Twitter Hackers Used ‘Phone Spear Phishing Attack’ to Pull Off Bitcoin Scam

Twitter has provided another update on the security breach two weeks ago that saw the Twitter accounts of Apple and other high-profile figures and companies hacked by bitcoin scammers.

According to the company, a small number of employees were targeted in a “phone spear phishing attack,” suggesting that hackers called some of its staff and duped them into thinking they were speaking with fellow Twitter employees, leading them to reveal the credentials the hackers needed to access internal account support tools.

The attack on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. This attack relied on a significant and concerted attempt to mislead certain employees and exploit human vulnerabilities to gain access to our internal systems.

Twitter previously called the hack a “coordinated social engineering attack” that had targeted some employees with access to internal systems. The internal tools were used to target 130 accounts, and for 45 of those accounts, hackers initiated a password reset and had full access to the account to send tweets.

For the 130 accounts that were breached, which included the accounts of Tesla CEO Elon Musk, former U.S. President Barack Obama, former Microsoft CEO Bill Gates, Amazon CEO Jeff Bezos, presidential candidate Joe Biden, and others, hackers were able to see personal information like email addresses and phone numbers, and for some accounts taken over, additional information was available, including Direct Messages.

The attack on July 15, 2020, targeted a small number of employees through a phone spear phishing attack. This attack relied on a significant and concerted attempt to mislead certain employees and exploit human vulnerabilities to gain access to our internal systems.

— Twitter Support (@TwitterSupport) July 31, 2020

Following the attack, Twitter temporarily locked accounts for some users and limited features. Most of those features are now back, but some, such as the “Your Twitter Data” download feature, are still not working as usual.

Twitter says it is taking a “hard look” at how it can improve the sophistication of its internal tools and systems, and in the meantime it has significantly limited access to them until it can safely resume normal operations.Tag: Twitter
This article, “Twitter Hackers Used ‘Phone Spear Phishing Attack’ to Pull Off Bitcoin Scam” first appeared on MacRumors.com

Discuss this article in our forums

MacRumors-All?d=6W8y8wAjSf4 MacRumors-All?d=qj6IDK7rITs

Latest posts

Ikea just took over your smart home

Hi, friends! Welcome to Installer No. 105, your guide to the best and Verge-iest stuff in the world. (If you're new here, welcome, hope...

The algorithm failed music

This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on how to break free of...

65daysofstatic’s new No Man’s Sky album searches for humanity in an AI-filled world

It's not often that a band returns to soundtrack the same game nine years after its release - then again, most games aren't No...

Deck out your tree with ornaments of retro consoles, movie moments, and more

Do the ornaments you adorn your Christmas tree with reflect you or your family’s interests? If not, maybe you should rectify that. We recently...

The tale of the Fire Phone, Amazon’s very strange smartphone

When Jeff Bezos decided Amazon needed to get in the smartphone game, he went all in. And the resulting device, the Fire Phone, wound...

How to stretch the clock on your lock screen in iOS 26

Apple has continued its trend of giving users more creative freedom over how their iPhones look and feel, and one of the most striking...

Get half off our favorite budgeting app for Black Friday

Budgeting can be a stressful, challenging and uncomfortable experience. While it's completely possible to do it on your own, we've become fans of a...

Gen AI is becoming a major security worry for all firms – here’s how your business can stay safe

AI agents pose insider risks due to unsupervised access and lack of visibility controls, report claims66% of major data loss events stem from careless...

PNY’s microSD Express Card is one of the fastest Nintendo Switch 2 cards I’ve tested, and it costs the same as the competition –...

PNY microSD Express Card: reviewThe PNY microSD Express Card is one of the fastest Nintendo Switch 2 cards that I’ve tested.In my benchmarks, the...

Logitech MX Master 4 review: the master returns

Logitech MX Master 4: Two-minute reviewValueThis is a pricey mouse, but its value is well earned thanks to its plethora of top-quality features. You...