
Today, an Alabama man pleaded guilty to his involvement in the hijacking of the U.S. Securities and Exchange Commission (SEC) account on X in a January 2024 SIM swapping attack.
This comes after the defendant, 25-year-old Eric Council Jr., first pleaded not guilty to hacking the SEC account and enabling his co-conspirators to make a fake announcement that Bitcoin ETFs were approved.
"Today the SEC grants approval to Bitcoin ETFs for listing on registered national security exchanges. The approved Bitcoin ETFs will be subject to ongoing surveillance and compliance measures to ensure continued investor protection," read the fake post on X.
The fraudulent post caused Bitcoin to jump up in price by $1,000 and just as quickly plummetted by $2,000 after SEC Chairperson Gary Gensler tweeted that the SEC account had been hijacked and the Bitcoin ETF approval announcement was fake.

The SEC confirmed the next day that the @SECGov X account was compromised through a SIM-swapping attack targeting the phone number of the person in charge of the X account.
This attack allowed the defendant to gain control over the SEC employee's phone number, receive password reset codes, and send them to co-conspirators of the same scheme (who paid him $50,000 in Bitcoin) to access the compromised account and post the fake announcement.
"As part of the scheme, Council used an identification card printer to create a fraudulent identification card with a victim's personally identifiable information obtained from his co-conspirators," the Justice Department said.
"Council used the fraudulent identification card to impersonate the victim and gain access to the victim's cellular phone number for the purpose of accessing the SEC's account."
Court documents claim that Council used his personal computer to search for information related to the attack and expressed his concerns that the FBI was investigating him.
Among these searches, investigators found that the defendant was looking for details on "what are the signs that you are under investigation by law enforcement of the FBI even if you have not been contacted by them" and "how can i know for sure if I am being investigate by the FBI."
Council is scheduled to be sentenced on May 16 and faces a maximum penalty of five years in prison after pleading guilty to conspiracy to commit aggravated identity theft and access device fraud.
Break down IAM silos like Bitpanda, KnowBe4, and PathAI
Broken IAM isn't just an IT problem - the impact ripples across your whole business.
This practical guide covers why traditional IAM practices fail to keep up with modern demands, examples of what "good" IAM looks like, and a simple checklist for building a scalable strategy.





Post a Comment Community Rules
You need to login in order to post a comment
Not a member yet? Register Now