Block Journal
No Result
View All Result
  • Login
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianopt Portuguêsru Русскийes Españolth ไทยzh-CN 简体中文hi हिन्दीja 日本語
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine
Magazine
Newsletter
  • Trending Now
  • Bitcoin
  • Altcoin
  • Ethereum
  • Analysis
  • Blockchain
  • Metaverse
  • NFT
  • DeFi
  • Web3
  • GameFi
  • ICO
  • Legal
  • Security
Block Journal
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine
en English
nl Nederlandsen Englishfr Françaisde Deutschit Italianopt Portuguêsru Русскийes Españolth ไทยzh-CN 简体中文hi हिन्दीja 日本語
No Result
View All Result
Block Journal
No Result
View All Result
  • News
  • Crypto
  • Markets
  • Investing
  • Videos
  • Charts
Home News

Retool Attributes Breach That Affected Crypto Users with Google’s Authenticator

News Room by News Room
September 18, 2023
in News
Reading Time: 2 mins read
0 0
A A
0

Retool, a prominent software development company, has recently revealed that 27 of its cloud customers fell prey to a targeted SMS-based phishing attack.

The breach has raised concerns about the security of cloud synchronization features, particularly Google Authenticator’s cloud sync.

Retool Falls Prey to Targeted SMS Phishing Attack

The Aug. 27 attack began with a deceptive SMS phishing campaign directed at Retool’s employees. The malicious individuals pretended to be IT team members and urged recipients to click on a seemingly legitimate link to address a payroll-related problem. One employee fell for this trick and ended up on a fake login page with a multi-factor authentication form where their login credentials were stolen.

Once they had acquired the employee’s login details, they went a step further by contacting the person directly. Using advanced deepfake technology, they convincingly imitated the voice of a member of the IT team and tricked the employee into disclosing the multi-factor authentication code.

The situation took a turn due to the employee’s use of Google Authenticator’s cloud synchronization feature, allowing the attackers to gain access to internal administrative systems. Subsequently, they gained control of the accounts belonging to 27 customers within the cryptocurrency industry.

One of the affected clients, Fortress Trust, suffered a substantial loss, with approximately $15 million worth of cryptocurrency stolen as a result of the breach.

US Government Issues Warning Over Deepfake Threat

The use of deepfake technology in this attack has prompted concern within the U.S. government. A recent advisory warned about the potential misuse of audio, video, and text deepfakes for malicious purposes, such as business email compromise (BEC) attacks and cryptocurrency scams.

Although the identity of the hackers remains undisclosed, the tactics employed resemble those of a financially motivated threat actor known as Scattered Spider, or UNC3944, known for its sophisticated phishing techniques.

Mandiant, a cybersecurity firm, shared insights into the attackers’ methods, stating they might have used access to victim environments to enhance their phishing campaigns. This involved creating new phishing domains with internal system names, as observed in some cases.

Kodesh stressed the importance of this incident, emphasizing the risk of syncing one-time codes to the cloud. This compromised the “something the user has” factor in multi-factor authentication. He suggested that users consider using FIDO2-compliant hardware security keys or passkeys to strengthen security against phishing attacks.

Read the full article here

ShareTweetSharePinShareShareSend

Related News

Google Cloud Expands BigQuery with 11 New Blockchains, Including Ethereum’s Görli Testnet
News

Google Cloud Expands BigQuery with 11 New Blockchains, Including Ethereum’s Görli Testnet

September 25, 2023
News

Hollywood writers reach tentative deal with studios

September 25, 2023
HK regulator vows to intensify crackdown on unregistered crypto platforms
News

HK regulator vows to intensify crackdown on unregistered crypto platforms

September 25, 2023
News

Brussels trade chief says China-EU ties ‘at a crossroads’

September 25, 2023
JPEX scandal masterminds still at large as 11 suspects taken into custody: Report
News

JPEX scandal masterminds still at large as 11 suspects taken into custody: Report

September 25, 2023
News

Push by Bangladesh PM’s daughter for WHO role raises transparency concerns

September 25, 2023
Crypto exchange Upbit stems fake APT token flood, resumes services
News

Crypto exchange Upbit stems fake APT token flood, resumes services

September 25, 2023
News

Senior Nomura banker barred from leaving mainland China

September 25, 2023
News

AI poses ‘bracing test’ to multilateral system, says UK deputy prime minister

September 25, 2023

Discussion about this post

Latest News

EUR/GBP records modest gains amidst low liquidity conditions on Good Friday

EUR/GBP trades higher near 0.8700 to extend gains, focus on ECB Lagarde’s speech

September 25, 2023
Crude oil lower on global demand worries; API inventories due

US grid-scale energy storage installations hit new quarterly record – report

September 25, 2023
Roblox says ~5% of cash held with SVB ; No impact on operations

Brookfield cancels share conversion due to insufficient tenders

September 25, 2023
Bitcoin Price Grinds Lower And Seems Like Bears Are Not Done Yet

Bitcoin Price Grinds Lower And Seems Like Bears Are Not Done Yet

September 25, 2023
Ex-Ethereum Advisor Applauds XRP Community Amid ETH Gate News

Ex-Ethereum Advisor Applauds XRP Community Amid ETH Gate News

September 25, 2023
ADVERTISEMENT

Popular

  • Fed’s Williams: Expects inflation to decline to around 3.25% this year

    Fed Preview: Forecasts from 15 major banks, a pause, but the end of rate hikes?

    0 shares
    Share 0 Tweet 0
  • Former Alameda Engineer Exposes Firm’s Role in Bitcoin’s 87% Plunge in 2021

    0 shares
    Share 0 Tweet 0
  • Wall Street Memes Presale Enters Final Week After Raising Over $25 Million

    0 shares
    Share 0 Tweet 0
  • Vitalik Buterin Moves More Ethereum, ETH Price Drops Below $1600

    0 shares
    Share 0 Tweet 0
  • Nansen Warns Of Potential Phishing Attacks Following Vendor Security Incident Exposing Customer Data

    0 shares
    Share 0 Tweet 0
Block Journal

Block Journal is the world’s leading source in blockchain news and updates. Follow us to stay up-to-date with all you need to know in web3.

LEARN MORE »

Recent Posts

  • Google Cloud Expands BigQuery with 11 New Blockchains, Including Ethereum’s Görli Testnet
  • EUR/GBP trades higher near 0.8700 to extend gains, focus on ECB Lagarde’s speech
  • US grid-scale energy storage installations hit new quarterly record – report

Trending Topics

AI Altcoin Analysis Bitcoin Blockchain Commodities Crypto DeFi Ethereum Forex Futures GameFi ICO Interview Investing Legal Markets Metaverse News NFT Security Stocks Uncategorized Videos Web3

Get Informed

The most important crypto and finance news and events of the day

Be the first to know latest important news & events directly to your inbox.

By signing up, I agree to our TOS and Privacy Policy.

  • About
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Copyright © 2023 Block Journal - Created by Sawah Solutions.

No Result
View All Result
  • Home
  • News
  • Crypto
  • Markets
  • Investing
  • Glossary
  • Videos
  • Charts
    • Crypto
    • Forex
    • Stocks
    • Commodities
  • Magazine

Copyright © 2023 Block Journal - Created by Sawah Solutions.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.