Twitter mass hacking: Bill Gates, Elon Musk, Jeff Bezos, Mike Bloomberg, Biden, Obama, more hijacked to peddle Bitcoin scam
(2020/07/15)
- Reference: 1594851687
- News link: https://www.theregister.co.uk/2020/07/15/mass_twitter_account_hacking_bitcoin/
- Source link:
Updated The Twitter accounts of Microsoft co-founder Bill Gates, Tesla CEO Elon Musk, and other celebrities were briefly taken over on Wednesday, along with the accounts of various cryptocurrency businesses and affiliated executives, to promote a Bitcoin scam. Fellow twits were told by the A-list stars to transfer BTC to the celebs, who would then transfer back double the amount.
Here's what Twitter had to say about the shenanigans:
You may be unable to Tweet or reset your password while we review and address this incident. — Twitter Support (@TwitterSupport) [1]July 15, 2020
The accounts of Apple, Uber, Amazon CEO Jeff Bezos, celebrity Kanye West, billionaire Michael Bloomberg, President Barack Obama, former Vice President Joe Biden, and others were among those violated by an unidentified hacker or hackers. "Everyone is asking me to give back, and now is the time," read a message posted to Gates's Twitter account. "I am doubling all payments sent to my BTC address for the next 30 minutes. You send $1,000, I send you back $2,000."
Here's what Elon Musk's hijacked Twitter feed looked like:
[2]
Scam ... The message posted on Musk's account. Click to enlarge
The tweets, since removed, included a BTC address for those who somehow believed they might be able to double their money by sending it to the listed BTC address and hoping for the best. The [3]address in question has received over $110,000 worth of BTC and had a balance close to that on Wednesday afternoon, Pacific Time.
Similar Bitcoin solicitations appeared on the accounts of Binance, Coinbase, Gemini, Kucoin, Coindesk, Litecoin's Charlie Lee, Tron's Justin Sunand, and others. Twitter also silenced verified blue-tick accounts temporarily to prevent more abuse while it got to the bottom of the kerfuffle.
It is unclear how the accounts were hijacked, though it was noticed that at least some of the commandeered profiles had their registered email addresses changed, suggesting someone was able to go through high-profile accounts, change the email addresses and potentially disable multi-factor authentication, reset the passwords, and get in to tweet the Bitcoin-harvesting scam:
Yep! Crazy - looks like a full takeover/hijack [4]pic.twitter.com/toug6PYnYr — harrydenley.eth ◊ (@sniko_) [5]July 15, 2020
It is feared miscreants gained control of some kind of internal control panel at Twitter, such as a support system, and used it to change account details to take celebrities' profiles on a joyride.
Twitter said in an email to The Register that it is looking into the situation and plans to issue a statement when it knows more. Meanwhile, US Senator Josh Hawley (R-MO) has [6]demanded a full explanation from Twitter CEO Jack Dorsey. ®
Updated to add
Leaked yet unconfirmed screenshots are now circulating among infosec bods of an internal Twitter account control panel that may have been abused, by a rogue insider or outside miscreant, to change the registered email address of profiles so that they could be hijacked. Twitter is said to be removing these screenshots from its social network, and suspending accounts that share them, for violating its terms of use.
One example screenshot is below:
this is unconfirmed again but, maybe this is how it was done all thanks to [7]@UnderTheBreach for the original
I've redacted it a bunch to remove PII [8]pic.twitter.com/7Df20n3h4N — Oliver Hough (@olihough86) [9]July 15, 2020
Get our [10]Tech Resources
[1] https://twitter.com/TwitterSupport/status/1283526400146837511?ref_src=twsrc%5Etfw
[2] https://regmedia.co.uk/2020/07/15/screenshot_elon_musk_twitter_hacked.jpg
[3] https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh?page=1
[4] https://t.co/toug6PYnYr
[5] https://twitter.com/sniko_/status/1283485972286656517?ref_src=twsrc%5Etfw
[6] https://twitter.com/ssharmaTX/status/1283530654588731392
[7] https://twitter.com/UnderTheBreach?ref_src=twsrc%5Etfw
[8] https://t.co/7Df20n3h4N
[9] https://twitter.com/olihough86/status/1283541067955163137?ref_src=twsrc%5Etfw
[10] https://whitepapers.theregister.com/
Here's what Twitter had to say about the shenanigans:
You may be unable to Tweet or reset your password while we review and address this incident. — Twitter Support (@TwitterSupport) [1]July 15, 2020
The accounts of Apple, Uber, Amazon CEO Jeff Bezos, celebrity Kanye West, billionaire Michael Bloomberg, President Barack Obama, former Vice President Joe Biden, and others were among those violated by an unidentified hacker or hackers. "Everyone is asking me to give back, and now is the time," read a message posted to Gates's Twitter account. "I am doubling all payments sent to my BTC address for the next 30 minutes. You send $1,000, I send you back $2,000."
Here's what Elon Musk's hijacked Twitter feed looked like:
[2]
Scam ... The message posted on Musk's account. Click to enlarge
The tweets, since removed, included a BTC address for those who somehow believed they might be able to double their money by sending it to the listed BTC address and hoping for the best. The [3]address in question has received over $110,000 worth of BTC and had a balance close to that on Wednesday afternoon, Pacific Time.
Similar Bitcoin solicitations appeared on the accounts of Binance, Coinbase, Gemini, Kucoin, Coindesk, Litecoin's Charlie Lee, Tron's Justin Sunand, and others. Twitter also silenced verified blue-tick accounts temporarily to prevent more abuse while it got to the bottom of the kerfuffle.
It is unclear how the accounts were hijacked, though it was noticed that at least some of the commandeered profiles had their registered email addresses changed, suggesting someone was able to go through high-profile accounts, change the email addresses and potentially disable multi-factor authentication, reset the passwords, and get in to tweet the Bitcoin-harvesting scam:
Yep! Crazy - looks like a full takeover/hijack [4]pic.twitter.com/toug6PYnYr — harrydenley.eth ◊ (@sniko_) [5]July 15, 2020
It is feared miscreants gained control of some kind of internal control panel at Twitter, such as a support system, and used it to change account details to take celebrities' profiles on a joyride.
Twitter said in an email to The Register that it is looking into the situation and plans to issue a statement when it knows more. Meanwhile, US Senator Josh Hawley (R-MO) has [6]demanded a full explanation from Twitter CEO Jack Dorsey. ®
Updated to add
Leaked yet unconfirmed screenshots are now circulating among infosec bods of an internal Twitter account control panel that may have been abused, by a rogue insider or outside miscreant, to change the registered email address of profiles so that they could be hijacked. Twitter is said to be removing these screenshots from its social network, and suspending accounts that share them, for violating its terms of use.
One example screenshot is below:
this is unconfirmed again but, maybe this is how it was done all thanks to [7]@UnderTheBreach for the original
I've redacted it a bunch to remove PII [8]pic.twitter.com/7Df20n3h4N — Oliver Hough (@olihough86) [9]July 15, 2020
Get our [10]Tech Resources
[1] https://twitter.com/TwitterSupport/status/1283526400146837511?ref_src=twsrc%5Etfw
[2] https://regmedia.co.uk/2020/07/15/screenshot_elon_musk_twitter_hacked.jpg
[3] https://www.blockchain.com/btc/address/bc1qxy2kgdygjrsqtzq2n0yrf2493p83kkfjhx0wlh?page=1
[4] https://t.co/toug6PYnYr
[5] https://twitter.com/sniko_/status/1283485972286656517?ref_src=twsrc%5Etfw
[6] https://twitter.com/ssharmaTX/status/1283530654588731392
[7] https://twitter.com/UnderTheBreach?ref_src=twsrc%5Etfw
[8] https://t.co/7Df20n3h4N
[9] https://twitter.com/olihough86/status/1283541067955163137?ref_src=twsrc%5Etfw
[10] https://whitepapers.theregister.com/
iron
lol it's a Jita local scam irl
Obviously found a security hole in Twitter
No way all those people / companies used weak passwords and none of them were using 2FA.
Probably the only reason they didn't compromise Trump's account is Twitter probably has some extra layer of control on it due to the market moving potential if someone was able to tweet as him and claim we're declaring war on China or he's declaring nationwide martial law or whatever (especially because one couldn't be sure that either of those isn't something he would do...)