{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:21:39.243Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Twitter's July 2020 account takeover started with phone spear phishing of employees","date":"2020-07-15","date_precision":"day","victim_org":"Twitter, Inc.","sector":"Technology","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Credential Phishing Portal","Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"The callers used ordinary voice social engineering and pre-collected personal details; no synthetic voice was reported.","outcomes":["Cryptocurrency Theft","Data Breach","Credential Theft","Identity Theft","Wire Fraud / Financial Loss"],"loss_usd":118000,"loss_note":"The New York Department of Financial Services investigation report puts the bitcoin obtained through the scam tweets at approximately $118,000.","records_affected":130,"threat_actor":"Graham Ivan Clark and co-conspirators (later criminally charged)","summary":"On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.","how_it_worked":"Callers rang Twitter staff claiming to be from the internal help desk and offering to fix VPN connectivity problems, a plausible complaint during the shift to remote working. They used personal information gathered in advance about each employee to sound credible, then directed the target to a site that mirrored Twitter's real VPN portal. As the employee typed their credentials and MFA code, the attackers entered the same values into the genuine portal, completing the login inside the code's validity window. From there they reached internal account-management tooling and used it to reset the email addresses and disable MFA on high-profile accounts.","lessons":"Phishing-resistant FIDO2/WebAuthn authenticators would have broken the real-time credential relay, and out-of-band callback verification for any unsolicited IT help desk contact would have stopped the pretext at the first call.","confidence":"Confirmed","sources":[{"title":"Twitter Investigation Report","url":"https://www.dfs.ny.gov/system/files/documents/2026/07/Twitter-Investigation-Report.pdf","publisher":"New York State Department of Financial Services"},{"title":"Department of Financial Services Calls for Regulation of Social Media Giants After Twitter Hack Investigation","url":"https://www.dfs.ny.gov/reports_and_publications/press_releases/pr202010141","publisher":"New York State Department of Financial Services"},{"title":"Twitter breach: Staff tricked by 'phone spear phishing'","url":"https://www.welivesecurity.com/2020/07/31/twitter-breach-staff-tricked-phone-spear-phishing/","publisher":"ESET WeLiveSecurity"},{"title":"New York regulator faults Twitter for lax security measures prior to big account breach","url":"https://cyberscoop.com/twitter-hack-social-engineering-new-york-financial-services/","publisher":"CyberScoop"},{"title":"Twitter Investigation Report","url":"https://www.dfs.ny.gov/Twitter_Report","publisher":"New York State Department of Financial Services"},{"title":"Twitter says hackers used a telephone to fool staff and gain access","url":"https://www.nbcnews.com/business/business-news/twitter-says-hackers-used-telephone-fool-staff-gain-access-n1235466","publisher":"NBC News"}],"entry_type":"incident","slug":"2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o","year":2020,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-twitter-s-july-2020-account-takeover-started-with-phone-spear-phishing-o"}]}