Is there any information on whether a single employee or a number of employees were involved? I don't think the attackers could have had someone hired at Twitter Support only to carry out this attack, given how they tried to monetize. Also I suspect no more than one employee was involved, and that "social engineering" was done only to compromise their credentials, instead of asking them nicely to allow them access to…
Some of the people involved were interviewed by the New York Times [0] and indicated that the person who was offering access claimed they managed to get into the Twitter Slack account and saw credentials being shared. I don’t know if that is true or not, but all the external reporting doesn’t indicate that a Twitter employee was actively involved. It’s always possible someone was, but given the small amount of money…
Joseph Cox at Vice Motherboard is claiming exactly that from his interview with the hackers:
"We used a rep that literally done all the work for us," one of the sources told Motherboard. The second source added they paid the Twitter insider. Motherboard granted the sources anonymity to speak candidly about a security incident. A Twitter spokesperson told Motherboard that the company is still investigating whether the employee hijacked the accounts themselves or gave hackers access to the tool.
https://www.vice.com/en_us/article/jgxd3d/twitter-insider-ac...