British Army Twitter and YouTube feeds hijacked by crypto-promos
(2022/07/04)
- Reference: 1656896827
- News link: https://www.theregister.co.uk/2022/07/04/british_army_social_media_hijcaked/
- Source link:
The British Army has apologizsed after its Twitter and YouTube accounts were compromised by entities that used them to promote NFTs.
As recorded by [1]The Wayback Machine , the @BritishArmy Twitter feed hosted content promoting non-fungible tokens described thusly: "The Anomalies is a collection of special Possessed 1/1s".
[2]
@British Army Twitter account hijack from Wayback Machine. Click to enlarge
According to Web3-watcher [3]Web3 is going just great – the British Army YouTube account was taken over at the same time as the Twitter takedown.
The YouTube takeover replaced the legit account with fake logos resembling those used by an investment management firm and filled it with more crypto boosterism – namely a video that cut an old chat between Elon Musk and Twitter founder Jack Dorsey into a new and misleading narrative.
The @BritishArmy account apologized for the outage.
Apologies for the temporary interruption to our feed. We will conduct a full investigation and learn from this incident. Thanks for following us and normal service will now resume. — British Army 🇬🇧 (@BritishArmy) [4]July 3, 2022
The Ministry of Defence later swung into action, as follows:
We are aware of a breach of the Army's Twitter and YouTube accounts and an investigation is underway.
The Army takes information security extremely seriously and is resolving the issue. Until their investigation is complete it would be inappropriate to comment further. — Ministry of Defence Press Office (@DefenceHQPress) [5]July 3, 2022
The breach of the Army's Twitter and YouTube accounts that occurred earlier today has been resolved and an investigation is underway.
The Army takes information security extremely seriously and until their investigation is complete it would be inappropriate to comment further. — Ministry of Defence Press Office (@DefenceHQPress) [6]July 3, 2022
Social media services increasingly use two-factor authentication before allowing password changes. The Register mentions this only as it suggests whoever was behind the hijack was able to access a Defence email address to get into the social media accounts. Either that, or the British Army needs to use much stronger passwords.
[7]UK Ministry of Defence takes recruitment system offline, confirms data leak
[8]Five Eyes nations fear wave of Russian attacks against critical infrastructure
[9]This is AUKUS for China – US, UK, Australia reveal defence tech-sharing pact
The takeovers have of course sparked reams of disdainful comment.
Ironically, some of those appear on [10]this video that features General Sir Patrick Sanders, who in June assumed the post of chief of general staff – the head of the British Army – delivering a [11]speech in which he stated "Defence is only as strong as its weakest domain. And technology does not eliminate the relevance of combat mass."
[12]
Sanders added: "I bow to no one in my advocacy for the need for game changing digital transformation. To put it bluntly, you can't cyber your way across a river. No single platform, capability, or tactic will unlock the problem."
[13]
But better security for social media accounts looks like a good start. ®
Get our [14]Tech Resources
[1] https://web.archive.org/web/20220703165818/https://twitter.com/britisharmy
[2] https://regmedia.co.uk/2022/07/04/screenshot_british_army_twitter_hijack.jpg
[3] https://web3isgoinggreat.com/?id=twitter-and-youtube-accounts-for-the-british-army-simultaneously-hacked
[4] https://twitter.com/BritishArmy/status/1543688455145807873?ref_src=twsrc%5Etfw
[5] https://twitter.com/DefenceHQPress/status/1543658566200041472?ref_src=twsrc%5Etfw
[6] https://twitter.com/DefenceHQPress/status/1543712039734059008?ref_src=twsrc%5Etfw
[7] https://www.theregister.com/2022/03/24/ministry_of_defence/
[8] https://www.theregister.com/2022/04/21/five_eyes_russia/
[9] https://www.theregister.com/2021/09/16/aukus_defence_pact/
[10] https://www.youtube.com/watch?v=TwZWngofFyg
[11] https://www.gov.uk/government/speeches/chief-the-general-staff-speech-at-rusi-land-warfare-conference
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsJl4eBuR-5Z45ZeecB5bQAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsJl4eBuR-5Z45ZeecB5bQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
As recorded by [1]The Wayback Machine , the @BritishArmy Twitter feed hosted content promoting non-fungible tokens described thusly: "The Anomalies is a collection of special Possessed 1/1s".
[2]
@British Army Twitter account hijack from Wayback Machine. Click to enlarge
According to Web3-watcher [3]Web3 is going just great – the British Army YouTube account was taken over at the same time as the Twitter takedown.
The YouTube takeover replaced the legit account with fake logos resembling those used by an investment management firm and filled it with more crypto boosterism – namely a video that cut an old chat between Elon Musk and Twitter founder Jack Dorsey into a new and misleading narrative.
The @BritishArmy account apologized for the outage.
Apologies for the temporary interruption to our feed. We will conduct a full investigation and learn from this incident. Thanks for following us and normal service will now resume. — British Army 🇬🇧 (@BritishArmy) [4]July 3, 2022
The Ministry of Defence later swung into action, as follows:
We are aware of a breach of the Army's Twitter and YouTube accounts and an investigation is underway.
The Army takes information security extremely seriously and is resolving the issue. Until their investigation is complete it would be inappropriate to comment further. — Ministry of Defence Press Office (@DefenceHQPress) [5]July 3, 2022
The breach of the Army's Twitter and YouTube accounts that occurred earlier today has been resolved and an investigation is underway.
The Army takes information security extremely seriously and until their investigation is complete it would be inappropriate to comment further. — Ministry of Defence Press Office (@DefenceHQPress) [6]July 3, 2022
Social media services increasingly use two-factor authentication before allowing password changes. The Register mentions this only as it suggests whoever was behind the hijack was able to access a Defence email address to get into the social media accounts. Either that, or the British Army needs to use much stronger passwords.
[7]UK Ministry of Defence takes recruitment system offline, confirms data leak
[8]Five Eyes nations fear wave of Russian attacks against critical infrastructure
[9]This is AUKUS for China – US, UK, Australia reveal defence tech-sharing pact
The takeovers have of course sparked reams of disdainful comment.
Ironically, some of those appear on [10]this video that features General Sir Patrick Sanders, who in June assumed the post of chief of general staff – the head of the British Army – delivering a [11]speech in which he stated "Defence is only as strong as its weakest domain. And technology does not eliminate the relevance of combat mass."
[12]
Sanders added: "I bow to no one in my advocacy for the need for game changing digital transformation. To put it bluntly, you can't cyber your way across a river. No single platform, capability, or tactic will unlock the problem."
[13]
But better security for social media accounts looks like a good start. ®
Get our [14]Tech Resources
[1] https://web.archive.org/web/20220703165818/https://twitter.com/britisharmy
[2] https://regmedia.co.uk/2022/07/04/screenshot_british_army_twitter_hijack.jpg
[3] https://web3isgoinggreat.com/?id=twitter-and-youtube-accounts-for-the-british-army-simultaneously-hacked
[4] https://twitter.com/BritishArmy/status/1543688455145807873?ref_src=twsrc%5Etfw
[5] https://twitter.com/DefenceHQPress/status/1543658566200041472?ref_src=twsrc%5Etfw
[6] https://twitter.com/DefenceHQPress/status/1543712039734059008?ref_src=twsrc%5Etfw
[7] https://www.theregister.com/2022/03/24/ministry_of_defence/
[8] https://www.theregister.com/2022/04/21/five_eyes_russia/
[9] https://www.theregister.com/2021/09/16/aukus_defence_pact/
[10] https://www.youtube.com/watch?v=TwZWngofFyg
[11] https://www.gov.uk/government/speeches/chief-the-general-staff-speech-at-rusi-land-warfare-conference
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsJl4eBuR-5Z45ZeecB5bQAAAM0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsJl4eBuR-5Z45ZeecB5bQAAAM0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://whitepapers.theregister.com/
The standard
HildyJ
We apologize . . .
We are aware . . .
We are investigating . . .
We will have no further comment during the investigation.
And, as is standard, we will never learn the results.
Re: The standard
veti
Are they wrong to apologise? To be aware? To investigate? To refuse to speculate until the investigation is done?
Just trying to work out which part of the response you are finding offensive.
I have a secure computer.
A Commodore 64 that's gathering dust in a box. It's not plugged in to power, has no internet connection, doesn't run any modern OS, can't run most modern programs, is impervious to all modern exploits, and any successfull hijack would vanish with a simple reboot.
Granted, it also can't do much in the way of computational grunt work, but that's not what you said. You said there was no single computer security. That view is false. There is such a system, it's just that it's also not up to the task for which you need a massive supercomputer.
But I'll happily challenge you to a game of Blue Meanies from outer space! =-)