How the Retool breach happened: a deepfaked IT call and one synced code
In August 2023, one text message and one phone call gave an attacker the keys to Retool, a software company used by some of the biggest names in tech, and 27 of its cloud customers had their accounts taken over within days.[1][2] This case file covers how a fake IT call turned a single login code into all of them, what the attack cost, and the control that would have made the call useless.
What happened
Retool makes a platform companies use to build internal business tools. In summer 2023 it had announced that employee logins were moving to Okta, a common sign-in service.[1][4] On August 27, 2023, several employees received text messages that appeared to come from the IT team, saying there was a problem with their payroll or benefits enrollment and giving a link to fix it.[1][4] The link led to a fake login page dressed up to look like the company's new sign-in portal.[1]
Almost everyone ignored the text. One employee did not, and entered a username and password on the fake page.[1][4] Then the phone rang. The caller claimed to be from IT, used a voice that sounded like a real member of the IT team, and knew enough about the office layout, coworkers and internal processes to sound convincing.[1][3][5] The employee grew suspicious during the call but still read out one more multi-factor code.[1]
That one code was enough. The attacker used it to add their own device to the employee's Okta account, and from there reached the employee's Google account, Retool's VPN and its internal admin systems.[1][3] On August 29, Retool notified 27 cloud customers, all in the cryptocurrency industry, that someone had gotten into their accounts.[1][2]
How they got in
Multi-factor authentication, or MFA, means a login needs something beyond a password, often a 6-digit code from an app that changes every 30 seconds. The idea is that a stolen password alone is not enough. Here, the attacker did not steal the code. They asked for it, twice: once on the fake page and once on the phone.[1][4]
The bigger problem came next. In April 2023, Google Authenticator, a widely used code app, added a feature that backs up and syncs its codes to the user's Google account.[1][4] Retool's employee had those codes synced. So once the attacker controlled the Okta account, they could get into the Google account, and once in the Google account, they could see every code that app held.[1][2] Retool's engineering head called this a single point of failure: one account now held what was supposed to be several separate locks.[1]
With the VPN and admin tools open, the attacker went after a narrow target. They changed email addresses and reset passwords on the accounts of the 27 crypto customers, which let them take control of those accounts.[1][2]
What it cost
Retool said no customers running its software on their own servers were touched, only cloud customers, and that it revoked all internal sessions, locked the affected accounts and restored their original logins.[1]
At least one downstream loss followed. Fortress Trust, a crypto custody firm whose customers used a portal built on Retool, disclosed in September 2023 that customer funds had been taken, and the losses were reported at about $15 million.[3][6] Ripple, which had agreed to acquire Fortress, said it would cover the losses.[6]
Retool publicly blamed the Google sync feature for making the breach far worse.[1][2] Google responded that syncing codes is optional and encouraged businesses to move away from one-time codes toward phishing-resistant options such as passkeys and security keys.[2][3][4] No arrests have been announced.
The missing control
The missing control: phishing-resistant MFA, such as hardware security keys or passkeys, instead of codes a person can read out loud.
A hardware key is a small device that plugs into a laptop or taps a phone. It checks the real web address of the site asking for the login before it answers, so a fake page gets nothing, and there is no code for an employee to type into a lookalike site or recite to a friendly voice on the phone.[2] In the Retool attack, both handoffs of a code would have failed. The fake portal could not have collected a usable second factor, and the caller would have had nothing to ask for. Keeping those keys off a synced cloud account also removes the single point of failure that turned one stolen login into every login.[1]
Training helped here: nearly every employee ignored the text.[4] But training has to work every time, for every person. The attacker only needed one.
What to do in your business
- Start with your email and admin accounts. Turn on security keys or passkeys for email, your domain registrar, payroll and any admin console first. Give each person a spare key so a lost one does not lock them out.
- Set a phone rule and repeat it. Write it down: nobody from IT, the bank or a vendor will ever ask you for a login code. Anyone who does is the attacker, even if the voice sounds right.
- Check where your codes live. If staff use an authenticator app, know whether it syncs codes to a personal or work cloud account, and make sure that account is protected with a key, not just a password.
- Treat IT change announcements as bait. When you move to a new login system, tell staff exactly how and from whom they will hear about it, and that no one will text them a link.
- Know your vendors' blast radius. List the outside tools that can touch your money or customer data, and ask each how they protect their own staff logins.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- Retool: When MFA isn't actually MFA
- BleepingComputer: Retool blames breach on Google Authenticator MFA cloud sync feature
- Help Net Security: Attackers hit software firm Retool to get to crypto companies and assets
- The Cyber Express: Retool data breach linked to Google Authenticator sync
- IT World Canada: Cyber Security Today, Sept. 18, 2023 - How a deepfake voice caused a company to be hacked
- Web3 is Going Great: Fortress Trust breach