America Securities and Change Fee has confirmed it fell sufferer to a “SIM swap” assault, resulting in the false X post on Jan. 9 stating that spot Bitcoin (BTC) exchange-traded funds (ETFs) had been accepted.
“Two days after the incident, in session with the SEC’s telecom provider, the SEC decided that the unauthorized occasion obtained management of the SEC cellular phone quantity related to the account in an obvious ‘SIM swap’ assault,” an SEC spokesperson said on Jan. 22.
“As soon as accountable for the cellphone quantity, the unauthorized occasion reset the password for the @SECGov account,” the SEC spokesperson added.
The SEC mentioned legislation enforcement is investigating how the unauthorized occasion received the provider to vary the SIM for the account and the way the occasion knew which cellphone quantity was related to the SEC’s X account.
The SEC additionally revealed that six months previous to the assault, a workers member eliminated multifactor authentication as an extra layer of safety attributable to points accessing the account. The safety measure was not restored till after the Jan. 9 assault.
The SEC mentioned it hadn’t discovered any proof suggesting the unauthorized occasion gained entry to different SEC methods, knowledge or social media accounts.
Associated: Fake spot Bitcoin ETF tweet ‘likely wasn’t the SEC,’ says Blockchain Association director

SIM swapping is a method wherein attackers achieve management of a phone quantity by having it reassigned to a brand new gadget.
The SEC formally accepted several spot Bitcoin ETF applications the next day, Jan. 10, most of which started buying and selling on Jan. 11.
Journal: Crypto regulation: Does SEC Chair Gary Gensler have the final say?





