San Francisco-based software company Retool recently disclosed a major security breach. This hack affected 27 crypto customer accounts and involved $15 million in unlawful Fortress Trust withdrawals. A targeted SMS social engineering attack using a Google Account synchronization feature launched in April 2023 caused the compromise. This feature mistakenly reduced administrator multi-factor authentication (MFA) to a single-factor authentication mechanism.

Google Authenticator Sync Used in Breach
Retool has 27 cloud customers affected by the August 27, 2023, event. Note that the incident did not affect on-premises or managed accounts. Retool migrated logins to Okta, a cloud-based identity and access platform, during the incident.
The SMS phishing attack targeted Retool employees. Threat actors impersonated IT staff and persuaded employees to visit a payroll website. After falling for the phishing landing page’s trick, one employee unintentionally revealed their login information. After that, the criminals used deepfake technology to create the IT team member’s “authentic voice” to trick the target into giving over the MFA code.
According to Retool’s technical leader, Snir Kodesh, using a second OTP token allowed the attacker to link their device to the employee’s Okta account and create their own MFA. This allowed them to use G Suite (now Google Workspace) on the device.
The culprits utilized Google Authenticator’s cloud synchronization to gain access to internal administration systems and compromise 27 crypto customers’ accounts. Thus, the malicious actors changed user email and login passwords, costing Fortress Trust $15 million.
Trending Now: Islamic Coin Token Sale Receives Boost with Republic Partnership
Kodesh stressed the need to control Okta to obtain control over Google and all Google Authenticator OTPs, demonstrating the complexity of the attack.
This shows how synchronizing one-time codes with cloud storage might weaken multi-factor authentication’s “something the user has” part. Users should use FIDO2 hardware security keys or passkeys to prevent phishing.
Retool Breach Highlights Risks of Deepfake Technology in Cyberattacks
Threat actors have not been identified, although their techniques resemble those of Scattered Spider, a financially motivated threat actor known as UNC3944. Scattered Spider is known for clever phishing. A recent investigation found that threat actors may have exploited target settings to steal internal system data.
This incident highlights the vulnerabilities of deepfake technology, as malicious actors may use audio, video, and text deepfakes to commit business email compromise (BEC) attacks and cryptocurrency scams.

