Case file · RETOOL 2023

How the Retool breach happened: a deepfaked IT call and one synced code

Published 2026-09-29 · 4 min read · Missing control: Phishing-resistant MFA like hardware keys

In August 2023, one text message and one phone call gave an attacker the keys to Retool, a software company used by some of the biggest names in tech, and 27 of its cloud customers had their accounts taken over within days.[1][2] This case file covers how a fake IT call turned a single login code into all of them, what the attack cost, and the control that would have made the call useless.

What happened

Retool makes a platform companies use to build internal business tools. In summer 2023 it had announced that employee logins were moving to Okta, a common sign-in service.[1][4] On August 27, 2023, several employees received text messages that appeared to come from the IT team, saying there was a problem with their payroll or benefits enrollment and giving a link to fix it.[1][4] The link led to a fake login page dressed up to look like the company's new sign-in portal.[1]

Almost everyone ignored the text. One employee did not, and entered a username and password on the fake page.[1][4] Then the phone rang. The caller claimed to be from IT, used a voice that sounded like a real member of the IT team, and knew enough about the office layout, coworkers and internal processes to sound convincing.[1][3][5] The employee grew suspicious during the call but still read out one more multi-factor code.[1]

That one code was enough. The attacker used it to add their own device to the employee's Okta account, and from there reached the employee's Google account, Retool's VPN and its internal admin systems.[1][3] On August 29, Retool notified 27 cloud customers, all in the cryptocurrency industry, that someone had gotten into their accounts.[1][2]

How they got in

Multi-factor authentication, or MFA, means a login needs something beyond a password, often a 6-digit code from an app that changes every 30 seconds. The idea is that a stolen password alone is not enough. Here, the attacker did not steal the code. They asked for it, twice: once on the fake page and once on the phone.[1][4]

The bigger problem came next. In April 2023, Google Authenticator, a widely used code app, added a feature that backs up and syncs its codes to the user's Google account.[1][4] Retool's employee had those codes synced. So once the attacker controlled the Okta account, they could get into the Google account, and once in the Google account, they could see every code that app held.[1][2] Retool's engineering head called this a single point of failure: one account now held what was supposed to be several separate locks.[1]

With the VPN and admin tools open, the attacker went after a narrow target. They changed email addresses and reset passwords on the accounts of the 27 crypto customers, which let them take control of those accounts.[1][2]

What it cost

Retool said no customers running its software on their own servers were touched, only cloud customers, and that it revoked all internal sessions, locked the affected accounts and restored their original logins.[1]

At least one downstream loss followed. Fortress Trust, a crypto custody firm whose customers used a portal built on Retool, disclosed in September 2023 that customer funds had been taken, and the losses were reported at about $15 million.[3][6] Ripple, which had agreed to acquire Fortress, said it would cover the losses.[6]

Retool publicly blamed the Google sync feature for making the breach far worse.[1][2] Google responded that syncing codes is optional and encouraged businesses to move away from one-time codes toward phishing-resistant options such as passkeys and security keys.[2][3][4] No arrests have been announced.

The missing control

The missing control: phishing-resistant MFA, such as hardware security keys or passkeys, instead of codes a person can read out loud.

A hardware key is a small device that plugs into a laptop or taps a phone. It checks the real web address of the site asking for the login before it answers, so a fake page gets nothing, and there is no code for an employee to type into a lookalike site or recite to a friendly voice on the phone.[2] In the Retool attack, both handoffs of a code would have failed. The fake portal could not have collected a usable second factor, and the caller would have had nothing to ask for. Keeping those keys off a synced cloud account also removes the single point of failure that turned one stolen login into every login.[1]

Training helped here: nearly every employee ignored the text.[4] But training has to work every time, for every person. The attacker only needed one.

What to do in your business

Watch the case
A Deepfaked Voice and a Synced Code: The Retool BreachDrops 2026-10-22
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More identity and access cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Retool: When MFA isn't actually MFA
  2. BleepingComputer: Retool blames breach on Google Authenticator MFA cloud sync feature
  3. Help Net Security: Attackers hit software firm Retool to get to crypto companies and assets
  4. The Cyber Express: Retool data breach linked to Google Authenticator sync
  5. IT World Canada: Cyber Security Today, Sept. 18, 2023 - How a deepfake voice caused a company to be hacked
  6. Web3 is Going Great: Fortress Trust breach