<div data-wp-body=\"\" class=\"wp-lightbox-overlay zoom\" data-wp-effect=\"effects.core.image.initLightbox\">                 <button type=\"button\" aria-label=\"Close\" class=\"close-button\">                                      <\/button>                 <\/p>\n<div class=\"lightbox-image-container\">\n<figure class=\"wp-block-image aligncenter size-full is-resized responsive-image\"><img decoding=\"async\" src=\"\" alt=\"Choices are Text message, Authentication app, and Security key\" class=\"wp-image-101941\" style=\"width:700px\" \/><\/figure>\n<\/p><\/div>\n<div class=\"lightbox-image-container\">\n<figure class=\"wp-block-image aligncenter size-full is-resized enlarged-image\"><img decoding=\"async\" src=\"\" alt=\"Choices are Text message, Authentication app, and Security key\" class=\"wp-image-101941\" style=\"width:700px\" \/><\/figure>\n<\/p><\/div>\n<div class=\"scrim\" style=\"background-color: #fff\" aria-hidden=\"true\"><\/div>\n<\/p><\/div>\n<\/figure>\n<p>You will be prompted to enter your X password and click Confirm. From there, follow the instructions in the prompts. Since not many people have security keys, I\u2019ll continue with the Authentication app instructions.<\/p>\n<figure data-wp-context=\"{ &quot;core&quot;: \t\t\t\t{ &quot;image&quot;: \t\t\t\t\t{   &quot;imageLoaded&quot;: false, \t\t\t\t\t\t&quot;initialized&quot;: false, \t\t\t\t\t\t&quot;lightboxEnabled&quot;: false, \t\t\t\t\t\t&quot;hideAnimationEnabled&quot;: false, \t\t\t\t\t\t&quot;preloadInitialized&quot;: false, \t\t\t\t\t\t&quot;lightboxAnimation&quot;: &quot;zoom&quot;, \t\t\t\t\t\t&quot;imageUploadedSrc&quot;: &quot;https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/authentication-app.png&quot;, \t\t\t\t\t\t&quot;imageCurrentSrc&quot;: &quot;&quot;, \t\t\t\t\t\t&quot;targetWidth&quot;: &quot;594&quot;, \t\t\t\t\t\t&quot;targetHeight&quot;: &quot;636&quot;, \t\t\t\t\t\t&quot;scaleAttr&quot;: &quot;&quot;, \t\t\t\t\t\t&quot;dialogLabel&quot;: &quot;Enlarged image&quot; \t\t\t\t\t} \t\t\t\t} \t\t\t}\" data-wp-interactive class=\"wp-block-image aligncenter size-full wp-lightbox-container\"><img decoding=\"async\" loading=\"lazy\" width=\"594\" height=\"636\" data-wp-effect=\"effects.core.image.setButtonStyles\" data-wp-init=\"effects.core.image.initOriginImage\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/authentication-app.png\" alt=\"Prompt to protect your account in just two steps\" class=\"wp-image-101942\" \/><button class=\"lightbox-trigger\" type=\"button\" aria-label=\"Enlarge image: Prompt to protect your account in just two steps\"> \t\t\t \t\t\t\t \t\t\t \t\t<\/button>        <\/p>\n<div data-wp-body=\"\" class=\"wp-lightbox-overlay zoom\" data-wp-effect=\"effects.core.image.initLightbox\">                 <button type=\"button\" aria-label=\"Close\" class=\"close-button\">                                      <\/button>                 <\/p>\n<div class=\"lightbox-image-container\">\n<figure class=\"wp-block-image aligncenter size-full responsive-image\"><img decoding=\"async\" src=\"\" alt=\"Prompt to protect your account in just two steps\" class=\"wp-image-101942\" \/><\/figure>\n<\/p><\/div>\n<div class=\"lightbox-image-container\">\n<figure class=\"wp-block-image aligncenter size-full enlarged-image\"><img decoding=\"async\" src=\"\" alt=\"Prompt to protect your account in just two steps\" class=\"wp-image-101942\" \/><\/figure>\n<\/p><\/div>\n<div class=\"scrim\" style=\"background-color: #fff\" aria-hidden=\"true\"><\/div>\n<\/p><\/div>\n<\/figure>\n<ul>\n<li>Click <strong>Get started<\/strong><\/li>\n<li>Open your preferred authentication app and add the X account to the app. Usually this is as simple as scanning the QR code.<\/li>\n<li>You\u2019ll be prompted to enter the authentication code shown by the app.<\/li>\n<\/ul>\n<p>You\u2019re all set. Store the displayed backup code in a safe place in case you need it.<\/p>\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" loading=\"lazy\" width=\"615\" height=\"657\" src=\"https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2024\/01\/all-set.png\" alt=\"The prompt that says you're all set also displays your backup code\" class=\"wp-image-101943\" \/><\/figure>\n<p>You\u2019ll receive a confirmation mail at the address associated with the account.<\/p>\n<p>And if you see tweets from an account about cryptocurrencies, NFTs, ETFs or other financial news that you would not expect from that account, keep a ten foot pole between you and what they are linking to.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity is-style-wide\" \/>\n<p><strong>We don&#8217;t just report on threats &#8211; we help safeguard your entire digital identit<\/strong>y<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using\u00a0<a href=\"https:\/\/www.malwarebytes.com\/identity-theft-protection\" target=\"_blank\" rel=\"noreferrer noopener\">Malwarebytes Identity Theft Protection<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/01\/sec-x-account-hacked-to-hawk-crypto-scams\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> The US Securities and Exchange Commission&#8217;s X account was compromised to take advantage of an expected Bitcoin ETFs announcement. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10598,19975,30673,32,24839,5897,10574,19232,30674,30675],"class_list":["post-23646","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-2fa","tag-crypto-scams","tag-etfs","tag-news","tag-nfts","tag-privacy","tag-scams","tag-sim-swapping","tag-take-over","tag-x-accounts"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23646"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23646\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23646"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}