Attackers sent a Retool employee an SMS phishing link impersonating IT, harvested credentials, then phoned the employee using a deepfaked clone of a real colleague's voice to obtain the MFA/OTP code. That let them register their own device on the victim's Okta account and pivot into customer accounts.
AIC-0006 S4 · Severe
Retool breach via smishing + deepfake voice, enabling ~$15M crypto theft
- Harm
- 27 Retool cloud customers (all crypto-industry) compromised; linked to ~US$15 million in cryptocurrency stolen from Fortress Trust.
- Detection
- Detected and disclosed by Retool after the account takeovers; tied to a Google Authenticator cloud-sync feature that widened blast radius.
- Outcome
- Retool disclosed the breach publicly (September 2023); no public arrests reported.
A documented entry in the AI Crime Registry, a Defici non-profit initiative. Sourced from public reporting; corrections: [email protected].