Twitter says hack of key staff led to celebrity, politician, biz account hijack mega-spree
- Reference: 1594879751
- News link: https://www.theregister.co.uk/2020/07/16/twitter_account_hijack_latest/
- Source link:
Judging from leaked screenshots of Twitter's internal systems circulating online and seen by El Reg , it appears one or more miscreants were able to gain direct or indirect access to an administration panel used by Twitter employees to configure accounts, by tricking or coercing the social network's staff.
From there, the crooks were, at least in some cases, seemingly able to change the registered email addresses of celebrities, corporations, crypto-coin exchanges, publications, and politicians' accounts – think Apple, Uber, Bill Gates, Elon Musk, Joe Biden, and so on – to an inbox they controlled, requested password resets, and logged in to tweet Bitcoin scams to millions of followers. The miscreants may have been able to disable multi-factor authentication from the inside, too.
According to Vice, hackers boasted they had a paid mole [2]inside Twitter who did all the dirty work for them. The social network's spokespeople said it was still investigating exactly how it all went down.
Twitter's support account spelled out its side of the story so far this evening:
We know they used this access to take control of many highly-visible (including verified) accounts and Tweet on their behalf. We’re looking into what other malicious activity they may have conducted or information they may have accessed and will share more here as we have it. — Twitter Support (@TwitterSupport) [3]July 16, 2020
We also limited functionality for a much larger group of accounts, like all verified accounts (even those with no evidence of being compromised), while we continue to fully investigate this. — Twitter Support (@TwitterSupport) [4]July 16, 2020
We have locked accounts that were compromised and will restore access to the original account owner only when we are certain we can do so securely. — Twitter Support (@TwitterSupport) [5]July 16, 2020
Internally, we’ve taken significant steps to limit access to internal systems and tools while our investigation is ongoing. More updates to come as our investigation continues. — Twitter Support (@TwitterSupport) [6]July 16, 2020
The Twitter accounts of both The Register and your humble hack’s brother [7]Anthony Sharwood are verified by the avian network. Both were unable to tweet once Twitter discovered the incident and both received no direct communication from Twitter about the status of our accounts nor any details of whether the incident posed a risk to personal data.
But not all functionality was removed. Sharwood the younger said he was able to send direct messages during the incident. "I sent a guy a DM to apologise that I couldn't respond to a tweet," he said.
Indeed, The Register 's own [8]verified account couldn't tweet, but could send direct messages as well as retweet and like other tweets.
And that’s all we know at the time of writing. The Register is willing to speculate about a few factors, namely:
Twitter appears not to have been aware of the account takeover until the scammy tweets appeared.
Social engineering of staff with known access to internal tools hints at spear-phishing. If the attackers knew who can access Twitter’s innards, that’s quite scary. If it was a broader attack, it suggests Twitter’s phishing defenses may need some improvements. If it was an inside job, Twitter has a huge trust and compartmentalization problem on its hands.
If the attackers were outside Twitter, it suggests that the company’s internal tools may be publicly accessible, and perhaps without multi-factor authentication.
The hijackers used their ill-gotten access to post tweets in which celebrities promised to double users’ Bitcoin balances as an act of philanthropy – and more than $100,000 in cryptocurrency was transferred by hopefuls with no sign of any payback. That's probably a better result than putting incendiary remarks in the mouth of a world leader with millions of followers, though. Or more-than-usually incendiary in the case of a certain US President. ®
Get our [9]Tech Resources
[1] https://www.theregister.com/2020/07/15/mass_twitter_account_hacking_bitcoin/
[2] https://www.vice.com/en_us/article/jgxd3d/twitter-insider-access-panel-account-hacks-biden-uber-bezos
[3] https://twitter.com/TwitterSupport/status/1283591848729219073?ref_src=twsrc%5Etfw
[4] https://twitter.com/TwitterSupport/status/1283591850604015618?ref_src=twsrc%5Etfw
[5] https://twitter.com/TwitterSupport/status/1283591852982231040?ref_src=twsrc%5Etfw
[6] https://twitter.com/TwitterSupport/status/1283591853955219458?ref_src=twsrc%5Etfw
[7] https://twitter.com/antsharwood
[8] https://twitter.com/TheRegister
[9] https://whitepapers.theregister.com/
Re: Twitter hack
I can't believe you came out of hiding after best part of a year – having posted only two things in the last nearly four years – just to post that. I guess maybe you're usually AC. Also, you weren't the first. Just that someone else got cold feet and deleted it. But maybe that was you too. In summary: what?
Ha bloody ha
I was thrown off Twitter because I refused to give them my mobile number.
Sod 'em.
Re: Ha bloody ha
I just gave them a number of an old telemetry SIM I had access to. Other than the initial verification code they don’t seem to use it. If they did, they’d be getting no answer from a data station in the middle of Ireland.
Celebs and Politicians Silenced
... and nothing of any value was lost.
Re: Celebs and Politicians Silenced
... and nothing of any value was lost.
Unless you were one of the simps transferring your $1000 BTC hoping a Billionaire will double it for you for shits n giggles.
I suppose in theory the BTC isn't actually lost, to quote Gekko "Money itself isn't lost or made, it's simply transferred from one perception to another". That's $100,000 in BTC definitely transferred in someones perception.
Re: Celebs and Politicians Silenced
That's $100,000 in BTC definitely transferred in someones perception
Given that they were gullible enough to fall for this scam they were only ever going to be a temporary custodian of those BTC
Just imagine ..
Both Xi Jinping and Trump's twitter accounts being hacked and being used to start a war.
On second thought, Trump doesn't need to have his account hacked to do that.
Re: Just imagine ..
How many wars has Trump started during his time in office? How does that compare to every other President in the last.. 200 years?
Re: Just imagine ..
Hey, he isn't gone yet. Give the man a chance!
Re: Just imagine ..
I don't think he has the attention span to start one. Even if he did start one, when it starts going wrong, he'll deny it ever happened and it was someone else's fault, even though it was just him joking.
I wonder if hackers too the time to harvest the compromised accounts DMs... interesting times ahead.
Working from Home
Assume most Twitter Admins working from home, so remote access a given. Plus probably running some BOYD build on an average joe wifi-router + ISP build which would be an easier target? Can't see Twitter being the sort of company that goes in for locked down corporate builds for it's employees?
Re: Working from Home
Surely they'd have a VPN with 2FA before letting anybody near a vital internal system?
Re: Working from Home
Agreed, but a) VPN's have holes (several high profile solutions have had exploits exposed recently). and b) if you hack the machine that has the VPN connection... Especially if that VPN is split tunneled...
The ideal of course is two workstations - one locked down tight for Admin tasks - but you send the people home, do you send them home with two laptops, again one locked down in such as way as it can only remote to the Admin box in the office? But then that's on the same wifi as your family kit, sky+, Alexa, ... So that should be on another network (4G maybe)... All nice, but this was short notice, so what setup did they have...
Also, it looks like they had access to a user admin panel (but perhaps not much else) so would all these security layers be in place, for a user support body...
I see, there was "a coordinated social engineering attack", or in layman's terms: "some of our staff fell for phishing"
or should that be "some of our soon to be ex-staff fell for phishing"
It does make you wonder how sophisticated it was, how they are going to prevent this in the future, and of course how many heads will roll.
Someone recently asked me whether I was on Twitter. The answer was "no", and that doesn't look like it is going to change any time soon, not just because of privacy concerns, but I also have the El Reg Commentard section to vent my more unhinged opinions
I did try Twitter once for six hours before deleting the account (only you can't really delete it, just as well it was in the name of a medieval theologian.)
Believe me, by Twitter standards I don't think you could even achieve an unhinged opinion.
I can't imagine any tweet they could have put from the POTUS's account that is any more unbelievable than the ones he normally puts out...…..
The red panic flag would possibly only be raised if the tweet was intelligent, correctly phrased and cogent.
Greed
So once again greed triumphs over common sense. I these people who paid Bitcoins if they went on the sucker list before they will be now. In recent news most of these celebrates (also known as rich people) have expressed interest in giving back something which makes this more plausible which goes back to greed.
I sympathies those of you who are having problems with twitter. In many ways they seem to have done it to them self's despite leaving the reservations (Facebook/Google) but they are a cooperate organization their to make money.
Re: Greed
JimPoak, is English not your first language are or you just enjoying a pint of whisky?
Agree with your point regarding the comparison with other social media companies - they are all there to make money and not necessarily there to make the world a better place.
Re: Greed
I do hope you're not a highly-paid IT pro...otherwise we're all fsck'd
Re: Greed
He's a Twitter admin.
You could tell Trump's account had been hacked when it started making sense.
I notice Trump's name or indeed any allies of Trump are conspicuous by their absence.
"I notice Trump's name or indeed any allies of Trump are conspicuous by their absence."
It were Trumpy wot done it!
I don't think anyone would trust our Con-Man in Chief to double their donation. A general stereotype of Republicans/Conservatives is that they do not like handouts. That's could be why they were not targeted.
They do love handouts as long as they're trousering them
I've read elsewhere that Trump's account may be more protected, because if it got hijacked, it could have grave consequences…
Sounds like a well executed plan, and scary if the numbers are accurate as to how many people fell for it.
What got me is the request is so obviously a scam "send me money and I'll send you twice back", most people should have thought that was too good to be true. I would have thought they would have had a better conversion rate if they had said "Donate 1 bitcoin to this address and I'll match your donation to help COVID", that I think would have got past more peoples mental barriers.
Who could possibly have done this?
So Twitter have been subject to a deeply embarrassing attack which will do long-term damage to their business. The same Twitter recently censored tweets from their most high-profile user, claiming that they contained provable falsehoods. Said high-profile user, in his day job as President of the United States, authorized a certain intelligence agency to carry out cyber attacks with little oversight (see story on this very site) some time ago.
I shall have to add some more tinfoil to my hat...
Re: Who could possibly have done this?
Oh I don't know in today's world......
It's ' all the not so famous user accounts that would be more interesting with an election coming up...
I have a bigger hat
I'm not on twitter
So, here I have a wonnerful offer for all you ElReg listeners.
Send me yr money and Ill dooble it. YES! TRUE!!
Send mnoey to my untrasable offshore accountg and Ill send yoo back dooble.
Dont daly. This gullibility won't last 4ever.*
*Unfortunately this bit is not true.
Re: I'm not on twitter
No probs here is all me savins
£0.00
Can u duble it for me?
Re: I'm not on twitter
No probs here is all me savins £0.00 Can u duble it for me?
Ignore their scam, my scam can increase your savings 100-fold!
There will be a small administration fee payable up front, which will be returned with your increased savings.
If there is a mole inside the company with system privs..
.... there's nothing the company can do to mitigate an attack until its happened. Hopefully they'll find this person and throw the book at them. While it might seem amusing to do it from various CEO accounts imagine if it had been from a hospital/government/police/large media provider account saying there'd been a new mass pandemic outbreak/terrorist attack etc.
What's really going on?
Something ain't right here. This lame bitcoin scam stinks of a diversion.
Re: What's really going on?
Yep, agreed. Sending out a Bitcoin scam request via a few rich peoples accounts sure seems to have grabbed the attention of everyone but what else might also have happened at the same time. I guess you only have a limited time before these sort of account takeovers get discovered so sending out these lame tweets from celebs accounts does seem like a diversion. I guess we'll never know.
I'm willing to speculate about a few factors, namely
if some unknown "miscreants" have been able to do it, why not any other, with - perhaps - similar or better skills and tools and with entirely different motives. Given how politicians have employed twitter to police the world, I can see a Mr President announcing, out of the blue, that yes, we are launching an all out nuke war against China (or not). I just hope that the Russians in charge of such accounts are not too drunk to do it as a prank.
*Reaches for the tinfoil.*
This would be an amusing way to tell the West that 'we can access your systems no matter whose hardware they're running on'.
Sophisticated Spear Phishing?
Maybe, or it could be exactly as the crooks said and they had paid one.
A few grand is tempting for a low paid offshorer.
A far better money making scheme...
...would have Elon Musk account posting about Tesla plans, and betting on the stock market reaction. Billions to be made not a few grand.
Re: A far better money making scheme...
Such a stock market move would stick out like a sore thumb.
Lovely example
It’s a pity I don’t teach infosec classes any more, this would make a perfect example to show the senior techies how a breach happens.
However from Twitters response I suspect someone found a weakness in their password reset system and they are putting up a smokescreen whilst they fix it. Either that or their separation of duties system is horrendous.
English is my first language but my sentence structure is odd when I remove the swearing.
Twitter hack
I can't believe I'm the first person to comment on this topic.