Mandiant, SEC Lose Control of X Accounts Without 2FA
ID: 8f0a16c2-ade7-573d-ab38-1f05c2aafaa9
STIX ID: report--8f0a16c2-ade7-573d-ab38-1f05c2aafaa9
Feed Name: Dark Reading
Threat Score
Mandiant temporarily lost control of its X account to cryptocurrency-drainer malware operators because it did not have two-factor authentication enabled after X limited SMS 2FA to paid subscribers; the SEC's X account was also hijacked via a compromised phone number, demonstrating how platform policy changes and understaffed security teams can enable account takeovers and related fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
