Toutes les vulnérabilités

PHISH-RETOOL-2023

Phishing · Smishing · Retool

Résumé

On August 27, 2023, Retool was breached through SMS phishing (smishing). Employees received texts impersonating IT about a payroll and health-insurance issue, linking to a fake internal identity portal during a real, previously announced migration to Okta. One employee entered credentials and an MFA code; the attacker then phoned the employee using a deepfaked, familiar-sounding voice (vishing) and talked them into providing an additional code, which added an attacker-controlled device. A compounding factor turned MFA into single-factor: Google Authenticator had recently enabled cloud sync, so when the employee's Google account was phished, all of their synced 2FA codes for internal services were exposed at once. The attacker reached 27 cloud customers, all in cryptocurrency, with at least one (Fortress Trust) reporting significant crypto theft. Retool publicly blamed Google Authenticator's cloud-sync feature for amplifying the breach.

Comment l’éviter dans votre code

  • Use phishing-resistant hardware MFA (FIDO2 security keys); disable cloud-synced TOTP for privileged accounts.
  • Treat SMS and voice as untrusted channels for authentication; never read an MFA code to a caller.
  • Lock MFA-device enrollment behind strong verification and alert on every new-device addition.
  • Watch for smishing tied to real internal events (migrations, payroll) that attackers time to look legitimate.
  • Scope and isolate customer-facing admin systems so one employee compromise cannot reach many tenants.

Références

Vulnérabilités liées

Tout Phishing →