What happened
On 15 July 2020 attackers took control of 130 Twitter accounts, including those of Barack Obama, Elon Musk and Apple, and used 45 of them to post a bitcoin doubling scam. The New York Department of Financial Services investigation found the attackers phoned Twitter employees posing as IT help desk staff, exploited the confusion of pandemic-era remote work, and drove them to a fake VPN login page to capture credentials and one-time codes in real time.
How the deception worked
Callers rang Twitter staff claiming to be from the internal help desk and offering to fix VPN connectivity problems, a plausible complaint during the shift to remote working. They used personal information gathered in advance about each employee to sound credible, then directed the target to a site that mirrored Twitter's real VPN portal. As the employee typed their credentials and MFA code, the attackers entered the same values into the genuine portal, completing the login inside the code's validity window. From there they reached internal account-management tooling and used it to reset the email addresses and disable MFA on high-profile accounts.
AI involvement · No AI reported
The callers used ordinary voice social engineering and pre-collected personal details; no synthetic voice was reported.
The control that would have caught it· our reading, not a claim from the sources
Phishing-resistant FIDO2/WebAuthn authenticators would have broken the real-time credential relay, and out-of-band callback verification for any unsolicited IT help desk contact would have stopped the pretext at the first call.
Sources (6)
- Twitter Investigation ReportNew York State Department of Financial Services·dfs.ny.govOpen ↗
- Department of Financial Services Calls for Regulation of Social Media Giants After Twitter Hack InvestigationNew York State Department of Financial Services·dfs.ny.govOpen ↗
- Twitter breach: Staff tricked by 'phone spear phishing'ESET WeLiveSecurity·welivesecurity.comOpen ↗
- New York regulator faults Twitter for lax security measures prior to big account breachCyberScoop·cyberscoop.comOpen ↗
- Twitter Investigation ReportNew York State Department of Financial Services·dfs.ny.govOpen ↗
- Twitter says hackers used a telephone to fool staff and gain accessNBC News·nbcnews.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.