>We detected what we believe to be a coordinated social engineering attack by people who successfully targeted some of our employees with access to internal systems and tools. I wonder the size of the population of employees that have access to these internal tools. How many people can independently fire off a Tweet from Jeff Bezos or Elon Musk and erase billions from the stock market? How many people can seize the a…
Twitter internal panel linked to account hijackings
71–80 of 477 posts
Re: Twitter internal panel linked to account hijackings
#72So it was a social engineering attack against employees with high level access. This sentence still doesn’t make sense to me: “ Once we became aware of the incident, we immediately locked down the affected accounts and removed Tweets posted by the attackers.” The accounts were posting for hours after it seemed Twitter became aware what was going on.
Oddly, it was just Elon Musk's account that had multiple tweets over a long period of time. The other accounts did just one.
Re: Twitter internal panel linked to account hijackings
#73Earlier quoted context omitted.
The next time we swing the other way: "Maybe government should embrace popular communication media instead of spending billions on custom IT infrastructure to post a message on a custom page that everyone screenshots and copies to their timeline anyway." (Also if they don't create an "official account", someone else will do it for them)
> (Also if they don't create an "official account", someone else will do it for them) What do you mean? How would anyone not affiliated with a given government agency convince human verifiers at Twitter that they're official?
Re: Twitter internal panel linked to account hijackings
#74Earlier quoted context omitted.
The FBI is very commonly involved in cyber crimes and the other departments have a role to play as well. Calling the FBI during a major security incident is not unusual at all, I’ve done it a number of times.
In the early days of the internet the FBI was kind enough to call my employer and inform us that we had left open an anonymous FTP server, and it was serving up Disney movies. Those were good times.
Re: Twitter internal panel linked to account hijackings
#75had that feeling... wonder how much more vulnerable working from home is making us to such things.
also scary that targeted employees with such level of access fell for it. must have been really sophisticated.
Re: Twitter internal panel linked to account hijackings
#76Re: Twitter internal panel linked to account hijackings
#77Earlier quoted context omitted.
It's painful (although I suppose all airgap solutions are) but remote access protocols like RDP or SSH tunneling to a jump host which has access to the administration portal is one common(?) solution.
That's only safer from attacks that bypass the public admin portal authentication. Any social engineering attack that steals credentials directly won't be impacted.
Re: Twitter internal panel linked to account hijackings
#78Re: Twitter internal panel linked to account hijackings
#79This must be some new meaning of the word 'immediately' that I wasn't previously aware of. It took them quite a while to get these accounts locked.
Re: Twitter internal panel linked to account hijackings
#80To me, it seems a little weird they can tweet on behalf of a user. Especially a user with 2FA on their account. Curious as to what types of changes might come out of this going forward