Hackers manipulated employees to access accounts: Twitter

‘They accessed tools only available to our internal support teams to target 130 accounts’

July 18, 2020 09:19 pm | Updated 09:19 pm IST - Washington

(FILES) In this file photo illustration, a Twitter logo is displayed on a mobile phone on May 27, 2020, in Arlington, Virginia. - Twitter says hackers "manipulated" some of its employees to access accounts in a high-profile attack on the social media company, including those of Democratic presidential challenger Joe Biden and tech entrepreneur Elon Musk. Posts trying to dupe people into sending the hackers Bitcoin were tweeted by the official accounts of Apple, Uber, Bill Gates and many others on Wednesday, forcing Twitter to lock large numbers of accounts in damage control. (Photo by Olivier DOULIERY / AFP)

(FILES) In this file photo illustration, a Twitter logo is displayed on a mobile phone on May 27, 2020, in Arlington, Virginia. - Twitter says hackers "manipulated" some of its employees to access accounts in a high-profile attack on the social media company, including those of Democratic presidential challenger Joe Biden and tech entrepreneur Elon Musk. Posts trying to dupe people into sending the hackers Bitcoin were tweeted by the official accounts of Apple, Uber, Bill Gates and many others on Wednesday, forcing Twitter to lock large numbers of accounts in damage control. (Photo by Olivier DOULIERY / AFP)

Twitter says hackers “manipulated” some of its employees to access accounts in a high-profile attack on the social media company, including those of Democratic presidential challenger Joe Biden and tech entrepreneur Elon Musk.

Posts trying to dupe people into sending the hackers Bitcoin were tweeted by the official accounts of Apple, Uber, Bill Gates and many others on Wednesday, forcing Twitter to lock large numbers of accounts in damage control.

Virtual currency

More than $1,00,000 worth of the virtual currency was sent to email addresses mentioned in the tweets, according to Blockchain.com, which monitors crypto transactions. “We know that they accessed tools only available to our internal support teams to target 130 Twitter accounts,” said a statement posted on Saturday on Twitter’s blog.

For 45 of those accounts, the hackers were able to reset passwords, login and send tweets, it added, while the personal data of up to eight unverified users was downloaded. Twitter locked down affected accounts and removed the fraudulent tweets. It also shut off accounts not affected by the hack as a precaution. Most of those have now been restored, Twitter said on Saturday.

The attack was carried out by a group of young friends with no links to state or organised crime, The New York Times reported on Friday.

The paper said it interviewed four people who participated in the hacking, who shared logs and screenshots backing up their accounts of what happened.

The young hackers said a mysterious user who went by the name “Kirk” initiated the scheme with a message and was the one with access to Twitter accounts. They added they were only involved in taking control of lesser-known but desirable Twitter accounts, such as an “@” sign and single letters or numbers that could easily be sold, according to the report.

The hackers maintained they stopped serving as middlemen for “Kirk” when high-profile users became targets.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.