01.11.2024

House Committee Demands SEC Briefing on Hacked X Account

01.11.2024
House Committee Demands SEC Briefing on Hacked X Account

The Chairman of the House Financial Services Committee, Patrick McHenry (NC-10), the Chairman of the Subcommittee on Oversight and Investigations, Bill Huizenga (MI-04), the Chairman of the Subcommittee on Digital Assets, Financial Technology and Inclusion, French Hill (AR-02), and the Chairman of the Subcommittee on Capital Markets, Ann Wagner (MO-02), sent a letter to Securities and Exchange Commission (SEC) Chair Gary Gensler. The lawmakers are demanding a briefing on the SEC’s compromised X account, which led to a false tweet announcing the approval of Bitcoin ETFs on January 9.

Read the full letter to SEC Chair Gensler here or below:

“Dear Chair Gensler:

“The U.S. Securities and Exchange Commission’s (SEC) ability to fulfill its mission—to protect investors, maintain fair, orderly, and efficient markets, and facilitate capital formation—is directly tied to the Commission’s ability to communicate with market participants. Yesterday, a tweet was posted on the SEC X account stating that the SEC granted the approval of Bitcoin ETFs to be listed on all registered national securities exchanges.  As a result, Bitcoin’s value quickly rose, until you clarified that the SEC account was “compromised.”  During those fifteen minutes, the time between the compromised tweet and your announcement of the “hack,” the price of Bitcoin increased to nearly $48,000.

“According to X’s preliminary investigation, the SEC account did not have two-factor authentication enabled and an unidentified individual obtained control of a phone number associated with the SEC’s account.  This failure is unacceptable, and it is disturbing that your agency could not even meet the standard you require of private industry.

“Last year, the SEC adopted a cybersecurity risk management rule requiring companies to disclose within four business days if a “material” cybersecurity incident occurs.  The disclosure must include a description of the nature, scope, and timing of the incident.  Given yesterday’s tweet, we expect the SEC to hold itself to the same requirements that are imposed on companies throughout the country. All market participants deserve transparency from you and your agency.

“The Committee has jurisdiction to oversee the activities of the SEC pursuant to Rule X of the Rules of the House of Representatives. To better understand how this breach occurred and how the SEC will ensure it cannot happen again, please provide a briefing to Committee staff no later than January 17, 2024. Thank you for your attention to this important matter.”

Source: House Financial Services Committee

Related articles

  1. SEC Targets Cyber Security

    Third-party risk was the headline culprit in 2023.

  2. Cybersecurity Still a Work in Progress

    Regulators have proposed new rules for operational resilience and cyber security.

  3. Regulators Target Cybercrime

    An unauthorized party took control of an SEC cell phone number in an apparent “SIM swap” attack.

  4. Financial Institutions Vulnerable to Cyber Attacks

    Staff are coordinating with appropriate law enforcement and federal oversight entities.

  5. Regulators Target Cybercrime

    Senator says Congress needs answers on 'colossal market-moving mistake.'