SEC Says Other Systems Secure After X Account Hack

CoinDeskPolicyPublicado a 2024-01-12Actualizado a 2024-01-13

Resumen

The regulator's latest update on the hack suggests it never lost access to the account.

The U.S. Securities and Exchange Commission said Friday its systems and devices were not breached by the party responsible for tweeting out a fake bitcoin ETF approval announcement earlier this week.

On Tuesday, the SEC's official X (formerly Twitter) account, @SECgov, tweeted that the agency had approved a number of spot bitcoin exchange-traded fund (ETF) applications to begin trading, a message that was ultimately shown to be faked by someone who was able to gain access to the account through the phone number associated with it. On Friday, the SEC statement provided a timeline of events on Tuesday, saying the first "unauthorized post" came at 4:11 p.m. ET (21:11 UTC), and SEC Chair Gary Gensler published his clarification 15 minutes later.

10

The statement suggested that SEC staff never lost access to the account, saying they had deleted the fake post, un-liked some other bitcoin-related tweets and shared an update on the main SECgov account within 30 minutes.

Advertisement
Advertisement

"Staff also reached out to X.com for assistance in terminating the unauthorized access to the @SECGov account. Based on information currently available, staff believe that the unauthorized access to the account was terminated between 4:40 pm ET and 5:30 pm ET," the statement said.

An SEC spokesperson said on Wednesday that the FBI was investigating the issue, adding that the SEC did not draft the message (dispelling rumors that the fake approval notice was an already planned announcement that was released prematurely). Friday's statement added that the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) are also investigating.

On Wednesday, the SEC did approve nearly a dozen bitcoin ETF applications, which began trading a day later.

The hack alarmed a number of lawmakers, who publicly demanded answers about how it happened. Senators Ron Wyden (D-Ore.) and Cynthia Lummis (R-Wyo.) published a letter on Thursday asking that SEC Inspector General Deborah Jeffrey's office open an investigation into the hack "and the SEC's apparent failure to follow cybersecurity best practices."

Future hacks could harm public markets and their stability, the letter said.

The letter followed Senators J.D. Vance (R-Ohio) and Thom Tillis (R-N.C.), who similarly asked Gensler to brief their teams on a number of questions around the hack and the SEC's decision-making on bitcoin ETFs, including how the SEC "plans to rectify any financial losses borne by investors as a result of the errant announcement."

Advertisement
Advertisement

"The SEC takes its cybersecurity obligations seriously. Commission staff are still assessing the impacts of this incident on the agency, investors, and the marketplace but recognize that those impacts include concerns about the security of the SEC’s social media accounts. The staff also will continue to assess whether additional remedial measures are warranted," the SEC's statement on Friday said.

Lecturas Relacionadas

Acceso a sesiones activas en lugar de bases de datos: cómo ha cambiado el mercado clandestino en Rusia

El mercado negro en Rusia ha cambiado su prioridad: en lugar de vender grandes bases de datos corporativas robadas, los delincuentes ahora comercializan acceso activo y de corta duración a las cuentas de usuarios. El valor de la información interceptada por malware desde dispositivos infectados ha aumentado casi un 13% en el último año, según expertos de BI.ZONE en agosto de 2026. Los usuarios rusos representan del 14% al 18% de este segmento. Los nuevos paquetes, a diferencia de los archivos obsoletos, contienen herramientas para la intrusión instantánea: tokens de sesión activos, contraseñas vigentes, credenciales para VPN y almacenamiento en la nube, y accesos administrativos a redes corporativas. Mientras un archivo con datos antiguos cuesta solo $10-15, una suscripción a un canal privado con datos actualizados diariamente cuesta $250-300 al mes, lo que demuestra que el mercado paga por la actualidad, no por el volumen. Aunque las estadísticas oficiales muestran un descenso en el número de grandes filtraciones de bases de datos desde 2024 y se aplican multas a las empresas por incidentes repetidos, estas medidas regulatorias son ineficaces contra la nueva amenaza. El malware roba datos directamente de los dispositivos personales de los usuarios, fuera del perímetro corporativo protegido, lo que deja sin efecto los mecanismos de responsabilidad administrativa. La vulnerabilidad clave reside en que tokens de sesión robados pueden eludir la autenticación multifactor. En la primera mitad de 2026, 6 de cada 10 ataques web analizados buscaban obtener estas claves para infiltrarse en infraestructuras corporativas. Un solo ordenador infectado puede comprometer toda una red. El artículo también señala una brecha similar en las regulaciones de marcado de llamadas telefónicas, que ha resultado difícil de implementar incluso para los grandes bancos, confundiendo a los usuarios. En conclusión, los delincuentes se han adaptado a las medidas regulatorias contra filtraciones masivas, centrándose ahora en la extracción selectiva de claves de acceso activas. Este tipo de ataque opera en el espacio entre el perímetro corporativo y el dispositivo personal, una zona gris fuera del alcance de las normas actuales. A medida que aumentan las operaciones remotas, el valor de estos tokens de corta vida seguirá creciendo. La experiencia internacional (como el cierre del mercado Genesis en 2023) muestra que cerrar plataformas no elimina la fuente de la infección, y que nuevos canales emergen rápidamente.

cryptonews.ruHace 1 hora(s)

Acceso a sesiones activas en lugar de bases de datos: cómo ha cambiado el mercado clandestino en Rusia

cryptonews.ruHace 1 hora(s)

Trading

Spot
活动图片