All vulnerabilities
HIGHOpSec

OPSEC-TWITTER-2020

Social media · Twitter

Summary

On July 15, 2020, attackers ran a coordinated phone spear-phishing (vishing) campaign against a small number of Twitter employees, gathering employee details and tricking staff into surrendering credentials that gave access to Twitter's internal account-management admin tools. Using the admin tool, they took over high-profile accounts (changing associated emails and bypassing 2FA), targeting 130 accounts, tweeting from 45, accessing DM inboxes for 36, and downloading full account data for 7. Compromised accounts included Obama, Biden, Musk, Gates, Bezos, and Apple. A Bitcoin doubling scam netted over $100,000, and three people were charged, including the alleged 17-year-old mastermind.

References

Related vulnerabilities

All OpSec →