{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval"},"incident":{"title":"SIM swap of the SEC's X account posted a fake Bitcoin ETF approval","date":"2024-01-09","date_precision":"day","victim_org":"U.S. Securities and Exchange Commission","sector":"Government","country":"United States","primary_vector":"SIM Swap","secondary_vectors":["Physical Pretexting"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported; the impersonation used a physically printed counterfeit ID card.","outcomes":["Identity Theft","Service Disruption","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"No direct loss to the SEC was published. The fake post moved bitcoin roughly $1,000 higher, then more than $2,000 lower once the SEC disclosed the compromise. Council was paid about $50,000 in bitcoin for performing SIM swaps and was ordered to forfeit that amount.","records_affected":null,"threat_actor":"Eric Council Jr. and co-conspirators","summary":"On January 9, 2024, attackers took over the SEC's @SECgov account on X and posted a false announcement that the agency had approved spot Bitcoin ETFs. Eric Council Jr., 26, of Athens, Alabama, executed the SIM swap that made it possible; he pleaded guilty on February 10, 2025 to conspiracy to commit aggravated identity theft and access device fraud, and was sentenced to 14 months in prison plus forfeiture of $50,000.","how_it_worked":"Council printed a counterfeit identification card on a portable card printer using personal details supplied by co-conspirators, then walked into an AT&T store in Huntsville, Alabama and asked for a replacement SIM for the number tied to the @SECgov account. Store staff issued it against the fake document. He activated the SIM in a newly purchased iPhone, received the password-reset code for the X account, and passed it to the conspirators, who posted the fabricated ETF approval. Bitcoin moved over $1,000 within minutes. The FBI later found fake-ID templates and searches about FBI investigations at his residence.","lessons":"High-consequence institutional social accounts should be secured with hardware security keys rather than SMS-based recovery, and carrier retail ID checks need document-authentication technology rather than visual inspection.","confidence":"Confirmed","sources":[{"title":"Alabama Man Sentenced in Hack of SEC X Account that Spiked the Value of Bitcoin","url":"https://www.justice.gov/usao-dc/pr/alabama-man-sentenced-hack-sec-x-account-spiked-value-bitcoin","publisher":"U.S. Department of Justice"},{"title":"Hacker pleads guilty to SIM swap attack on US SEC X account","url":"https://www.bleepingcomputer.com/news/security/hacker-pleads-guilty-to-sim-swap-attack-on-us-sec-x-account/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-sim-swap-of-the-sec-s-x-account-posted-a-fake-bitcoin-etf-approval"}}