Block Journal
No Result
View All Result
  • Login
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianopt Portuguêsru Русскийes Españolth ไทยzh-CN 简体中文hi हिन्दीja 日本語
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine
Magazine
Newsletter
  • Trending Now
  • Bitcoin
  • Altcoin
  • Ethereum
  • Analysis
  • Blockchain
  • Metaverse
  • NFT
  • DeFi
  • Web3
  • GameFi
  • ICO
  • Legal
  • Security
Block Journal
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianopt Portuguêsru Русскийes Españolth ไทยzh-CN 简体中文hi हिन्दीja 日本語
No Result
View All Result
Block Journal
No Result
View All Result
  • News
  • Crypto
  • Markets
  • Investing
  • Videos
  • Charts
Home Crypto Security

New Google cloud sync feature implicated in $15M crypto heist at Ripple-owned Fortress Trust

News Room by News Room
September 18, 2023
in Security
Reading Time: 2 mins read
0 0
A A
0

Software development company Retool has blamed the hack of crypto custodian Fortress Trust on a recently introduced Google Account cloud synchronization feature, Hacker News reported on Sept. 18.

Retool, which provides cloud services for several customers, including Fortress Trust, disclosed that all the accounts of its 27 cloud customers were compromised. The breach led to Fortress Trust losing $15 million.

The hack process

Retool’s head of engineering, Snir Kodesh, said the new Google update changed its multifactor authentication standard to single-factor authentication without the administrators being aware.

This allowed the breach, which started as an SMS social engineering attack targeting the company’s employees, to be successful. The bad actor had sent malicious links to employees while pretending to be a member of the IT team.

The message accompanying the link said it was to resolve a payroll issue, and one of the employees unknowingly entered their credentials on the fake landing page. The hackers then called the employee using deepfake voice to obtain a multifactor authentication code.

The hackers could add their device to the employee’s account and produce their multifactor authentication code. This meant they could have an active Google Workspace session on the device.

The hackers gained access to the internal admin system from their devices by activating Google Authenticator cloud sync. They immediately took control of customers’ accounts, changing their email and password.

Retool did not disclose how the attack affected its other customers. However, the sophistication of the process suggests that hackers are experts who might even have insider access to tailor their phishing campaigns to targets.

Following the Aug. 27 incident, Ripple acquired Fortress Trust, reimbursing the affected customer’s funds. Meanwhile, this incident underscores the increasing sophistication of social engineering scammers and hackers now focusing on crypto firms.

Read the full article here

ShareTweetSharePinShareShareSend

Related News

SFC and Hong Kong Police Collaborate
Security

SFC and Hong Kong Police Collaborate

October 4, 2023
Are Data Leaks the New Norm or Is There Anything You Can Do to Reduce Your Risk?
Security

Are Data Leaks the New Norm or Is There Anything You Can Do to Reduce Your Risk?

October 4, 2023
Shiba Inu Community at Risk as SHIB Telegram Admin Account Gets Hacked
Security

Shiba Inu Community at Risk as SHIB Telegram Admin Account Gets Hacked

October 4, 2023
Study Finds Blackmail Leads in $20B Bitcoin Scams
Security

Study Finds Blackmail Leads in $20B Bitcoin Scams

October 4, 2023
Even More Celebrities Battle Deepfakes of Themselves
Security

Even More Celebrities Battle Deepfakes of Themselves

October 4, 2023
Five Held In Himachal Pradesh’s $25 Mln Crypto Scam
Security

Five Held In Himachal Pradesh’s $25 Mln Crypto Scam

October 3, 2023
Orbiter Finance Developers Allegedly Started Making Some Suspicious Fraudulent Transactions
Security

Orbiter Finance Developers Allegedly Started Making Some Suspicious Fraudulent Transactions

October 3, 2023
Hackers selling discounted tokens linked to CoinEx, Stake hacks
Security

Hackers selling discounted tokens linked to CoinEx, Stake hacks

October 3, 2023
Binance Aids Thai Police in Crackdown on Crypto-Related Criminal Networks
Security

Binance Aids Thai Police in Crackdown on Crypto-Related Criminal Networks

October 3, 2023

Discussion about this post

Latest News

Crypto Exchange Bybit Launches Derivatives Products in South Africa

Crypto Exchange Bybit Launches Derivatives Products in South Africa

October 4, 2023
SBF arrived 30 minutes late for the first day of the rest of his life

SBF arrived 30 minutes late for the first day of the rest of his life

October 4, 2023

Oligarchs are losing out as Putin courts a new class of loyal asset owners

October 4, 2023
Alameda sent $4.1B of FTT tokens to FTX before crash: Nansen report

Alameda sent $4.1B of FTT tokens to FTX before crash: Nansen report

October 4, 2023
Ripple’s Singapore Subsidiary Secures Full Payments License from MAS

Ripple’s Singapore Subsidiary Secures Full Payments License from MAS

October 4, 2023
ADVERTISEMENT

Popular

  • EUR/NOK has still room to fall in the days and weeks to come – Nordea

    EUR/NOK has still room to fall in the days and weeks to come – Nordea

    0 shares
    Share 0 Tweet 0
  • Oil: Upside is limited to $120 in the long run – Nordea

    0 shares
    Share 0 Tweet 0
  • Galaxy Digital Eyes European Expansion With New Regional CEO

    0 shares
    Share 0 Tweet 0
  • US CFTC orders 3 major US banks to pay over $50 million for swap reporting failures

    0 shares
    Share 0 Tweet 0
  • Valkyrie’s Ethereum Futures ETF Approved and Will Start Trading Tomorrow, According to FOX

    0 shares
    Share 0 Tweet 0
Block Journal

Block Journal is the world’s leading source in blockchain news and updates. Follow us to stay up-to-date with all you need to know in web3.

LEARN MORE »

Recent Posts

  • Crypto Exchange Bybit Launches Derivatives Products in South Africa
  • SBF arrived 30 minutes late for the first day of the rest of his life
  • SFC and Hong Kong Police Collaborate

Trending Topics

AI Altcoin Analysis Bitcoin Blockchain Commodities Crypto DeFi Ethereum Forex Futures GameFi ICO Interview Investing Legal Markets Metaverse News NFT Security Stocks Uncategorized Videos Web3

Get Informed

The most important crypto and finance news and events of the day

Be the first to know latest important news & events directly to your inbox.

By signing up, I agree to our TOS and Privacy Policy.

  • About
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Copyright © 2023 Block Journal - Created by Sawah Solutions.

No Result
View All Result
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine

Copyright © 2023 Block Journal - Created by Sawah Solutions.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.