Skip to content
NetarxImpact Database
Vishing (Voice Phishing)No AI reportedConfirmed

Twitter's July 2020 account takeover started with phone spear phishing of employees

Twitter, Inc. · Technology · United States · July 15, 2020

Criminal proceeds
$118,000
What the attackers earned. Not the same as what the victims lost, and often much smaller.
The New York Department of Financial Services investigation report puts the bitcoin obtained through the scam tweets at approximately $118,000.
People or records affected
130
130 as reported

What happened

On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.

How the deception worked

Callers rang Twitter staff claiming to be from the internal help desk and offering to fix VPN connectivity problems, a plausible complaint during the shift to remote working. They used personal information gathered in advance about each employee to sound credible, then directed the target to a site that mirrored Twitter's real VPN portal. As the employee typed their credentials and MFA code, the attackers entered the same values into the genuine portal, completing the login inside the code's validity window. From there they reached internal account-management tooling and used it to reset the email addresses and disable MFA on high-profile accounts.

AI involvement · No AI reported

The callers used ordinary voice social engineering and pre-collected personal details; no synthetic voice was reported.

The control that would have caught it· our reading, not a claim from the sources

Phishing-resistant FIDO2/WebAuthn authenticators would have broken the real-time credential relay, and out-of-band callback verification for any unsolicited IT help desk contact would have stopped the pretext at the first call.

Sources (6)

  1. Twitter Investigation Report
    New York State Department of Financial Services·dfs.ny.govOpen ↗
  2. Department of Financial Services Calls for Regulation of Social Media Giants After Twitter Hack Investigation
    New York State Department of Financial Services·dfs.ny.govOpen ↗
  3. Twitter breach: Staff tricked by 'phone spear phishing'
    ESET WeLiveSecurity·welivesecurity.comOpen ↗
  4. New York regulator faults Twitter for lax security measures prior to big account breach
    CyberScoop·cyberscoop.comOpen ↗
  5. Twitter Investigation Report
    New York State Department of Financial Services·dfs.ny.govOpen ↗
  6. Twitter says hackers used a telephone to fool staff and gain access
    NBC News·nbcnews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.