A tangled mess: Government rules for social media security lack clarity
ID: 66a3b44f-2d73-5b28-ac45-b6a95e9e4cdc
STIX ID: report--66a3b44f-2d73-5b28-ac45-b6a95e9e4cdc
Feed Name: CyberScoop
The report analyzes the hijacking of the SEC’s X account—conducted via a SIM-swapping attack after multifactor authentication was disabled—and the broader policy ambiguity around securing federal social media accounts. Drawing on responses from multiple agencies, it highlights inconsistent adoption of MFA and phishing-resistant methods, references to EO 14028 and OMB zero trust guidance, unclear authority for OMB/CISA to mandate controls on third-party platforms, and concludes that clearer, enforceable baseline requirements are needed to reduce the risk of market-moving account compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
