2020 Twitter Account Hijacking
   HOME

TheInfoList



OR:

On July 15, 2020, between 20:00 and 22:00 UTC, reportedly 130 high-profile
Twitter Twitter is an online social media and social networking service owned and operated by American company Twitter, Inc., on which users post and interact with 280-character-long messages known as "tweets". Registered users can post, like, and ...
accounts were compromised by outside parties to promote a
bitcoin Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public distr ...
scam A confidence trick is an attempt to defraud a person or group after first gaining their trust. Confidence tricks exploit victims using their credulity, naïveté, compassion, vanity, confidence, irresponsibility, and greed. Researchers have def ...
. Twitter and other media sources confirmed that the perpetrators had gained access to Twitter's administrative tools so that they could alter the accounts themselves and post the tweets directly. They appeared to have used
social engineering Social engineering may refer to: * Social engineering (political science), a means of influencing particular attitudes and social behaviors on a large scale * Social engineering (security), obtaining confidential information by manipulating and/or ...
to gain access to the tools via Twitter employees. Three individuals were arrested by authorities on July 31, 2020, and charged with
wire fraud Mail fraud and wire fraud are terms used in the United States to describe the use of a physical or electronic mail system to fraud, defraud another, and are Federal crime in the United States, federal crimes there. Jurisdiction is claimed by the ...
,
money laundering Money laundering is the process of concealing the origin of money, obtained from illicit activities such as drug trafficking, corruption, embezzlement or gambling, by converting it into a legitimate source. It is a crime in many jurisdictions ...
,
identity theft Identity theft occurs when someone uses another person's personal identifying information, like their name, identifying number, or credit card number, without their permission, to commit fraud or other crimes. The term ''identity theft'' was co ...
, and unauthorized computer access related to the scam. The scam tweets asked individuals to send bitcoin currency to a specific
cryptocurrency wallet A cryptocurrency wallet is a device, physical medium, program or a service which stores the public and/or private keys for cryptocurrency transactions. In addition to this basic function of storing the keys, a cryptocurrency wallet more often a ...
, with the promise of the Twitter user that money sent would be doubled and returned as a charitable gesture. Within minutes from the initial tweets, more than 320 transactions had already taken place on one of the wallet addresses, and bitcoin to a value of more than had been deposited in one account before the scam messages were removed by Twitter. In addition, full message history data from eight non-verified accounts was also acquired.
Dmitri Alperovitch Dmitri Mikhailovich Alperovitch (born 1980) is a Soviet-born American think-tank founder, investor, philanthropist, podcast host and former computer security industry executive. He is the chairman of Silverado Policy Accelerator, a geopolitics th ...
, the co-founder of
cybersecurity Computer security, cybersecurity (cyber security), or information technology security (IT security) is the protection of computer systems and networks from attack by malicious actors that may result in unauthorized information disclosure, the ...
company
CrowdStrike CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides cloud workload and endpoint security, threat intelligence, and cyberattack response services. The company has been involved in inves ...
, described the incident as "the worst hack of a major social media platform yet." Security researchers expressed concerns that the social engineering used to execute the hack could affect the use of social media in important online discussions, including the lead-up into the
2020 United States presidential election The 2020 United States presidential election was the 59th quadrennial presidential election, held on Tuesday, November 3, 2020. The Democratic ticket of former vice president Joe Biden and the junior U.S. senator from California Kamala Ha ...
. On July 31, 2020, the
U.S. Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a federal executive department of the United States government tasked with the enforcement of federal law and administration of justice in the United State ...
announced charges against three individuals in connection with the incident.


Incident

Forensic Forensic science, also known as criminalistics, is the application of science to Criminal law, criminal and Civil law (legal system), civil laws, mainly—on the criminal side—during criminal investigation, as governed by the legal standard ...
analysis of the scam showed that the initial scam messages were first posted by accounts with short, one- or two-character distinctive names, such as "@6". This was followed by
cryptocurrency A cryptocurrency, crypto-currency, or crypto is a digital currency designed to work as a medium of exchange through a computer network that is not reliant on any central authority, such as a government or bank, to uphold or maintain it. It i ...
Twitter accounts at around 20:00 UTC on July 15, 2020, including those of
Coinbase Coinbase Global, Inc., branded Coinbase, is an American publicly traded company that operates a cryptocurrency exchange platform. Coinbase is a distributed company; all employees operate via remote work and the company lacks a physical headquar ...
,
CoinDesk ''CoinDesk'' is a news site specializing in bitcoin and digital currencies. ''CoinDesk'' also provides guides to bitcoin for those new to digital currencies. Founded by Shakil Khan, the site was subsequently acquired by Digital Currency Group. ...
and
Binance Binance is a cryptocurrency exchange which is the largest exchange in the world in terms of daily trading volume of cryptocurrencies. It was founded in 2017 and is registered in the Cayman Islands. Binance was founded by Changpeng Zhao, a deve ...
. The scam then moved to more high-profile accounts with the first such tweet sent from
Elon Musk Elon Reeve Musk ( ; born June 28, 1971) is a business magnate and investor. He is the founder, CEO and chief engineer of SpaceX; angel investor, CEO and product architect of Tesla, Inc.; owner and CEO of Twitter, Inc.; founder of The Bori ...
's Twitter account at 20:17 UTC. Other apparently compromised accounts included those of well-known individuals such as
Barack Obama Barack Hussein Obama II ( ; born August 4, 1961) is an American politician who served as the 44th president of the United States from 2009 to 2017. A member of the Democratic Party, Obama was the first African-American president of the U ...
, Joe Biden,
Bill Gates William Henry Gates III (born October 28, 1955) is an American business magnate and philanthropist. He is a co-founder of Microsoft, along with his late childhood friend Paul Allen. During his career at Microsoft, Gates held the positions ...
,
Jeff Bezos Jeffrey Preston Bezos ( ;; and Robinson (2010), p. 7. ''né'' Jorgensen; born January 12, 1964) is an American entrepreneur, media proprietor, investor, and commercial astronaut. He is the founder, executive chairman, and former preside ...
,
MrBeast Jimmy Donaldson (born May 7, 1998), better known as MrBeast, is an American YouTube personality, credited with pioneering a genre of YouTube videos that centers on expensive stunts. His MrBeast YouTube channel had 112.2 million subscribers as ...
,
Michael Bloomberg Michael Rubens Bloomberg (born February 14, 1942) is an American businessman, politician, philanthropist, and author. He is the majority owner, co-founder and CEO of Bloomberg L.P. He was Mayor of New York City from 2002 to 2013, and was a ca ...
,
Warren Buffett Warren Edward Buffett ( ; born August 30, 1930) is an American business magnate, investor, and philanthropist. He is currently the chairman and CEO of Berkshire Hathaway. He is one of the most successful investors in the world and has a net w ...
,
Floyd Mayweather Jr. Floyd Joy Mayweather Jr. (''né'' Sinclair; February 24, 1977) is an American boxing promoter and former professional boxer. He currently owns a team in the NASCAR Cup Series named The Money Team Racing. As a professional boxer he competed b ...
,
Kim Kardashian Kimberly Noel Kardashian (formerly West; born October 21, 1980) is an American socialite, media personality, and businesswoman. She first gained media attention as a friend and stylist of Paris Hilton, but received wider notice after the sex ...
, and
Kanye West Ye ( ; born Kanye Omari West ; June 8, 1977) is an American rapper, singer, songwriter, record producer, and fashion designer. Born in Atlanta and raised in Chicago, West gained recognition as a producer for Roc-A-Fella Records in the ea ...
; and companies such as
Apple An apple is an edible fruit produced by an apple tree (''Malus domestica''). Apple fruit tree, trees are agriculture, cultivated worldwide and are the most widely grown species in the genus ''Malus''. The tree originated in Central Asia, wh ...
,
Uber Uber Technologies, Inc. (Uber), based in San Francisco, provides mobility as a service, ride-hailing (allowing users to book a car and driver to transport them in a way similar to a taxi), food delivery (Uber Eats and Postmates), package ...
, and
Cash App Cash App (formerly Square Cash) is a mobile payment service available in the United States and the United Kingdom that allows users to transfer money to one another (for a 1.5% fee for immediate transfer) using a mobile phone app. In September 2 ...
. Twitter believed 130 accounts were affected, though only 45 were actually used to tweet the scam message; most of the accounts that were accessed in the scam had at least a million followers. The tweets involved in the scam hack claimed that the sender, in charity, would repay any user double the value of any bitcoin they sent to given wallets, often as part of a
COVID-19 Coronavirus disease 2019 (COVID-19) is a contagious disease caused by a virus, the severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2). The first known case was COVID-19 pandemic in Hubei, identified in Wuhan, China, in December ...
relief effort. The tweets followed the sharing of malicious links by a number of cryptocurrency companies; the website hosting the links was taken down shortly after the tweets were posted. While such "double your bitcoin" scams have been common on Twitter before, this is the first major instance of them being sent from breached high-profile accounts. Security experts believe that the perpetrators ran the scam as a "
smash and grab A smash and grab is a particular form of burglary or looting that involves smashing a barrier, usually a display window in a shop or a showcase, grabbing valuables, and then making a quick getaway, without concern for setting off alarms or creati ...
" operation: Knowing that the intrusion into the accounts would be closed quickly, the perpetrators likely planned that only a small fraction of the millions that follow these accounts needed to fall for the scam in that short time to make quick money from it. Multiple bitcoin wallets had been listed at these websites; the first one observed had received from over 320 transactions, valued at more than , and had about removed from it, while a second had amounts in only the thousands of dollars as Twitter took steps to halt the postings. It is unclear if these had been funds added by those led on by the scam, as bitcoin scammers are known to add funds to wallets prior to starting schemes to make the scam seem legitimate. Of the funds added, most had originated from wallets with Chinese ownerships, but about 25% came from United States wallets. After it was added, the cryptocurrency was then subsequently transferred through multiple accounts as a means to obscure their identity. Some of the compromised accounts posted scam messages repeatedly, even after having some of the messages deleted. The tweets were labelled as having been sent using the Twitter
Web app A web application (or web app) is application software that is accessed using a web browser. Web applications are delivered on the World Wide Web to users with an active network connection. History In earlier computing models like client-serve ...
. One of the phrases involved in the scam was tweeted more than 3,000 times in the space of four hours, with tweets being sent from
IP address An Internet Protocol address (IP address) is a numerical label such as that is connected to a computer network that uses the Internet Protocol for communication.. Updated by . An IP address serves two main functions: network interface ident ...
es linked to many different countries. The reused phrasing allowed Twitter to remove the offending tweets easily as they took steps to stop the scam. By 21:45 UTC, Twitter released a statement saying they were "aware of a security incident impacting accounts on Twitter" and that they were "taking steps to fix it". Shortly afterwards, it disabled the ability for some accounts to tweet, or to reset their password; Twitter has not confirmed which accounts were restricted, but many users with accounts Twitter had marked as "verified" confirmed that they were unable to tweet. Approximately three hours after the first scam tweets, Twitter reported they believed they had resolved all of the affected accounts to restore credentials to their rightful owners. Later that night, Twitter CEO
Jack Dorsey Jack Patrick Dorsey (born November 19, 1976) is an American Internet entrepreneur and programmer who is a co-founder and former CEO of Twitter, Inc., as well as a co-founder and the CEO and chairperson of Block, Inc., the developer of the Squar ...
said it was a "tough day for us at Twitter. We all feel terrible this happened. We're diagnosing and will share everything we can when we have a more complete understanding of exactly what happened." At least one cryptocurrency exchange, Coinbase, blacklisted the bitcoin addresses to prevent money from being sent. Coinbase said they stopped over 1,000 transactions totaling over from being sent. In addition to sending out tweets, the account data for eight compromised accounts was downloaded, including all created posts and direct messages, though none of these accounts belonged to verified users. Twitter also suspected that thirty-six other accounts had their direct messages accessed but not downloaded including Dutch Parliament Representative
Geert Wilders Geert Wilders (; born 6 September 1963) is a Dutch politician who has led the Party for Freedom (''Partij voor de Vrijheid'' – PVV) since he founded it in 2006. He is also the party's leader in the House of Representatives (''Tweede Kamer'' ...
, but believed no other current or former elected official had their messages accessed.


Method of attack

As Twitter was working to resolve the situation on July 15, ''
Vice A vice is a practice, behaviour, or habit generally considered immoral, sinful, criminal, rude, taboo, depraved, degrading, deviant or perverted in the associated society. In more minor usage, vice can refer to a fault, a negative character tra ...
'' was contacted by at least four individuals claiming to be part of the scam and presented the website with screenshots showing that they had been able to gain access to a Twitter administrative tool, also known as an "agent tool", that allowed them to change various account-level settings of some of the compromised accounts, including confirmation emails for the account. This allowed them to set email addresses which any other user with access to that email account could initiate a password reset and post the tweets. These hackers told ''Vice'' that they had paid insiders at Twitter to get access to the administrative tool to be able to pull this off. ''
TechCrunch TechCrunch is an American online newspaper focusing on high tech and startup companies. It was founded in June 2005 by Archimedes Ventures, led by partners Michael Arrington and Keith Teare. In 2010, AOL acquired the company for approximately ...
'' reported similarly, based on a source that stated some of the messages were from a member of the hacking forum OGUsers, who had claimed to have made over from it. According to ''TechCrunch'' source, this member "Kirk" had reportedly gained access to the Twitter administrative tool likely through a compromised employee account, and after initially offering to take over any account on request, switched strategies to target cryptocurrency accounts starting with Binance and then higher-profile ones. The source did not believe Kirk had paid a Twitter employee for access. The "@6" Twitter had belonged to
Adrian Lamo Adrián Alfonso Lamo Atwood (February 20, 1981 – March 14, 2018) was an American threat analyst and hacker. Lamo first gained media attention for breaking into several high-profile computer networks, including those of ''The New York Times'', ...
, and the user maintaining the account on behalf of Lamo's family reported that the group that performed the hack were able to bypass numerous security factors they had set up on the account, including
two-factor authentication Multi-factor authentication (MFA; encompassing two-factor authentication, or 2FA, along with similar terms) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting ...
, further indicating that the administrative tools had been used to bypass the account security. Spokespersons for the
White House The White House is the official residence and workplace of the president of the United States. It is located at 1600 Pennsylvania Avenue NW in Washington, D.C., and has been the residence of every U.S. president since John Adams in 1800. ...
stated that President
Donald Trump Donald John Trump (born June 14, 1946) is an American politician, media personality, and businessman who served as the 45th president of the United States from 2017 to 2021. Trump graduated from the Wharton School of the University of Pe ...
's account, which may have been a target, had extra security measures implemented at Twitter after an incident in 2017, and therefore was not affected by the scam. ''Vice''s and ''
TechCrunch TechCrunch is an American online newspaper focusing on high tech and startup companies. It was founded in June 2005 by Archimedes Ventures, led by partners Michael Arrington and Keith Teare. In 2010, AOL acquired the company for approximately ...
'' sources were corroborated by ''
The New York Times ''The New York Times'' (''the Times'', ''NYT'', or the Gray Lady) is a daily newspaper based in New York City with a worldwide readership reported in 2020 to comprise a declining 840,000 paid print subscribers, and a growing 6 million paid ...
'', who spoke to similar persons involved with the events, and from other security researchers who had been given similar screens, and tweets of these screens had been made, but Twitter removed these since they revealed personal details of the compromised accounts. ''
The New York Times ''The New York Times'' (''the Times'', ''NYT'', or the Gray Lady) is a daily newspaper based in New York City with a worldwide readership reported in 2020 to comprise a declining 840,000 paid print subscribers, and a growing 6 million paid ...
'' further affirmed that the vector of the attack was related to most of the company
remote work Remote work, also called work from home (WFH), work from anywhere, telework, remote job, mobile work, and distance work is an employment arrangement in which employees do not commute to a central place of work, such as an office building, ware ...
ing during the
COVID-19 pandemic The COVID-19 pandemic, also known as the coronavirus pandemic, is an ongoing global pandemic of coronavirus disease 2019 (COVID-19) caused by severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2). The novel virus was first identif ...
. The OGUsers members were able to gain access to the Twitter employees' Slack communications channel where information and authorization processes on accessing the company's servers while
remote work Remote work, also called work from home (WFH), work from anywhere, telework, remote job, mobile work, and distance work is an employment arrangement in which employees do not commute to a central place of work, such as an office building, ware ...
ing had been pinned. Twitter subsequently confirmed that the scam involved
social engineering Social engineering may refer to: * Social engineering (political science), a means of influencing particular attitudes and social behaviors on a large scale * Social engineering (security), obtaining confidential information by manipulating and/or ...
, stating "We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools." In addition to taking further steps to lock down the verified accounts affected, Twitter said they have also begun an internal investigation and have limited employee access to their system administrative tools as they evaluate the situation, as well as if any additional data was compromised by the malicious users. By the end of July 17, 2020, Twitter affirmed what had been learned from these media sources, stating that "The attackers successfully manipulated a small number of employees and used their credentials to access Twitter's internal systems, including getting through our two-factor protections. As of now, we know that they accessed tools only available to our internal support teams." Twitter had been able to further confirm by July 30 that the method used was what they called a "phone spear phishing attack": they initially used social engineering to breach the credentials of lower-level Twitter employees who did not have access to the admin tools, and then using those employee accounts, engaged in additional social engineering attacks to get the credentials to the admin tools from employees who did have authorization for their use. ''
Bloomberg News Bloomberg News (originally Bloomberg Business News) is an international news agency headquartered in New York City and a division of Bloomberg L.P. Content produced by Bloomberg News is disseminated through Bloomberg Terminals, Bloomberg Televi ...
'', after investigation with former and current Twitter employees, reported that as many as 1500 Twitter employees and partners had access to the admin tools that would allow for the ability to reset accounts as had been done during the incident. Former Twitter employees had told ''Bloomberg'' that even as late as 2017 and 2018, those with access would make a game of using these tools to track famous celebrities though the amount of data visible through the tools alone was limited to elements like
IP address An Internet Protocol address (IP address) is a numerical label such as that is connected to a computer network that uses the Internet Protocol for communication.. Updated by . An IP address serves two main functions: network interface ident ...
and
geolocation Geopositioning, also known as geotracking, geolocalization, geolocating, geolocation, or geoposition fixing, is the process of determining or estimating the geographic position of an object. Geopositioning yields a set of Geographic coordinate s ...
information. A Twitter spokesperson told ''Bloomberg'' that they do use "extensive security training and managerial oversight" to manage employees and partners with access to the tools, and that there was "no indication that the partners we work with on customer service and account management played a part here". Former members of Twitter's security departments stated that since 2015, the company was alerted to the potential from an inside attack and other cybersecurity measures, but these were put aside in favor of more revenue-generating initiatives. ''
Ars Technica ''Ars Technica'' is a website covering news and opinions in technology, science, politics, and society, created by Ken Fisher and Jon Stokes in 1998. It publishes news, reviews, and guides on issues such as computer hardware and software, sci ...
'' obtained a more detailed report from a researcher who worked with FBI on the investigation. According to this report, attackers scraped
LinkedIn LinkedIn () is an American business and employment-oriented online service that operates via websites and mobile apps. Launched on May 5, 2003, the platform is primarily used for professional networking and career development, and allows job se ...
in search for Twitter employees likely to have administrator privileges account-holder tools. Then attackers obtained these employees' cell phone numbers and other private contact information via paid tools LinkedIn makes available to job recruiters. After choosing victims for the next stage, attackers contacted Twitter employees, most who were
remote work Remote work, also called work from home (WFH), work from anywhere, telework, remote job, mobile work, and distance work is an employment arrangement in which employees do not commute to a central place of work, such as an office building, ware ...
ing due to the
COVID-19 pandemic The COVID-19 pandemic, also known as the coronavirus pandemic, is an ongoing global pandemic of coronavirus disease 2019 (COVID-19) caused by severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2). The novel virus was first identif ...
, and, using the information from LinkedIn and other public sources, pretended to be Twitter personnel. Attackers directed victims to log into a fake internal Twitter VPN. To bypass two-factor authentication, attackers entered stolen credentials into the real Twitter VPN portal, and "within seconds of the employees entering their info into the fake one", asked victims for the two-factor authentication code.


Perpetrators

Security researcher
Brian Krebs Brian Krebs (born 1972) is an American journalist and investigative reporter. He is best known for his coverage of profit-seeking cybercriminals.Perlroth, Nicole.Reporting From the Web's Underbelly. ''The New York Times''. Retrieved February 28, ...
corroborated with ''
TechCrunch TechCrunch is an American online newspaper focusing on high tech and startup companies. It was founded in June 2005 by Archimedes Ventures, led by partners Michael Arrington and Keith Teare. In 2010, AOL acquired the company for approximately ...
'' source and with information obtained by
Reuters Reuters ( ) is a news agency owned by Thomson Reuters Corporation. It employs around 2,500 journalists and 600 photojournalists in about 200 locations worldwide. Reuters is one of the largest news agencies in the world. The agency was estab ...
that the scam appeared to have originated in the "OGUsers" group. The OGUsers forum ("OG" standing for "original") was established for selling and buying social media accounts with short or "rare" names, and according to its owner, speaking to Reuters, the practice of trafficking in hacked credentials was prohibited. Screenshots from the forum show various users on the forum offering to hack into Twitter accounts at each. Krebs stated one of the members might have been tied to the August 2019 takeover of Twitter CEO Jack Dorsey's Twitter account. The OGUsers owner told Reuters that the accounts shown in the screenshots were since banned. The FBI announced on July 16 it was launching an investigation into the scam, as it was used to "perpetuate cryptocurrency fraud", a criminal offense. The
Senate Select Committee on Intelligence The United States Senate Select Committee on Intelligence (sometimes referred to as the Intelligence Committee or SSCI) is dedicated to overseeing the United States Intelligence Community—the agencies and bureaus of the federal government of ...
also planned to ask Twitter for additional information on the hack, as the committee's vice-chair
Mark Warner Mark Robert Warner (born December 15, 1954) is an American businessman and politician serving as the senior United States senator from Virginia, a seat he has held since 2009. A member of the Democratic Party, Warner served as the 69th governo ...
stated "The ability of bad actors to take over prominent accounts, even fleetingly, signals a worrisome vulnerability in this media environment, exploitable not just for scams but for more impactful efforts to cause confusion, havoc and political mischief". The UK's National Cyber Security Centre said its officers had reached out to Twitter regarding the incident. BitTorrent CEO
Justin Sun Justin Sun (Chinese: 孙宇晨; pinyin: Sūn Yǔchén; born July 30, 1990) is a Chinese cryptocurrency entrepreneur, and business executive. He is the founder of Tron (founded July 2017), a blockchain DAO ecosystem. Sun is the Permanent Represen ...
announced a bounty against the hackers, with his company's Twitter account stating "He will personally pay those who successfully track down, and provide evidence for bringing to justice, the hackers/people behind this hack affecting our community." The
United States Department of Justice The United States Department of Justice (DOJ), also known as the Justice Department, is a federal executive department of the United States government tasked with the enforcement of federal law and administration of justice in the United State ...
announced the arrest and charges of three individuals tied to the scam on July 31, 2020. A 19-year-old from the United Kingdom was charged with multiple counts of conspiracy to commit wire fraud, conspiracy to commit
money laundering Money laundering is the process of concealing the origin of money, obtained from illicit activities such as drug trafficking, corruption, embezzlement or gambling, by converting it into a legitimate source. It is a crime in many jurisdictions ...
, and the intentional access of a protected computer and a 22-year-old from Florida was charged with aiding and abetting the international access. Both will be tried in the
United States District Court for the Northern District of California The United States District Court for the Northern District of California (in case citations, N.D. Cal.) is the federal United States district court whose jurisdiction comprises the following counties of California: Alameda, Contra Costa, Del ...
. A third individual, Graham Ivan Clark, of
Hillsborough County, Florida Hillsborough County is located in the west central portion of the U.S. state of Florida. In the 2020 census, the population was 1,459,762, making it the fourth-most populous county in Florida and the most populous county outside the Miami metrop ...
, was also indicted; the charges were originally sealed in juvenile court, but he was eventually charged as an adult on 30 felony counts. The charges included organized fraud, communications fraud, identity theft, and hacking. Florida state law allows for trying minors as adults in financial fraud cases. Clark pleaded not guilty to the charges on August 4, 2020. He accepted a plea bargain in March 2021 and was sentenced to 3 years in prison followed by 3 years of probation; he was sentenced under Florida’s Youthful Offender Act, which limits the penalties on convicted felons under the age of 21. According to the
Tampa Bay Times The ''Tampa Bay Times'', previously named the ''St. Petersburg Times'' until 2011, is an American newspaper published in St. Petersburg, Florida, United States. It has won fourteen Pulitzer Prizes since 1964, and in 2009, won two in a single y ...
, he would be able to "to serve some of his time in a military-style boot camp". A fourth individual, a 16-year-old from
Massachusetts Massachusetts (Massachusett language, Massachusett: ''Muhsachuweesut assachusett writing systems, məhswatʃəwiːsət'' English: , ), officially the Commonwealth of Massachusetts, is the most populous U.S. state, state in the New England ...
, had been identified as a possible suspect in the scam by the
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and its principal Federal law enforcement in the United States, federal law enforcement age ...
. Though federal agents had conducted a warranted search of his possessions in late August 2020, no indictments have been made yet.


Reaction and aftermath

Affected users could only retweet content, leading
NBC News NBC News is the news division of the American broadcast television network NBC. The division operates under NBCUniversal Television and Streaming, a division of NBCUniversal, which is, in turn, a subsidiary of Comcast. The news division's var ...
to set up a temporary non-verified account so that they could continue to tweet, retweeting "significant updates" on their main account. Some
National Weather Service The National Weather Service (NWS) is an Government agency, agency of the Federal government of the United States, United States federal government that is tasked with providing weather forecasts, warnings of hazardous weather, and other weathe ...
forecast offices were unable to tweet severe weather warnings, with the National Weather Service in Lincoln, Illinois initially unable to tweet a
tornado warning A tornado warning ( SAME code: TOR) is a severe weather warning product issued by regional offices of weather forecasting agencies throughout the world to alert the public when a tornado has been reported or indicated by weather radar within the ...
. Joe Biden's campaign stated to
CNN CNN (Cable News Network) is a multinational cable news channel headquartered in Atlanta, Georgia, U.S. Founded in 1980 by American media proprietor Ted Turner and Reese Schonfeld as a 24-hour cable news channel, and presently owned by the M ...
that they were "in touch with Twitter on the matter", and that his account had been "locked down". Google temporarily disabled its Twitter carousel in its search feature as a result of these security issues. During the incident, Twitter, Inc.'s stock price fell by 4% after the markets closed. By the end of the next day, Twitter, Inc.'s stock price ended at $36.40, down 38 cents, or 0.87%. Security experts expressed concern that while the scam may have been relatively small in terms of financial impact, the ability for social media to be taken over through
social engineering Social engineering may refer to: * Social engineering (political science), a means of influencing particular attitudes and social behaviors on a large scale * Social engineering (security), obtaining confidential information by manipulating and/or ...
involving employees of these companies poses a major threat in the use of social media particularly in the lead-up to the
2020 United States presidential election The 2020 United States presidential election was the 59th quadrennial presidential election, held on Tuesday, November 3, 2020. The Democratic ticket of former vice president Joe Biden and the junior U.S. senator from California Kamala Ha ...
, and could potentially cause an international incident.
Alex Stamos Alex Stamos is a Greek American computer scientist and adjunct professor at Stanford University's Center for International Security and Cooperation. He is the former chief security officer (CSO) at Facebook. His planned departure from the compan ...
of
Stanford University Stanford University, officially Leland Stanford Junior University, is a private research university in Stanford, California. The campus occupies , among the largest in the United States, and enrolls over 17,000 students. Stanford is consider ...
's
Center for International Security and Cooperation Stanford University has many centers and institutes dedicated to the study of various specific topics. These centers and institutes may be within a department, within a school but across departments, an independent laboratory, institute or center ...
said, "Twitter has become the most important platform when it comes to discussion among political elites, and it has real vulnerabilities." Twitter chose to delay the rolling out of its new
API An application programming interface (API) is a way for two or more computer programs to communicate with each other. It is a type of software Interface (computing), interface, offering a service to other pieces of software. A document or standa ...
in the aftermath of the security issues. By September, Twitter stated they had put new protocols in place to prevent similar social engineering attacks, including heightening background checks for employees that would have access to the key user data, implementing phishing-resistant security keys to use this day, and having all employees involved in customer support participate in training to be aware of future social engineering scams. Though not part of the Twitter incident,
Steve Wozniak Stephen Gary Wozniak (; born August 11, 1950), also known by his nickname "Woz", is an American electronics engineer, computer programmer, philanthropist, inventor, and technology entrepreneur. In 1976, with business partner Steve Jobs, he c ...
and seventeen others initiated a lawsuit against
Google Google LLC () is an American multinational technology company focusing on search engine technology, online advertising, cloud computing, computer software, quantum computing, e-commerce, artificial intelligence, and consumer electronics. ...
the following week, asserting that the company did not take sufficient steps to remove similar Bitcoin scam videos posted to
YouTube YouTube is a global online video platform, online video sharing and social media, social media platform headquartered in San Bruno, California. It was launched on February 14, 2005, by Steve Chen, Chad Hurley, and Jawed Karim. It is owned by ...
that used his and the other plaintiffs' names, fraudulently claiming to back the scam. Wozniak's complaint identified that Twitter was able to act within the same day, while he and the other plaintiffs' requests to Google had never been acted upon. On September 29, 2020, Twitter hired Rinki Sethi as CISO and VP of the company after the breach. On November 20, 2020,
Hulu Hulu () is an American subscription streaming service majority-owned by The Walt Disney Company, with Comcast's NBCUniversal holding a minority stake. It was launched on October 29, 2007 and it offers a library of films and television serie ...
aired the 5th episode of "The New York Times Presents" series entitled "The Teenager Who Hacked Twitter," which details the events of this incident.


References


External links


Ongoing updates from Twitter
on investigation into the intrusion on its systems, what had been accessed, and their steps to correct and prevent similar attacks.
Overview of the bitcoin address' transactions
{{Bitcoin Bitcoin Cryptocurrency theft Criticisms of software and websites
Twitter Twitter is an online social media and social networking service owned and operated by American company Twitter, Inc., on which users post and interact with 280-character-long messages known as "tweets". Registered users can post, like, and ...
Hacking in the 2020s July 2020 crimes Confidence tricks Twitter controversies