Skip to main content
  1. Home
  2. Social Media
  3. News

Twitter offers more details on how hackers cracked its internal systems

Add as a preferred source on Google
 

Twitter has shared another update on its investigation into the major hack that targeted numerous high-profile accounts on its platform on July 15.

Recommended Videos

In a blog post and series of tweets, the company said the perpetrators began by targeting a small number of employees through a phone spear phishing attack. This involves a hacker calling a target and pretending to be a trusted person to extract specific information that ultimately enables them to gain entry to an internal computer system.

“A successful attack required the attackers to obtain access to both our internal network as well as specific employee credentials that granted them access to our internal support tools,” Twitter said in its blog post. “Not all of the employees that were initially targeted had permissions to use account management tools, but the attackers used their credentials to access our internal systems and gain information about our processes.”

It said that this knowledge “then enabled them to target additional employees who did have access to our account support tools. Using the credentials of employees with access to these tools, the attackers targeted 130 Twitter accounts, ultimately Tweeting from 45, accessing the DM inbox of 36, and downloading the Twitter Data of 7.”

Targeted accounts included those of prominent political figures such as former President Barack Obama and former Vice President Joe Biden, as well as the likes of Tesla and SpaceX CEO Elon Musk, Microsoft co-founder Bill Gates, and celebrity Kanye West.

The company said that although its internal tools, controls, and processes are constantly being updated and improved, it’s now “taking a hard look” at how it can make them more secure.

Mindful of the concern the attack has caused among the Twitter community, the company insisted, “Everyone at Twitter is committed to keeping your information safe. We recognize the trust you place in us, and are committing to earning it by continued open, honest and timely updates anytime an incident like this happens.”

The scam involved a fake tweet that appeared on the targeted accounts that encouraged followers to send payments to a Bitcoin wallet, with hundreds of people doing just that. When Twitter spotted the attack, it locked down the affected accounts and removed the bogus tweets.

Last week the incident took a darker turn when it emerged that the hackers had been able to download data linked to some of the accounts, and also managed to obtain access to the direct messages of others.

Twitter has promised to provide a more detailed report on the incident once law enforcement has made more progress with its investigation and after the company has completed work to further safeguard the microblogging service.

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Child abuse material continues to surface on X despite Elon Musk’s promises
New investigation claims several previously flagged child abuse images were found on X.
X-logo

Elon Musk once called removing child sexual abuse material from X his top priority. Yet new investigations suggest the platform still struggles to keep known abusive content offline. Reviews by The New York Times and the Canadian Center for Child Protection found previously flagged material on X, while Grok generated sexualized images involving children earlier this year.

Grok generated images involving known abuse victims

Read more
Researchers warn that social media can reveal sensitive details about users
Social media activity can reveal your politics, religion, and shopping habits, researchers warn
Social Media

What you post online is only part of the story. A new review of research into social media privacy warns that platforms and third parties can potentially infer sensitive details about people from seemingly ordinary digital activity, including their political opinions, religious leanings and shopping habits.

The findings, as reported by Techxplore, published in the International Journal of Management Concepts and Philosophy, point to a widening gap between the amount of personal information generated online and the legal and ethical protections designed to safeguard it. The researchers examined privacy breaches, regulatory frameworks, and the responsibilities of both social media companies and their users.

Read more
Instagram scammers are holding creators’ accounts hostage with copyright strikes
Meta’s copyright system is being weaponized against the creators it’s supposed to protect
A person holding a phone with the Instagram app open on it.

Imagine waking up to find your Instagram account suspended because someone claims you stole their content. You might know that the claim is false, but appealing it could take weeks. If you're a content creator, each day offline could cost you money. Meanwhile, the person behind the complaint offers to make the problem disappear for just a few hundred dollars.

According to a new BBC investigation, Instagram creators are being hit with this new online racket. Scammers are filing bogus copyright complaints and demanding payment to withdraw them, exploiting the fact that repeated claims can put an account at risk of suspension. The account owner may still have their password and login credentials, but that does little good when their content or account has been taken offline.

Read more