Published 09:00 IST, July 16th 2020
Twitter hacking 'coordinated social engineered attack'; says 'most functionality restored'
Social media giant Twitter labelled the latest attack on verified Twitter accounts of major companies and individuals as a coordinated social engineering attack
Advertisement
Social media giant Twitter labelled the latest attack on verified Twitter accounts of major companies and individuals as 'a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools'.
On July 16, the Twitter accounts of Barack Obama, Bill Gates, Jeff Bezos, Elon Musk, and many other personalities and well as companies were hacked by purported Bitcoin scammers to launch a bitcoin scam. Providing the latest update, Twitter, in its statement, said that the investigation was ongoing and further detailed into the steps taken immediately by the company to respond to the attack.
In the latest update provided by Twitter, the social media giant said that the attackers who targetted their employees used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf. Further, Twitter said that it immediately locked down the affected accounts and removed Tweets posted by the attackers. Functionality was also limited in large group accounts. Twitter further said that it had locked the accounts which had been compromised and that it will lift the lock once it's secure to do so.
'Coordinated social engineering attack'
Our investigation is still ongoing but here’s what we know so far:
— Twitter Support (@TwitterSupport) July 16, 2020
We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.
— Twitter Support (@TwitterSupport) July 16, 2020
We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf. We’re looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it.
— Twitter Support (@TwitterSupport) July 16, 2020
We also limited functionality for a much larger group of accounts, like all verified accounts (even those with no evidence of being compromised), while we continue to fully investigate this.
— Twitter Support (@TwitterSupport) July 16, 2020
This was disruptive, but it was an important step to reduce risk. Most functionality has been restored but we may take further actions and will update you if we do.
— Twitter Support (@TwitterSupport) July 16, 2020
We have locked accounts that were compromised and will restore access to the original account owner only when we are certain we can do so securely.
— Twitter Support (@TwitterSupport) July 16, 2020
Internally, we’ve taken significant steps to limit access to internal systems and tools while our investigation is ongoing. More updates to come as our investigation continues.
— Twitter Support (@TwitterSupport) July 16, 2020
Twitter accounts hacked by Bitcoin scammers
The scam was traced when Musk’s account issued a tweet at 4:17PM ET that read - “I‘m feeling generous because of Covid-19. I’ll double any BTC payment sent to my BTC address for the next hour. Good luck, and stay safe out there!” Soon after, the identical tweet was posted from the account of Microsoft co-founder Bill Gates’ account. Thereafter, a wave of tweets with the fake promotion was posted from accounts of personalities like Barack Obama, Kanye West, Joe Biden, Mike Bloomberg, and Warren Buffet. Twitter accounts of Apple, Uber, Square’s CashApp, and Coinbase were also hacked with the intent to post similar messages which contained a bitcoin wallet address that directed to the hackers.
While some of the scam tweets were taken down by Twitter, subsequent tweets followed that read, “Feeling grateful doubling all payments sent to my BTC address! You send $1,000, I send back $2,000! Only doing this for the next 30 minutes.” The BTC address of all the tweets from the hacked accounts was the same including on the tweets by the Cameron and Tyler Winklevoss’ Gemini cryptocurrency exchange. While Gemini claimed that its account was protected by two-factor authentication and the company used a strong password, the account was hacked into by the spammers that earned more than $55,000.
09:00 IST, July 16th 2020