How Retool's $15M Hack Exposed the Fatal Flaw in Standard Security Checklists
In August 2023, software company Retool suffered a multi-stage cyberattack in which an employee was manipulated via a phishing text, a fake portal, and a deepfake voice call into surrendering authentication codes. The attacker used these codes to enroll a rogue device on the employee's Okta account, then exploited Google Authenticator's cloud-sync feature to harvest all one-time passwords the employee held. This led to the takeover of 27 customer accounts, with crypto firm Fortress Trust reportedly losing around $15 million. Despite having MFA, SSO, and a password policy in place, Retool's security failed because its account recovery pathway — not its primary login — was the weakest link. The incident highlights that standard security checklists overlook account recovery flows, which effectively function as a second, weaker authentication system that attackers routinely exploit.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in