Skip to content
  • Sunday, May 25, 2025
Get E-Cube

Get E-Cube

Proceed with Tech

  • Development
  • Gadget
  • Internet Marketing
  • SEO
  • Social Media
  • Technology
  • About Us
    • Contact Us
    • Advertise Here
    • Privacy Policy
    • Sitemap
  • Home
  • Defending In opposition to Company Social Media Account Takeovers
Social Media

Defending In opposition to Company Social Media Account Takeovers

February 3, 2024
Karla Madsen

Fraud Administration & Cybercrime
,
Social Media

Not a Fantastic Seem: Hijacked @SECgov Social Media Account Spews Bitcoin Rumors

Mathew J. Schwartz
(euroinfosec)

•
January 31, 2024    

Defending In opposition to Company Social Media Account Takeovers
Do not be taken by shock, as Mandiant and the U.S. Securities and Exchange Commission not too long ago were being. (Picture: Shutterstock)

Social media accounts – in particular those people tied to government businesses, huge-title providers and substantial-profile men and women – go on to be a top concentrate on for takeover by fraudsters and scammers, specially when it arrives to X, previously recognized as Twitter. What is the ideal way to continue to keep these accounts protected?

See Also: OnDemand Panel | Securing Operational Excellence: Thwarting CISOs 5 Major Safety Fears

&#13
&#13

Stability professional Rachel Tobac explained to me her assistance remains unchanged: Use multifactor authentication any time readily available, as properly as in shape-for-goal password management applications.

&#13
&#13

“I advocate my consumers use a team password manager and team password supervisor MFA instrument,” said Tobac, who is CEO of SocialProof Safety and chair of Women of all ages in Security and Privateness.

&#13
&#13

The query of how to secure company social media accounts has been given renewed emphasis pursuing two latest account takeovers. On Jan. 3, a write-up to the formal X account for Google Cloud’s Mandiant incident response group shared a url to a cryptocurrency drainer web page. On Jan. 9, a put up to the U.S. Securities and Trade Commission’s official @SECgov account on X broadcast fake cryptocurrency information, triggering a non permanent surge in the value of bitcoin.

&#13
&#13

Neither Mandiant nor the SEC had been defending their accounts making use of X’s MFA supplying, which they ascribed in part to usability complications. Devoid of it, Mandiant reported, somebody had been in a position to just brute-pressure guess the account password. “Typically, 2FA would have mitigated this, but owing to some group transitions and a adjust in X’s 2FA coverage, we have been not sufficiently shielded,” Mandiant stated.

&#13
&#13

That’s a reference to X CEO Elon Musk in February 2023 asserting that working with SMS-centered MFA would be deactivated for all nonpremium accounts. Whilst that strategy isn’t as protected as utilizing an authenticator application or components crucial, stability authorities at the time – and considering the fact that – have decried the shift, stating even SMS-based mostly MFA is much better than none at all.

&#13
&#13

The SEC blamed its account takeover on a SIM swapping assault. By spoofing a cell phone selection registered to the account on X, an attacker was capable to induce a password reset. The attacker then established the password to a person of their picking, which allowed them to acquire regulate.

&#13
&#13

Yet again, MFA would have prevented such an assault, except the SEC claimed employees final yr asked for that MFA for its official X account be disabled “because of to issues accessing the account.” That also seems like fallout from X’s change connected to MFA via SMS.

&#13
&#13

In an update, the agency documented previous 7 days that MFA “at present is enabled for all SEC social media accounts that offer it.”

&#13
&#13

Use a Social Media Management System?

&#13
&#13

Somewhat than relying exclusively on whatever is staying supplied by personal social media platforms, or obtaining to log into just about every a person every time they want to publish, quite a few companies also use social media administration platforms, these types of as Hootsuite, Sprout Social or one of the quite a few other selections. These facilitate less complicated scheduling, cross-posting and delegating entry throughout numerous personnel.

&#13
&#13

Tobac stated of the organizations she advises: “If they select to use Hootsuite and Sprout Social, I endorse they retailer their passwords in a team password supervisor and use group MFA by means of the password manager so they can all safely entry, as desired.”

&#13
&#13

Tobac also suggested not tying a telephone range to an X account – to block the use of SIM swapping assaults to aid account takeovers. “Do not tie your telephone amount to accounts of worth,” she claimed in an “account takeover avoidance information,” pursuing the @SECgov slipping sufferer. “Over time, our cellular phone numbers have turn into much more and far more crucial to our digital lives. This genuinely shouldn’t have happened at all but that’s how the dominoes fell as the internet and authentication changed promptly in the 2000s.”

&#13
&#13

The SEC has been criticized for not employing MFA, which is each a simple protection defense and one that it requires of the publicly traded businesses it regulates. Although the takeover of its X account was not a fantastic look, the social community alone is also partly to blame many thanks to Musk’s weak “no cost-free MFA by way of SMS for the masses” transfer.

&#13
&#13

“All multifactor authentication must be free, obtainable and straightforward to use,” Tobac explained. “Twitter putting SMS 2FA at the rear of a paywall is not supporting their users’ protection greatest techniques.”

Tags: Account, Company, Defending, Media, opposition, Social, Takeovers

Post navigation

When an Search engine optimization Will have to Go Past Best Tactics
How Canada Can Rebuild Have faith in and Accelerate Entry to Cash for All Business people

Archives

Categories

You may Missed

SEO

9 Advanced Enterprise SEO Strategies for 2024

June 24, 2024
Karla Madsen
SEO

Are SEO Myths Finally Busted by Google Leak?

June 19, 2024
Karla Madsen
SEO

A Paradigm Shift in Digital Marketing Strategy

June 17, 2024
Karla Madsen
SEO

Beware of anti-SEO studies that misguide your marketing strategy

June 15, 2024
Karla Madsen
Copyright © 2025 Get E-Cube
Theme by: Theme Horse
Proudly Powered by: WordPress
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT