The U.S. Securities and Exchange Commission (SEC) clarified on Friday that the recent breach of its X account did not extend to a breach of the agency’s broader systems, devices, data, or additional social media accounts. Earlier this week, a fraudulent post on the compromised account falsely claimed the SEC’s approval of spot bitcoin exchange-traded funds (ETFs), causing significant market turbulence.
In a statement, the SEC stated, “While SEC staff is still assessing the scope of the incident, there is currently no evidence that the unauthorized party gained access to SEC systems, data, devices, or other social media accounts.” The agency acted promptly to disavow and remove the misleading post, clarifying that the compromise resulted from an “unidentified individual” gaining control of a phone number associated with the account.
Despite the incident, the SEC proceeded to officially approve bitcoin ETFs on Wednesday, bringing regulatory clarity to the cryptocurrency market. The agency has initiated an investigation into the breach, with the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency collaborating with the FBI and the SEC’s inspector general.
The SEC’s reassurance underscores the resilience of its broader cybersecurity measures, emphasizing that the breach appears limited to the compromised X account. Market participants are urged to exercise caution and verify information through official channels, especially during times of heightened sensitivity in financial markets.
