置信度
1- 信息类型
- 这条记录保留 Retool 的组织身份;法律实体、网络资源、服务范围、领导层及相关公开来源留待后续补充。
相关细节
- Retool 将 MFA 支持工作流变成社会工程问责测试
支持公开目录档案、文章证据边界和运营背景。
公开证据
最近更新: 2026-08-27
当前状态
相关研究
2- Retool 将 MFA 支持工作流变成社会工程问责测试
Retool 2023 年的社会工程事件成为了一个企业自动化问责案例,因为故障路径并未止于一名被钓鱼的员工。Retool 表示,攻击者结合了短信钓鱼、语音电话、虚假身份门户、一次性密码、云同步验证器密钥、VPN 访问和内部支持 Retool 实例,接管了 27 个云客户账户。公开的问责问题是:支持工作流、身份恢复路径和内部管理工具是否能够覆盖企业客户认为已经购买的 MFA 保证?
主文章发布时间 2026-07-15 - Retool made MFA support workflows a social-engineering accountability test
Retool's 2023 social-engineering incident became an enterprise automation accountability case because the failure path did not stop at one phished employee. Retool said the attacker combined SMS phishing, a voice call, a fake identity portal, a one-time code, cloud-synced authenticator secrets, VPN access, and an internal support Retool instance to take over 27 cloud customer accounts. The public accountability question is whether support workflows, identity recovery paths, and internal administrative tools can override the very MFA guarantees that enterprise customers think they have bought.
主文章发布时间 2026-07-15
