Retool disclosed that accounts belonging to 27 of its cloud customers were compromised following an SMS-based social engineering attack in late August 2023. Every affected customer was in the cryptocurrency industry.
Messages appearing to come from internal IT directed employees to a convincing link about payroll. One employee entered credentials and a multi-factor code. The company reported that the attacker then telephoned that employee using a cloned version of a real colleague’s voice and obtained a further code.
The Sync Feature Is The File
Retool attributed the escalation to a cloud synchronisation feature added to the authenticator application earlier that year, which backs up one-time-password seeds to the user’s cloud account. Control of the identity provider account led to control of the cloud account, which led to control of every one-time password stored in the authenticator.
That is the collapse. A second factor is only a second factor if compromising the first does not deliver it. Once the seeds live in an account protected by the same identity, there is one factor wearing two names.
A Usability Improvement With A Security Consequence
The sync feature exists for a real reason: people lose phones and lose access to everything. Solving that problem well is genuinely hard, and the solution shipped here moved the seeds somewhere recoverable.
The corpus is careful not to file this as negligence. It is a design trade-off whose security consequence emerged in deployment — the same category as the DNA Relatives feature at 23-1204 and consent-grant persistence at 25-1207.
Synthetic Voice, Used In Anger
The reported use of a cloned voice on a live call is the earliest instance in this database of that technique appearing in an incident rather than in a demonstration.
The corpus goes on to record voice cloning as a standard component of impersonation fraud at 26-0421, and deepfake components in around 40% of business email compromise incidents at 26-0712. This is where that line starts.
Built on Retool’s own public account of the incident as reported, and on contemporaneous technical reporting. The 27 affected customers, the SMS phishing, the cloned-voice call and the attribution of escalation to authenticator cloud synchronisation are Retool’s own statements. The reported loss at one affected customer is not carried in this record: it is a third party’s loss, reported at the time, and this file does not assert a figure for it. No actor attribution is made. No indicators are reproduced. Graded high on Retool’s account. Corrections: corrections@forensicpost.com.