CryptoMediaClub
Monday, October 13, 2025
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis
No Result
View All Result
CryptoMediaClub
No Result
View All Result
Home All news

Retool Attributes Breach That Affected Crypto Users with Google’s Authenticator

19.09.2023
A A
0
123
VIEWS
ShareShare

Retool, a prominent software development company, has recently revealed that 27 of its cloud customers fell prey to a targeted SMS-based phishing attack.

The breach has raised concerns about the security of cloud synchronization features, particularly Google Authenticator’s cloud sync.

Retool Falls Prey to Targeted SMS Phishing Attack

The Aug. 27 attack began with a deceptive SMS phishing campaign directed at Retool’s employees. The malicious individuals pretended to be IT team members and urged recipients to click on a seemingly legitimate link to address a payroll-related problem. One employee fell for this trick and ended up on a fake login page with a multi-factor authentication form where their login credentials were stolen.

Once they had acquired the employee’s login details, they went a step further by contacting the person directly. Using advanced deepfake technology, they convincingly imitated the voice of a member of the IT team and tricked the employee into disclosing the multi-factor authentication code.

The situation took a turn due to the employee’s use of Google Authenticator’s cloud synchronization feature, allowing the attackers to gain access to internal administrative systems. Subsequently, they gained control of the accounts belonging to 27 customers within the cryptocurrency industry.

One of the affected clients, Fortress Trust, suffered a substantial loss, with approximately $15 million worth of cryptocurrency stolen as a result of the breach.

US Government Issues Warning Over Deepfake Threat

The use of deepfake technology in this attack has prompted concern within the U.S. government. A recent advisory warned about the potential misuse of audio, video, and text deepfakes for malicious purposes, such as business email compromise (BEC) attacks and cryptocurrency scams.

Although the identity of the hackers remains undisclosed, the tactics employed resemble those of a financially motivated threat actor known as Scattered Spider, or UNC3944, known for its sophisticated phishing techniques.

Mandiant, a cybersecurity firm, shared insights into the attackers’ methods, stating they might have used access to victim environments to enhance their phishing campaigns. This involved creating new phishing domains with internal system names, as observed in some cases.

Kodesh stressed the importance of this incident, emphasizing the risk of syncing one-time codes to the cloud. This compromised the “something the user has” factor in multi-factor authentication. He suggested that users consider using FIDO2-compliant hardware security keys or passkeys to strengthen security against phishing attacks.

SPECIAL OFFER (Sponsored) Binance Free $100 (Exclusive): Use this link to register and receive $100 free and 10% off fees on Binance Futures first month (terms).
PrimeXBT Special Offer: Use this link to register & enter CRYPTOPOTATO50 code to receive up to $7,000 on your deposits.

Share9Tweet6ShareSharePin2

Related Posts

South Koreans Poured $1.24B Into US Tech, Crypto During the Korean Thanksgiving
All news

South Koreans Poured $1.24B Into US Tech, Crypto During the Korean Thanksgiving

13.10.2025
0

South Korean investors turned their Chuseok holiday into a week of aggressive risk-taking, funneling $1.24 billion into US tech and...

Read moreDetails
Hyperliquid Goes Permissionless with HIP-3 Challenging CEX — But Entry Costs 500,000 HYPE

Hyperliquid Goes Permissionless with HIP-3 Challenging CEX — But Entry Costs 500,000 HYPE

13.10.2025
Strategy Boosts Bitcoin Holdings to 640,250 BTC After $27.2M Purchase

Strategy Boosts Bitcoin Holdings to 640,250 BTC After $27.2M Purchase

13.10.2025
Why Is Crypto Up Today? – October 13, 2025

Why Is Crypto Up Today? – October 13, 2025

13.10.2025
Fast Food Chain Steak ‘n Shake Halts Ether Payment Plan After Bitcoin Fans Push Back

Fast Food Chain Steak ‘n Shake Halts Ether Payment Plan After Bitcoin Fans Push Back

13.10.2025
Load More
Next Post
BTC price hits $27.4K as Bitcoin open interest matches Grayscale peak

BTC price hits $27.4K as Bitcoin open interest matches Grayscale peak

0 0 votes
Рейтинг статьи
Subscribe
Notify of
guest
guest
0 комментариев
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recommended

SEC Vs. Coinbase Case Sets Precedent for DeFi Solution Providers

SEC Vs. Coinbase Case Sets Precedent for DeFi Solution Providers

2 years ago
Metaplanet to Raise $11.3M Through Bonds to Fund Bitcoin Acquisition

Metaplanet to Raise $11.3M Through Bonds to Fund Bitcoin Acquisition

11 months ago
Axelar Launches ‘Open Web3 Design Space’ with Sui, XRP, EigenLayer, OpenZeppelin

Axelar Launches ‘Open Web3 Design Space’ with Sui, XRP, EigenLayer, OpenZeppelin

1 year ago
Can Frogwifhat Meme Coin Catch Dogwifhat? New Crypto Fair Launch Pumps on Uniswap, Rumours of Big Influencer Backing

Can Frogwifhat Meme Coin Catch Dogwifhat? New Crypto Fair Launch Pumps on Uniswap, Rumours of Big Influencer Backing

2 years ago

Categories

  • All news
  • Altcoins
  • Analysis
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
No Result
View All Result

Highlights

Why Is Crypto Up Today? – October 13, 2025

Fast Food Chain Steak ‘n Shake Halts Ether Payment Plan After Bitcoin Fans Push Back

Bitcoin Mining Firm MARA Holdings Adds 400 Bitcoin Worth $46.31M: On-Chain Data

FedMining Releases Free Cloud Mining Tool, Allowing Crypto Enthusiasts To Mine Anytime, Anywhere

India Probes 400 Binance Traders for Alleged Crypto Tax Evasion: Report

Russia’s Central Bank: Tokenization Will Let Foreigners Buy Domestic Shares

Trending

South Koreans Poured $1.24B Into US Tech, Crypto During the Korean Thanksgiving
All news

South Koreans Poured $1.24B Into US Tech, Crypto During the Korean Thanksgiving

13.10.2025
0

South Korean investors turned their Chuseok holiday into a week of aggressive risk-taking, funneling $1.24 billion into...

Hyperliquid Goes Permissionless with HIP-3 Challenging CEX — But Entry Costs 500,000 HYPE

Hyperliquid Goes Permissionless with HIP-3 Challenging CEX — But Entry Costs 500,000 HYPE

13.10.2025
Strategy Boosts Bitcoin Holdings to 640,250 BTC After $27.2M Purchase

Strategy Boosts Bitcoin Holdings to 640,250 BTC After $27.2M Purchase

13.10.2025
Why Is Crypto Up Today? – October 13, 2025

Why Is Crypto Up Today? – October 13, 2025

13.10.2025
Fast Food Chain Steak ‘n Shake Halts Ether Payment Plan After Bitcoin Fans Push Back

Fast Food Chain Steak ‘n Shake Halts Ether Payment Plan After Bitcoin Fans Push Back

13.10.2025
  • All news
  • Altcoins
  • Bitcoin
  • Blockchain
  • Ethereum
  • NFT
  • Analysis
Editor: cryptomediaclub.com@gmail.com
Advertising: digestmediaholding@gmail.com

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

No Result
View All Result
  • All news
  • Bitcoin
  • Ethereum
  • Altcoins
  • NFT
  • Blockchain
  • Analysis

Disclaimer: Information found on CryptoMediaClub is those of writers quoted. It does not represent the opinions of CryptoMediaClub on whether to sell, buy or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk.
CryptoMediaClub covers fintech, blockchain and Bitcoin bringing you the latest crypto news and analyses on the future of money.

© 2023 Crypto News. All Rights Reserved

wpDiscuz