X confirms the @SECGov account was compromised and says “the compromise was not due to any breach of X's systems” and that the account didn't have 2FA enabled
- X said late Tuesday it has completed a preliminary probe into the compromised account of the U.S. Securities … Source: @safety .
CNBC
Context & Ripple Effects
The compromise forced the SEC to disavow a post implying a spot bitcoin ETF approval, showing how a verified government social account can become a high-impact channel for false market-sensitive information. The agency’s public correction established that the message was unauthorized.
X’s preliminary finding shifts attention from platform intrusion to account-level controls: the SEC account lacked two-factor authentication. Subsequent reporting identified a SIM-swap password reset and said 2FA had been disabled over access issues. The later SIM-swap account adds operational context to X’s initial conclusion.
First-order effects
The SEC must treat @SECGov credential recovery and multi-factor access as an immediate communications-security issue, while X avoids attribution of the incident to a breach of its own systems.
The false post’s removal and public correction leave the SEC and X managing trust in an official account whose verification signals did not prevent takeover.
Second-order effects
Other government and business accounts on X face added pressure to review phone-number-based recovery and 2FA enforcement, particularly after reports of hijacked verified organizational accounts promoting crypto scams.
The incident makes platform verification less sufficient as a trust signal for time-sensitive announcements; audiences may demand corroboration from official web channels or filings.
Third-order effects
If official agencies continue to depend on social platforms for consequential announcements, account-security policy will increasingly be part of market-communications governance rather than a back-office IT matter.
The episode points to a wider need for resilient publishing and recovery processes that do not trade away strong authentication for administrative convenience; the degree of regulatory response remains uncertain.
The trend: High-consequence institutions are being pushed to harden social-media identity and recovery controls as verified accounts become targets for market-moving misinformation.
We can confirm that the account @SECGov was compromised and we have completed a preliminary investigation. Based on our investigation, the compromise was not due to any breach of X's systems, but rather due to an unidentified individual obtaining control over a phone number...
@Safety @SECGov The people in charge of “protecting investors” and “regulating” #Bitcoin can't even protect their own X account with basic 2FA... What a joke.
the goddamn @secgov didn't have 2fa enabled on its x account, you literally can't make this stuff up, clown car goat rodeo of an organization, clean house
@SECGov A vulnerability on Twitter is that many high profile accounts must add a phone number to become “verified” (even if they choose to hide their checkmark). Then, if you don't go and remove your phone number after the verification process, you're at risk for SIM swap account…
@Chris_Yeung98 1. Enable MFA that matches your threat model: app based or FIDO solution 2. Don't tie phone number to Twitter account to prevent SIM swap risk (if you must temporarily add phone number for verification, remove it as soon as possible) 3. If you use a 3rd party socia…
@Safety @SECGov Hi @GaryGensler this is a reminder to secure your financial accounts as well as protect against identity theft and fraud. Remember to: 🔒Use strong passphrases or passwords 🔒Set up multifactor authentication 🔒Keep account alerts turned on #CybersecurityAwarenessMon…
First off, what the ever loving fuck? A government regulator who wants to control technical standards for financial markets can't use 2FA? Second, hey Twitter, stop letting people reset passwords by phone number without secondary verification. 🤷♂️
No 2FA on the SEC's Twitter account??!! Oh the irony. The reason people created bitcoin in the first place was because they didn't trust the security & integrity of large government bodies