Twitter Releases Details of Attack Vector Used by Crypto Hacker

Published at: July 31, 2020

Twitter released an update on July 30 revealing how hackers gained access to its internal network and account management tools in the recent attack.

It also gave details of additional measures taken to improve security since the hack, which netted 12 Bitcoin (BTC) through targeting the Twitter accounts of celebrities and crypto businesses.

Phishing for complements

The update confirmed that Twitter had been the victim of a social engineering attack, putting paid to rumors that the hack could have been an inside job.

According to the report, the July 15 incident started with a spear-phishing attack, targeting a small number of employees by telephone to gain network access credentials:

“Not all of the employees that were initially targeted had permissions to use account management tools, but the attackers used their credentials to access our internal systems and gain information about our processes.”

The attackers then used this knowledge to target additional employees with access to account support tools.

A poor workman loses his tools

Responding to reports that over 1,000 employees had access to the admin tools, Twitter explained that it has teams around the world that help with account support.

However, access to the tools is strictly limited and only granted for legitimate business reasons. Since the attack it has further limited access, and will continue a continuous education program on the risks of phishing attacks.

During the hack the attackers accessed 130 Twitter accounts, tweeted from 45 of these, got into the direct messages inbox of 36 and downloaded the Twitter data of seven.

Tags
Related Posts
Facial Recognition Could Help to Stamp Out Bitcoin Social Media Scams
Facial recognition can help prevent future Bitcoin (BTC) scams like those that hit Twitter and YouTube, said Rod Hsu, president and co-founder of virtual currency platform Coincurve. During an interview with Cointelegraph, Hsu said Bitcoin is an electronic form of currency that is non-reversible and somewhat anonymous, “coupled with this gap in understanding makes it appealing for scam artists.” But because of the negative publicity the cryptocurrency got with the scams, it may have discouraged many from adopting it. “Due to the nature of this, people may see scams and Bitcoin being synonymous. In either traditional payment methods or Bitcoin, …
Technology / Aug. 9, 2020
Scott Melker on Twitter: ‘We Cannot Depend on Centralized Platforms’
The "Wolf of All Streets" Scott Melker has been unable to do anything more on Twitter than read or retweet more than 24 hours after the massive hack on verified accounts. In a livestreamed interview with Cointelegraph on July 15, the crypto trader said in the midst of the attack he had been unable to verify his account using two-factor authentication. Melker then briefly had full access to read, retweet and post for roughly an hour before having his account restricted following the interview. Twitter Support reported that the platform had “locked accounts that were compromised” and would restore access …
Bitcoin / July 17, 2020
Crypto sleuth debunks 3 biggest misconceptions about the FTX hack
On-chain sleuth ZachXBT has shared his findings on what he sees as the three most common misconceptions about the FTX hack — taking to Twitter to correct a "ton of misinformation" about the event and the possible culprits. In a lengthy Nov. 20 post on Twitter, the self-proclaimed “on-chain sleuth” debunked speculation that Bahamian officials were behind the FTX hack, that exchanges knew the hacker's true identity, and that the culprit is trading memecoins. 1/ I have seen a ton of misinformation being spread on Twitter and in the news about the FTX event so let me debunk the three …
Bitcoin / Nov. 21, 2022
Jack Dorsey still thinks Bitcoin is the strongest contender for an internet-native currency
The world of cryptocurrency moves at a whirlwind pace but Twitter CEO Jack Dorsey remains committed to its earliest lodestone, Bitcoin (BTC). In an interview with Reuters on Sept. 10, Dorsey, who also founded the mobile-payment platform Square, said he believes the coin’s potential still outshines later developments: “I think the internet warrants a [...] native currency and [...] Bitcoin is probably the best manifestation of that thus far. I can’t see that changing given all the people who want the same thing and build it for that potential.” Dorsey connected Bitcoin’s founding principles with the cooperative and decentralized ethos …
Decentralization / Sept. 10, 2020
Making sense of the Bitfinex Bitcoin billions
It’s the Netflix script that wrote itself. A story so outlandish, it’s stunned the crypto community; an industry accustomed to apparent suicides in Spanish jail cells and nonfungible token auctions for dead rappers. The plot involves the United States Department of Justice (DoJ), a crypto exchange with a checkered history, a rapper-cum-Forbes magazine writer, a voucher to buy a new PlayStation, an occasional magician and $4 billion worth of Bitcoin (BTC). The alleged Bitfinex hack money launderers have kept the internet enraptured since the larger-than-life story emerged last week. It’s no wonder that Netflix has actually announced that they will …
Adoption / Feb. 16, 2022