How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
The takeover of the U.S. Securities and Exchange Commission's X account, the one that briefly moved the price of bitcoin, started at a cellphone store in Alabama with a homemade ID card.[2][3] This case file covers what happened on January 9, 2024, how a phone number became the key to a federal regulator's account, what it cost the man who pleaded guilty, and the one control that would have stopped it.
What happened
In early January 2024, crypto traders were waiting to hear whether the SEC would approve exchange-traded funds that hold bitcoin directly. Shortly after 4 p.m. Eastern on January 9, the SEC's official X account, @SECGov, answered the question. At 4:11 p.m. it posted that the agency had approved bitcoin ETFs for listing on all registered national exchanges. About two minutes later a second post, just the ticker symbol for bitcoin, appeared and was later deleted. The account also liked two posts that had nothing to do with the SEC.[1]
None of it came from the SEC. According to prosecutors, bitcoin's price rose by more than $1,000 after the fake announcement.[2][3] Chair Gary Gensler posted from his own account that the agency had not approved the products, the bogus post came down within about 30 minutes, and bitcoin then fell by more than $2,000.[3][5][6]
That evening, X's safety team said its own systems had not been breached. Instead, someone had taken control of a phone number tied to the @SECGov account through a third party, and the account did not have two-factor authentication turned on at the time.[5][6] The next day, the SEC approved the real bitcoin ETFs anyway.[5]
On January 22, the SEC said the attacker had used an apparent SIM swap, moving the phone number to another device without permission, and that the access came through the phone carrier rather than SEC systems. The agency said it found no sign the attacker reached its systems, data, devices or other social media accounts.[1]
How they got in
A SIM card is the small chip that ties a phone number to a physical phone. A SIM swap convinces a carrier to move someone's number onto a new SIM, so calls and text messages go to a different device. Anything that sends login codes or password-reset links by text then goes to the wrong person.
According to court filings, Eric Council Jr. received the account holder's personal information and a template for an ID card from others in the scheme. He printed a fake ID on his own printer and used it at an AT&T store in Huntsville, Alabama, to pose as the person whose phone number was linked to the SEC's account and get a replacement SIM. He bought a new iPhone with cash, used it to receive the codes needed to get into the account, and passed them to his co-conspirators, who wrote and posted the fake announcement.[2][3] Reporting on the SEC's later update said the hijacked number let the attacker reset the account's password.[5]
There was also a weak spot on the SEC's side. The agency said multifactor authentication on the account had been turned off in July 2023 because of account access issues. Access was restored, but the setting stayed off until after the hack.[1] For six months, a phone number was effectively the only thing standing between strangers and a market-moving account.
How it was caught
The FBI's Washington Field Office and the SEC's Office of Inspector General investigated.[4] Council, then 25, was arrested in Athens, Alabama, on October 17, 2024. Prosecutors say that after the hack he returned the iPhone for cash in Birmingham, and that he later searched online for terms about the SEC hack and about how to tell if the FBI was investigating him.[2]
On February 10, 2025, Council pleaded guilty to one count of conspiracy to commit aggravated identity theft, which carries up to 5 years in prison. He admitted he was paid in bitcoin for the job. Prosecutors said he had received about $50,000 from members of the conspiracy for SIM swaps over the previous 6 months.[3] On May 16, 2025, he was sentenced to 14 months in prison followed by 3 years of supervised release.[4]
The missing control
The missing control: no SMS account recovery. A phone number should never be enough, by itself, to reset the password on an account that matters.
Text messages follow the phone number, not the phone, and the phone number is controlled by a carrier's store clerk, not by you. If the SEC's account had required an authenticator app or a hardware security key, with no fallback to a text message, a new SIM would have delivered nothing useful.
The second lesson is about exceptions. Turning off MFA to fix a login problem is common. Leaving it off for six months, with no end date and no one assigned to switch it back on, is how a temporary fix becomes the open door. Every security exception needs an expiry date and an owner.
What to do in your business
- Remove phone numbers from account recovery. On your social media, email, banking and domain accounts, switch text-message codes to an authenticator app or security key, and delete the phone number as a recovery option where the service allows it.
- Put a PIN on your business phone lines. Ask your carrier for a port-out or account PIN and any SIM-lock option, so a stranger with a fake ID needs more than a convincing card.
- Give every exception an end date. If you turn MFA off to fix a problem, write down who did it, why, and the date it goes back on, then check that it did.
- Know who holds your public accounts. List each social media account, the person responsible and the recovery methods on file, and review it every quarter.
- Plan for a fake post. Decide in advance how you will lock the account, alert followers through another channel and report it to the platform.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Hot Lotto was rigged: the security director who wrote the numbers
- How the Target breach happened: a vendor's billing login and the alarms nobody answered
- How the Bangladesh Bank heist happened: $81 million over SWIFT, stopped short by a typo
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- What caused the Equifax breach? An unpatched website and an expired certificate
- How the Capital One breach happened: one misconfigured cloud firewall
Facts are drawn from court records, government reports and reputable reporting, listed below. People are named only where they were convicted or spoke publicly in an official role.
- U.S. Securities and Exchange Commission: SEC Statement on @SECGov X Account Compromise
- U.S. Attorney's Office, District of Columbia: FBI Arrests Alabama Man for January 2024 SEC X Hack That Spiked the Value of Bitcoin
- U.S. Attorney's Office, District of Columbia: Guilty Plea in Hacking of SEC's X Account That Caused Bitcoin Value Spike
- U.S. Department of Justice: Alabama Man Sentenced to 14 Months in Connection with SEC X Hack That Spiked Bitcoin Value
- Help Net Security: SEC's X account hacked to post fake news of Bitcoin ETF approval
- Quartz: The SEC didn't have 2-factor authentication when it got hacked, X says