Twitter Hacking Spree Alarms Experts Concerned About the Platform's Security

Twitter said late Wednesday hackers obtained control of employee credentials to hijack accounts including those of US presidential candidate Joe Biden.

Advertisement
By Reuters | Updated: 16 July 2020 12:16 IST
Highlights
  • The hackers took about $120,000 worth of bitcoins
  • The damage to Twitter's reputation may be more serious
  • Wednesday's hack was the worst to date

Twitter said it was not yet certain what the hackers may have done beyond sending the bitcoin messages

The extraordinary hacking spree that hit Twitter on Wednesday, leading it to briefly muzzle some of its most widely followed accounts, is drawing questions about the platform's security and resilience in the run-up to the US presidential election.

Twitter said late Wednesday hackers obtained control of employee credentials to hijack accounts including those of Democratic presidential candidate Joe Biden, former president Barack Obama, reality television star Kim Kardashian, and tech billionaire and Tesla founder Elon Musk.

Advertisement

In a series of tweets, the company said: "We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools."

We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools.

Advertisement

— Twitter Support (@TwitterSupport) July 16, 2020

The hackers then "used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf."

Advertisement

The company statements confirmed the fears of security experts that the service itself - rather than users - had been compromised.

Twitter's role as a critical communications platform for political candidates and public officials, including President Donald Trump, has led to fears that hackers could wreak havoc with the November 3 presidential election or otherwise compromise national security.

Advertisement

Adam Conner, vice president for technology policy at the Center for American Progress, a liberal think-tank, said on Twitter: "This is bad on July 15 but would be infinitely worse on November 3rd."

Bitcoin Bounty

Posing as celebrities and the wealthy, the hackers asked followers to send the digital currency bitcoin to a series of addresses. By evening, 400 bitcoin transfers were made worth a combined $120,000 (roughly Rs. 90,29,300). Half of the victims had funds in US bitcoin exchanges, a quarter in Europe and a quarter in Asia, according to forensics company Elliptic.

Those transfers left history that could help investigators identify the perpetrators of the hack. The financial damage may be limited because multiple exchanges blocked other payments after their own Twitter accounts were targeted.

The damage to Twitter's reputation may be more serious. Most troubling to some was how long the company took to stop the bad tweets.

"Twitter's response to this hack was astonishing. It's the middle of the day in San Francisco, and it takes them five hours to get a handle on the incident," said Dan Guido, CEO of security company Trail of Bits.

An even worse scenario was that the bitcoin fraud was a distraction for more serious hacking, such as harvesting the direct messages of the account holders.

Twitter said it was not yet certain what the hackers may have done beyond sending the bitcoin messages.

"We're looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it," the company said.

Mass compromises of Twitter accounts via theft of employee credentials or problems with third-party applications that many users employ have occured before.

Wednesday's hack was the worst to date. Several users with two-factor authentication - a security procedure that helps prevent break-in attempts - said they were powerless to stop it.

"If the hackers do have access to the backend of Twitter, or direct database access, there is nothing potentially stopping them from pilfering data in addition to using this tweet-scam as a distraction," said Michael Borohovski, director of software engineering at security company Synopsys.

© Thomson Reuters 2020


Poco M2 Pro: Did we really need a Redmi Note 9 Pro clone? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Also seeCryptocurrency Prices across Indian exchanges

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Twitter, Twitter Hack, Bitcoin
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Poco X8 Pro Series Could Cost in India
  2. Vivo T5x 5G Goes Official in India With 7,200mAh Battery
  3. Oppo K14 5G Debuts With 7,000mAh Battery at This Price in India
  4. Samsung Could Equip Galaxy Z Fold 8, Wide Fold With These Batteries
  5. Claude Is Doubling the Usage Limits for the Next Two Weeks: Details
  6. Poco X8 Pro Series Camera, Display Features Revealed a Day Before Launch
  7. Samsung Galaxy Z TriFold Sales to Wind Down Just Three Months After Launch
  8. Oura Ring 4 Launched as Company's First Smart Ring in India at This Price
  9. Samsung Galaxy M17e 5G Debuts With 6,000mAh Battery at This Price in India
  10. Sony's Upgraded PSSR Upscaler Is Now Rolling Out to More Games on PS5 Pro
  1. Oura Ring 4 Launched in India With Smart Sensing Technology and HRV Tracking: Price, Specifications
  2. Sony's Upgraded PSSR Upscaler Is Rolling Out to Silent Hill f, Crimson Desert and More Games on PS5 Pro
  3. Google, Amazon, Microsoft and Others Join Hands to Fight Online Scams and Fraud
  4. Oppo K14 5G Launched in India With 7,000mAh Battery, 50-Megapixel Camera: Price, Specifications
  5. Operation Atlantic: Canada, UK and US Conduct Joint Operation to Disrupt Crypto Fraud Networks
  6. Samsung Galaxy Z TriFold Sales Set to End Just Three Months After Launch: Report
  7. Samsung Galaxy Z Fold 8, Wide Fold to Feature Larger Batteries Than Last Year’s Galaxy Z Fold 7: Report
  8. Peaky Blinders: The Immortal Man OTT Release Date: Know When and Where to Watch This Film Online
  9. Seetha Payanam OTT Release Date: When and Where to Watch Aishwarya Sarja’s Romantic Film Online?
  10. The Family McMullen Out on OTT: Know Where to Watch it Online?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.