SEC's X Account Compromised Via Phone Number and Lack of Two-Factor Authentication

January 10, 2024

Oh, and speaking of a bit of hypocrisy and a whole lot of mismanagement, let's not forget this:

SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies (SEC Release / July 26, 2023)
https://www.sec.gov/news/press-release/2023-139

The Securities and Exchange Commission today adopted rules requiring registrants to disclose material cybersecurity incidents they experience and to disclose on an annual basis material information regarding their cybersecurity risk management, strategy, and governance. The Commission also adopted rules requiring foreign private issuers to make comparable disclosures.

“Whether a company loses a factory in a fire — or millions of files in a cybersecurity incident — it may be material to investors,” said SEC Chair Gary Gensler. “Currently, many public companies provide cybersecurity disclosure to investors. I think companies and investors alike, however, would benefit if this disclosure were made in a more consistent, comparable, and decision-useful way. Through helping to ensure that companies disclose material cybersecurity information, today’s rules will benefit investors, companies, and the markets connecting them.”

The new rules will require registrants to disclose on the new Item 1.05 of Form 8-K any cybersecurity incident they determine to be material and to describe the material aspects of the incident's nature, scope, and timing, as well as its material impact or reasonably likely material impact on the registrant. An Item 1.05 Form 8-K will generally be due four business days after a registrant determines that a cybersecurity incident is material. The disclosure may be delayed if the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the Commission of such determination in writing. . . . 

But even more disturbing is the SEC's lack of TIMELY and PUBLIC disclosure of the hacking that should have been promptly posted as both an SEC Press Release and as a Statement from Chair Gensler -- so much for the federal regulator's advocacy for "cybersecurity disclosure to investors." Note the two screenshots from sec.gov that were taken on January 10, 2024, at 11:06 am ET:



As I have often noted, the modern-day regulation of Wall Street is less about substance and more about the "marketing" of regulation. Once, regulation was about regulation; but today, it's about likes and posts and thumbs up and smiley faces. How nice that as its X Account is hacked, the SEC still found time to launch an Instagram  account https://www.sec.gov/sec-instagram.

Bill Singer Submits Online "Indication of Interest" to FINRA for Appointment to Board of Governors

SEC's X Account Compromised Via Phone Number And Lack Of Two-Factor Authentication (BrokeAndBroker.com Blog)

After a 26-Year Regulatory Nap, FINRA Discovers Firm's WSPs Are Inadequate (BrokeAndBroker.com Blog)

FINRA Bars Its Arbitration Forum To TDA Customer Citing Unspecified Risks Of Health And Safety (BrokeAndBroker.com Blog)

Former Merrill Lynch Rep Stuck In FINRA Arbitration Expungement Turnstile (BrokeAndBroker.com Blog)

US DEPARTMENT OF LABOR ANNOUNCES FINAL RULE ON CLASSIFYING WORKERS AS EMPLOYEES OR INDEPENDENT CONTRACTORS UNDER THE FAIR LABOR STANDARDS ACT /
Rescinds 2021 independent contractor rule; replaces it with analysis consistent with caselaw (DOL Press Release)

Prometheum Receives First of Its Kind Approval From FINRA to Clear and Settle Digital Asset Securities / Prometheum’s digital asset securities custody platform is launching in Q1 2024 (BusinessWire)

Financial Professionals Coalition, Ltd. JOIN TODAY -- FREE MEMBERSHIP

DOJ

Former Employee Of Two Leading Global Financial Institutions And His Associate Plead Guilty To Insider Trading (DOJ Release)

Five Individuals Indicted for Long-Running Pump-and-Dump Schemes / Defendants allegedly generated at least tens of millions in illicit proceeds using a sophisticated nominee entity platform based in Vancouver, Canada (DOJ Release)

Moreno Valley Man Pleads Guilty to Running Ponzi Scheme That Took in More Than $24 Million from Hundreds of Victim Investors (DOJ Release)

Foreign National Sentenced for Conspiring to Launder Proceeds of Internet Fraud Schemes (DOJ Release)

Serial Fraudster Sentenced for Role in Multiple Investment Fraud Schemes (DOJ Release)

Srinivasa Kakkera was Sentenced to 18 Months in Prison, and Abbas Saeedi was Sentenced to 5 Months in Prison, for Trading on Material, Non-public Information About Impending Corporate Transactions by Lumentum (SEC Release)

Founder And Former CEO Of Tingo Companies Charged With Securities Fraud (DOJ Release)

SEC

SEC Charges Future FinTech CEO Shanchun Huang With Fraud and Disclosure Failures (SEC Release)

SEC Approves Whistleblower Award to Claimant 
Order Determining Whistleblower Award Claim

SEC Awards $1.5 Million to Whistleblower Claimant 
Order Determining Whistleblower Award Claim

Self-Regulatory Organizations; NYSE Arca, Inc.; The Nasdaq Stock Market LLC; Cboe BZX Exchange, Inc.; Order Granting Accelerated Approval of Proposed Rule Changes, as Modified by Amendments Thereto, to List and Trade Bitcoin-Based Commodity-Based Trust Shares and Trust Units
-and-
SEC Chair and Commissioners Statements of Bitcoin Order

SEC Charges Global Software Company SAP for FCPA Violations / German multinational agrees to monetary sanctions of nearly $100 million to settle SEC's bribery charges (SEC Release)

X says that SEC's account was compromised via phone number and lack of two-factor authentication

SEC Revokes Transfer Agent Registration
In the Matter of THE EDWARD WALKER BENIFIELD TRUST (SEC Opinion)

SEC Charges Florida Real Estate Developer Rishi Kapoor with Perpetuating $93 Million Fraud Scheme and Obtains Emergency Relief (SEC Release)

SEC Obtains Judgment Against Individual for Participating in Fraudulent Microcap Scheme (SEC Release)

SEC Obtains Final Judgment Against California Man for Insider Trading (SEC Release)

Mark Uyeda Sworn in for Second Term as SEC Commissioner (SEC Release)

CFTC

FINRA

Investor Alert: Social Media ‘Investment Group’ Imposter Scams on the Rise (FINRA Investor Alert)

STOP THE PRESSES!!! FINRA Issues 2024 Regulatory Oversight Report!!!!

FINRA Fines and Suspends Five Reps for Not Disclosing That Another Person Took Their Insurance Continuing Education

FINRA Fines and Suspends Rep for Associating with Sequoia Investments While Statutorily Disqualified
In the Matter of David A. Elgart, Respondent (FINRA AWC)

FINRA Fines and Suspends Rep for Inaccurate Rep Code
In the Matter of Jimmy J. Galindo Respondent (FINRA AWC)