Senators Demand Probe into SEC Hack After Bitcoin Price Spike

US lawmakers have demanded an investigation into the hack of the Securities and Exchange Commission's X account last week.
Senators Ron Wyden, who sits on the Senate Intelligence Committee, and Cynthia Lummis, accused the federal agency of failing to secure its social media accounts using industry best practices in a letter dated January 11, 2024.
Hackers compromised the SEC's X account on January 10 and posted a fake announcement regarding the approval of Bitcoin exchange-traded funds on security exchanges, leading to Bitcoin prices briefly spiking.
X also noted that the SEC's account did not have two-factor authentication enabled at the time the account was hacked.
This attack came amid a wave of crypto-related X account hijacks targeting prominent companies, including Mandiant, Hyundai and Certik.
They argued that the SEC should have used security keys to secure their social media accounts as well as 2FA, following recent guidance from the Office of Management and Budget and the Cybersecurity and Infrastructure Security Agency.
The option to enable security keys has been available for users of X since 2021.
This includes an independent evaluation in FY23 which determined that the SEC's information security program and practices were not effective.
Wyden and Lummis have given the SEC a deadline of February 12 to provide an update into their investigation and its cybersecurity remediations.


This Cyber News was published on www.infosecurity-magazine.com. Publication date: Mon, 15 Jan 2024 16:50:22 +0000


Cyber News related to Senators Demand Probe into SEC Hack After Bitcoin Price Spike

Tracers in the Dark: The Global Hunt for the Crime Lords of Crypto - Y is the author of a book I can very greatly recommend, with the fascinating title Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency. As I dug into this cypherpunk world, around 2010 and 2011, I came upon this thing that ...
1 year ago Nakedsecurity.sophos.com
D-Link D-View 8 Unauthenticated Probe-Core Server Communication - A security issue exists in D-Link D-View 8 v2.0.2.89 and prior that could allow an attacker to manipulate the probe inventory of the D-View service. An unauthenticated remote attacker can register a host of his/her choice as a Probe server by sending ...
6 months ago Tenable.com
Crypto Enthusiasts Embrace New Frontier: Investing in Bitcoin ETFs Explained - This was the first time the Securities and Exchange Commission approved an exchange-traded fund that contained bitcoin, but the Commission stressed that its decision does not mean it endorses or approves Bitcoin, but that it remains deeply sceptical ...
5 months ago Cysecurity.news
Senators Demand Probe into SEC Hack After Bitcoin Price Spike - US lawmakers have demanded an investigation into the hack of the Securities and Exchange Commission's X account last week. Senators Ron Wyden, who sits on the Senate Intelligence Committee, and Cynthia Lummis, accused the federal agency of failing to ...
5 months ago Infosecurity-magazine.com
SEC Approves Bitcoin ETFs, Crypto Industry Rejoices - The US securities regulator has officially approved the first US-listed exchange traded funds to track bitcoin, in what is being labelled a watershed moment for the world's largest cryptocurrency, as well as the broader crypto industry. Earlier this ...
5 months ago Silicon.co.uk
Bitcoin ETFs Approved Following Official SEC X Account Compromise - For many years, the cryptocurrency industry has waited with bated breath for the U.S. Securities and Exchange Commission to finally approve Bitcoin ETFs. This was not before a hacker had the first laugh. Tuesday afternoon, a day prior, the official X ...
5 months ago Itsecurityguru.org
SEC Twitter hacked to push fake news of Bitcoin ETF approval The Register - Breaking The SEC today said its Twitter/X account was hijacked to wrongly claim it had approved hotly anticipated Bitcoin ETFs, causing cryptocurrency to spike and then slip in price. In the past few minutes, the tweet was vanished. The SEC has not ...
5 months ago Go.theregister.com
SEC Chair Says Account on X Was Hacked - An ETF would provide a way to invest in bitcoin without having to buy the cryptocurrency outright on a crypto exchange such as Binance or Coinbase. The price of bitcoin swung from about $46,730 to just below $48,000 after the unauthorized post hit, ...
5 months ago Securityweek.com
The United States is Monitoring Vulnerabilities in Bitcoin - The United States has shown a keen interest in the cybersecurity aspects of Bitcoin, particularly honing in on a vulnerability associated with the Ordinals Protocol in 2022. The National Vulnerability Database, overseen by the National Institute of ...
6 months ago Cysecurity.news
SEC Twitter hacked to push fake news of ETF approval The Register - Breaking The SEC today said its Twitter account was hijacked to wrongly claim it had approved hotly anticipated Bitcoin ETFs, causing cryptocurrency to spike and then slip in price. In the past few minutes, the tweet was vanished. The SEC has not ...
5 months ago Go.theregister.com
Here's Some Bitcoin: Oh, and You've Been Served! - The case is thought to be first in which a federal court has recognized the use of information included in a bitcoin transaction - such as a link to a civil claim filed in federal court - as reasonably likely to provide notice of the lawsuit to the ...
5 months ago Krebsonsecurity.com
SEC confirms X account was hacked in SIM swapping attack - The U.S. Securities and Exchange Commission confirmed today that its X account was hacked through a SIM-swapping attack on the cell phone number associated with the account. Earlier this month, the SEC's X account was hacked to issue a fake ...
5 months ago Bleepingcomputer.com
Navigating the Paradox: Bitcoin's Self-Custody and the Privacy Challenge - Self-custody in Bitcoin refers to individuals holding and controlling their private keys, which in turn control their bitcoin. This concept is akin to securing physical gold in a personal safe rather than relying on a bank or third-party custodian. ...
5 months ago Cysecurity.news
Securities and Exchange Commission Cyber Disclosure Rules: How to Prepare for December Deadlines - Starting Dec. 18, publicly traded companies will need to report material cyber threats to the SEC. Deloitte offers business leaders tips on how to prepare for these new SEC rules. The U.S. Securities and Exchange Commission’s new rules around ...
6 months ago Techrepublic.com
The SEC's Official X Account Was 'Compromised' and Used to Post Fake Bitcoin News - The SEC has not yet responded to WIRED's request for comment. The fake post appeared to lead to a brief spike in Bitcoin's value of around 2.5 percent, to nearly $47,870, before crashing around 3.2 percent from its original price. Following news of ...
5 months ago Wired.com
CISOs on alert following SEC charges against SolarWinds - While the outcome of the Security and Exchange Commission's complaint against SolarWinds remains to be seen, infosec experts say the charges are likely to have a major impact on the role of the CISO going forward. In late October, the SEC charged ...
5 months ago Techtarget.com
SEC's X account hacked to post fake news of Bitcoin ETF approval - Someone has hijacked the X account of the US Securities and Exchange Commission, and posted an announcement saying the agency has decided to allow the listing of Bitcoin ETFs on registered national security exchanges. The fake announcement was posted ...
5 months ago Helpnetsecurity.com
SEC X Account Hacked to Publish Bitcoin ETFs Approval Message - In a scene ripped from a digital thriller, the U.S. The Securities and Exchange Commission saw its Twitter account hijacked by an unknown entity, plunging the crypto world into a roller coaster ride of frenzied excitement and crushing disappointment. ...
5 months ago Cybersecuritynews.com
US SEC's X account hacked to announce fake Bitcoin ETF approval - The X account for the U.S. Securities and Exchange Commission was hacked today to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges. The announcement came this afternoon in a now-deleted tweet from the SEC's hacked X ...
5 months ago Bleepingcomputer.com
Biden veto waiting for bill to kill SEC breach report rule The Register - The Biden administration has expressed to congressional representatives its strong opposition to undoing the Securities and Exchange Commission's strict data breach reporting rule. The joint resolution, along with House Joint Resolution 100, ...
5 months ago Go.theregister.com
SEC Shares Important Clarifications as New Cyber Incident Disclosure Rules Come Into Effect - The US Securities and Exchange Commission has shared some important clarifications on its new cyber incident disclosure requirements, which come into effect on Monday, December 18. The SEC announced in late July that it had adopted new cybersecurity ...
6 months ago Securityweek.com
MeridianLink confirms cyberattack after ransomware gang claims to report company to SEC - Financial software company MeridianLink confirmed that it is dealing with a cyberattack after the hackers behind the incident took extraordinary measures to pressure the company into paying a ransom. MeridianLink, which reported more than $76 million ...
7 months ago Therecord.media
Congressman Coming for Answers After No-Fly List Hack - U.S. Congressman Bennie Thompson is demanding answers from airlines and the federal government after a "massive hack" of the no-fly list. The congressman sent a letter to the airlines and the Department of Homeland Security asking for an explanation ...
1 year ago Therecord.media
Understanding the New SEC Rules for Disclosing Cybersecurity Incidents - The U.S. Securities and Exchange Commission recently announced its new rules for public companies regarding cybersecurity risk management, strategy, governance, and incident exposure. "Currently, many public companies provide cybersecurity disclosure ...
7 months ago Feeds.dzone.com
Hack The Box Launches 5th Annual University CTF Competition - PRESS RELEASE. Hack The Box, the leading gamified cybersecurity upskilling, certification, and talent assessment platform, is announcing its fifth annual global University Capture The Flag competition that will take place from December 8 to 10, 2023. ...
7 months ago Darkreading.com

Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)