logo

Mandiant, SEC Lose Control of X Accounts Without 2FA

ID: 8f0a16c2-ade7-573d-ab38-1f05c2aafaa9

STIX ID: report--8f0a16c2-ade7-573d-ab38-1f05c2aafaa9

Feed Name: Dark Reading

Threat Score
40/100

Date Published: 2024-01-12

Date Updated: 2026-04-21

Author: Becky Bracken, Editor, Dark Reading

...
...

Mandiant temporarily lost control of its X account to cryptocurrency-drainer malware operators because it did not have two-factor authentication enabled after X limited SMS 2FA to paid subscribers; the SEC's X account was also hijacked via a compromised phone number, demonstrating how platform policy changes and understaffed security teams can enable account takeovers and related fraud.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.