FB pixel

US’ SEC disables MFA, falls to fraud attack

Categories Access Control  |  Biometrics News
US’ SEC disables MFA, falls to fraud attack
 

A pair of events, one nefarious and the other seemingly innocuous, allegedly combined to allow the takeover of a U.S. government regulator’s X account.

Someone reportedly was able to perform a SIM swap on a Securities and Exchange Commission phone account January 9.

Complicating the situation, SEC staff in July decided to temporarily disable multi-factor authentication on the agency’s X account to deal with problems staff were having accessing the account.

MFA was not restored until after the January 9 SIM swap attack.

That means the X account was unprotected for whoever swapped the SIM card and changed the access password.

It is not known who pulled off the attack, but there was at least one fraudulent post on @SECGov: the bogus announcement that the SEC signed off on spot bitcoin exchange-traded funds.

The government is still collecting information on both incidents, but as of January 22, investigators could find no evidence that someone “gained access to SEC systems, data, devices, or other social media accounts,” according to an agency statement.

The SIM swap occurred using the SEC’s telecommunication carrier systems and not SEC systems. The carrier has not been named.

It is not known how someone persuaded the telco to alter the card or how the person knew which phone number was on the account.

The American government’s top cybersecurity bodies urged IAM developers and vendors to strengthen MFA implementations to protect against hacks late last year.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Leidos, Idemia PS advance checkpoint modernization with biometrics, CAT-2 systems

Leidos and Idemia Public Security have formed a strategic partnership to deploy biometric‑enabled eGates and integrated Credential Authentication Technology (CAT-2)…

 

Google Wallet supports Aadhaar verifiable credentials in India

Google has added support for Aadhaar Verifiable Credentials in India, allowing users to store and present their digital Aadhaar ID…

 

India scales farmer ID system for payments with KPMG support

The India office of influential accounting firm KPMG has explained how it supported the advancement of the country’s Digital Agriculture…

 

Digital ID systems fail migrants due to policy gaps, Caribou finds

A new report by research organization Caribou has warned that digital ID systems around the world have continued to deepen…

 

Hopae launches eIDAS 2.0, AMLR onboarding readiness tool

Hopae has launched a free self-assessment tool to help financial institutions offering customer onboarding and identity verification to evaluate their…

 

Certainty vs flexibility – does the UK need a Biometric Surveillance Act?

By Professor Fraser Sampson, former UK Biometrics & Surveillance Camera Commissioner Last week London became a city of two tales. Two…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events