Skip to content

2023-08-27 (incident) · US · Retool

Retool breached through SMS phishing and a follow-up call, 2023

Disclosed by the affected organisation.

On 27 August 2023 several Retool employees received texts claiming an account issue would block healthcare open enrollment, linking to a fake internal identity portal. One employee logged in, then took a call from someone claiming to be IT who, in Retool's words, deepfaked "our employee's actual voice" and obtained one more MFA code. Because the employee's Google Authenticator codes synced to the cloud, the attacker reached internal admin tools and took over 27 cloud customer accounts, all in the crypto industry.

Timeline

  1. 2023-08-27 An employee enters credentials on a fake identity portal linked from a text message, then gives a caller an extra MFA code.
  2. 2023-08-29 Retool notifies 27 cloud customers of unauthorised access to their accounts.
  3. 2023-09-13 Retool publishes its account of the attack, criticising cloud syncing of MFA codes.

Lessons

Scam types: Employee SMS phishing (0ktapus-style) · Techniques: SMS phishing (smishing), Voice phishing (vishing)

Sources

  1. Retool: When MFA isn't actually MFA (Company disclosure, primary, accessed 2026-09-24)