What happened
On 23 April 2013 the Associated Press's main Twitter account posted a false report of two explosions at the White House injuring President Obama. The Dow Jones Industrial Average dropped roughly 143 points in minutes before recovering once AP disavowed the tweet. AP said the account takeover was preceded by phishing attempts against its corporate network; the Syrian Electronic Army claimed responsibility, a claim that was not independently corroborated at the time.
How the deception worked
Staff at AP received phishing emails aimed at the corporate network shortly before the hijack. The lure exploited newsroom urgency and normal internal circulation of story links, leading recipients toward a credential capture page. Harvested credentials gave the attackers control of the wire service's verified Twitter account, whose authority with algorithmic traders and human readers alike was the real payload. A single 12-word tweet asserting an attack on the President was enough to move equity markets before any verification could occur.
AI involvement · No AI reported
No AI or synthetic media involvement was reported.
The control that would have caught it· our reading, not a claim from the sources
Two-factor authentication on corporate social accounts, plus separation of newsroom publishing credentials from ordinary staff email, would have prevented a single phished mailbox from becoming a market-moving broadcast channel.
Sources (2)
- AP Twitter Account Hacked; Tweet About Obama Shakes MarketNPR·npr.orgOpen ↗
- Hackers compromise AP Twitter accountCBS News·cbsnews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.