Desk live·
ForensicPost
Cloud/Identity/File 23-0913

A Synced Authenticator Turned Retool’s Second Factor Into No Factor

One employee clicked a convincing text message and answered a phone call using a cloned voice. Because the authenticator app had recently begun syncing one-time-password seeds to a cloud account, control of that account handed over every code at once.

Constructed geometry · not a chart of case data
TargetRetool
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

Retool disclosed that accounts belonging to 27 of its cloud customers were compromised following an SMS-based social engineering attack in late August 2023. Every affected customer was in the cryptocurrency industry.

Messages appearing to come from internal IT directed employees to a convincing link about payroll. One employee entered credentials and a multi-factor code. The company reported that the attacker then telephoned that employee using a cloned version of a real colleague’s voice and obtained a further code.

The Sync Feature Is The File

Retool attributed the escalation to a cloud synchronisation feature added to the authenticator application earlier that year, which backs up one-time-password seeds to the user’s cloud account. Control of the identity provider account led to control of the cloud account, which led to control of every one-time password stored in the authenticator.

That is the collapse. A second factor is only a second factor if compromising the first does not deliver it. Once the seeds live in an account protected by the same identity, there is one factor wearing two names.

A Usability Improvement With A Security Consequence

The sync feature exists for a real reason: people lose phones and lose access to everything. Solving that problem well is genuinely hard, and the solution shipped here moved the seeds somewhere recoverable.

The corpus is careful not to file this as negligence. It is a design trade-off whose security consequence emerged in deployment — the same category as the DNA Relatives feature at 23-1204 and consent-grant persistence at 25-1207.

Synthetic Voice, Used In Anger

The reported use of a cloned voice on a live call is the earliest instance in this database of that technique appearing in an incident rather than in a demonstration.

The corpus goes on to record voice cloning as a standard component of impersonation fraud at 26-0421, and deepfake components in around 40% of business email compromise incidents at 26-0712. This is where that line starts.

How we reported this

Built on Retool’s own public account of the incident as reported, and on contemporaneous technical reporting. The 27 affected customers, the SMS phishing, the cloned-voice call and the attribution of escalation to authenticator cloud synchronisation are Retool’s own statements. The reported loss at one affected customer is not carried in this record: it is a third party’s loss, reported at the time, and this file does not assert a figure for it. No actor attribution is made. No indicators are reproduced. Graded high on Retool’s account. Corrections: corrections@forensicpost.com.

Sources
  1. Retool blames breach on Google Authenticator MFA cloud sync featureBleepingComputer
  2. Retool Falls Victim to SMS-Based Phishing Attack Affecting 27 Cloud ClientsThe Hacker News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary