The SEC's X account hack, start to finish: a fake ID, a phone store and a bitcoin jump
On January 9, 2024, the official X account of the Securities and Exchange Commission announced a decision the agency had not made, and the price of bitcoin rose by more than $1,000 before falling by more than $2,000 once the truth came out.[2][3] This long read follows the hijacking from the fake post to the phone store in Alabama, the switched-off login protection that made it possible, the searches that helped investigators, the sentence, and the one control that was missing.
The fake bitcoin fund post
For years, companies had asked the SEC to approve exchange-traded funds that hold bitcoin directly, the kind of fund that trades on a stock exchange like an ordinary share. By early 2024 the market was watching the agency closely for any word on those applications.
At 4:11 p.m. Eastern time on January 9, 2024, the @SECGov account on X posted that the SEC had granted approval for bitcoin funds to list on all registered national securities exchanges. At 4:13 p.m. a second post appeared, containing only the ticker symbol for bitcoin. The account also liked 2 posts from accounts unrelated to the agency.[1]
None of it came from the SEC. The agency said an unauthorized party had gained control of the account shortly after 4 p.m., and it moved to delete the posts and regain control.[1] In that short window, prosecutors later said, the price of bitcoin rose by more than $1,000, then fell by more than $2,000 after the SEC said the post was false.[2][3]
The episode showed how much weight a single official account can carry. A regulator's verified feed is where traders expect real announcements to appear first. For a few minutes, whoever controlled the login effectively spoke for the agency that oversees America's securities markets, and trading software and human traders reacted before anyone could check.
How the SEC lost its phone number
The SEC's own review, published in a series of updates on January 9, 10, 12 and 22, found that nobody had broken into the agency's computers. It said there was no evidence the intruders had reached SEC systems, data, devices or its other social media accounts.[1]
Instead, the attackers went around the agency entirely. They took control of the mobile phone number linked to the X account through the phone carrier, a technique known as a SIM swap. A SIM card is the small chip that ties a phone number to a handset. Persuade a carrier to issue a new one for someone else's number, and that person's calls and text messages start arriving on your phone. With the number in hand, the attackers could reset the account's password.[1]
That should have hit a second wall. Multifactor authentication, the extra sign-in step that asks for something beyond a password, is designed to stop exactly this. But the SEC said that in July 2023, X Support had turned off multifactor authentication on the account at the request of SEC staff, because they were having trouble getting into it. Once access was sorted out, it was not switched back on. It stayed off for about 6 months, until staff re-enabled it after the January 9 compromise.[1]
The fake ID and the phone store in Alabama
The investigation drew in the SEC's inspector general, the FBI, the Cybersecurity and Infrastructure Security Agency, the Commodity Futures Trading Commission and the Justice Department.[1] In October 2024, it reached a man in northern Alabama.
According to federal prosecutors, co-conspirators sent Eric Council Jr. of Athens, Alabama, personal details of the person whose phone number controlled the SEC account, along with a template for an identification card. He used a portable card printer to produce a fake ID in that person's name and went to a phone carrier store in Huntsville, where he used it to obtain a replacement SIM card for the number.[2][3]
He then bought a new iPhone with cash at a nearby Apple store, put the SIM card in it, and received the password reset codes for the @SECGov account as text messages. He photographed the codes and passed them on. A co-conspirator used them to get into the account and post the false announcement.[3] Afterward, prosecutors said, Council drove to Birmingham and returned the iPhone for cash. He was paid in bitcoin for his part.[2]
His role took a printed card, a store counter and a phone he later returned. No hacking of the SEC or of X was needed at any point, which is what makes the case so instructive: the weakest link was a customer service process built to help people who lose their phones.
The searches that pointed to him
Investigators did not need to reverse-engineer anything clever. Prosecutors said that after the hack, Council searched online for terms about hacking the SEC account, for information about SIM swaps, and for how he could know for sure whether the FBI was investigating him.[2]
In June 2024, agents searched his home and recovered a fake ID, the portable ID card printer and a laptop holding templates for more fake IDs.[3] On October 17, 2024, the FBI arrested him, then 25, on charges of conspiracy to commit aggravated identity theft and access device fraud.[2] The U.S. Attorney for the District of Columbia said his office would hold accountable people who commit such crimes.[2]
Prosecutors also said the SEC job was not a one-off. According to the Justice Department, Council received about $50,000 for performing SIM swaps.[3] The people who wrote and published the fake post have not been named in public filings, and nothing in the public record says whether anyone else has been charged.
The sentence and what the SEC changed
On February 10, 2025, Council pleaded guilty to conspiracy to commit aggravated identity theft. On May 16, 2025, a federal judge in Washington, D.C., sentenced him, then 26, to 14 months in prison and 3 years of supervised release, with conditions barring him from dark web access and identity fraud, and ordered him to forfeit $50,000.[3]
The SEC turned multifactor authentication back on for the account after the compromise.[1] The fix was simple, which is the uncomfortable part. The protection existed, was available and had been in use. It was switched off to solve a short-term access problem and then forgotten.
The deeper weakness sits in how many services still let a text message reset a password. A phone number feels personal, but it is controlled by a carrier and can be moved by anyone who convinces a store clerk. When a text message is both the way to reset a password and the only second factor, whoever controls the number controls the account.
Timeline
| Date | What happened |
|---|---|
| Jul 2023 | Multifactor sign-in on @SECGov turned off at staff request.[1] |
| Jan 9, 2024 | Phone number hijacked through the carrier; password reset.[1][3] |
| Jan 9, 2024, 4:11 p.m. | False post announcing approval of bitcoin funds.[1] |
| Jan 9, 2024, 4:13 p.m. | Second unauthorized post; bitcoin jumps, then falls.[1][2] |
| Jan 22, 2024 | SEC publishes its finding of a SIM swap.[1] |
| Jun 2024 | Agents search the Alabama man's home and find ID-making gear.[3] |
| Oct 17, 2024 | FBI arrests him.[2] |
| Feb 10, 2025 | He pleads guilty to conspiracy to commit aggravated identity theft.[3] |
| May 16, 2025 | Sentenced to 14 months in prison and $50,000 forfeiture.[3] |
The missing control
The missing control: a second sign-in factor that cannot be moved to another phone, such as a hardware security key, kept on even when it is inconvenient, and account recovery that never trusts a text message alone. With that in place, a stolen phone number would have been a dead end.[1]
- Put security keys on your most visible accounts. For company social media, email and banking, register a physical security key or passkey, and keep a backup key in a safe place.
- Remove phone numbers as a recovery route where you can. In each account's security settings, check whether a text message alone can reset the password, and switch to an app or key if possible.
- Never switch off two-factor sign-in to fix a lockout. If you must, set a calendar reminder and name a person responsible for turning it back on the same day.
- Add a carrier PIN or port lock. Ask your mobile carrier to add a PIN or lock to every business line so a store cannot move the number without it.
- List who controls each shared account. For every company account, record whose phone and email it is tied to, and review the list whenever someone changes roles or leaves.
What it means now
The SEC was not outwitted by advanced hacking. It was undone by a phone number, a printed card and a security setting that had been switched off months earlier to solve a small problem.
Every small business has an account that speaks for it in public or moves its money. Ask one question about each: if someone walked into a phone store with a fake ID tomorrow, would they get in? If the answer is maybe, the fix takes an afternoon, and it costs far less than explaining a fake announcement to customers.
How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA: the case file and the Shorts from this case.
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- All episodes
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- U.S. Securities and Exchange Commission: SEC statement on @SECGov X account compromise
- U.S. Attorney's Office, District of Columbia: FBI arrests Alabama man for January 2024 SEC X hack that spiked the value of bitcoin
- U.S. Attorney's Office, District of Columbia: Alabama man sentenced for hack of SEC X account that spiked value of bitcoin