logo

A tangled mess: Government rules for social media security lack clarity

ID: 66a3b44f-2d73-5b28-ac45-b6a95e9e4cdc

STIX ID: report--66a3b44f-2d73-5b28-ac45-b6a95e9e4cdc

Feed Name: CyberScoop

Date Published: 2024-01-29

Date Updated: 2026-04-21

Author: mbracken

...
...

The report analyzes the hijacking of the SEC’s X account—conducted via a SIM-swapping attack after multifactor authentication was disabled—and the broader policy ambiguity around securing federal social media accounts. Drawing on responses from multiple agencies, it highlights inconsistent adoption of MFA and phishing-resistant methods, references to EO 14028 and OMB zero trust guidance, unclear authority for OMB/CISA to mandate controls on third-party platforms, and concludes that clearer, enforceable baseline requirements are needed to reduce the risk of market-moving account compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.