SEC Says Other Systems Secure After X Account Hack

CoinDeskPolicyDipublikasikan tanggal 2024-01-12Terakhir diperbarui pada 2024-01-13

Abstrak

The regulator's latest update on the hack suggests it never lost access to the account.

The U.S. Securities and Exchange Commission said Friday its systems and devices were not breached by the party responsible for tweeting out a fake bitcoin ETF approval announcement earlier this week.

On Tuesday, the SEC's official X (formerly Twitter) account, @SECgov, tweeted that the agency had approved a number of spot bitcoin exchange-traded fund (ETF) applications to begin trading, a message that was ultimately shown to be faked by someone who was able to gain access to the account through the phone number associated with it. On Friday, the SEC statement provided a timeline of events on Tuesday, saying the first "unauthorized post" came at 4:11 p.m. ET (21:11 UTC), and SEC Chair Gary Gensler published his clarification 15 minutes later.

10

The statement suggested that SEC staff never lost access to the account, saying they had deleted the fake post, un-liked some other bitcoin-related tweets and shared an update on the main SECgov account within 30 minutes.

Advertisement
Advertisement

"Staff also reached out to X.com for assistance in terminating the unauthorized access to the @SECGov account. Based on information currently available, staff believe that the unauthorized access to the account was terminated between 4:40 pm ET and 5:30 pm ET," the statement said.

An SEC spokesperson said on Wednesday that the FBI was investigating the issue, adding that the SEC did not draft the message (dispelling rumors that the fake approval notice was an already planned announcement that was released prematurely). Friday's statement added that the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) are also investigating.

On Wednesday, the SEC did approve nearly a dozen bitcoin ETF applications, which began trading a day later.

The hack alarmed a number of lawmakers, who publicly demanded answers about how it happened. Senators Ron Wyden (D-Ore.) and Cynthia Lummis (R-Wyo.) published a letter on Thursday asking that SEC Inspector General Deborah Jeffrey's office open an investigation into the hack "and the SEC's apparent failure to follow cybersecurity best practices."

Future hacks could harm public markets and their stability, the letter said.

The letter followed Senators J.D. Vance (R-Ohio) and Thom Tillis (R-N.C.), who similarly asked Gensler to brief their teams on a number of questions around the hack and the SEC's decision-making on bitcoin ETFs, including how the SEC "plans to rectify any financial losses borne by investors as a result of the errant announcement."

Advertisement
Advertisement

"The SEC takes its cybersecurity obligations seriously. Commission staff are still assessing the impacts of this incident on the agency, investors, and the marketplace but recognize that those impacts include concerns about the security of the SEC’s social media accounts. The staff also will continue to assess whether additional remedial measures are warranted," the SEC's statement on Friday said.

Bacaan Terkait

Akses ke Sesi Aktif Alih-alih Basis Data: Bagaimana Pasar Gelap di Rusia Berubah

Pasar gelap di Rusia telah bergeser prioritasnya: dari menjual basis data massal yang dicuri dari korporasi, kini pelaku kejahatan memperdagangkan akses aktif jangka pendek ke akun pengguna. Nilai informasi yang dicegat oleh perangkat lunak berbahaya langsung dari komputer dan ponsel yang terinfeksi tumbuh hampir 13% dalam setahun terakhir, dengan pengguna Rusia mencapai 14–18% dari segmen ini. Berbeda dengan arsip usang, paket data baru berisi alat untuk infiltrasi instan ke lingkungan digital individu, seperti token sesi aktif yang memungkinkan login tanpa kata sandi, kata sandi aktif, akses langsung ke email, kredensial layanan VPN dan penyimpanan cloud, serta akses administratif ke jaringan perusahaan. Paket data lama dijual hanya $10–15, sementara langganan saluran tertutup dengan data segar harian berharga $250–300 per bulan, menunjukkan pasar lebih menghargai kemutakhiran daripada volume. Statistik resmi menciptakan ilusi kontrol penuh. Meski regulator berhasil menindak perusahaan untuk kebocoran data dari penyimpanan terpusat—dengan denda dan investigasi administratif—langkah ini tidak efektif terhadap model ancaman baru. Malware mencuri data setelah meninggalkan perimeter perusahaan dan berada di perangkat pribadi, sehingga basis data korporat secara formal tidak terganggu dan mekanisme regulasi tidak berlaku. Kerentanan infrastruktur korporat meningkat: token sesi yang dicuri seringkali dapat menghindari autentikasi ulang dan verifikasi dua faktor. Pada paruh pertama 2026, 6 dari 10 serangan web ditargetkan untuk memperoleh kunci akses ke infrastruktur internal. Satu komputer karyawan yang terinfeksi dapat membuka jaringan yang terlindungi. Pengalaman internasional (seperti penutupan Genesis Market pada 2023) menunjukkan bahwa operasi semacam ini hanya menggeser titik penjualan, bukan menghilangkan sumbernya—infeksi perangkat terus berlanjut. Permintaan akan data "segar" juga mendorong operator botnet untuk mempertahankan mesin yang terinfeksi sebagai sumber pendapatan berkelanjutan. Tantangan bagi regulator adalah mengembangkan alat untuk lapisan antara perangkat pribadi dan perimeter korporat, yang saat ini berada di luar kendali regulasi yang ada.

cryptonews.ru1j yang lalu

Akses ke Sesi Aktif Alih-alih Basis Data: Bagaimana Pasar Gelap di Rusia Berubah

cryptonews.ru1j yang lalu

SlowMist Tandai Repositori Palsu Qwen 3.8 27B di GitHub yang Menyembunyikan Informasi StealC

SlowMist menandai repositori palsu Qwen 3.8 27B di GitHub yang menyembunyikan informasi tentang StealC. Repositori GitHub berbahaya ini mengunggah virus pencuri data yang menyamar sebagai file berat model AI Qwen 3.8 27B milik Alibaba. Repositori palsu tersebut menawarkan file ZIP berukuran hanya 487 KB, jauh lebih kecil dari model asli yang membutuhkan lebih dari 16 GB. File berbahaya bernama `uncensored_qwen_v2.6.zip` berisi skrip yang menyuntikkan malware StealC. Setelah dijalankan, StealC mengumpulkan informasi sistem, nama pengguna, tangkapan layar, serta mencuri data login browser, cookie, sejarah, kata sandi email, dan informasi dompet kripto. Malware ini bahkan memiliki sistem cadangan yang membaca alamat server dari blockchain Polygon. SlowMist menemukan setidaknya 23 repositori GitHub serupa dan 29 file ZIP yang menggunakan metode pengiriman berbasis Lua yang sama. Kampanye yang disebut FakeGit, aktif sejak Maret 2025, telah membuat sekitar 7.600 repositori berbahaya dan menghasilkan lebih dari 14 juta acara unduhan. Sekitar 800 repositori dirancang khusus untuk meniru alat-alat terkait AI. Serangan otomatis lain seperti Megalodon dapat membuat lebih dari 5.000 repositori palsu dalam enam jam. Peretas menyalin proyek nyata, membuat halaman README yang meyakinkan, dan mendaftarkan proyek palsu ke dalam registri AI publik untuk meningkatkan kredibilitasnya. Pengguna yang menjalankan model AI sumber terbuka secara lokal disarankan untuk sangat berhati-hati dan memverifikasi keaslian repositori serta ukuran file sebelum mengunduh.

cryptonews.ru1j yang lalu

SlowMist Tandai Repositori Palsu Qwen 3.8 27B di GitHub yang Menyembunyikan Informasi StealC

cryptonews.ru1j yang lalu

Trading

Spot
活动图片