18 September 2023

DevOps firm Retool hit with SMS-based phishing attack


DevOps firm Retool hit with SMS-based phishing attack

Software development company Retool disclosed it suffered a security incident involving an SMS-based phishing attack that affected the cloud accounts of some of its customers.

The company said the breach took place on August 29, 2023, with the attacker tricking one of its employees into clicking on a phishing link sent in a text message.

“Several employees received targeted texts, claiming that a member of IT was reaching out about an account issue that would prevent open enrollment (which affects the employee’s healthcare coverage). The timing coincided with a recently announced migration of logins to Okta, and the message contained a url disguised to look like our internal identity portal. Almost all employees didn’t engage, but unfortunately one employee logged into the link provided by the attackers,” the company explained.

The employee has activated Google Authenticator's cloud sync feature which allowed the threat actor to gain elevated access to the company’s internal admin systems and commandeer the accounts belonging to 27 customers in the crypto industry. As per media reports, one of the victims, financial infrastructure company Fortress Trust, lost $15 million worth of customers’ cryptocurrency due to the Retool incident.

“The fact that Google Authenticator syncs to the cloud is a novel attack vector. What we had originally implemented was multi-factor authentication. But through this Google update, what was previously multi-factor-authentication had silently (to administrators) become single-factor-authentication, because control of the Okta account led to control of the Google account, which led to control of all OTPs stored in Google Authenticator,” Retool noted in a blog post.

In related news, another DevOps company, Rollbar, informed customers of a data breach impacting its data warehouse. The attackers initially tried to launch compute resources but then that failed started nosing around for Bitcoin wallets or other cloud credentials and data.

 

Back to the list

Latest Posts

North Korea’s Lazarus adds new LightlessCan backdoor to its arsenal

North Korea’s Lazarus adds new LightlessCan backdoor to its arsenal

The hackers posed as a recruiter from Meta to gain access to the network of an aerospace firm.
2 October 2023
Critical Exim flaws put millions of servers at risk of hacker attacks

Critical Exim flaws put millions of servers at risk of hacker attacks

The vulnerabilities could allow attackers to breach the servers and gain access to sensitive data.
2 October 2023
Cyber Security Week in Review: September 29, 2023

Cyber Security Week in Review: September 29, 2023

The world in brief: the MOVEit protocol maker releases fixes for new critical bugs, Cisco warns of a zero-day in IOS and IOS XE software, and more.
29 September 2023