SEC Says Other Systems Secure After X Account Hack

CoinDeskPolicy2024-01-12 tarihinde yayınlandı2024-01-13 tarihinde güncellendi

Özet

The regulator's latest update on the hack suggests it never lost access to the account.

The U.S. Securities and Exchange Commission said Friday its systems and devices were not breached by the party responsible for tweeting out a fake bitcoin ETF approval announcement earlier this week.

On Tuesday, the SEC's official X (formerly Twitter) account, @SECgov, tweeted that the agency had approved a number of spot bitcoin exchange-traded fund (ETF) applications to begin trading, a message that was ultimately shown to be faked by someone who was able to gain access to the account through the phone number associated with it. On Friday, the SEC statement provided a timeline of events on Tuesday, saying the first "unauthorized post" came at 4:11 p.m. ET (21:11 UTC), and SEC Chair Gary Gensler published his clarification 15 minutes later.

10

The statement suggested that SEC staff never lost access to the account, saying they had deleted the fake post, un-liked some other bitcoin-related tweets and shared an update on the main SECgov account within 30 minutes.

Advertisement
Advertisement

"Staff also reached out to X.com for assistance in terminating the unauthorized access to the @SECGov account. Based on information currently available, staff believe that the unauthorized access to the account was terminated between 4:40 pm ET and 5:30 pm ET," the statement said.

An SEC spokesperson said on Wednesday that the FBI was investigating the issue, adding that the SEC did not draft the message (dispelling rumors that the fake approval notice was an already planned announcement that was released prematurely). Friday's statement added that the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) are also investigating.

On Wednesday, the SEC did approve nearly a dozen bitcoin ETF applications, which began trading a day later.

The hack alarmed a number of lawmakers, who publicly demanded answers about how it happened. Senators Ron Wyden (D-Ore.) and Cynthia Lummis (R-Wyo.) published a letter on Thursday asking that SEC Inspector General Deborah Jeffrey's office open an investigation into the hack "and the SEC's apparent failure to follow cybersecurity best practices."

Future hacks could harm public markets and their stability, the letter said.

The letter followed Senators J.D. Vance (R-Ohio) and Thom Tillis (R-N.C.), who similarly asked Gensler to brief their teams on a number of questions around the hack and the SEC's decision-making on bitcoin ETFs, including how the SEC "plans to rectify any financial losses borne by investors as a result of the errant announcement."

Advertisement
Advertisement

"The SEC takes its cybersecurity obligations seriously. Commission staff are still assessing the impacts of this incident on the agency, investors, and the marketplace but recognize that those impacts include concerns about the security of the SEC’s social media accounts. The staff also will continue to assess whether additional remedial measures are warranted," the SEC's statement on Friday said.

İlgili Okumalar

Access to Active Sessions Instead of Databases: How the Shadow Market in Russia Has Changed

The Russian cybercriminal underground is shifting from selling massive, stolen corporate databases to trading active, short-term access to user accounts, according to a 2026 report. The value of information intercepted directly from infected devices by malware has risen nearly 13% in a year. Attackers now sell packets containing active session tokens (bypassing passwords and two-factor authentication), live email credentials, VPN and cloud storage logins, and corporate network access. A subscription for a steady stream of fresh data costs $250-$300 per month, far exceeding the value of outdated archives. While Russian regulators have successfully penalized companies for data leaks from centralized storage—with no repeat violations recorded after imposing turnover fines—this framework fails against the new threat model. Malware now steals data *after* it leaves the corporate perimeter and is on a user's personal device, a legal grey area. In 2026, 60% of studied web attacks aimed to steal keys for infiltrating corporate infrastructure. The situation mirrors global trends, akin to the Genesis Market shutdown in 2023, and highlights a structural risk: the demand for "fresh" data incentivizes botnet operators to maintain long-term control of infected devices for recurring revenue. This creates a persistent vulnerability layer between personal devices and corporate networks, currently outside the reach of existing regulatory protections.

cryptonews.ru1 saat önce

Access to Active Sessions Instead of Databases: How the Shadow Market in Russia Has Changed

cryptonews.ru1 saat önce

SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Concealing StealC Information

SlowMist has identified a fake GitHub repository impersonating Alibaba's Qwen 3.8 27B AI model, which contains an information-stealing virus. The repository, created in August 2026, offered a download file of only 487 KB, far smaller than a legitimate 27-billion-parameter model (over 16 GB). The malicious ZIP file contained a Lua-based script disguised as a certificate, which deploys the StealC malware. Once executed, StealC harvests system data, takes screenshots, and steals browser credentials, cryptocurrency wallet information, and more, sending it to attacker-controlled servers. The malware also includes a backup system that can read new server addresses from the Polygon blockchain if the primary server is taken down. This incident is part of a broader campaign called FakeGit, active since March 2025, which has created thousands of malicious repositories. Approximately 800 of these specifically target AI tools using a method called AgentBaiting, sometimes tricking AI assistants into recommending them. Separate reports detail hundreds of other fake GitHub repositories spreading malware like BoryptGrab and campaigns like Megalodon that generate thousands of clones rapidly. Attackers copy legitimate projects, create convincing documentation, and even list them on public AI registries to appear trustworthy. The fake repositories exploit the high demand for open-source AI capabilities, putting users who run models locally at significant risk of data theft.

cryptonews.ru1 saat önce

SlowMist Flags Fake Qwen 3.8 27B GitHub Repository Concealing StealC Information

cryptonews.ru1 saat önce

İşlemler

Spot
活动图片