Skip to main content

Twitter employees gave their log-in credentials to hackers in July when they were fooled into thinking those individuals were from the company’s IT department, a state agency in New York said Wednesday, leading to a massive hack into several high-profile accounts.

The scheme, which was promptly stopped, allowed the hackers to briefly control the accounts of several high-profile politicians and celebrities, like Joe Biden and Elon Musk.

The hackers called on their followers to send them money through a link, which ended up generating $118,000 in cryptocurrency before the attack was neutralized. Users were asked to make their payments to those accounts in bitcoins.

But the hackers didn’t have to develop a complicated attack on the social media network’s system to gain access to those accounts, the state Department of Financial Services said.

The hackers literally called employees of the social media giant and asked for their log-in credentials, which allowed them access to accounts with millions of followers. They claimed to be part of the company’s IT department.

The hackers, according to DFS, claimed to be investigating an issue with the company’s internal network. They directed the employees to a fake website, which looked like the real website for Twitter employees, and asked them to enter their credentials.

The information entered into the fake website was then used by the hackers to access the real Twitter internal network, DFS said.

After gaining access to the network, the hackers used it to gain access to several user accounts. Overall, 130 accounts were compromised during the attack, and 45 were used to send tweets, the agency said.

Linda Lacewell, the superintendent of DFS, said the incident is indicative of the need for stronger federal and state cybersecurity standards regulations over social media platforms.

“Social media platforms have quickly become the leading source of news and information, yet no regulator has adequate oversight of their cybersecurity,” Lacewell said. “The fact that Twitter was vulnerable to an unsophisticated attack shows that self-regulation is not the answer.”

At the time of the attack, Twitter did not have adequate security monitors to prevent the attack, the agency said. That’s evidence that stronger government oversight is needed, the agency said.

Twitter had already committed to beefing up its cybersecurity protections in September, but a spokesperson said again Wednesday that the company is continuing to improve its defenses against future attacks.

“We will continue to prioritize and accelerate our efforts to increase the security of our platform and how our teams work,” the spokesperson said. “We have been continuously investing in improvements to our teams and our technology that enable people to use Twitter securely. This work is constant and always evolving.”

Related

PBS NewsHour
What high-profile hacking attacks say about cybersecurity
8:48
Published:

What high-profile hacking attacks say about cybersecurity