A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA codes, letting attackers exploit Google Authenticator cloud sync to take over 27 crypto customer accounts and steal ~$15M.
Reviewed by the Social Engineering Examples team.
On August 27, 2023, Retool was compromised through a multi-stage social engineering attack. Several employees received SMS text messages impersonating a member of Retool's IT team, claiming an account/payroll issue needed to be fixed or the employee would lose access to open enrollment for healthcare benefits. The text linked to a fake login page mimicking Retool's internal identity portal. The timing was chosen to coincide with a genuine, recently announced company migration of logins to Okta, making the request plausible. Almost all employees ignored the message, but one logged in and entered credentials plus a one-time MFA code on the spoofed portal. The attacker then phoned that employee, posing as a member of the IT team. According to Retool's head of engineering Snir Kodesh, the caller used a deepfake of an actual employee's voice and displayed detailed knowledge of the office floor plan, coworkers, and internal processes. Although the employee grew suspicious during the call, they provided one additional MFA (OTP) code. One outlet, Ars Technica, noted the deepfake-voice claim was unverified and questioned whether it was emphasized to deflect from Retool's own controls. That extra OTP let the attacker enroll their own device on the employee's Okta account and generate valid Okta MFA going forward, which gave them an active Google Workspace (GSuite) session on the attacker device. Because the employee had enabled Google Authenticator's then-new cloud-sync feature, control of the Google account exposed all of that employee's OTP seeds at once. Retool used OTPs for Google, Okta, its VPN, and its internal admin tools, so the attacker reached the VPN and an internal Retool instance used for customer support, then ran account-takeover attacks (changing emails and resetting passwords) against 27 cloud customers, all in crypto. Retool notified the 27 affected cloud customers on August 29, revoked all internal sessions, locked down and restored the hijacked accounts, and worked with law enforcement. CoinDesk identified Fortress Trust as an affected customer; its customers lost roughly $15M in crypto, an incident that accelerated Ripple's acquisition talks with Fortress Trust. Ripple ultimately canceled that acquisition on September 28, 2023. Retool stressed that no on-premise or managed customers were affected because on-prem runs in a zero-trust environment isolated from Retool cloud.
Recon/setup: attackers picked a moment that matched a real internal change (an announced Okta login migration) and crafted an IT-help-desk pretext tied to benefits/payroll, making an unusual request feel routine and time-sensitive. Contact: a smishing text to multiple employees drove them to a look-alike identity portal; only one engaged. Rapport/escalation: a phone call impersonating IT, reportedly using a voice cloned to sound like a known colleague and seeded with insider details (office layout, coworker names, processes), built enough trust to overcome the target's growing doubt. Exploitation: the target entered one OTP on the fake portal and disclosed a second OTP by phone; the second code let the attacker register their own device to the Okta account, achieving durable MFA control and a live Google Workspace session. Amplification: the employee's Google Authenticator cloud-sync turned single-account access into access to every OTP seed stored there, collapsing multi-factor authentication into effectively single-factor and unlocking the VPN and internal admin tooling. Payout: attackers used the internal customer-support tool to reset emails/passwords on crypto customers' accounts and drain funds. Awareness lesson: legitimate-looking context plus a familiar voice can defeat a cautious employee, and syncing OTPs to a cloud account can silently undermine the whole MFA model.
Pretext: an SMS from "IT" warning that a payroll/account sync problem would block healthcare open enrollment, with a link to a fake "retool.okta[.]com" style identity portal, followed by a phone call from "IT" using a familiar-sounding (allegedly cloned) voice. Red flags: an unsolicited text about account/benefits problems; a login link sent over SMS rather than an official internal channel; a login domain that only superficially resembled the real Okta/identity portal (attacker-controlled subdomain/path); being asked for an MFA/OTP code by a caller, since legitimate IT never needs your one-time code; pressure and urgency; and a request to approve or read out a second code after already logging in. The employee's own rising suspicion during the call was itself the signal to stop and verify out-of-band.
27 crypto cloud customers had accounts taken over; Fortress Trust customers lost ~$15M in cryptocurrency. Retool reverted all 27 takeovers, restored original account settings, revoked internal sessions, and engaged law enforcement; no on-prem/managed customers were affected. The breach accelerated Ripple's acquisition talks with Fortress Trust, though Ripple ultimately canceled that acquisition on September 28, 2023; affected Fortress customers were made whole primarily from Fortress's own balance sheet, with a $15M down payment from Ripple covering the remainder. Retool publicly blamed Google Authenticator's cloud-sync design and urged Google to remove the dark patterns or let admins disable sync; Google defended the feature while noting users can opt out and pointing to phishing-resistant passkeys/FIDO2.
This is a landmark real-world case of a smishing-plus-vishing combo layered with an AI voice-clone claim, showing how attackers chain channels and impersonate trusted IT to defeat a security-conscious workforce. It also exposed a systemic weakness: syncing TOTP seeds to a cloud account can silently downgrade multi-factor authentication to single-factor, so compromising one identity account cascades into everything. And it demonstrates supply-chain blast radius, where breaching one SaaS vendor let attackers reach and rob its downstream crypto customers. It is a canonical teaching example for why OTP-based MFA is phishable and why phishing-resistant FIDO2/passkeys and out-of-band verification matter.
Deploy phishing-resistant, hardware-backed MFA (FIDO2 security keys / passkeys) so there is no code to read out or phish. Do not sync OTP/TOTP seeds to personal cloud accounts in enterprise settings; where possible, enforce local-only storage. Train staff that IT/help desk will never ask for an MFA code and that unsolicited SMS login links are suspect; verify any such request through a known internal channel, not the number that contacted you. Require out-of-band, human-in-the-loop verification for high-risk actions (new device enrollment, MFA resets, mass customer email/password changes) rather than trusting a live voice, which can be cloned. Alert on and gate new-device MFA enrollments and anomalous admin-tool activity. Segment and isolate sensitive systems (Retool's zero-trust on-prem architecture prevented on-prem customer impact). Run red-team/phishing simulations that include voice/deepfake scenarios.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…