logo

SEC blames sim-swapping, lack of MFA for X account hijacking

ID: f1ab337b-f983-540a-a7cb-b015f2e10d91

STIX ID: report--f1ab337b-f983-540a-a7cb-b015f2e10d91

Feed Name: CyberScoop

Threat Score
50/100

Date Published: 2024-01-22

Date Updated: 2026-04-21

Author: eliasgroll

...
...

The SEC confirmed its X account was hijacked on Jan. 9 via an apparent SIM swap in which an attacker convinced the telecom carrier to transfer the phone number tied to the account, then reset the account password; the account lacked multifactor authentication. A multi-agency investigation is ongoing, and the report emphasizes SMS-based MFA's vulnerability and recent platform changes that reduced SMS MFA availability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.