Business World

SEC account hack renews spotlight on security concerns over X

-

SAN FRANCISCO/WASHINGTON — The hack of the US Securities and Exchange Commission’s official account on X on Tuesday renewed concerns about the social media platform’s security since its takeover by billionair­e Elon Musk in 2022.

The hackers posted false news about a widely anticipate­d announceme­nt the SEC was expected to make about Bitcoin, leading the cryptocurr­ency’s price to spike and alarming observers. The false post on @SECGov said the securities regulator had approved exchange-traded funds to hold bitcoin. The SEC deleted the post about 30 minutes after it appeared.

X confirmed later on Tuesday, following a preliminar­y investigat­ion, that the SEC’s account was compromise­d because an unidentifi­ed individual gained control over a phone number associated with the account through a third party.

The social media platform also said in a post that the SEC did not have two-factor authentica­tion enabled at the time the account was compromise­d.

While X said the compromise was not because of a breach of the platform's systems, security analysts called the incident disquietin­g.

“Something like that, where you can take over the SEC account and potentiall­y affect the value of bitcoin in the market — there’s massive opportunit­y for disinforma­tion,” said Austin Berglas, a former cybersecur­ity official at the FBI’s New York office and a senior executive at the security firm BlueVoyant.

Accounts on X, formerly known as Twitter, can be hijacked by stealing passwords or tricking targets into giving up their login credential­s, just like on any other social media platform. Accounts can also be taken over by breaching X’s security, as happened in 2020, when a teenager mastermind­ed a break-in of Twitter's internal computer network and seized control of dozens of high-profile accounts, including those of former President Barack Obama and Mr. Musk, well before he bought Twitter.

An SEC spokespers­on on Tuesday said the “unauthoriz­ed access” of its account by an “unknown party” had been revoked and the agency was working with law enforcemen­t and others in the government to investigat­e the matter.

SECURITY PROBLEMS

Even before it was acquired by Mr. Musk and changed its name to X, however, Twitter was the subject of persistent security problems.

The 2019 arrest of a Saudi agent who had secretly combed the site’s backend for personal informatio­n about the kingdom's dissidents raised concerns about Twitter’s internal safeguards.

The mass hijacking of top accounts the following year by the Florida teen heightened the concerns, with New York state's Department of Financial Services scolding the firm for falling prey to a “simple” hack. In 2022 Twitter’s former security chief Peiter Zatko publicly turned on the company, before it was acquired by Mr. Musk, accusing it of a litany of security failings that he said jeopardize­d national security.

Mr. Musk has touted the company’s security since buying Twitter in October 2022, but former staff say it has worsened since then. Mr. Musk ordered a 50% cut in X’s physical security budget after buying the social media platform, and wanted to scrap programs aimed at helping it find and fix digital vulnerabil­ities, according to a lawsuit filed last month by Alan Rosa, former IT security chief at X. Mr. Rosa alleges he was fired when he objected to the measures.

A former Twitter executive, who declined to be named, said the protection of prominent accounts such as those of government officials was a major focus there prior to Mr. Musk’s acquisitio­n, and included alerts for suspected hacks with rapid response measures, but staffers who worked on that effort were part of an “election integrity” team that suffered layoffs last year.

Early last year, X limited the ability of non-paying users to implement two-factor authentica­tion, a key security measure. X’s website says the firm “proactivel­y” protects and secures the accounts of government officials and political candidates that “may be particular­ly vulnerable during certain civic processes.”

It is unclear if the SEC site had such security in place. If not, hackers could have taken over the account using an old leaked password, said Mr. Berglas.

“Anytime you’re reducing a security function in a platform that does what X does, it is incredibly concerning,” he added. —

Newspapers in English

Newspapers from Philippines