Incident Score: Analysis & Impact (SIMSWAGOO1788942524)
The details regarding individual company incidents & reports gives you full view from every side.
Rankiteo Score Impact Analysis
Key Highlights From The Incident Analysis
- Timeline of SimpleSwap's Cyber Attack and lateral movement inside company's environment.
- Overview of affected data sets, including SSNs and PHI, and why they materially increase incident severity.
- How Rankiteo’s incident engine converts technical details into a normalized incident score.
- How this cyber incident impacts SimpleSwap Rankiteo cyber scoring and cyber rating.
- Rankiteo’s MITRE ATT&CK correlation analysis for this incident, with associated confidence level.
Full Incident Analysis Transcript
In this Rankiteo incident briefing, we review the SimpleSwap breach identified under incident ID SIMSWAGOO1788942524.
The analysis begins with a detailed overview of SimpleSwap's information like the linkedin page: https://www.linkedin.com/company/simpleswap, the number of followers: 203, the industry type: Blockchain Services and the number of employees: 5 employees
After the initial compromise, the video explains how Rankiteo's incident engine converts technical details into a normalized incident score. The incident score before the incident was 753 and after the incident was 692 with a difference of -61 which is could be a good indicator of the severity and impact of the incident.
In the next step of the video, we will analyze in more details the incident and the impact it had on SimpleSwap and their customers.
Cryptocurrency enthusiasts, developers, and cybersecurity professionals recently reported "Cybercriminals Exploit Google Sheets as Covert C2 in Cryptocurrency Theft Campaign", a noteworthy cybersecurity incident.
A sophisticated cryptocurrency-stealing operation is leveraging Google Sheets and the Google Visualization API as a command-and-control (C2) channel, delivering malicious JavaScript directly into victims’ browsers.
The disruption is felt across the environment, affecting Victim browsers (Chrome) and Cryptocurrency exchange platforms (SwapZone, SimpleSwap), and exposing Cryptocurrency wallet addresses, transaction details, plus an estimated financial loss of ~$10,000 (0.159 BTC as of August 2026).
Formal response steps have not been shared publicly yet.
The case underscores how teams are taking away lessons such as Risks of unmanaged browser extensions, need to monitor unexpected Google Visualization API traffic, and vulnerabilities in trusted-service abuse (e.g., Google Sheets), and recommending next steps like Monitor for unexpected Google Visualization API traffic (e.g., `docs.google.com/spreadsheets/…/gviz/tq`), Educate users on the risks of executing untrusted JavaScript or installing browser extensions from unverified sources and Implement transaction verification mechanisms to detect wallet address swaps.
Finally, we try to match the incident with the MITRE ATT&CK framework to see if there is any correlation between the incident and the MITRE ATT&CK framework.
The MITRE ATT&CK framework is a knowledge base of techniques and sub-techniques that are used to describe the tactics and procedures of cyber adversaries. It is a powerful tool for understanding the threat landscape and for developing effective defense strategies.
MITRE ATT&CK® Correlation Analysis
Rankiteo's analysis has identified several MITRE ATT&CK tactics and techniques associated with this incident, each with varying levels of confidence based on available evidence. Under the Initial Access tactic, the analysis identified Phishing: Spearphishing Link (T1566.002) with high confidence (90%), supported by evidence indicating lured via Telegram channels, dark web forums, and Pastebin comments and User Execution: Malicious Link (T1204.001) with moderate to high confidence (80%), supported by evidence indicating tricking users into executing code within Chrome via fake API flaw reports. Under the Execution tactic, the analysis identified Command and Scripting Interpreter: JavaScript (T1059.007) with high confidence (90%), supported by evidence indicating malicious JavaScript executed in Chrome or via Tampermonkey and Native API (T1106) with moderate to high confidence (80%), supported by evidence indicating overrides browser’s fetch API to modify responses. Under the Persistence tactic, the analysis identified Browser Extensions (T1176) with high confidence (90%), supported by evidence indicating tampermonkey scripts auto-load on targeted sites. Under the Defense Evasion tactic, the analysis identified Obfuscated Files or Information (T1027) with high confidence (90%), supported by evidence indicating obfuscated JavaScript pasted into Chrome’s address bar, Valid Accounts: Cloud Accounts (T1078.004) with moderate to high confidence (80%), supported by evidence indicating abuses Google Sheets and Google Visualization API as C2, and Hide Artifacts: Hidden Files and Directories (T1564.001) with moderate to high confidence (70%), supported by evidence indicating hides code in white-on-white text and deep spreadsheet rows. Under the Command and Control tactic, the analysis identified Web Service: Bidirectional Communication (T1102.002) with high confidence (90%), supported by evidence indicating google Sheets as C2 via Google Visualization API. Under the Collection tactic, the analysis identified Clipboard Data (T1115) with high confidence (90%), supported by evidence indicating clipboard hijacking to swap copied wallet addresses. Under the Exfiltration tactic, the analysis identified Exfiltration Over C2 Channel (T1041) with high confidence (90%), supported by evidence indicating cryptocurrency funds diverted to attacker-controlled wallets. Under the Impact tactic, the analysis identified Resource Hijacking (T1496) with moderate to high confidence (80%), supported by evidence indicating intercepts cryptocurrency transactions to divert funds. These correlations help security teams understand the attack chain and develop appropriate defensive measures based on the observed tactics and techniques.
Sources & References
- SimpleSwap Rankiteo Cyber Incident Details: https://www.rankiteo.com/company/simpleswap/incident/SIMSWAGOO1788942524
- SimpleSwap CyberSecurity Rating page: https://www.rankiteo.com/company/simpleswap
- SimpleSwap Rankiteo Cyber Incident Blog Article: https://blog.rankiteo.com/simswagoo1788942524-google-simpleswap-swapzone-cyber-attack-august-2026/
- SimpleSwap CyberSecurity Score History: https://www.rankiteo.com/company/simpleswap/history
- SimpleSwap CyberSecurity Incident Source: https://gbhackers.com/google-sheets-c2-abuse/
- Rankiteo A.I CyberSecurity Rating methodology: https://www.rankiteo.com/Images/rankiteo_algo.pdf
- Rankiteo TPRM Scoring methodology: https://static.rankiteo.com/model/rankiteo_tprm_methodology.pdf